fix: harden runtime config helper protocol and lifecycle

This commit is contained in:
2026-08-11 13:03:37 +02:00
parent ec92f7f994
commit 11cc8628cf
4 changed files with 290 additions and 34 deletions
+11 -1
View File
@@ -492,6 +492,10 @@ def publish(inp: dict) -> dict:
# failed after the no-replace publication on an earlier invocation.
publication_fsync(mandir, "manifest-parent")
return {
"protocol_version": 1,
"kind": "publication",
"workspace_id": wid,
"workspace_revision": rev,
"path": f"{canonical}/sessions/{wid}/preprocessing/runtime-config/{name}",
"manifestPath": f"{canonical}/sessions/{wid}/preprocessing/runtime-config-manifests/{mname}",
"manifest": mb.decode(),
@@ -630,6 +634,8 @@ def verified_snapshot(inp: dict) -> dict:
if blob != record.get("blob"):
fail("workspace Git descriptor identity mismatch")
return {
"protocol_version": 1,
"kind": "verified_snapshot",
"workspace_id": wid,
"workspace_revision": rev,
"source": source.decode(),
@@ -663,7 +669,10 @@ def binding(inp: dict) -> dict:
stream.write(raw)
path = Path(stream.name)
try:
return config_dwh_binding(load_config(path))
result = config_dwh_binding(load_config(path))
if not isinstance(result, dict) or set(result) != {"workspace_id", "config_fingerprint", "input_fingerprint"}:
fail("runtime config binding returned malformed output")
return result
finally:
try:
path.unlink()
@@ -690,6 +699,7 @@ def main() -> None:
result = verified_snapshot(inp)
else:
result = binding(inp)
result = {"protocol_version": 1, "kind": "binding", **result}
print(json.dumps(result))
except Exception as e: # noqa: BLE001
print(json.dumps({"error": str(e)}))