commit 1c6de529ee3e5af711ccdfaf9eda8aba6fdd1504
parent fd6b2a47f7fee459aa4de2091275cc3cb96af83d
Author: triesap <tyson@radroots.org>
Date: Wed, 23 Sep 2026 14:04:34 +0000
test(hyf): verify measurement identity and child environment (H005A review)
- Record the exact capsule source revision and working directory in the measurement identity instead of resting source identity on an external receipt.
- Read the measured child's HYF_PATHS profile back from the live environment and raise when the source revision is unavailable, so the recorded profile is verified rather than asserted.
- Apply the verified profile through the scoped environment in the measurement lane and standalone runner, and treat any nonzero sampler exit as an unavailable descriptor census.
- Keep the tooling test-only; no product src, schema, dependency or pixi.lock change.
Diffstat:
3 files changed, 154 insertions(+), 73 deletions(-)
diff --git a/tests/measurement_process_helper.mojo b/tests/measurement_process_helper.mojo
@@ -20,6 +20,7 @@ Explicit failure policy (R56/R57):
child is always terminated and reaped through the shared ownership guard.
"""
+import std.os
from std.collections import List
from std.ffi import CStringSlice, c_int, external_call
@@ -85,6 +86,7 @@ def run_capture(
var args: List[String],
deadline_ms: Int,
mut guard: CleanupGuard,
+ cwd: String = "",
) raises -> CommandOutput:
"""Run one bounded child command and capture its stdout/stderr.
@@ -115,6 +117,8 @@ def run_capture(
var stderr_write_fd = pipes.stderr_pipe.write_fd
var command_ptr = elements[0].as_c_string_slice().unsafe_ptr()
var argv_ptr = argv.unsafe_ptr()
+ var cwd_local = String(cwd)
+ var cwd_ptr = cwd_local.as_c_string_slice().unsafe_ptr()
var pid = fork_owned_or_close3(pipes)
if pid == 0:
@@ -130,6 +134,9 @@ def run_capture(
close_fd(stdout_write_fd)
close_fd(stderr_read_fd)
close_fd(stderr_write_fd)
+ if cwd != "":
+ if Int(external_call["chdir", c_int](cwd_ptr)) != 0:
+ child_exit(126)
_ = set_alarm(MEASUREMENT_CHILD_ALARM_SECONDS)
_ = external_call["execvp", c_int](command_ptr, argv_ptr)
child_exit(127)
@@ -321,6 +328,8 @@ struct MeasurementIdentity(Movable):
"""Exact source/binary/toolchain/host identity and launch profile."""
var source_root: String
+ var source_revision: String
+ var cwd: String
var binary_path: String
var binary_sha256: String
var pixi_toml_sha256: String
@@ -332,7 +341,11 @@ struct MeasurementIdentity(Movable):
def describe(self) -> String:
return (
- "binary_sha256="
+ "source_revision="
+ + self.source_revision
+ + " cwd="
+ + self.cwd
+ + " binary_sha256="
+ self.binary_sha256
+ " pixi_toml_sha256="
+ self.pixi_toml_sha256
@@ -376,15 +389,59 @@ def build_product_binary(
return output^
+def source_revision(
+ source_root: String, mut guard: CleanupGuard
+) raises -> String:
+ """Exact capsule source revision; a measurement must not guess it."""
+ var args = List[String]()
+ args.append("rev-parse")
+ args.append("HEAD")
+ var out = run_capture(
+ "git", args^, MEASUREMENT_SAMPLE_DEADLINE_MS, guard, source_root
+ )
+ var text = String(out.stdout.strip())
+ if out.exit_code != 0 or text.byte_length() != 40:
+ raise Error(
+ "measurement: source revision unavailable in " + source_root
+ )
+ return text^
+
+
+def working_directory(mut guard: CleanupGuard) raises -> String:
+ var args = List[String]()
+ var out = run_capture_simple("pwd", args^, guard)
+ if out.exit_code != 0:
+ raise Error("measurement: working directory unavailable")
+ return String(out.stdout.strip())
+
+
+def verified_environment_profile() -> String:
+ """The environment actually inherited by the measured child, read back.
+
+ Recorded from the live process environment rather than asserted, so the
+ reproduced profile is truthful: the measured child inherits exactly these
+ values through ``execvp``.
