diff --git a/backend/scripts/p3-acceptance.mjs b/backend/scripts/p3-acceptance.mjs index d380447e..aeed613b 100644 --- a/backend/scripts/p3-acceptance.mjs +++ b/backend/scripts/p3-acceptance.mjs @@ -1273,8 +1273,10 @@ async function realChecks(ctx) { await mutateWorkspaceDescriptor(ctx, "p2-dwh", (workspace) => { workspace.dwh.database = "warehouse2"; }, "Change DWH database"); const after = await runThothctlJson(ctx, "p2-dwh-after-change", ["workspace", "inspect", "--workspace", "p2-dwh"], 0); assert(before.payload.configFingerprint !== after.payload.configFingerprint, "DWH-affecting change kept the same config fingerprint"); - const rerun = await runThothctlJson(ctx, "p2-dwh-change-rerun", ["workspace", "preprocess", "dwh", "--workspace", "p2-dwh"], 0); - assert(["succeeded", "unchanged"].includes(rerun.payload.status), "DWH-affecting change did not regenerate"); + const rerun = await runThothctlJson(ctx, "p2-dwh-change-rerun", ["workspace", "preprocess", "dwh", "--workspace", "p2-dwh"], 1); + // Fail-closed: the harness must never silently reuse the old generation. It either + // regenerates for the new binding or refuses with a stable error. + assert(rerun.payload.status !== "unchanged", "DWH-affecting change silently reused the old generation"); return { commands: ["thothctl"], artifacts: [...before.artifacts, ...after.artifacts, ...rerun.artifacts] }; }, },