fix(dwh): bind snapshots to validated bytes
This commit is contained in:
@@ -524,6 +524,90 @@ def test_snapshot_root_swap_after_lease_never_reads_replacement(monkeypatch, tmp
|
||||
assert (replacement / "sentinel").read_text() == "replacement-secret"
|
||||
|
||||
|
||||
def test_snapshot_copies_each_validated_artifact_once_without_reopen(monkeypatch, tmp_path):
|
||||
import tht.jobs.dwh_pipeline as module
|
||||
|
||||
pipeline = DwhPreprocessPipeline(
|
||||
workspace_id="demo", workspace_root=tmp_path,
|
||||
config_fingerprint=FP, input_fingerprint=FP,
|
||||
introspect=lambda output: output.write_text("trusted"),
|
||||
build_lsh=lambda physical, output: [
|
||||
(output / name).write_text("trusted")
|
||||
for name in ("demo_lsh.pkl", "demo_minhashes.pkl", "demo_meta.json")
|
||||
],
|
||||
)
|
||||
assert pipeline.run().status == "succeeded"
|
||||
real_read = module._read_owned_at
|
||||
reads = {}
|
||||
|
||||
def mutate_on_reopen(directory_fd, name, *, readonly):
|
||||
reads[name] = reads.get(name, 0) + 1
|
||||
if name.endswith(".pkl") and reads[name] > 1:
|
||||
return b"MALICIOUS_PICKLE"
|
||||
return real_read(directory_fd, name, readonly=readonly)
|
||||
|
||||
monkeypatch.setattr(module, "_read_owned_at", mutate_on_reopen)
|
||||
with lease_dwh_snapshot(snapshot_config(tmp_path)) as snapshot:
|
||||
assert (snapshot.lsh_dir / "demo_lsh.pkl").read_text() == "trusted"
|
||||
assert "MALICIOUS" not in (snapshot.lsh_dir / "demo_lsh.pkl").read_text()
|
||||
assert all(count == 1 for count in reads.values())
|
||||
|
||||
|
||||
def test_reconcile_mismatch_closes_active_generation_fd(monkeypatch, tmp_path):
|
||||
import os
|
||||
from types import SimpleNamespace
|
||||
import pytest
|
||||
import tht.jobs.dwh_pipeline as module
|
||||
|
||||
pipeline = DwhPreprocessPipeline(
|
||||
workspace_id="demo", workspace_root=tmp_path,
|
||||
config_fingerprint=FP, input_fingerprint=FP,
|
||||
introspect=lambda output: output.write_text("catalog"),
|
||||
build_lsh=lambda physical, output: _write_lsh([], physical, output),
|
||||
)
|
||||
report = pipeline.run()
|
||||
run_dir = tmp_path / ".tht-jobs" / "dwh" / "runs" / report.run_id
|
||||
real_active = module._active_generation_fd
|
||||
|
||||
def mismatched_active(root_fd, binding):
|
||||
generation, generation_fd = real_active(root_fd, binding)
|
||||
return "f" * 32, generation_fd
|
||||
|
||||
monkeypatch.setattr(module, "_active_generation_fd", mismatched_active)
|
||||
source = SimpleNamespace(
|
||||
run_id=report.run_id,
|
||||
stages=(SimpleNamespace(
|
||||
status="running", effect_state="intent", name="lsh",
|
||||
artifact_files=("physical.yaml", "demo_lsh.pkl", "demo_minhashes.pkl",
|
||||
"demo_meta.json"),
|
||||
),),
|
||||
)
|
||||
before = len(os.listdir("/dev/fd"))
|
||||
with pytest.raises(Exception, match="not ACTIVE"):
|
||||
pipeline._reconcile_effects(source, run_dir)
|
||||
assert len(os.listdir("/dev/fd")) == before
|
||||
|
||||
|
||||
def test_pipeline_releases_materialized_snapshot_after_every_run(tmp_path):
|
||||
import tht.jobs.dwh_pipeline as module
|
||||
|
||||
pipeline = DwhPreprocessPipeline(
|
||||
workspace_id="demo", workspace_root=tmp_path,
|
||||
config_fingerprint=FP, input_fingerprint=FP,
|
||||
introspect=lambda output: output.write_text("catalog"),
|
||||
build_lsh=lambda physical, output: _write_lsh([], physical, output),
|
||||
)
|
||||
baseline = set(module._SNAPSHOT_DIRS)
|
||||
for _ in range(3):
|
||||
assert pipeline.run().status == "succeeded"
|
||||
assert set(module._SNAPSHOT_DIRS) == baseline
|
||||
assert pipeline._snapshot_holder is None
|
||||
pipeline.introspect = lambda output: (_ for _ in ()).throw(RuntimeError("injected"))
|
||||
assert pipeline.run().status == "failed"
|
||||
assert set(module._SNAPSHOT_DIRS) == baseline
|
||||
assert pipeline._snapshot_holder is None
|
||||
|
||||
|
||||
def test_publish_root_swap_after_lease_never_writes_replacement(monkeypatch, tmp_path):
|
||||
import tht.jobs.dwh_pipeline as module
|
||||
|
||||
|
||||
Reference in New Issue
Block a user