fix(harness): remediation difetti review — gate↔CLI, D15, D7/D6, D14, robustezza
Implementazione del piano di remediation progressiva sui difetti emersi dall'analisi dell'harness. Tutto verificato: 214 test Python (incl. L0 su Postgres reale), 14 test JS del gate, ruff pulito. Blocco 1 (CRITICA, integrazione gate↔CLI): - phase advance: gate usa --auto + exit 6; reviewer_confirm kind:phase fa advance esplicito che applica i prerequisiti (prima non avanzava per le fasi a conferma umana). - cte plan riceve i --name dal gate (param names); set-question con id posizionale; skill `tht search find`; nuovo comando `tht memory save-one` con dedup hash client-side in save_one_memory. Blocco 2 (D15, stato post-rollback): - campo `phase` su DecisionRecord + effective_decisions phase-aware per i subject "a nome" (cte_approved ecc.); _compute_promotions e finalize sulla vista effective; finalize confronta col piano CTE effettivo, non glob; `decision add --retracts` + comando `decision retract`. Blocco 3 (D7 read-only + D6 manifest): - assert_read_only su tutti e quattro i codepath (direct + REST); - manifest author/summary/updated_at/updated_by/schema_version popolati + helper touch_manifest sulle mutazioni. Blocco 4-5 (D14a/D14b): - decision_min_phase data-driven via `emits:` in workflow.yaml; - formula evidence: status auto, search_formulas, gruppo CLI `tht formula`, `search find --kind formula`, load_evidence_dir salta i .sql.md. Blocco 6 (robustezza): - taskdoc slice promoted_tables + bound enforced; report escaping/bound + rsplit note; filtro kind reader REST/direct; conteggio upserted robusto; guard REST run_query non-list; LSH disallineato -> LshIndexError. Blocco 7 (pulizia): - dead code gate e KIND_TO_TABLE morto rimossi; doc Postgres-only (README + connection.py). Blocco 0 (parziale): test di compatibilità firma gate↔CLI (tests/integration). Rinviati: fake-Pi runtime completo, artifact-gate da disco (#23), parità eligibility REST/direct (#28), unificazione reserved-labels (#30), memory_rejected da deselezione (#33). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -37,6 +37,24 @@ def _inject_limit(sql: str, limit: int) -> tuple[str, bool]:
|
||||
return ast.limit(limit + 1).sql(dialect="postgres"), True
|
||||
|
||||
|
||||
def assert_read_only(sql: str) -> None:
|
||||
"""Guard read-only strutturale condiviso dai due codepath di esecuzione (D7).
|
||||
|
||||
Difesa in profondita': oltre alla rete server (utente RO / READ ONLY tx / RPC
|
||||
SELECT-only), ogni esecuzione passa da qui, cosi' anche un riuso diretto delle API
|
||||
Python (es. dal backend) non puo' bypassare il single-statement + SELECT-only.
|
||||
Usa sqlcheck.validate_sql senza schema fisico: parse + un solo statement +
|
||||
read-only per struttura + funzioni vietate.
|
||||
"""
|
||||
from tht.sqlcheck import validate_sql
|
||||
|
||||
check = validate_sql(sql)
|
||||
if not check.ok:
|
||||
raise ExecutionError(
|
||||
"SQL rifiutato (read-only enforcement): " + "; ".join(check.errors)
|
||||
)
|
||||
|
||||
|
||||
def _translate_error(e: DBAPIError) -> ExecutionError:
|
||||
msg = str(e.orig)
|
||||
if "statement timeout" in msg or "canceling statement" in msg:
|
||||
@@ -48,7 +66,8 @@ def _translate_error(e: DBAPIError) -> ExecutionError:
|
||||
|
||||
def run_controlled(engine: Engine, sql: str, *, limit: int, timeout_ms: int) -> ExecResult:
|
||||
"""Esecuzione nelle 4 reti: utente RO (a monte), transazione READ ONLY,
|
||||
statement_timeout, LIMIT iniettato via AST."""
|
||||
statement_timeout, LIMIT iniettato via AST. Guard read-only client-side a monte."""
|
||||
assert_read_only(sql)
|
||||
final_sql, injected = _inject_limit(sql, limit)
|
||||
start = time.monotonic()
|
||||
with engine.connect() as conn:
|
||||
@@ -71,7 +90,11 @@ def run_controlled(engine: Engine, sql: str, *, limit: int, timeout_ms: int) ->
|
||||
|
||||
|
||||
def explain(engine: Engine, sql: str, *, timeout_ms: int) -> PlanSummary:
|
||||
"""EXPLAIN (FORMAT JSON), mai ANALYZE: il piano si stima, non si esegue."""
|
||||
"""EXPLAIN (FORMAT JSON), mai ANALYZE: il piano si stima, non si esegue.
|
||||
|
||||
assert_read_only a monte: l'EXPLAIN interpola lo SQL, quindi il single-statement +
|
||||
SELECT-only va garantito anche qui (non solo nel chiamante CLI)."""
|
||||
assert_read_only(sql)
|
||||
with engine.connect() as conn:
|
||||
trans = conn.begin()
|
||||
try:
|
||||
|
||||
Reference in New Issue
Block a user