fix(jobs): validate resume checkpoints before allocation
This commit is contained in:
@@ -85,3 +85,23 @@ Task 4 scoped Ruff: All checks passed
|
||||
```
|
||||
|
||||
Repository-wide Ruff continues to report the same 34 unrelated pre-existing legacy-test findings.
|
||||
|
||||
## Final resume-integrity fix
|
||||
|
||||
Resume is now read-only until the source checkpoint proves trustworthy. The runner loads the source
|
||||
before allocating a new run ID or directory, validates the exact stage state/timestamp/error ledger,
|
||||
rejects duplicate stage identifiers, and recomputes compatibility from every persisted compatibility
|
||||
field plus the exact ordered persisted stage IDs. It first requires the stored fingerprint to match
|
||||
that recomputation, then compares the trusted recomputation with the requested job fingerprint.
|
||||
|
||||
Valid-JSON tampering tests cover removed, inserted/duplicated, reordered, and substituted stages;
|
||||
input-field and stored-fingerprint changes; and invalid stage-state shapes. Every rejection occurs
|
||||
before stage execution and asserts that the runs directory contains no orphan allocation.
|
||||
|
||||
Final verification:
|
||||
|
||||
```text
|
||||
focused job/lock suite: 34 passed in 0.56s
|
||||
full harness suite: 620 passed, 5 deselected, 17 warnings in 27.42s
|
||||
Task 4 scoped Ruff: All checks passed
|
||||
```
|
||||
|
||||
Reference in New Issue
Block a user