betterwithage Claude Opus 4.7 commited on
Commit
97e31a9
·
verified ·
1 Parent(s): e78672f

deploy(hf): sync szl-holdings/a11oy@19cb88a6a814e7a54e9ec683e0b478397a595466 derived COPY set

Browse files

Reusable Dockerfile-COPY-derived deploy from szl-holdings/a11oy 19cb88a6a814e7a54e9ec683e0b478397a595466.
Files: 1179 Pruned: 0
Derived from Dockerfile COPY sources (NO hand-maintained allowlist).

Signed-off-by: SZL Holdings <noreply@szlholdings.ai>
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

Files changed (2) hide show
  1. gdw_runtime.py +62 -24
  2. gdw_workspace.py +10 -2
gdw_runtime.py CHANGED
@@ -15,6 +15,7 @@ from typing import Any, Mapping, Optional
15
  from gdw_proofs import (
16
  export_proof_payload,
17
  export_receipt_projection,
 
18
  )
19
  from gdw_workspace import GDWWorkspace
20
 
@@ -270,6 +271,34 @@ def _verify_effect_binding(
270
  raise ValueError("invalid effect binding: " + ",".join(errors))
271
 
272
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
273
  def _export_effect(
274
  workspace: GDWWorkspace,
275
  row: Mapping[str, Any],
@@ -328,30 +357,39 @@ def drain_once(
328
  remaining = bounded - exported - failed
329
  if remaining <= 0:
330
  break
331
- if not store.production:
332
- for row in store.pending_proofs(
333
- remaining,
334
- namespace=namespace,
335
- owner_id=owner_id,
336
- ):
337
- try:
338
- artifact = export_proof_payload(
339
- row["payload"],
340
- owner_id=owner_id,
341
- )
342
- store.mark_proof_exported(
343
- row["proposal_id"],
344
- artifact,
345
- _now(),
346
- namespace=namespace,
347
- owner_id=owner_id,
348
- )
349
- exported += 1
350
- except Exception as exc:
351
- failed += 1
352
- errors.append(f"legacy:{type(exc).__name__}")
353
- if exported + failed >= bounded:
354
- break
 
 
 
 
 
 
 
 
 
355
 
356
  remaining = bounded - exported - failed
357
  if remaining <= 0:
 
15
  from gdw_proofs import (
16
  export_proof_payload,
17
  export_receipt_projection,
18
+ sha256_json,
19
  )
20
  from gdw_workspace import GDWWorkspace
21
 
 
271
  raise ValueError("invalid effect binding: " + ",".join(errors))
272
 
273
 
274
+ def _verify_legacy_proof_binding(
275
+ workspace: GDWWorkspace,
276
+ row: Mapping[str, Any],
277
+ ) -> None:
278
+ payload = row["payload"]
279
+ claimed_digest = str(payload.get("payload_sha256") or "")
280
+ unsigned_payload = dict(payload)
281
+ unsigned_payload.pop("payload_sha256", None)
282
+ if row["proposal_id"] != payload.get("proposal_id"):
283
+ raise ValueError("legacy proof proposal binding is invalid")
284
+ if row["payload_sha256"] != claimed_digest:
285
+ raise ValueError("legacy proof row digest is invalid")
286
+ if claimed_digest != sha256_json(unsigned_payload):
287
+ raise ValueError("legacy proof payload digest is invalid")
288
+ for field, expected in (
289
+ ("namespace", row["namespace"]),
290
+ ("owner_id", row["owner_id"]),
291
+ ):
292
+ if field in payload and payload[field] != expected:
293
+ raise ValueError(f"legacy proof {field} binding is invalid")
294
+ if (
295
+ "database_generation_id" in payload
296
+ and payload["database_generation_id"]
297
+ != workspace.database_generation_id
298
+ ):
299
+ raise ValueError("legacy proof database generation binding is invalid")
300
+
301
+
302
  def _export_effect(
303
  workspace: GDWWorkspace,
304
  row: Mapping[str, Any],
 
