fix(preprocess): restrict DWH root claims to writers
This commit is contained in:
@@ -6,6 +6,7 @@ from typer.testing import CliRunner
|
||||
|
||||
from tht.cli import app
|
||||
from tht.jobs.dwh_pipeline import DwhPreprocessPipeline
|
||||
from tht.jobs.dwh_pipeline import active_generation_dir, config_dwh_binding
|
||||
from tht.jobs.dwh_pipeline import resolve_dwh_snapshot
|
||||
from tht.jobs.dwh_pipeline import lease_dwh_snapshot
|
||||
from tht.jobs.locking import _lock_name
|
||||
@@ -30,6 +31,94 @@ def test_dwh_and_evidence_jobs_have_distinct_lock_names():
|
||||
assert _lock_name("demo", "dwh") != _lock_name("demo", "evidence")
|
||||
|
||||
|
||||
def test_unowned_reads_fail_closed_without_creating_any_files(tmp_path):
|
||||
import pytest
|
||||
|
||||
cfg = snapshot_config(tmp_path)
|
||||
with pytest.raises(Exception, match="not initialized"):
|
||||
resolve_dwh_snapshot(cfg)
|
||||
with pytest.raises(Exception, match="not initialized"):
|
||||
with lease_dwh_snapshot(cfg):
|
||||
pass
|
||||
assert not (tmp_path / ".tht-dwh").exists()
|
||||
|
||||
|
||||
def test_writer_claim_allows_only_lock_and_empty_generations(tmp_path):
|
||||
import pytest
|
||||
|
||||
for name, make_entry in (
|
||||
("unexpected", lambda root: (root / "unexpected").write_text("x")),
|
||||
("stale-temp", lambda root: (root / ".OWNER.json.stale.tmp").write_text("x")),
|
||||
("unexpected-dir", lambda root: (root / "other").mkdir()),
|
||||
):
|
||||
root = tmp_path / name / ".tht-dwh"
|
||||
root.mkdir(parents=True, mode=0o700)
|
||||
make_entry(root)
|
||||
calls = []
|
||||
pipeline = DwhPreprocessPipeline(
|
||||
workspace_id="demo", workspace_root=root.parent,
|
||||
config_fingerprint=FP, input_fingerprint=FP,
|
||||
introspect=lambda output: calls.append("called"),
|
||||
build_lsh=lambda physical, output: None,
|
||||
)
|
||||
with pytest.raises(Exception, match="unbound"):
|
||||
pipeline.run()
|
||||
assert calls == []
|
||||
assert not (root / "OWNER.json").exists()
|
||||
|
||||
allowed = tmp_path / "allowed"
|
||||
(allowed / ".tht-dwh" / "generations").mkdir(parents=True, mode=0o700)
|
||||
report = DwhPreprocessPipeline(
|
||||
workspace_id="demo", workspace_root=allowed,
|
||||
config_fingerprint=FP, input_fingerprint=FP,
|
||||
introspect=lambda output: output.write_text("catalog"),
|
||||
build_lsh=lambda physical, output: _write_lsh([], physical, output),
|
||||
).run()
|
||||
assert report.status == "succeeded"
|
||||
|
||||
|
||||
def test_writer_rejects_unbound_legacy_artifacts_before_building(tmp_path):
|
||||
import pytest
|
||||
|
||||
legacy = tmp_path / "artifacts" / "mschema" / "physical.yaml"
|
||||
legacy.parent.mkdir(parents=True)
|
||||
legacy.write_text("legacy")
|
||||
calls = []
|
||||
pipeline = DwhPreprocessPipeline(
|
||||
workspace_id="demo", workspace_root=tmp_path,
|
||||
config_fingerprint=FP, input_fingerprint=FP,
|
||||
introspect=lambda output: calls.append("called"),
|
||||
build_lsh=lambda physical, output: None,
|
||||
current_physical=legacy,
|
||||
)
|
||||
with pytest.raises(Exception, match="legacy artifacts are unbound"):
|
||||
pipeline.run()
|
||||
assert calls == []
|
||||
assert not (tmp_path / ".tht-dwh" / "OWNER.json").exists()
|
||||
|
||||
|
||||
def test_owner_requires_exact_read_only_owner_mode_and_active_requires_binding(tmp_path):
|
||||
import pytest
|
||||
|
||||
pipeline = DwhPreprocessPipeline(
|
||||
workspace_id="demo", workspace_root=tmp_path,
|
||||
config_fingerprint=FP, input_fingerprint=FP,
|
||||
introspect=lambda output: output.write_text("catalog"),
|
||||
build_lsh=lambda physical, output: _write_lsh([], physical, output),
|
||||
)
|
||||
pipeline.run()
|
||||
cfg = snapshot_config(tmp_path)
|
||||
binding = config_dwh_binding(cfg)
|
||||
assert active_generation_dir(tmp_path, binding) is not None
|
||||
with pytest.raises(Exception, match="different workspace configuration"):
|
||||
active_generation_dir(tmp_path, {**binding, "workspace_id": "other"})
|
||||
|
||||
marker = tmp_path / ".tht-dwh" / "OWNER.json"
|
||||
marker.chmod(0o440)
|
||||
with pytest.raises(Exception, match="ownership marker"):
|
||||
resolve_dwh_snapshot(cfg)
|
||||
|
||||
|
||||
def test_selected_dwh_stages_run_in_declared_order(tmp_path):
|
||||
calls = []
|
||||
pipeline = DwhPreprocessPipeline(
|
||||
|
||||
@@ -5,6 +5,8 @@ from types import SimpleNamespace
|
||||
from typer.testing import CliRunner
|
||||
|
||||
from tht.cli import app
|
||||
from tht.config import load_config
|
||||
from tht.jobs.dwh_pipeline import DwhPreprocessPipeline, config_dwh_binding
|
||||
from tht.mschema.models import ColumnPhysical, PhysicalSchema, TablePhysical
|
||||
from tht.vectorstore.embeddings import EmbeddingsError
|
||||
|
||||
@@ -43,11 +45,11 @@ class _FakeSearcher:
|
||||
|
||||
|
||||
def _workspace(tmp_path, with_session=None):
|
||||
PhysicalSchema(
|
||||
physical = PhysicalSchema(
|
||||
database="d", schema="s", introspected_at=datetime(2026, 1, 1),
|
||||
tables={"fact_ablazione": TablePhysical(
|
||||
comment="Ablazioni", columns={"cod_paz": ColumnPhysical(type="bigint")})},
|
||||
).to_yaml(tmp_path / "artifacts" / "mschema" / "physical.yaml")
|
||||
)
|
||||
cfg = tmp_path / "workspace.yaml"
|
||||
cfg.write_text(
|
||||
"database: {database: d, schema: s, user: u, password: p, transport: direct}\n"
|
||||
@@ -56,6 +58,18 @@ def _workspace(tmp_path, with_session=None):
|
||||
f"paths: {{artifacts: {tmp_path/'artifacts'}, indexes: {tmp_path/'i'}, "
|
||||
f"sessions: {tmp_path/'sessions'}}}\n"
|
||||
)
|
||||
binding = config_dwh_binding(load_config(cfg))
|
||||
DwhPreprocessPipeline(
|
||||
workspace_id=binding["workspace_id"], workspace_root=tmp_path,
|
||||
config_fingerprint=binding["config_fingerprint"],
|
||||
input_fingerprint=binding["input_fingerprint"],
|
||||
introspect=lambda output: physical.to_yaml(output),
|
||||
build_lsh=lambda _physical, output: [
|
||||
(output / name).write_text("index")
|
||||
for name in ("s_lsh.pkl", "s_minhashes.pkl", "s_meta.json")
|
||||
],
|
||||
lsh_filenames=("s_lsh.pkl", "s_minhashes.pkl", "s_meta.json"),
|
||||
).run()
|
||||
if with_session:
|
||||
sdir = tmp_path / "sessions" / with_session
|
||||
sdir.mkdir(parents=True)
|
||||
|
||||
Reference in New Issue
Block a user