fix(jobs): bind completed effects to checkpoints

This commit is contained in:
2026-07-12 04:54:00 +02:00
parent c964920f16
commit b6a52995ae
5 changed files with 174 additions and 7 deletions
+28
View File
@@ -145,6 +145,34 @@ def test_nonexistent_well_formed_resume_run_id_is_rejected(tmp_path):
run_job(_spec(tmp_path).with_resume("a" * 32), [lambda _context: None])
@pytest.mark.parametrize("tamper", ["artifact_and_manifest", "spec", "producer"])
def test_resume_rejects_manifest_root_or_binding_tamper(tmp_path, tamper):
def stage(context):
artifacts = context.run_dir / "artifacts"
artifacts.mkdir()
(artifacts / "effect.json").write_text("ok")
return StageArtifacts(("effect.json",))
report = run_job(_spec(tmp_path), [stage])
artifacts = tmp_path / ".tht-jobs" / "evidence" / "runs" / report.run_id / "artifacts"
manifest_path = artifacts / "artifact-manifest.json"
manifest = json.loads(manifest_path.read_text())
if tamper == "artifact_and_manifest":
(artifacts / "effect.json").write_text("evil")
digest = __import__("hashlib").sha256(b"evil").hexdigest()
manifest["stages"]["stage"]["files"]["effect.json"] = {
"sha256": digest, "size": 4,
}
elif tamper == "spec":
manifest["spec_fingerprint"] = "sha256:" + "0" * 64
else:
manifest["stages"]["other"] = manifest["stages"].pop("stage")
manifest_path.write_text(json.dumps(manifest, sort_keys=True, separators=(",", ":")) + "\n")
with pytest.raises(CorruptCheckpointError, match="artifact"):
run_job(_spec(tmp_path).with_resume(report.run_id), [stage])
def test_successful_job_is_idempotently_resumable(tmp_path):
calls = []