08b741671d
The findings clustered exactly where prediction said: the unreviewed web layer. The big ones: decisions made while an extract/resolve job runs are now refused with a 409 (the job's end-of-run rewrite from a start-of-run snapshot would silently revert them); a cross-origin guard blocks preflight-free mutations from hostile webpages (bodyless run triggers, cross-site photo form posts); the JobRunner sets terminal status in a finally catching BaseException (a greenlet death could wedge every future run behind 409s) and writes tracebacks into the visible job log; and a boot token lets clients accept the revision reset after a server restart instead of freezing forever. Even the thrice-audited core yielded one HIGH: an unvetoed bare typo-read sibling of a confident row duplicated its add when the game wasn't in the collection — diff now treats it as satisfied. Second-copy adds carry a flag through to_add.csv and the upload log so verify honestly reports them unverifiable instead of OK. Also: merged_into chains collapse transitively; diff/enrich treat a BGG queue timeout like a missing token; enrich prunes orphaned games.json keys; the wizard shell-quotes .env values and creates the file 0600 from the first byte; fsio stats the tmp inode before replace and uses unique tmp names; an explicit missing --config errors; storage state is owner-only; extract re-extracts corrupt caches, aborts on 3 identical failures, and exits nonzero when nothing succeeded; torn JSON artifacts degrade with in-browser warnings instead of 500ing every page; photo uploads are atomic with cache-invalidation ordered first; the pipeline page computes `running` before the buttons that depend on it; the photo dropzone alerts on network failure; and lost-contact banners clear on recovery everywhere. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
50 lines
1.7 KiB
Python
50 lines
1.7 KiB
Python
"""fsio carries the project's central resumability promise: a kill or
|
|
crash mid-write must never leave a torn file. These pin that promise
|
|
directly — six modules depend on it."""
|
|
|
|
from __future__ import annotations
|
|
|
|
import os
|
|
import stat
|
|
|
|
import pytest
|
|
|
|
from bggpipe.fsio import atomic_write_bytes, atomic_write_csv, atomic_write_text
|
|
|
|
|
|
def test_failed_write_leaves_original_intact(tmp_path, monkeypatch):
|
|
target = tmp_path / "artifact.json"
|
|
target.write_text("precious")
|
|
# a read-only directory makes the tmp-file write fail
|
|
os.chmod(tmp_path, stat.S_IRUSR | stat.S_IXUSR)
|
|
try:
|
|
with pytest.raises(OSError):
|
|
atomic_write_text(target, "replacement")
|
|
finally:
|
|
os.chmod(tmp_path, 0o755)
|
|
assert target.read_text() == "precious"
|
|
assert not list(tmp_path.glob("*.tmp")) # no leftovers
|
|
|
|
|
|
def test_returned_mtime_matches_the_written_file(tmp_path):
|
|
target = tmp_path / "rows.csv"
|
|
mtime = atomic_write_csv(target, ["a", "b"], [{"a": "1", "b": "2"}])
|
|
# ReviewSession records this as "my own write" — it must be the mtime
|
|
# the file actually carries, or external-change detection breaks
|
|
assert mtime == target.stat().st_mtime_ns
|
|
|
|
|
|
def test_bytes_variant_round_trips(tmp_path):
|
|
target = tmp_path / "photo.jpg"
|
|
atomic_write_bytes(target, b"\xff\xd8jpeg")
|
|
assert target.read_bytes() == b"\xff\xd8jpeg"
|
|
atomic_write_bytes(target, b"\xff\xd8jpeg2") # overwrite is atomic too
|
|
assert target.read_bytes() == b"\xff\xd8jpeg2"
|
|
|
|
|
|
def test_concurrent_writers_use_distinct_tmp_names(tmp_path):
|
|
from bggpipe.fsio import _tmp_for
|
|
|
|
target = tmp_path / "x.csv"
|
|
assert _tmp_for(target) != _tmp_for(target) # no shared-inode interleave
|