357
  remaining = bounded - exported - failed
358
  if remaining <= 0:
359
  break
360
+ for row in store.pending_proofs(
361
+ remaining,
362
+ namespace=namespace,
363
+ owner_id=owner_id,
364
+ ):
365
+ try:
366
+ _verify_legacy_proof_binding(store, row)
367
+ artifact = export_proof_payload(
368
+ row["payload"],
369
+ artifact_id=row["payload_sha256"],
370
+ owner_id=owner_id,
371
+ )
372
+ artifact.update(
373
+ {
374
+ "migration_status": "LEGACY_PROOF_PRESERVED",
375
+ "source_payload_sha256": row["payload_sha256"],
376
+ }
377
+ )
378
+ store.mark_proof_exported(
379
+ row["proposal_id"],
380
+ artifact,
381
+ _now(),
382
+ expected_payload=row["payload"],
383
+ expected_payload_sha256=row["payload_sha256"],
384
+ namespace=namespace,
385
+ owner_id=owner_id,
386
+ )
387
+ exported += 1
388
+ except Exception as exc:
389
+ failed += 1
390
+ errors.append(f"legacy:{type(exc).__name__}")
391
+ if exported + failed >= bounded:
392
+ break
393
 
394
  remaining = bounded - exported - failed
395
  if remaining <= 0:
gdw_workspace.py CHANGED
@@ -2189,18 +2189,22 @@ class GDWWorkspace:
2189
  artifact: Dict[str, Any],
2190
  exported_at: str,
2191
  *,
 
 
2192
  namespace: Optional[str] = None,
2193
  owner_id: Optional[str] = None,
2194
  ) -> None:
2195
  ns, owner = self._identity(namespace, owner_id)
2196
  artifact_text = _json_text(artifact)
 
2197
  with self.transaction() as connection:
2198
  updated = connection.execute(
2199
  """
2200
  UPDATE proof_outbox
2201
  SET status = 'EXPORTED', artifact_json = ?, exported_at = ?
2202
  WHERE namespace = ? AND owner_id = ? AND proposal_id = ?
2203
- AND status = 'PENDING'
 
2204
  """,
2205
  (
2206
  artifact_text,
@@ -2208,10 +2212,14 @@ class GDWWorkspace:
2208
  ns,
2209
  owner,
2210
  proposal_id,
 
 
2211
  ),
2212
  )
2213
  if updated.rowcount != 1:
2214
- raise RuntimeError("proof is absent, exported, or owned elsewhere")
 
 
2215
  self._reserve_usage(
2216
  connection,
2217
  ns,
 
2189
  artifact: Dict[str, Any],
2190
  exported_at: str,
2191
  *,
2192
+ expected_payload: Dict[str, Any],
2193
+ expected_payload_sha256: str,
2194
  namespace: Optional[str] = None,
2195
  owner_id: Optional[str] = None,
2196
  ) -> None:
2197
  ns, owner = self._identity(namespace, owner_id)
2198
  artifact_text = _json_text(artifact)
2199
+ expected_payload_text = _json_text(expected_payload)
2200
  with self.transaction() as connection:
2201
  updated = connection.execute(
2202
  """
2203
  UPDATE proof_outbox
2204
  SET status = 'EXPORTED', artifact_json = ?, exported_at = ?
2205
  WHERE namespace = ? AND owner_id = ? AND proposal_id = ?
2206
+ AND status = 'PENDING' AND payload_json = ?
2207
+ AND payload_sha256 = ?
2208
  """,
2209
  (
2210
  artifact_text,
 
2212
  ns,
2213
  owner,
2214
  proposal_id,
2215
+ expected_payload_text,
2216
+ expected_payload_sha256,
2217
  ),
2218
  )
2219
  if updated.rowcount != 1:
2220
+ raise RuntimeError(
2221
+ "proof is absent, changed, exported, or owned elsewhere"
2222
+ )
2223
  self._reserve_usage(
2224
  connection,
2225
  ns,