fix(dwh): bind snapshots to validated bytes

This commit is contained in:
2026-07-12 07:31:46 +02:00
parent 2f6daaaea6
commit 4aae6c433d
3 changed files with 136 additions and 15 deletions
+84
View File
@@ -524,6 +524,90 @@ def test_snapshot_root_swap_after_lease_never_reads_replacement(monkeypatch, tmp
assert (replacement / "sentinel").read_text() == "replacement-secret"
def test_snapshot_copies_each_validated_artifact_once_without_reopen(monkeypatch, tmp_path):
import tht.jobs.dwh_pipeline as module
pipeline = DwhPreprocessPipeline(
workspace_id="demo", workspace_root=tmp_path,
config_fingerprint=FP, input_fingerprint=FP,
introspect=lambda output: output.write_text("trusted"),
build_lsh=lambda physical, output: [
(output / name).write_text("trusted")
for name in ("demo_lsh.pkl", "demo_minhashes.pkl", "demo_meta.json")
],
)
assert pipeline.run().status == "succeeded"
real_read = module._read_owned_at
reads = {}
def mutate_on_reopen(directory_fd, name, *, readonly):
reads[name] = reads.get(name, 0) + 1
if name.endswith(".pkl") and reads[name] > 1:
return b"MALICIOUS_PICKLE"
return real_read(directory_fd, name, readonly=readonly)
monkeypatch.setattr(module, "_read_owned_at", mutate_on_reopen)
with lease_dwh_snapshot(snapshot_config(tmp_path)) as snapshot:
assert (snapshot.lsh_dir / "demo_lsh.pkl").read_text() == "trusted"
assert "MALICIOUS" not in (snapshot.lsh_dir / "demo_lsh.pkl").read_text()
assert all(count == 1 for count in reads.values())
def test_reconcile_mismatch_closes_active_generation_fd(monkeypatch, tmp_path):
import os
from types import SimpleNamespace
import pytest
import tht.jobs.dwh_pipeline as module
pipeline = DwhPreprocessPipeline(
workspace_id="demo", workspace_root=tmp_path,
config_fingerprint=FP, input_fingerprint=FP,
introspect=lambda output: output.write_text("catalog"),
build_lsh=lambda physical, output: _write_lsh([], physical, output),
)
report = pipeline.run()
run_dir = tmp_path / ".tht-jobs" / "dwh" / "runs" / report.run_id
real_active = module._active_generation_fd
def mismatched_active(root_fd, binding):
generation, generation_fd = real_active(root_fd, binding)
return "f" * 32, generation_fd
monkeypatch.setattr(module, "_active_generation_fd", mismatched_active)
source = SimpleNamespace(
run_id=report.run_id,
stages=(SimpleNamespace(
status="running", effect_state="intent", name="lsh",
artifact_files=("physical.yaml", "demo_lsh.pkl", "demo_minhashes.pkl",
"demo_meta.json"),
),),
)
before = len(os.listdir("/dev/fd"))
with pytest.raises(Exception, match="not ACTIVE"):
pipeline._reconcile_effects(source, run_dir)
assert len(os.listdir("/dev/fd")) == before
def test_pipeline_releases_materialized_snapshot_after_every_run(tmp_path):
import tht.jobs.dwh_pipeline as module
pipeline = DwhPreprocessPipeline(
workspace_id="demo", workspace_root=tmp_path,
config_fingerprint=FP, input_fingerprint=FP,
introspect=lambda output: output.write_text("catalog"),
build_lsh=lambda physical, output: _write_lsh([], physical, output),
)
baseline = set(module._SNAPSHOT_DIRS)
for _ in range(3):
assert pipeline.run().status == "succeeded"
assert set(module._SNAPSHOT_DIRS) == baseline
assert pipeline._snapshot_holder is None
pipeline.introspect = lambda output: (_ for _ in ()).throw(RuntimeError("injected"))
assert pipeline.run().status == "failed"
assert set(module._SNAPSHOT_DIRS) == baseline
assert pipeline._snapshot_holder is None
def test_publish_root_swap_after_lease_never_writes_replacement(monkeypatch, tmp_path):
import tht.jobs.dwh_pipeline as module