fix(dwh): bind snapshots to validated bytes
This commit is contained in:
@@ -18,3 +18,13 @@ ACTIVE publication, and retention cleanup. Each test proves the replacement tree
|
||||
written, or deleted; the descriptor-pinned original either completes consistently or fails closed.
|
||||
Existing owner binding, legacy rejection, crash reconciliation, resume, atomic rollback, retention,
|
||||
and reader/writer exclusion behavior remains covered.
|
||||
|
||||
## Final review correction
|
||||
|
||||
Snapshot materialization now reads the manifest and every owned artifact exactly once through the
|
||||
already-open generation descriptor, validates each hash against those exact bytes, and writes the
|
||||
same byte objects to the private snapshot. A deterministic second-read mutation test proves hostile
|
||||
pickle bytes can neither pass validation nor enter the snapshot. Reconciliation closes the ACTIVE
|
||||
generation descriptor in a `finally` block on matches, mismatches, and exceptions. Pipeline-owned
|
||||
snapshot directories are removed and deregistered after `run_job` on both successful and failed
|
||||
runs, preventing repeated pipeline use from accumulating temporary directories or registry entries.
|
||||
|
||||
Reference in New Issue
Block a user