fix(evidence): bind corpus to workspace identity

This commit is contained in:
2026-07-12 05:57:23 +02:00
parent 78ff360882
commit db35ddb041
6 changed files with 109 additions and 10 deletions
+14 -3
View File
@@ -3,12 +3,17 @@
from tht.corpus.store import CorpusStore
class CorpusWorkspaceMismatchError(RuntimeError):
"""The configured workspace does not own the persisted corpus."""
class ActiveEvidenceSearcher:
"""Searcher facade that enforces ACTIVE generation predicates before LIMIT."""
def __init__(self, corpus: CorpusStore, delegate):
def __init__(self, corpus: CorpusStore, delegate, expected_workspace_id: str | None = None):
self.corpus = corpus
self.delegate = delegate
self.expected_workspace_id = expected_workspace_id
def search(self, embedding, top_n=10, kinds=None, metadata_filter=None):
requested = set(kinds) if kinds is not None else {
@@ -31,6 +36,12 @@ class ActiveEvidenceSearcher:
if include_evidence:
manifest = self.corpus.active_manifest()
workspace_id = manifest.metadata.get("workspace_id") if manifest else None
if manifest is not None and self.expected_workspace_id is not None and (
workspace_id != self.expected_workspace_id
):
raise CorpusWorkspaceMismatchError(
"corpus belongs to a different workspace; use a new corpus root or rebuild"
)
if manifest is not None and isinstance(workspace_id, str):
by_generation: dict[str, list[str]] = {}
mapping = dict(manifest.metadata.get("document_generations", {}))
@@ -50,9 +61,9 @@ class ActiveEvidenceSearcher:
return sorted(hits, key=lambda hit: (-hit.similarity, hit.id))[:top_n]
def active_searcher(cfg, delegate):
def active_searcher(cfg, delegate, *, workspace_id: str | None = None):
corpus_root = cfg.paths.artifacts.parent / "corpus"
return ActiveEvidenceSearcher(CorpusStore(corpus_root), delegate)
return ActiveEvidenceSearcher(CorpusStore(corpus_root), delegate, workspace_id)
def resolve_evidence_file(