Files
gbrain/test/handlers-embed-backfill.test.ts
T
df86ea5f1d v0.40.5.0 Federated Sync v2 — parallel source sync + push triggers + per-source health (#1322)
* wip: federated sync v2 pre-merge snapshot

* v0.40.5.0 Federated Sync v2 — parallel source sync + push triggers + per-source health

Bump VERSION + package.json + CHANGELOG header + migration walkthrough filename
to v0.40.5.0 (claiming the next free slot in the v0.40.x patch series after
master's v0.40.1.0).

What ships (6 components, all behind sync.federated_v2 feature flag default-on):
1. Per-source sync lock — syncLockId(sourceId), phantom-redirect parity
2. Parallel sync --all — pMapAllSettled fan-out, --max-sources N cap
3. embed-backfill minion handler — D2 per-source lock + D6 $10/job budget + D15.1
   fire-and-forget submission + D19 source-level cooldown + 24h $25 rolling cap
4. sync trigger CLI + POST /webhooks/github — HMAC-verified (60 req/min/IP),
   X-GitHub-Event=push + ref filter against tracked_branch
5. sources status + federation_health doctor — batched GROUP BY pipeline
   (4 queries instead of 6×N per-source roundtrips)
6. sources federate/unfederate hook — auto-submit embed-backfill on flip

Correctness fixes (unconditional):
- D21: sync.ts:959 facts backstop now passes sourceId to engine.getPage
- D15.4: redactSourceConfig + CI guard prevent webhook_secret leak
- D15.5: safeHexEqual extracted to src/core/timing-safe.ts

Schema:
- Migration v89 (sources_github_repo_index): partial expression index on
  config->>'github_repo' for fast webhook source-lookup

Tests:
- 14 new test files, 112 cases. 4 IRON-RULE regressions pinned (SYNC_LOCK_ID
  back-compat, phantom per-source lock, embed-backfill kill+resume,
  webhook HMAC prefix-strip). All 9449 unit tests pass.

Caught at test-write time: the webhook handler had a Buffer.from('sha256=...',
'hex') truncation bug — without the prefix-strip, every signature would have
"matched" empty buffers. Pinned by a test/sources-webhook.test.ts IRON-RULE.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(check-source-config-leak): tighten regex to source-row patterns only

The v0.40.5.0 wave added scripts/check-source-config-leak.sh with a
too-broad pattern (JSON\.stringify\(.*config) that flagged any variable
named 'config' — catching the GLOBAL gbrain config.json serializers in
src/commands/init.ts (status envelopes) and src/core/config.ts (the
config-file write site). On the CI runner without rg installed, the
grep -rE fallback fired correctly and produced 4 false positives that
broke the `verify` script.

Tightened the patterns to specifically match `(source|src|row|s).config`
property access — the actual risk shape (a sources-table row being
serialized whole). The global gbrain config has a different shape and
threat model (file-mode 0o600 at the write site), so it's safe to
exempt at the regex level rather than per-file whitelist.

Also fixed a latent bug: the rg branch used `--include='*.ts'` (grep's
flag, not rg's). rg silently rejected it and CANDIDATES came back empty,
so the local-dev runs (which have rg) would never have caught a real
leak. Now branches on tool availability: `-g '*.ts'` for rg, `--include`
for grep -rE. Both branches verified against a synthetic leak fixture.

Also added init.ts + config.ts to the whitelist as a belt-and-suspenders
since they handle gbrain-global config (not source rows) and could
otherwise reflect-back via regex iteration.

CI: `bun run verify` exit 0 locally with both the original false-positive
fixture (clean repo) and a synthetic leak fixture (correctly caught,
exit 1).