+ """
+ var profile = std.os.getenv("HYF_PATHS_PROFILE")
+ var root = std.os.getenv("HYF_PATHS_REPO_LOCAL_ROOT")
+ return (
+ "HYF_PATHS_PROFILE="
+ + (profile if profile != "" else "<unset>")
+ + " HYF_PATHS_REPO_LOCAL_ROOT="
+ + (root if root != "" else "<unset>")
+ )
+
+
def measurement_identity(
source_root: String,
binary_path: String,
argv_profile: String,
- env_profile: String,
mut guard: CleanupGuard,
) raises -> MeasurementIdentity:
return MeasurementIdentity(
source_root=source_root,
+ source_revision=source_revision(source_root, guard),
+ cwd=working_directory(guard),
binary_path=binary_path,
binary_sha256=file_sha256(binary_path, guard),
pixi_toml_sha256=file_sha256(source_root + "/pixi.toml", guard),
@@ -392,7 +449,7 @@ def measurement_identity(
toolchain_version=toolchain_version(guard),
host_platform=host_platform(guard),
argv_profile=argv_profile,
- env_profile=env_profile,
+ env_profile=verified_environment_profile(),
)
@@ -748,7 +805,7 @@ def sample_fd_count(
args.append("-F")
args.append("f")
var out = run_capture(command, args^, MEASUREMENT_SAMPLE_DEADLINE_MS, guard)
- if out.exit_code != 0 and out.stdout.strip().byte_length() == 0:
+ if out.exit_code != 0:
raise Error(
"measurement: descriptor sampling unavailable ("
+ command
@@ -862,8 +919,9 @@ def measure_persistent_process(
"""
if warmup_frames < 0 or measured_frames < 1:
raise Error("measurement: invalid warmup/measured frame counts")
+ _ = env_profile
var identity = measurement_identity(
- source_root, binary_path, argv_profile, env_profile, guard
+ source_root, binary_path, argv_profile, guard
)
var process = spawn_measurement_process(
identity.binary_path, argv^, deadline_ms, guard
diff --git a/tests/measurement_runner.mojo b/tests/measurement_runner.mojo
@@ -12,6 +12,11 @@ from std.collections import List
from safe_tempdir import SafeTempDir
from parent_lifecycle import CleanupGuard
+from stdio_process_helper import (
+ HYF_PATHS_PROFILE_ENV,
+ HYF_PATHS_REPO_LOCAL_ROOT_ENV,
+ ScopedEnvVar,
+)
from measurement_process_helper import (
build_product_binary,
measure_persistent_process,
@@ -26,22 +31,27 @@ comptime MEASURED_FRAMES = 1000
def main() raises:
var guard = CleanupGuard()
with SafeTempDir() as temp_dir:
- var binary = build_product_binary(temp_dir, guard)
- var argv = List[String]()
- var measured = measure_persistent_process(
- ".",
- binary,
- "argv=[<hyfd>]",
- "env=HYF_PATHS_PROFILE=repo_local HYF_PATHS_REPO_LOCAL_ROOT=<temp>",
- argv^,
- WARMUP_FRAMES,
- MEASURED_FRAMES,
- MEASUREMENT_DEADLINE_MS,
- guard,
- )
- print("h005a.identity", measured.identity.describe())
- print("h005a.measurement", measured.summary())
- print("h005a.sampling_method", measured.sampling_method)
- print("h005a.stderr_bytes", measured.stderr_excerpt.byte_length())
+ with ScopedEnvVar(HYF_PATHS_PROFILE_ENV, "repo_local"):
+ with ScopedEnvVar(HYF_PATHS_REPO_LOCAL_ROOT_ENV, temp_dir):
+ var binary = build_product_binary(temp_dir, guard)
+ var argv = List[String]()
+ var measured = measure_persistent_process(
+ ".",
+ binary,
+ "argv=[<hyfd>]",
+ "env=verified at run time",
+ argv^,
+ WARMUP_FRAMES,
+ MEASURED_FRAMES,
+ MEASUREMENT_DEADLINE_MS,
+ guard,
+ )
+ print("h005a.identity", measured.identity.describe())
+ print("h005a.measurement", measured.summary())
+ print("h005a.sampling_method", measured.sampling_method)
+ print(
+ "h005a.stderr_bytes",
+ measured.stderr_excerpt.byte_length(),
+ )
guard.assert_clean()
print("h005a_measurement: ok")
diff --git a/tests/test_measurement_contract.mojo b/tests/test_measurement_contract.mojo
@@ -88,59 +88,72 @@ def _run_sh_measurement(
def test_persistent_measurement_validates_every_frame() raises:
# D29: one process serves warmup and measured frames; every frame has a
# parsed envelope, matching correlation and expected outcome, with numeric
- # RSS/FD samples, a checked child exit and proved cleanup.
+ # RSS/FD samples, a checked child exit and proved cleanup. The recorded
+ # environment profile is the verified live profile of the measured child.
var guard = CleanupGuard()
with SafeTempDir() as temp_dir:
- var binary = build_product_binary(temp_dir, guard)
- assert_true(file_sha256(binary, guard).byte_length() == 64)
- var argv = List[String]()
- var session = measure_persistent_process(
- ".",
- binary,
- "argv=[<hyfd>]",
- "env=HYF_PATHS_PROFILE=repo_local HYF_PATHS_REPO_LOCAL_ROOT=<temp>",
- argv^,
- WARMUP_FRAMES,
- MEASURED_FRAMES,
- MEASUREMENT_DEADLINE_MS,
- guard,
- )
- assert_equal(session.ok_frames, WARMUP_FRAMES + MEASURED_FRAMES)
- assert_equal(session.failed_frames, 0)
- assert_equal(session.first_failure, "")
- # Startup, warmup and measured timing are recorded separately (ms).
