chore(deps): re-pin llm-ingestion-okf to v0.3.1 + migrate tests to stable error codes

Pin dae0bd1a -> v0.3.1 (=692f2df) on the public Forgejo mirror; uv.lock pins
the exact commit behind the tag.

- Drop the mypy override: the library ships py.typed from v0.2.0, so strict
  mode now follows its real types instead of follow_untyped_imports.
- Migrate 8 library-error assertions from pytest.raises(match=...) to
  exc.value.code — message text is explicitly unstable from v0.3.0, the
  codes are the stability contract.
- Fix a real breakage the bump surfaced: IngestResult gained a required
  `stamp` field (d3a3bcc), which the delegation fake did not construct.
- The read-only SQL test loses resolution under the code contract
  (`sql_failed` is generic), so it now proves read-onlyness by effect —
  the write never lands — instead of by message wording.
- Correct the guard plan: G1's persist-gate anchor (ingest.py:372-387) died
  with the 2026-07-16 adoption. Door A is ungated by the library's own
  README, so gating stays our responsibility at the call site.

Verified: 426 tests green, golden output byte-exact unchanged, full gate
clean (ruff + format + mypy strict).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RmNAgbRXUgvoSKxVK4Bevv
This commit is contained in:
Kjell Tore Guttormsen 2026-07-20 07:22:09 +02:00
commit a7e8ffecb8
6 changed files with 41 additions and 23 deletions

View file

@ -113,16 +113,18 @@ class TestSecurityFrame:
manifest = _valid()
manifest["extractions"][0]["max_rows"] = 1
case = _write_case(tmp_path, manifest, {"e.csv": "col\n1\n2\n"}) # 2 data rows > 1
with pytest.raises(SourceError, match="max_rows"):
with pytest.raises(SourceError) as exc:
materialize(case / "manifest.json", tmp_path / "bundle", INGESTED_AT)
assert exc.value.code == "max_rows_exceeded"
def test_query_escaping_root_is_refused(self, tmp_path: Path) -> None:
manifest = _valid()
manifest["extractions"][0]["query"] = "../secret.csv"
case = _write_case(tmp_path, manifest, {"e.csv": "col\n1\n"})
(case / "secret.csv").write_text("col\nx\n", encoding="utf-8")
with pytest.raises(SourceError, match="escapes"):
with pytest.raises(SourceError) as exc:
materialize(case / "manifest.json", tmp_path / "bundle", INGESTED_AT)
assert exc.value.code == "path_escape"
def test_collision_with_non_ingest_file_fails(self, tmp_path: Path) -> None:
case = _write_case(tmp_path, _valid(), {"e.csv": "col\n1\n"})
@ -132,7 +134,8 @@ class TestSecurityFrame:
(bundle / "ingest-e.md").write_text(
"---\ntype: reference\ntitle: hand\n---\n\nCurated.\n", encoding="utf-8"
)
with pytest.raises(MaterializationError, match="collides"):
with pytest.raises(MaterializationError) as exc:
materialize(case / "manifest.json", bundle, INGESTED_AT)
assert exc.value.code == "collision_unstamped"
# The curated file is untouched — never overwritten.
assert "Curated." in (bundle / "ingest-e.md").read_text(encoding="utf-8")