mirror of
https://github.com/garrytan/gbrain.git
synced 2026-07-27 22:15:33 +00:00
* wip: federated sync v2 pre-merge snapshot
* v0.40.5.0 Federated Sync v2 — parallel source sync + push triggers + per-source health
Bump VERSION + package.json + CHANGELOG header + migration walkthrough filename
to v0.40.5.0 (claiming the next free slot in the v0.40.x patch series after
master's v0.40.1.0).
What ships (6 components, all behind sync.federated_v2 feature flag default-on):
1. Per-source sync lock — syncLockId(sourceId), phantom-redirect parity
2. Parallel sync --all — pMapAllSettled fan-out, --max-sources N cap
3. embed-backfill minion handler — D2 per-source lock + D6 $10/job budget + D15.1
fire-and-forget submission + D19 source-level cooldown + 24h $25 rolling cap
4. sync trigger CLI + POST /webhooks/github — HMAC-verified (60 req/min/IP),
X-GitHub-Event=push + ref filter against tracked_branch
5. sources status + federation_health doctor — batched GROUP BY pipeline
(4 queries instead of 6×N per-source roundtrips)
6. sources federate/unfederate hook — auto-submit embed-backfill on flip
Correctness fixes (unconditional):
- D21: sync.ts:959 facts backstop now passes sourceId to engine.getPage
- D15.4: redactSourceConfig + CI guard prevent webhook_secret leak
- D15.5: safeHexEqual extracted to src/core/timing-safe.ts
Schema:
- Migration v89 (sources_github_repo_index): partial expression index on
config->>'github_repo' for fast webhook source-lookup
Tests:
- 14 new test files, 112 cases. 4 IRON-RULE regressions pinned (SYNC_LOCK_ID
back-compat, phantom per-source lock, embed-backfill kill+resume,
webhook HMAC prefix-strip). All 9449 unit tests pass.
Caught at test-write time: the webhook handler had a Buffer.from('sha256=...',
'hex') truncation bug — without the prefix-strip, every signature would have
"matched" empty buffers. Pinned by a test/sources-webhook.test.ts IRON-RULE.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* fix(check-source-config-leak): tighten regex to source-row patterns only
The v0.40.5.0 wave added scripts/check-source-config-leak.sh with a
too-broad pattern (JSON\.stringify\(.*config) that flagged any variable
named 'config' — catching the GLOBAL gbrain config.json serializers in
src/commands/init.ts (status envelopes) and src/core/config.ts (the
config-file write site). On the CI runner without rg installed, the
grep -rE fallback fired correctly and produced 4 false positives that
broke the `verify` script.
Tightened the patterns to specifically match `(source|src|row|s).config`
property access — the actual risk shape (a sources-table row being
serialized whole). The global gbrain config has a different shape and
threat model (file-mode 0o600 at the write site), so it's safe to
exempt at the regex level rather than per-file whitelist.
Also fixed a latent bug: the rg branch used `--include='*.ts'` (grep's
flag, not rg's). rg silently rejected it and CANDIDATES came back empty,
so the local-dev runs (which have rg) would never have caught a real
leak. Now branches on tool availability: `-g '*.ts'` for rg, `--include`
for grep -rE. Both branches verified against a synthetic leak fixture.
Also added init.ts + config.ts to the whitelist as a belt-and-suspenders
since they handle gbrain-global config (not source rows) and could
otherwise reflect-back via regex iteration.
CI: `bun run verify` exit 0 locally with both the original false-positive
fixture (clean repo) and a synthetic leak fixture (correctly caught,
exit 1).
