fix(5): preflight kjenner samme endepunkt-variabler som kjørestien [skip-docs]
Målt fra den utpakkede overleveringspakka: med KUN plattformens injiserte FOUNDRY_PROJECT_ENDPOINT — altså nøyaktig situasjonen i en hostet Foundry-container — avslo preflight en konfigurasjon backends.py ville godtatt. Gaten og kjørestien kjente ulike navn; det er repoets egen «checker og kjøresti validerer ulikt»-klasse, og for mottakeren av pakka er det et falskt avslag på riktig oppsett. _ENDPOINT_ENVS IMPORTERES nå fra backends i stedet for å gjentas, så de to kan ikke drifte fra hverandre igjen. Presedens over VERDIER, ikke deklarasjoner: et eksportert-men- tomt eget navn faller igjennom i stedet for å skygge et ekte injisert inn i en fail-fast. Avslaget navngir BEGGE variablene. Iron Law: 3 røde diskriminatorer + 1 grønn kontroll FØR fiksen. 854 passed / 4 skipped. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SeW1LhH5TtXxKZPe9JkqL1
This commit is contained in:
parent
a3300ab0f6
commit
88c223276c
3 changed files with 91 additions and 12 deletions
|
|
@ -155,3 +155,58 @@ def test_auth_recipe_doc_exists_and_names_facts() -> None:
|
|||
assert "Foundry User" in text
|
||||
assert "services.ai.azure.com" in text
|
||||
assert "necessary-but-not-sufficient" in text
|
||||
|
||||
|
||||
# --- Fase 5: preflight and the run path must know the SAME endpoint variables -----------------
|
||||
# Before this, preflight read ONLY our own name while backends.py accepted the platform-injected
|
||||
# one as a fallback. Inside a hosted Foundry container — where the platform injects
|
||||
# FOUNDRY_PROJECT_ENDPOINT and nothing else — the gate therefore refused a configuration the run
|
||||
# path would have accepted. That is the repo's own "checker and run path validate differently"
|
||||
# defect class, and it is friction the receiver of the handover package pays.
|
||||
|
||||
_INJECTED_ENV = "FOUNDRY_PROJECT_ENDPOINT"
|
||||
_OURS_ENV = "PORTFOLIO_FOUNDRY_PROJECT_ENDPOINT"
|
||||
|
||||
|
||||
def test_injected_endpoint_alone_is_accepted(
|
||||
monkeypatch: pytest.MonkeyPatch, tmp_path: Path
|
||||
) -> None:
|
||||
"""A hosted container sets only the platform name. Detach the fallback → RED (refuses)."""
|
||||
monkeypatch.delenv(_OURS_ENV, raising=False)
|
||||
monkeypatch.setenv(_INJECTED_ENV, _VALID_ENDPOINT)
|
||||
monkeypatch.setenv("PORTFOLIO_MODEL_MAP", str(_write_map(tmp_path, _VALID_MAP)))
|
||||
assert isinstance(preflight.check_azure_preflight("azure"), preflight.PreflightOK)
|
||||
|
||||
|
||||
def test_our_name_wins_over_the_injected_one(
|
||||
monkeypatch: pytest.MonkeyPatch, tmp_path: Path
|
||||
) -> None:
|
||||
"""Precedence mirrors backends.py: ours first. The injected value here is a WRONG host, so a
|
||||
green result can only mean ours was read — the two arms are distinguishable."""
|
||||
monkeypatch.setenv(_OURS_ENV, _VALID_ENDPOINT)
|
||||
monkeypatch.setenv(_INJECTED_ENV, "https://wrong.openai.azure.com/")
|
||||
monkeypatch.setenv("PORTFOLIO_MODEL_MAP", str(_write_map(tmp_path, _VALID_MAP)))
|
||||
assert isinstance(preflight.check_azure_preflight("azure"), preflight.PreflightOK)
|
||||
|
||||
|
||||
def test_precedence_is_over_values_not_declarations(
|
||||
monkeypatch: pytest.MonkeyPatch, tmp_path: Path
|
||||
) -> None:
|
||||
"""An exported-but-EMPTY own name must fall through to a real injected one rather than shadow
|
||||
it into a refusal (the 4b rule, same seam)."""
|
||||
monkeypatch.setenv(_OURS_ENV, "")
|
||||
monkeypatch.setenv(_INJECTED_ENV, _VALID_ENDPOINT)
|
||||
monkeypatch.setenv("PORTFOLIO_MODEL_MAP", str(_write_map(tmp_path, _VALID_MAP)))
|
||||
assert isinstance(preflight.check_azure_preflight("azure"), preflight.PreflightOK)
|
||||
|
||||
|
||||
def test_missing_endpoint_refusal_names_both_variables(monkeypatch: pytest.MonkeyPatch) -> None:
|
||||
"""Line-anchored, not substring: PORTFOLIO_FOUNDRY_PROJECT_ENDPOINT CONTAINS
|
||||
FOUNDRY_PROJECT_ENDPOINT, so a message naming only ours satisfies a naive assert (the repo's
|
||||
08-09 defect class). Strip our name before looking for the injected one."""
|
||||
monkeypatch.delenv(_OURS_ENV, raising=False)
|
||||
monkeypatch.delenv(_INJECTED_ENV, raising=False)
|
||||
result = preflight.check_azure_preflight("azure")
|
||||
assert isinstance(result, preflight.PreflightRefusal)
|
||||
assert _OURS_ENV in result.reason
|
||||
assert _INJECTED_ENV in result.reason.replace(_OURS_ENV, "")
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue