Some checks failed
Governed runtime contract / contract (push) Failing after 16s
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e387-534d-70e3-ad53-4ea05676db8c
70 lines
3.8 KiB
Python
70 lines
3.8 KiB
Python
"""Repair the one unclaimed proof row from its existing typed owner definition.
|
|
|
|
Run inside the Activity Core owner process context, first without --apply.
|
|
No trigger, claim, inferred authority, retry, or new task is created.
|
|
"""
|
|
import asyncio
|
|
import json
|
|
import sys
|
|
import uuid
|
|
|
|
RUN = "6efa9436-6a91-47c0-94e5-b31b5a0e7e3a"
|
|
DEFINITION = "5bae5505-77f1-5ba3-8dfa-2e10ed15531e"
|
|
TRIGGER = "manual-dab6c4c7-db03-4887-a17b-9d99b752482e"
|
|
GRANT = {"version": "1", "allowed_paths": ["PROOF.md"], "commit_count": {"min": 1, "max": 1}, "publish": False}
|
|
|
|
|
|
def validate(definition, row, live_worker_image):
|
|
if live_worker_image != "sha256:713bddad10a41950f446100a8b370fca8ccdd0b8969cccae751e3870c9c63ccd":
|
|
raise ValueError("grant_aware_worker_required")
|
|
if str(definition.id) != DEFINITION or definition.enabled or definition.version != 1:
|
|
raise ValueError("definition_drift")
|
|
rules = definition.rules_json
|
|
if len(rules) != 1 or rules[0]["id"] != "execute-hfact-glas-metered-proof" or rules[0]["condition"] != "True":
|
|
raise ValueError("rule_drift")
|
|
action = rules[0]["action"]
|
|
if action.get("repository_grant") != GRANT or action.get("target_repo") != "hfact-glas-proof" or action.get("harness_profile_ref") != "harness.agent-dev-local@1.1.1" or action.get("labels") != ["hfact-metered"]:
|
|
raise ValueError("typed_authority_drift")
|
|
expected = dict(id=RUN, activity_definition_id=DEFINITION, state="open", attempt=0, claim_owner=None, lease_until=None, target_repo="hfact-glas-proof", harness_profile_ref="harness.agent-dev-local@1.1.1", triggering_event_id=TRIGGER, source_type="rule", source_id=rules[0]["id"], repository_grant=None)
|
|
for field, value in expected.items():
|
|
actual = getattr(row, field)
|
|
if field in ("id", "activity_definition_id"):
|
|
actual = str(actual)
|
|
if actual != value:
|
|
raise ValueError("queue_row_drift")
|
|
if row.description != action["description"] or row.title != action["task_template"] or row.labels != action["labels"]:
|
|
raise ValueError("task_content_drift")
|
|
return action["repository_grant"]
|
|
|
|
|
|
async def main(apply, image):
|
|
from sqlalchemy import select
|
|
from sqlalchemy.ext.asyncio import async_sessionmaker
|
|
from activity_core.db import make_engine
|
|
from activity_core.orm import ActivityDefinition, OpsRun
|
|
from activity_core.repository_grant import RepositoryGrant
|
|
engine = make_engine()
|
|
try:
|
|
async with async_sessionmaker(engine, expire_on_commit=False)() as session:
|
|
async with session.begin():
|
|
definition = (await session.execute(select(ActivityDefinition).where(ActivityDefinition.id == uuid.UUID(DEFINITION)).with_for_update())).scalar_one()
|
|
row = (await session.execute(select(OpsRun).where(OpsRun.id == uuid.UUID(RUN)).with_for_update())).scalar_one()
|
|
grant = RepositoryGrant.model_validate(validate(definition, row, image))
|
|
if grant.grant_id != "656911f7dff83e871434b415f0cee685":
|
|
raise ValueError("spend_grant_binding_mismatch")
|
|
if apply:
|
|
row.repository_grant = grant.payload()
|
|
receipt = dict(status="applied" if apply else "dry_run_passed", run_id=RUN, definition_id=DEFINITION, definition_version=1, triggering_event_id=TRIGGER, source="typed_existing_definition_rule", grant_id=grant.grant_id, grant=grant.payload(), attempt=0, claim_owner=None, new_trigger=False, new_task=False)
|
|
print(json.dumps(receipt, indent=2))
|
|
finally:
|
|
await engine.dispose()
|
|
|
|
|
|
if __name__ == "__main__":
|
|
args = sys.argv[1:]
|
|
apply = args[:1] == ["--apply"]
|
|
if apply:
|
|
args = args[1:]
|
|
if len(args) != 1:
|
|
raise SystemExit("Supply the independently observed live worker image digest")
|
|
asyncio.run(main(apply, args[0]))
|