fix: close task5 state and capability blockers

This commit is contained in:
2026-08-11 19:52:10 +02:00
parent e35e62a5c6
commit 11ca7d111d
9 changed files with 200 additions and 185 deletions
+15 -2
View File
@@ -60,8 +60,21 @@ def annotations_path(cfg: Config) -> Path:
def refresh_catalog(cfg, *, dwh=None, output_path: Path | None = None):
_require_writer_capability()
"""Run the existing catalog algorithm and persist its canonical output."""
"""Run the catalog algorithm only under the exact backend-bound root capability."""
import os
import stat
cap = __import__("tht.workspace_writer_lock", fromlist=["require_workspace_writer_capability"]).require_workspace_writer_capability()
cfg_workspace = getattr(cfg, "_workspace_id", None)
cfg_revision = getattr(cfg, "_workspace_revision", None)
runtime = getattr(cfg, "runtime_identity", None)
if cfg_workspace != cap.workspace_id or cfg_revision != cap.revision or runtime is None or runtime.workspace_id != cap.workspace_id or runtime.workspace_revision != cap.revision:
raise RuntimeError("preprocessing_conflict")
try:
st = os.stat(cfg.paths.sessions, follow_symlinks=False)
except OSError as exc:
raise RuntimeError("preprocessing_conflict") from exc
if not stat.S_ISDIR(st.st_mode) or (st.st_dev, st.st_ino) != (cap.device, cap.inode) or st.st_uid != os.getuid() or (st.st_mode & 0o777) != 0o700:
raise RuntimeError("preprocessing_conflict")
target = dwh if dwh is not None else build_dwh(cfg)
physical = target.introspect()
_add_examples(target, physical, cfg.examples)