feat(assets): a bundle carries the images its sources declare (0.10.0)
Until now no reader in this package fetched, named, described or copied a single image. `<img>`'s attributes were never read, a NISO-STS `<graphic>` was walked past, a PDF was opened for its text alone, the converter's markdown writer dropped every picture, and the only writer into a bundle took `content: str`. The two lossiness warnings said so on every run, which made the loss honest and did not make it smaller. Measured on R761 Prosesskoden:2025, published as a 701-page PDF and as a NISO-STS delivery: the process text is carried in full while 12 `Tabell N-N` and 9 `Figur N-N` captions stand over nothing, because that publisher ships those tables as raster pictures in both. Process 84's "toleranseklasse ... er gitt i tabell 84-2" points at empty space. THE GATE WAS WRITTEN FIRST AND RED. `tests/test_asset_gate.py` reads its denominator out of the source (`page.images`, `word/media/`, `ppt/media/`, `<img`, `<graphic`), never from a constant here. Measured at332961a, built from `git archive` and not from the editable tree: carried 0 of 8 local images across 5 documents (9 declared), and no `assets/` at all. After: 8 of 8, with the ninth a remote source carried as a pointer without a file. FIVE READERS PLACE, ONE MODULE DECIDES. `assets.py` owns what an image is (sniffed from the bytes, never from the claimed extension), what it is called (`<sha256[:12]>-<the source's own basename>`) and how it is pointed at (one two-line block, one regex). `.xlsx` is deliberately not a row: a block inside its pipe tables would break the `source_rows` locator, and 0 of 4 K2 workbooks hold media. A PDF stream that is already a file is carried VERBATIM (29 of R761's 50 objects are DCTDecode); raw samples are encoded to PNG with stdlib zlib, so no new dependency. Rendering the page region was the alternative and was felled on determinism: a rasterised crop's bytes, and therefore the asset's content-addressed name and the bundle's digest, would depend on the installed rasteriser. What the encoder cannot express exactly is refused with a code and counted, never approximated. NO SIZE FLOOR, and that is a measurement: over the 4 828 image objects of the K2 corpus the size distribution is a broad spread with no gap, unlike OCR_CID_SHARE's bimodal one, so a threshold would be a number we chose. ON BY DEFAULT, AND THE CONTROL IS TWO WHOLE BUILDS. The 43-document reference corpus at332961aversus rebuilt at HEAD with `--no-assets`: 865 files on both sides, `diff -rq` reports ONE difference, the added `Images: NOT CARRIED` line in log.md. Every concept byte-identical. Against the default: 453 -> 454 concepts, 865 -> 867 md, 0 -> 2 964 assets (2 964 carried of 3 145 found, 4 622 pointers), 4.7 MB -> 115 MB, 2 414 s -> 3 088 s, peak RSS 6.26 -> 8.74 GB, 422 of 865 md files differ. The one new concept has a measured cause: the pointers are body text, so a section holding 146 of that document's images grew from 19.0 % to 30.6 % of the extracted text and crossed `--outline-gate`'s 0.20 share clause. THE IMAGE BYTES ARE NOT SCREENED. The guard is text-only, the pointer block passes the gate as body text, the picture beside it passes nothing, and log.md says so on every run. Also fixed, both found by measuring rather than by reading: - a markdown image is no longer read as a cross-reference. `structure._LINK` never looked at the character in front of the bracket, so every pointer would have arrived in the index as an edge to a concept that cannot exist. - Door C carries the assets its merged concepts point at. Before this, importing a bundle built with `--assets` merged 6 of 6 concepts and wrote no `assets/` at all, so every pointer named a missing file. Report: docs/2026-09-17-bilder-i-bundlen-trinn1.md Spec proposal: docs/plan/okf-assets-section-6-4.md Suite 1 955 passed / 1 skipped (from 1 896), ruff and mypy --strict clean. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
parent
332961a19c
commit
bc39e8091f
33 changed files with 3638 additions and 64 deletions
|
|
@ -27,11 +27,13 @@ obeys the verdict it returns.
