feat: pin sessions to workspace revisions

This commit is contained in:
2026-08-04 05:18:08 +02:00
parent bc39730b58
commit 6c09adc05e
3 changed files with 68 additions and 4 deletions
@@ -26,6 +26,24 @@
completed with 22 passing tests.
- `git diff --check` completed cleanly.
## Review fixes — round 3
- The active registry snapshot that located a session now remains the authorization and mutation
config for response, steer, events, close/delete, archive/group/rename, documents, and detail.
A pruned historical revision cannot block an already-located session's active lifecycle.
- Only Resume resolves the retained pinned descriptor because Pi needs that immutable config to
restart safely. A pruned pin therefore returns the existing sanitized
`workspace_revision_unavailable` 409 solely for Resume.
### Round 3 verification
- RED: with a manifest found through an active registry snapshot and `readPinned` forced to fail,
`POST /sessions/:id/response` returned 409 instead of forwarding the active gate response.
- GREEN: `npx vitest run test/routes-sessions.test.ts test/tht-runner.test.ts test/routes-settings.test.ts && npx tsc --noEmit -p .`
— 102 tests passed with a clean type check. The regression confirms response, close, and delete
use the locating snapshot without calling `readPinned`, while Resume returns a sanitized 409.
- `git diff --check` completed cleanly.
## Review fixes — round 2
- Lifecycle authorization no longer selects the installation-default workspace. The backend now
+2 -4
View File
@@ -121,10 +121,8 @@ export function sessionRoutes(
};
/** RLS makes a foreign session indistinguishable from a missing one. */
const authorize = async (principal: PrincipalContext, id: string): Promise<LocatedSession | undefined> => {
const located = await locateSession(principal, id);
return located && await resolveSessionWorkspace(located);
};
const authorize = async (principal: PrincipalContext, id: string): Promise<LocatedSession | undefined> =>
await locateSession(principal, id);
const storageFailure = (reply: any) => reply.code(503).send({ error: "session storage is unavailable" });
const lifecycleFailure = (reply: any, error: unknown) =>
+48
View File
@@ -603,6 +603,54 @@ test("POST /sessions/:id/resume returns a sanitized error when its retained revi
expect(response.json()).toMatchObject({ code: "workspace_revision_unavailable" });
});
test("a pruned pin blocks Resume but not active or mutation lifecycle routes", async () => {
const activePath = "/registry/snapshots/aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa/b-workspace.yaml";
const prunedError = "cannot read /registry/snapshots/secret-pruned-revision/b-workspace.yaml";
const calls: string[] = [];
const readPinned = vi.fn(async () => { throw new Error(prunedError); });
let active: any = { bridge: { respond: () => true } };
const app = buildApp(loadConfig({ THT_HARNESS_DIR: "../harness" }), {
thtRunner: {
sessionShow: async (_id: string, workspace: string) => {
expect(workspace).toBe(activePath);
return {
id: "pruned", status: "open", archived: false,
workspace_id: "b-workspace", workspace_revision: "b".repeat(40),
};
},
closeSession: async (_id: string, workspace: string) => { calls.push(`close:${workspace}`); },
deleteSession: async (_id: string, workspace: string) => { calls.push(`delete:${workspace}`); },
} as any,
mgr: {
get: () => active,
teardownIfCurrent: (_id: string, expected: any) => {
if (active !== expected) return false;
active = undefined;
return true;
},
} as any,
workspaceRegistry: {
list: async () => [{
id: "b-workspace", commit: "a".repeat(40), blob: "a".repeat(40), snapshotPath: activePath, state: "operational",
}],
readPinned,
} as any,
});
expect((await app.inject({ method: "POST", url: "/sessions/pruned/response", payload: { ui_response: {} } })).statusCode)
.toBe(204);
expect((await app.inject({ method: "POST", url: "/sessions/pruned/close" })).statusCode).toBe(200);
expect((await app.inject({ method: "DELETE", url: "/sessions/pruned" })).statusCode).toBe(204);
expect(calls).toEqual([`close:${activePath}`, `delete:${activePath}`]);
expect(readPinned).not.toHaveBeenCalled();
const resume = await app.inject({ method: "POST", url: "/sessions/pruned/resume" });
expect(resume.statusCode).toBe(409);
expect(resume.body).not.toContain(prunedError);
expect(resume.json()).toMatchObject({ code: "workspace_revision_unavailable" });
expect(readPinned).toHaveBeenCalledWith("b-workspace", "b".repeat(40));
});
test("POST /sessions/:id/resume refuses a pinned finalized session before reading its snapshot", async () => {
const readPinned = vi.fn(async () => { throw new Error("must not resolve"); });
const app = buildApp(loadConfig({ THT_HARNESS_DIR: "../harness" }), {