fix: harden task3 qdrant compatibility boundaries

This commit is contained in:
2026-08-11 07:34:44 +02:00
parent 0724a73300
commit 99e0024973
11 changed files with 410 additions and 227 deletions
@@ -1,4 +1,3 @@
import { execFileSync } from "node:child_process";
import { mkdtempSync, rmSync, writeFileSync } from "node:fs";
import { tmpdir } from "node:os";
import { join } from "node:path";
@@ -109,7 +108,7 @@ test("keeps create_if_missing for non-registry runtime renders", () => {
});
test.each(["session", "maintenance"])(
"renders require_existing vectors for %s acquisition",
"pure renderer emits require_existing vectors for %s acquisition",
(mode) => {
const rendered = parse(renderRuntimeConfig(workspaceV3, directBindings, paths, {
workspaceId: "psd-clinical", workspaceRevision: "a".repeat(40),
@@ -124,36 +123,12 @@ test.each(["session", "maintenance"])(
},
);
test("session and maintenance renders are byte-identical and bind identically in harness", () => {
test("pure session and maintenance renders are byte-identical", () => {
const context = { workspaceId: "psd-clinical", workspaceRevision: "a".repeat(40) };
const passwordFile = evidenceSecretFile("dwh-password", "not-a-canary");
const bindings = {
...directBindings,
dwh: { ...directBindings.dwh, values: {
...directBindings.dwh.values,
THT_WS_PSD_CLINICAL_DWH_PASSWORD_FILE: passwordFile,
} },
};
const session = renderRuntimeConfig(workspaceV3, bindings, paths, context, {}, semanticRuntime);
const maintenance = renderRuntimeConfig(workspaceV3, bindings, paths, context, {}, semanticRuntime);
const session = renderRuntimeConfig(workspaceV3, directBindings, paths, context, {}, semanticRuntime);
const maintenance = renderRuntimeConfig(workspaceV3, directBindings, paths, context, {}, semanticRuntime);
expect(maintenance).toBe(session);
const script = `
import json, sys, tempfile
from pathlib import Path
from tht.config import load_config
from tht.jobs.dwh_pipeline import config_dwh_binding
with tempfile.TemporaryDirectory() as root:
path = Path(root) / "runtime.yaml"
path.write_text(sys.stdin.read())
print(json.dumps(config_dwh_binding(load_config(path)), sort_keys=True))
`;
const python = join(process.cwd(), "../harness/.venv/bin/python");
const run = (yaml: string) => execFileSync(python, ["-c", script], {
cwd: join(process.cwd(), "../harness"), input: yaml, encoding: "utf8",
}).trim();
expect(run(session)).toBe(run(maintenance));
});
test("renders schema-v3 DWH REST without exposing secret contents", () => {