|
|||
|
||||
from __future__ import annotations
|
||||
|
||||
from collections.abc import Mapping
|
||||
from collections.abc import Mapping, Sequence
|
||||
from dataclasses import dataclass
|
||||
from pathlib import Path
|
||||
from typing import Protocol
|
||||
|
||||
from .assets import ASSETS_DIR, IMAGE_POINTER
|
||||
from .connectors import safe_resolve
|
||||
from .errors import IngestError, MaterializationError, SourceError
|
||||
from .extract import decode_text
|
||||
from .materialize import (
|
||||
|
|
@ -355,6 +357,48 @@ def _read_bundle(
|
|||
return documents, failed
|
||||
|
||||
|
||||
def _carry_assets(source: Path, bundle: Path, merged: Sequence[MergedConcept]) -> None:
|
||||
"""Copy each asset a merged concept points at, by content identity.
|
||||
|
||||
The sender's bytes verbatim, exactly as the concept beside them: this door
|
||||
may not rewrite a merged concept, so it may not rewrite the pointer either,
|
||||
and the file therefore has to land under the name the pointer already
|
||||
names. An occupied name is re-used only when the bytes there are already
|
||||
identical -- Door C's ownership rule, and here the name carries the digest
|
||||
of those bytes, so a mismatch is a `sha256[:12]` collision and is refused
|
||||
rather than resolved.
|
||||
|
||||
A pointer whose asset the sender did not ship is left alone. SPEC SS 6.1
|
||||
requires a consumer to tolerate a broken link, and a pointer recording that
|
||||
the source had a figure nobody holds is information, not corruption.
|
||||
"""
|
||||
for entry in merged:
|
||||
try:
|
||||
text = entry.path.read_text(encoding="utf-8")
|
||||
except OSError:
|
||||
continue
|
||||
for match in IMAGE_POINTER.finditer(text):
|
||||
name = match.group("asset")
|
||||
try:
|
||||
origin = safe_resolve(source / ASSETS_DIR, name)
|
||||
target = safe_resolve(bundle / ASSETS_DIR, name)
|
||||
except SourceError:
|
||||
continue
|
||||
if not origin.is_file():
|
||||
continue
|
||||
data = origin.read_bytes()
|
||||
if target.exists():
|
||||
if target.read_bytes() != data:
|
||||
raise MaterializationError(
|
||||
f"the asset {name!r} already exists here with different bytes; "
|
||||
"refusing to overwrite content this import did not write",
|
||||
code="asset_collision",
|
||||
)
|
||||
continue
|
||||
target.parent.mkdir(parents=True, exist_ok=True)
|
||||
target.write_bytes(data)
|
||||
|
||||
|
||||
def import_bundle(
|
||||
source_dir: Path,
|
||||
bundle_dir: Path,
|
||||
|
|
@ -544,6 +588,19 @@ def import_bundle(
|
|||
MergedConcept(concept_path=concept_path, path=path, reasons=verdict.reasons)
|
||||
)
|
||||
|
||||
# THE ASSETS THE MERGED CONCEPTS POINT AT (0.10.0), read off the files
|
||||
# that actually landed. Measured before this existed: a bundle built
|
||||
# with `--assets` imported as 6 of 6 concepts and NO `assets/`
|
||||
# directory, so every pointer in the imported bundle named a file that
|
||||
# was not there -- the same "complete and not" defect the capability
|
||||
# exists to close, one door over.
|
||||
#
|
||||
# POINTED AT, never "every file in the sender's assets/". An asset
|
||||
# belonging to a concept the gate refused must not ride in on the back
|
||||
# of one it cleared, and an asset nothing names is a file no retirement
|
||||
# pass ever reaches.
|
||||
_carry_assets(source, bundle, merged)
|
||||
|
||||
# §10 pointers, surfaced over what actually landed. Read AFTER the merge
|
||||
# decision and never before it: this door's tolerance is structural —
|
||||
# it writes the sender's bytes verbatim and judges no shape — and a
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue