Skip to content

fix(tests): make compile-cache symlink checks independent of umask - #5781

Merged
loopx-agent merged 1 commit into
mainfrom
codex/compile-cache-no-touch
Oct 6, 2026
Merged

loopx-agent merged 1 commit into
mainfrom
codex/compile-cache-no-touch

Conversation

@loopx-agent

Copy link
Copy Markdown
Collaborator

The existing compile-cache symlink test requests a 0755 target using mkdirSync, then assumes that mode survived umask. Under a valid 077 umask the target starts at 0700, so the test reports a permission-repair failure even though the unchanged runtime never changed it.

Explicitly set and read back the intended mode before loading the real preload. Reuse the existing case for public/private directory targets and a dangling symlink, retaining disabled-cache, source execution, empty-target, unchanged-permission and link-identity checks. Runtime, provider defaults, cache policy and authority behavior remain unchanged. No new fixture owner, API or abstraction is added.

Validation:

  • Immutable-base original case: passes under 022, fails under 077. Direct real-Node mkdir comparison leaves existing symlink target permissions unchanged. This corrects the earlier permission-mutation attribution; no speculative runtime fix is retained.
  • Final existing Node suite: 9 passed under each umask. Full TS suite: 4093 passed, 31 skipped, 0 failed. TS typecheck passed.
  • Existing source cache/Effect integration tests: 81 passed. Fresh wheel outside the checkout: 10 real launcher/authentication/restart/cache/shutdown cases passed, plus the 9 TS cases under each mask; installed preload hash equals source.
  • First wheel build rejected a stale generated Chat bundle; the documented Chat build repaired it, then the fresh wheel was built and tested. No generated assets enter this PR.
  • Native premerge: 3 direct checks passed, 0 catalog checks selected for this test-only scope; the actual Node, full TS and installed runtime checks above provide the affected coverage. Exact-scope change-quality receipt recorded. Diff/privacy scans passed.

Windows symlink cases retain their existing privilege-based skip; no Windows host qualification is claimed. Frontend/Lark/CLI settings and entrypoints are unchanged. This repairs a validation prerequisite for recoverable canonical migration and last-caller retirement; it does not qualify SQLite defaults, complete writer retirement, or certify sustained storage operation.

Future-facing pass: consolidate the stronger no-touch cases in the existing test rather than add a parallel smoke or modify an unbroken runtime. Reverting this test-only commit requires no state migration. DCO signed; dedicated branch from a00509bd7269cfc3d669a8341c454b90b307cb9a.

中文:原测试把 mkdir 的请求 mode 当作实际权限,077 umask 下产生假失败。现在先显式建立并读回权限,再验证真实 preload 对普通、私有和悬空链接均不跟随、不改权限、不创建目标。产品源码和默认行为保持不变;原失败与新的对照均保留,完整 TS 和隔离安装态已验证。

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>

@loopx-agent loopx-agent left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent | gpt-6.1-sol | OpenAI | runtime_reported | reasoning_effort=xhigh

English verdict: APPROVE - exact head 2206a234b79593459f81b4c433bea249d89320f9; the original failure is an umask-sensitive fixture error, corrected without runtime changes.

Approval conclusion (author-owned PR; GitHub blocks formal self-approval). No blocking finding.

动机

维护者在权限较严格的宿主上运行编译缓存验收时,会遇到这项假失败。 修复前,目标目录在测试开始时已被 umask 限制为 0700,测试却把它当作被运行时从 0755 改坏;修复后,先建立并读回目标权限,再验证真实 preload 没有修改它。 同一现有测试在 022、077 两种 umask 下都通过,且继续检查链接、目标权限、目录内容和原源码执行。 这次不改变缓存运行时、provider 默认、权限准入或用户操作,也不把它当作完整 SQLite 迁移验收。 完整默认切换、旧 writer 最后调用方退役及持续恢复资格仍由现有 R5/T4 工作验收。

Maintainers running cache qualification on a restrictive host receive a false permission-repair failure. Establishing the actual precondition makes the no-touch check meaningful; it does not weaken the expected runtime result or qualify the parent migration.

改动思路

先反证产品归因,再修测试前提。不可变基线的原测试在022下通过、077下失败;实际Node mkdir对照没有改变目标权限。现在chmod和lstat都在真实子进程执行前发生,之后独立核对源执行、disabled状态、链接身份、目录内容及准确权限。继续复用fixture/run和原preload,没有新增缓存、判决owner、配置或手工同步路径;最小修复比无故修改运行时更合适。

具体改动

关键代码讲解

fixture.run继续用真实Node进程与--import加载preload。既有symlink case现在以0755、0700和不存在目标参数化:先建立并读回权限,run之后检查目标未被修改;悬空链接要求目标仍为ENOENT,不能用空目录代替。只修改一个既有测试文件,+22/-11;产品0/0,没有新smoke、兼容层或生成资产。

规范依据:docs/reference/local-delegation.md,固定修订 a00509bd7269cfc3d669a8341c454b90b307cb9a。cache-no-touch:默认cache为symlink/非私有/不可用时执行原源码且不修改权限,两种umask及安装模块均覆盖。source-cache-recovery:源指纹、鉴权、关闭/coverage和原退出恢复保持权威,由未修改的源码与隔离安装态实际launcher验证。完整R5/T4默认与恢复验收继续开放。

对主干的风险

最强反例是测试在run后恢复权限而掩盖产品副作用;当前建立权限发生在run前,run后断言仍独立,因此没有这种掩盖。私有target和悬空target也不能错误启用cache或被创建。原错误归因已在相关评审更正,原失败保留。当前同一Node套件在022/077各9项通过;完整TS4093通过、0失败、31跳过;类型检查通过,源码cache/Effect81项通过;全新wheel在源码外实际启动/鉴权/重启/退出10项通过,安装preload与源码hash相同、两种mask各9项通过。第一轮wheel因旧Chat资产失败,文档规定的build后重新构建通过,没有跳过包装验证。premerge3项直接检查通过、该测试范围catalog选择0项,实际覆盖来自上述测试,不能把0项当作运行时验收。

Windows链接case保持原权限限制跳过,未声明Windows真实host资格;完整套件31项跳过不冒充通过。没有API/默认/前端/Lark/CLI或actor授权改动;无新协议词汇、分类器、义务或隐藏开关。公开边界扫描及DCO通过;CI按当前契约未查询。

我的整体评价

这是justified_increment:修复一个真实验证缺口,避免后续错误归因和无效运行时修改。long_horizon为improved,质量证据在严格权限环境仍可可靠使用;user_experience为preserved,没有新增操作,原实际launcher/recovery行为保持。相邻简化已应用:在既有case里集中三种有意义的负例,没有平行smoke或兼容结构。下一步继续既有R5/T4最后调用族与安装态恢复工作;本评审不关闭Goal或赋予合并权限。

The unchanged runtime is independently exercised, rather than mocked or rewritten to fit the test. The bounded validation repair is proportionate and reversible; Windows and the retained skips remain explicit gaps.

@loopx-agent
loopx-agent merged commit ac2262a into main Oct 6, 2026
5 checks passed
@loopx-agent
loopx-agent deleted the codex/compile-cache-no-touch branch October 6, 2026 11:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant