fix(preprocess): harden crash recovery integrity
This commit is contained in:
@@ -41,3 +41,18 @@ def test_active_pointer_cannot_escape_generation_root(tmp_path):
|
||||
store.active_path.write_text("../outside\n")
|
||||
with pytest.raises(UnsafeCorpusPath):
|
||||
store.active_manifest()
|
||||
|
||||
|
||||
def test_publish_restores_previous_active_when_directory_fsync_fails_after_replace(tmp_path, monkeypatch):
|
||||
store = CorpusStore(tmp_path / "corpus")
|
||||
first = store.stage(CorpusManifest(), {})
|
||||
second = store.stage(CorpusManifest(), {})
|
||||
store.publish(first)
|
||||
def fail_once():
|
||||
store._fsync_directory = store._sync_root
|
||||
raise OSError("post replace crash")
|
||||
|
||||
store._fsync_directory = fail_once
|
||||
with pytest.raises(OSError, match="post replace"):
|
||||
store.publish(second)
|
||||
assert store.active_generation() == first
|
||||
|
||||
Reference in New Issue
Block a user