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-23 10:21:59 -07:00

144 lines
5.2 KiB
TypeScript

/**
* Tests for src/core/minions/handlers/embed-backfill.ts (v0.40 D2, D6).
*
* Validates the handler-side contract:
* - Happy path: embeds, returns 'success' with chunk + spend counts
* - D2 lock: second concurrent handler call returns 'already_in_progress'
* - D15.1 finally: lock ALWAYS releases (try/finally even on abort)
*
* Hermetic — uses injected embedFn via the underlying embedStaleForSource
* test seam? No — the handler doesn't expose embedFn passthrough. Instead
* we exercise the handler against a brain with zero stale chunks so no
* actual embed call lands. That gives us a deterministic test of the lock
* + budget + status branches without needing a fake gateway.
*
* The kill-resume contract is covered by test/embed-stale.test.ts at the
* helper layer; the handler just routes through.
*/
import { describe, test, expect, beforeAll, afterAll, beforeEach } from 'bun:test';
import { PGLiteEngine } from '../src/core/pglite-engine.ts';
import { makeEmbedBackfillHandler } from '../src/core/minions/handlers/embed-backfill.ts';
import { tryAcquireDbLock } from '../src/core/db-lock.ts';
import type { MinionJobContext } from '../src/core/minions/types.ts';
let engine: PGLiteEngine;
beforeAll(async () => {
engine = new PGLiteEngine();
await engine.connect({});
await engine.initSchema();
}, 30000);
afterAll(async () => {
await engine.disconnect();
});
beforeEach(async () => {
// Clean minion_jobs + lock rows. Preserve config (schema version + flags).
await engine.executeRaw('DELETE FROM minion_jobs');
await engine.executeRaw(`DELETE FROM gbrain_cycle_locks WHERE id LIKE 'gbrain-embed-backfill:%'`);
});
/** Build a minimal MinionJobContext for testing. */
function fakeJob(data: Record<string, unknown>): MinionJobContext {
const controller = new AbortController();
return {
id: 1,
name: 'embed-backfill',
data,
attempts_made: 0,
signal: controller.signal,
shutdownSignal: controller.signal,
updateProgress: async () => {},
updateTokens: async () => {},
log: async () => {},
isActive: async () => true,
readInbox: async () => [],
};
}
describe('embed-backfill handler — happy path', () => {
test('zero stale chunks → success with embedded=0', async () => {
const handler = makeEmbedBackfillHandler(engine);
const result = await handler(fakeJob({ sourceId: 'default' }));
expect(result).toMatchObject({
status: 'success',
sourceId: 'default',
embedded: 0,
chunksProcessed: 0,
pagesProcessed: 0,
});
});
test('throws when sourceId missing', async () => {
const handler = makeEmbedBackfillHandler(engine);
await expect(handler(fakeJob({}))).rejects.toThrow(/sourceId is required/);
});
test('throws when sourceId is empty string', async () => {
const handler = makeEmbedBackfillHandler(engine);
await expect(handler(fakeJob({ sourceId: '' }))).rejects.toThrow(/sourceId is required/);
});
});
describe('embed-backfill handler — D2 lock contract', () => {
test('IRON-RULE: second call returns already_in_progress when lock is held', async () => {
// Hold the per-source lock externally
const lock = await tryAcquireDbLock(engine, 'gbrain-embed-backfill:default', 60);
expect(lock).not.toBeNull();
try {
const handler = makeEmbedBackfillHandler(engine);
const result = await handler(fakeJob({ sourceId: 'default' }));
expect(result).toMatchObject({
status: 'already_in_progress',
sourceId: 'default',
embedded: 0,
spentUsd: 0,
});
} finally {
await lock?.release();
}
});
test('different sources do not contend on each other locks', async () => {
await engine.executeRaw(
`INSERT INTO sources (id, name, config) VALUES ('other-src', 'other-src', '{"federated":true}') ON CONFLICT (id) DO NOTHING`,
);
const lockA = await tryAcquireDbLock(engine, 'gbrain-embed-backfill:default', 60);
expect(lockA).not.toBeNull();
try {
// 'other-src' should still succeed
const handler = makeEmbedBackfillHandler(engine);
const result = await handler(fakeJob({ sourceId: 'other-src' }));
expect(result.status).toBe('success');
} finally {
await lockA?.release();
}
});
test('IRON-RULE: lock is released after handler completes (try/finally)', async () => {
const handler = makeEmbedBackfillHandler(engine);
await handler(fakeJob({ sourceId: 'default' }));
// After handler returns, the lock row should NOT block a fresh acquire.
const lock = await tryAcquireDbLock(engine, 'gbrain-embed-backfill:default', 60);
expect(lock).not.toBeNull();
await lock?.release();
});
test('IRON-RULE: lock released on throw (sourceId-missing path)', async () => {
const handler = makeEmbedBackfillHandler(engine);
try {
await handler(fakeJob({})); // throws before lock is acquired
} catch {
// expected
}
// Lock was never acquired (throw happened in parseParams pre-lock),
// so the row should be cleanly absent. Verify a fresh acquire works.
const lock = await tryAcquireDbLock(engine, 'gbrain-embed-backfill:default', 60);
expect(lock).not.toBeNull();
await lock?.release();
});
});