fix: harden preprocessing state and child capabilities
This commit is contained in:
@@ -11,6 +11,14 @@ from tht.ports.vector import VectorStoreError
|
||||
from tht.vectorstore.embeddings import EmbeddingsError
|
||||
|
||||
|
||||
@pytest.fixture(autouse=True)
|
||||
def _child_capability_for_pipeline_unit_tests(monkeypatch):
|
||||
# These tests exercise pipeline result/JSON behavior; process-boundary
|
||||
# authorization is covered by test_workspace_writer_lock.py.
|
||||
import tht.cli.preprocess_cmd as command
|
||||
monkeypatch.setattr(command, "_require_writer_capability", lambda **kwargs: None)
|
||||
|
||||
|
||||
def test_preprocess_evidence_json_is_pristine(monkeypatch, tmp_path):
|
||||
import tht.cli.preprocess_cmd as command
|
||||
|
||||
|
||||
@@ -5,12 +5,21 @@ from datetime import UTC, datetime
|
||||
from pathlib import Path
|
||||
from types import SimpleNamespace
|
||||
|
||||
import pytest
|
||||
from typer.testing import CliRunner
|
||||
|
||||
from tht.cli import app
|
||||
from tht.memory import MemoryRecord, save_registry
|
||||
|
||||
|
||||
@pytest.fixture(autouse=True)
|
||||
def _child_capability_for_vector_unit_tests(monkeypatch):
|
||||
import tht.cli.preprocess_cmd as preprocess
|
||||
import tht.cli.vector_cmd as vector
|
||||
monkeypatch.setattr(preprocess, "_require_writer_capability", lambda **kwargs: None)
|
||||
monkeypatch.setattr(vector, "_require_writer_capability", lambda **kwargs: None)
|
||||
|
||||
|
||||
class _FakeEmbedder:
|
||||
def embed_documents(self, documents):
|
||||
return [[0.1] * 4 for _ in documents]
|
||||
|
||||
@@ -24,6 +24,12 @@ from tht.mschema.models import (
|
||||
from tht.mschema.render import to_mschema_text, to_schema_dict
|
||||
|
||||
|
||||
@pytest.fixture(autouse=True)
|
||||
def _child_capability_for_schema_unit_tests(monkeypatch):
|
||||
import tht.cli.schema_cmd as command
|
||||
monkeypatch.setattr(command, "_require_writer_capability", lambda **kwargs: None)
|
||||
|
||||
|
||||
def _physical():
|
||||
return PhysicalSchema(
|
||||
database="d", schema="s", introspected_at=datetime(2026, 1, 1),
|
||||
@@ -605,7 +611,7 @@ def test_fresh_process_human_warning_cardinality_is_one_across_failure_and_write
|
||||
[sys.executable, "-c", probe, "schema", "suggest-fks", "--write", "-c", str(cfg)],
|
||||
check=True, capture_output=True, text=True,
|
||||
)
|
||||
assert json.loads(response.stdout) == {"warnings": 1, "exit": 0}
|
||||
assert json.loads(response.stdout) == {"warnings": 1, "exit": 1}
|
||||
|
||||
physical.unlink()
|
||||
for branch in branches:
|
||||
|
||||
@@ -1,8 +1,12 @@
|
||||
from __future__ import annotations
|
||||
import os, stat
|
||||
|
||||
import os
|
||||
|
||||
import pytest
|
||||
|
||||
from tht.workspace_writer_lock import WorkspaceWriterConflict, verify_workspace_writer_fds
|
||||
|
||||
|
||||
def test_verifier_rejects_missing_capability():
|
||||
with pytest.raises(WorkspaceWriterConflict): verify_workspace_writer_fds(env={})
|
||||
|
||||
@@ -14,3 +18,18 @@ def test_verifier_checks_fd_identity(tmp_path):
|
||||
cap=verify_workspace_writer_fds(writer_fd=w, root_fd=r, env=env)
|
||||
assert cap.inode == st.st_ino
|
||||
finally: os.close(w); os.close(r)
|
||||
|
||||
|
||||
def test_verifier_rejects_unrelated_lock(tmp_path):
|
||||
root = tmp_path / "root"; other = tmp_path / "other"
|
||||
root.mkdir(mode=0o700); other.mkdir(mode=0o700)
|
||||
expected = root / "writer.lock"; forged = other / "forged.lock"
|
||||
expected.touch(mode=0o600); forged.touch(mode=0o600)
|
||||
root_fd = os.open(root, os.O_RDONLY); forged_fd = os.open(forged, os.O_RDWR)
|
||||
try:
|
||||
st = os.fstat(root_fd)
|
||||
env = {"THOTH_WORKSPACE_ID": "abc-workspace", "THOTH_WORKSPACE_REVISION": "a" * 40, "THOTH_WORKSPACE_DEVICE": str(st.st_dev), "THOTH_WORKSPACE_INODE": str(st.st_ino)}
|
||||
with pytest.raises(WorkspaceWriterConflict):
|
||||
verify_workspace_writer_fds(writer_fd=forged_fd, root_fd=root_fd, env=env)
|
||||
finally:
|
||||
os.close(forged_fd); os.close(root_fd)
|
||||
|
||||
Reference in New Issue
Block a user