- assert_true(session.startup_ms >= 0)
- assert_true(session.measured_ms >= 0)
- # Numeric sampling with recorded units and method.
- assert_true(session.rss_kb_before_warmup > 0)
- assert_true(session.rss_kb_after_warmup > 0)
- assert_true(session.rss_kb_after_measured > 0)
- assert_true(session.rss_kb_peak >= session.rss_kb_after_warmup)
- assert_true(session.fd_before_warmup > 0)
- assert_true(session.fd_after_measured > 0)
- assert_true(session.fd_peak >= session.fd_after_measured)
- assert_true(session.sampling_method.find("kB") >= 0)
- assert_true(session.sampling_method.find("-F f") >= 0)
- # The declared per-process request policy is characterized, not assumed:
- # it is a declared limit that the persistent loop does not enforce.
- assert_equal(session.declared_max_requests_per_process, 1)
- assert_true(session.child_exit.find("exited=0") >= 0)
- assert_true(session.stderr_excerpt == "")
- # Identity is exact and reproducible.
- assert_equal(len(session.identity.binary_sha256), 64)
- assert_equal(len(session.identity.pixi_lock_sha256), 64)
- assert_equal(len(session.identity.pixi_toml_sha256), 64)
- assert_true(session.identity.toolchain_version != "")
- assert_true(
- session.identity.host_platform.find("Darwin") >= 0
- or session.identity.host_platform.find("Linux") >= 0
- )
- assert_true(
- session.summary().find(
- "frames=" + String(WARMUP_FRAMES + MEASURED_FRAMES)
- )
- >= 0
- )
+ with ScopedEnvVar(HYF_PATHS_PROFILE_ENV, "repo_local"):
+ with ScopedEnvVar(HYF_PATHS_REPO_LOCAL_ROOT_ENV, temp_dir):
+ var binary = build_product_binary(temp_dir, guard)
+ assert_true(file_sha256(binary, guard).byte_length() == 64)
+ var argv = List[String]()
+ var session = measure_persistent_process(
+ ".",
+ binary,
+ "argv=[<hyfd>]",
+ "env=verified at run time",
+ argv^,
+ WARMUP_FRAMES,
+ MEASURED_FRAMES,
+ MEASUREMENT_DEADLINE_MS,
+ guard,
+ )
+ assert_equal(session.ok_frames, WARMUP_FRAMES + MEASURED_FRAMES)
+ assert_equal(session.failed_frames, 0)
+ assert_equal(session.first_failure, "")
+ # Startup, warmup and measured timing are recorded separately (ms).
+ assert_true(session.startup_ms >= 0)
+ assert_true(session.measured_ms >= 0)
+ # Numeric sampling with recorded units and method.
+ assert_true(session.rss_kb_before_warmup > 0)
+ assert_true(session.rss_kb_after_warmup > 0)
+ assert_true(session.rss_kb_after_measured > 0)
+ assert_true(session.rss_kb_peak >= session.rss_kb_after_warmup)
+ assert_true(session.fd_before_warmup > 0)
+ assert_true(session.fd_after_measured > 0)
+ assert_true(session.fd_peak >= session.fd_after_measured)
+ assert_true(session.sampling_method.find("kB") >= 0)
+ assert_true(session.sampling_method.find("-F f") >= 0)
+ # The declared per-process request policy is characterized, not
+ # assumed: the persistent loop does not enforce it.
+ assert_equal(session.declared_max_requests_per_process, 1)
+ assert_true(session.child_exit.find("exited=0") >= 0)
+ assert_true(session.stderr_excerpt == "")
+ # Exact, truthful identity: source revision, cwd, binary, pixi
+ # files, toolchain, host and the verified environment profile.
+ assert_equal(len(session.identity.binary_sha256), 64)
+ assert_equal(len(session.identity.pixi_lock_sha256), 64)
+ assert_equal(len(session.identity.pixi_toml_sha256), 64)
+ assert_equal(len(session.identity.source_revision), 40)
+ assert_true(session.identity.cwd.find("oss/hyf") >= 0)
+ assert_true(
+ session.identity.env_profile.find(
+ "HYF_PATHS_PROFILE=repo_local"
+ )
+ >= 0
+ )
+ assert_true(session.identity.env_profile.find(temp_dir) >= 0)
+ assert_true(session.identity.toolchain_version != "")
+ assert_true(
+ session.identity.host_platform.find("Darwin") >= 0
+ or session.identity.host_platform.find("Linux") >= 0
+ )
+ assert_true(
+ session.summary().find(
+ "frames=" + String(WARMUP_FRAMES + MEASURED_FRAMES)
+ )
+ >= 0
+ )
guard.assert_clean()