test: verify outcome migrations and worker recovery on PostgreSQL
Some checks failed
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / pytest-smoke (push) Failing after 2s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e747-8f27-7242-8df8-8bc44f88c929
This commit is contained in:
tegwick 2026-09-28 14:22:05 +02:00
parent f0eff0ac92
commit 7f0dc78607
6 changed files with 315 additions and 8 deletions

View file

@ -50,12 +50,13 @@ harness reports only the implemented profile above.
## Access enforcement and CI gates
`make ci-check` runs the test suite, checks the reviewed access inventory for
source drift, builds distributions and validates an installed wheel outside the
source drift, runs disposable PostgreSQL integration tests, builds distributions
and validates an installed wheel outside the
checkout's import path. The wheel check uses a fresh environment and refreshes
the Hub package so rebuilding the same version cannot reuse an older installation. Forgejo runs these gates for `main` pushes and manual
runs, using the full commit SHA and a unique temporary checkout. CI installs the
locked development and runtime dependencies first. Individual gates are
`make test`, `make inventory-check` and `make package-check`.
`make test`, `make inventory-check`, `make package-check` and `make postgres-test`.
`tests/test_enforced_conformance.py` runs all twelve existing Tier 2/3 checks
through an explicitly enforced runtime using a real signed IAM JWT and synthetic
@ -71,3 +72,27 @@ It makes no owner requests and starts no service. The separate optional Audit
Core interoperability suite still requires `HUB_CORE_AUDIT_CORE_SOURCE` and is
not silently represented as covered by ordinary CI. Local CI-equivalent success
is not a deployed Forgejo receipt or live owner/platform acceptance.
## Disposable PostgreSQL gate
`make postgres-test` enables `tests/test_postgres_integration.py`. It creates its
own Docker container and a separate database for each test, then removes both.
It never accepts an operator database URL. The container uses a random fixture
password, a loopback-only ephemeral port and tmpfs data storage. The PostgreSQL
16 Alpine image is pinned by digest in the test file. Readiness waits for TCP so
the image's temporary initialization server cannot be mistaken for the final one.
The tests run the entire packaged Alembic chain through `0006_outcome_outbox`,
check the pending-outcome downgrade guard and re-upgrade, demonstrate concurrent
`SKIP LOCKED` delivery, roll back business and ledger writes after an outbox
failure, and verify persisted retry state. A child worker exits with `os._exit`
after writing a synthetic receiver receipt but before committing its local
acknowledgement; a new connection then replays the identical envelope.
This is a required gate of `make ci-check`, including Forgejo. The runner needs
Docker daemon access and the pinned image cached or registry pull access. Missing
Docker/image access fails this gate; it does not silently pass. Ordinary pytest
skips this module unless `HUB_CORE_TEST_POSTGRES=1`; the dedicated gate enables it
explicitly. Tests use disposable superuser credentials and synthetic custody,
so production runtime grants and live receiver admission remain separate checks.

View file

@ -82,8 +82,10 @@ The real Audit Core receiver/storage source accepts the eight-field envelope and
returns a duplicate receipt on replay. Its operational-readiness classification
is explicitly a test fixture; this is not live custody evidence.
PostgreSQL multiworker lock scheduling, production grants, retention and deployed
failure-detection/receiver acceptance still require integration receipts.
Disposable PostgreSQL tests now verify multiworker lock scheduling, the full
migration chain, rollback, persisted retries and process-exit replay. See the
[PostgreSQL gate](conformance.md#disposable-postgresql-gate). Production grants,
retention and deployed failure-detection/receiver acceptance still require receipts.
Validation on 2026-09-28: 366 tests pass with the opt-in owner-source suite enabled;
inventory drift, package build and isolated installed-wheel checks pass. The