---------
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
175 lines
6.5 KiB
TypeScript
175 lines
6.5 KiB
TypeScript
/**
|
|
* Tests for src/core/embed-backfill-submit.ts (v0.40 D19).
|
|
*
|
|
* Validates the submission gate layer:
|
|
* - Default path: submits with priority 5 + idempotency bucket
|
|
* - Cooldown: refuses re-submission inside the window
|
|
* - Active-job: refuses while a same-source job is active/waiting
|
|
* - 24h spend cap: refuses when accumulated spend >= cap
|
|
* - Config overrides honored (per-test cap + cooldown)
|
|
* - Override knobs in opts honored (test seam)
|
|
*/
|
|
import { describe, test, expect, beforeAll, afterAll, beforeEach } from 'bun:test';
|
|
import { PGLiteEngine } from '../src/core/pglite-engine.ts';
|
|
import { resetPgliteState } from './helpers/reset-pglite.ts';
|
|
import {
|
|
submitEmbedBackfill,
|
|
COOLDOWN_CONFIG_KEY,
|
|
SPEND_CAP_CONFIG_KEY,
|
|
} from '../src/core/embed-backfill-submit.ts';
|
|
import { MinionQueue } from '../src/core/minions/queue.ts';
|
|
|
|
let engine: PGLiteEngine;
|
|
|
|
beforeAll(async () => {
|
|
engine = new PGLiteEngine();
|
|
await engine.connect({});
|
|
await engine.initSchema();
|
|
}, 30000); // 30s — PGLite WASM cold-start + 89 migrations exceeds 5s default
|
|
|
|
afterAll(async () => {
|
|
await engine.disconnect();
|
|
});
|
|
|
|
beforeEach(async () => {
|
|
// Surgical reset (mirrors test/minions.test.ts) — full TRUNCATE wipes the
|
|
// config table's `version` key that MinionQueue.ensureSchema() reads.
|
|
await engine.executeRaw('DELETE FROM minion_jobs');
|
|
});
|
|
|
|
describe('submitEmbedBackfill — happy path', () => {
|
|
test('submits with priority 5 + idempotency key on a clean source', async () => {
|
|
const result = await submitEmbedBackfill(engine, 'default', { reason: 'unit' });
|
|
expect(result.status).toBe('submitted');
|
|
expect(result.jobId).toBeDefined();
|
|
|
|
const queue = new MinionQueue(engine);
|
|
const job = await queue.getJob(result.jobId!);
|
|
expect(job).not.toBeNull();
|
|
expect(job!.name).toBe('embed-backfill');
|
|
expect(job!.priority).toBe(5);
|
|
expect((job!.data as { sourceId: string }).sourceId).toBe('default');
|
|
});
|
|
|
|
test('respects opts.priority override', async () => {
|
|
const result = await submitEmbedBackfill(engine, 'default', {
|
|
reason: 'unit',
|
|
priority: -10,
|
|
});
|
|
expect(result.status).toBe('submitted');
|
|
const queue = new MinionQueue(engine);
|
|
const job = await queue.getJob(result.jobId!);
|
|
expect(job!.priority).toBe(-10);
|
|
});
|
|
});
|
|
|
|
describe('submitEmbedBackfill — cooldown gate', () => {
|
|
test('blocks re-submission while a same-source job is active', async () => {
|
|
const queue = new MinionQueue(engine);
|
|
// Seed an active job manually
|
|
await queue.add('embed-backfill', { sourceId: 'default' }, {});
|
|
await engine.executeRaw(
|
|
`UPDATE minion_jobs SET status='active' WHERE name='embed-backfill'`,
|
|
);
|
|
|
|
const result = await submitEmbedBackfill(engine, 'default', { reason: 'unit' });
|
|
expect(result.status).toBe('cooldown');
|
|
expect(result.cooldownRemainingSeconds).toBeUndefined();
|
|
});
|
|
|
|
test('blocks re-submission inside the cooldown window after recent finish', async () => {
|
|
const queue = new MinionQueue(engine);
|
|
const job = await queue.add('embed-backfill', { sourceId: 'default' }, {});
|
|
// Mark completed 1 minute ago
|
|
await engine.executeRaw(
|
|
`UPDATE minion_jobs SET status='completed', finished_at=NOW() - INTERVAL '1 minute' WHERE id=$1`,
|
|
[job.id],
|
|
);
|
|
|
|
const result = await submitEmbedBackfill(engine, 'default', {
|
|
reason: 'unit',
|
|
cooldownMinOverride: 10, // 10min cooldown; 1min elapsed → blocked
|
|
});
|
|
expect(result.status).toBe('cooldown');
|
|
expect(result.cooldownRemainingSeconds).toBeGreaterThan(0);
|
|
expect(result.cooldownRemainingSeconds).toBeLessThanOrEqual(10 * 60);
|
|
});
|
|
|
|
test('allows re-submission after cooldown elapses', async () => {
|
|
const queue = new MinionQueue(engine);
|
|
const job = await queue.add('embed-backfill', { sourceId: 'default' }, {});
|
|
// Mark completed 11 minutes ago — past the 10-min cooldown
|
|
await engine.executeRaw(
|
|
`UPDATE minion_jobs SET status='completed', finished_at=NOW() - INTERVAL '11 minutes' WHERE id=$1`,
|
|
[job.id],
|
|
);
|
|
|
|
const result = await submitEmbedBackfill(engine, 'default', {
|
|
reason: 'unit',
|
|
cooldownMinOverride: 10,
|
|
});
|
|
expect(result.status).toBe('submitted');
|
|
});
|
|
|
|
test('config-overridable cooldown (via embed.backfill_cooldown_min)', async () => {
|
|
await engine.setConfig(COOLDOWN_CONFIG_KEY, '60'); // 60min cooldown
|
|
const queue = new MinionQueue(engine);
|
|
const job = await queue.add('embed-backfill', { sourceId: 'default' }, {});
|
|
await engine.executeRaw(
|
|
`UPDATE minion_jobs SET status='completed', finished_at=NOW() - INTERVAL '30 minutes' WHERE id=$1`,
|
|
[job.id],
|
|
);
|
|
|
|
const result = await submitEmbedBackfill(engine, 'default', { reason: 'unit' });
|
|
expect(result.status).toBe('cooldown');
|
|
});
|
|
});
|
|
|
|
describe('submitEmbedBackfill — 24h spend cap', () => {
|
|
test('refuses when spend24hFn returns >= cap', async () => {
|
|
const result = await submitEmbedBackfill(engine, 'default', {
|
|
reason: 'unit',
|
|
spendCapUsdOverride: 25,
|
|
spend24hFn: async () => 25,
|
|
});
|
|
expect(result.status).toBe('spend_capped');
|
|
expect(result.spend24hUsd).toBe(25);
|
|
expect(result.spendCapUsd).toBe(25);
|
|
});
|
|
|
|
test('admits when spend24hFn returns < cap', async () => {
|
|
const result = await submitEmbedBackfill(engine, 'default', {
|
|
reason: 'unit',
|
|
spendCapUsdOverride: 25,
|
|
spend24hFn: async () => 24.99,
|
|
});
|
|
expect(result.status).toBe('submitted');
|
|
});
|
|
|
|
test('config-overridable spend cap (via embed.backfill_max_usd_per_source_24h)', async () => {
|
|
await engine.setConfig(SPEND_CAP_CONFIG_KEY, '5');
|
|
const result = await submitEmbedBackfill(engine, 'default', {
|
|
reason: 'unit',
|
|
spend24hFn: async () => 5,
|
|
});
|
|
expect(result.status).toBe('spend_capped');
|
|
expect(result.spendCapUsd).toBe(5);
|
|
});
|
|
});
|
|
|
|
describe('submitEmbedBackfill — source isolation', () => {
|
|
test('cooldown is per-source, not global', async () => {
|
|
await engine.executeRaw(
|
|
`INSERT INTO sources (id, name, config) VALUES ('other', 'other', '{"federated":true}') ON CONFLICT (id) DO NOTHING`,
|
|
);
|
|
const queue = new MinionQueue(engine);
|
|
// Active job on 'default'
|
|
await queue.add('embed-backfill', { sourceId: 'default' }, {});
|
|
await engine.executeRaw(`UPDATE minion_jobs SET status='active' WHERE name='embed-backfill'`);
|
|
|
|
// Submit for 'other' — should NOT be blocked
|
|
const result = await submitEmbedBackfill(engine, 'other', { reason: 'unit' });
|
|
expect(result.status).toBe('submitted');
|
|
});
|
|
});
|