hyf

Context-aware query service for Radroots
git clone https://radroots.dev/git/hyf.git
Log | Files | Refs | README | LICENSE

commit 1c6de529ee3e5af711ccdfaf9eda8aba6fdd1504
parent fd6b2a47f7fee459aa4de2091275cc3cb96af83d
Author: triesap <tyson@radroots.org>
Date:   Wed, 23 Sep 2026 14:04:34 +0000

test(hyf): verify measurement identity and child environment (H005A review)

- Record the exact capsule source revision and working directory in the measurement identity instead of resting source identity on an external receipt.
- Read the measured child's HYF_PATHS profile back from the live environment and raise when the source revision is unavailable, so the recorded profile is verified rather than asserted.
- Apply the verified profile through the scoped environment in the measurement lane and standalone runner, and treat any nonzero sampler exit as an unavailable descriptor census.
- Keep the tooling test-only; no product src, schema, dependency or pixi.lock change.

Diffstat:
Mtests/measurement_process_helper.mojo | 68+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++-----
Mtests/measurement_runner.mojo | 44+++++++++++++++++++++++++++-----------------
Mtests/test_measurement_contract.mojo | 115++++++++++++++++++++++++++++++++++++++++++++-----------------------------------
3 files changed, 154 insertions(+), 73 deletions(-)

diff --git a/tests/measurement_process_helper.mojo b/tests/measurement_process_helper.mojo @@ -20,6 +20,7 @@ Explicit failure policy (R56/R57): child is always terminated and reaped through the shared ownership guard. """ +import std.os from std.collections import List from std.ffi import CStringSlice, c_int, external_call @@ -85,6 +86,7 @@ def run_capture( var args: List[String], deadline_ms: Int, mut guard: CleanupGuard, + cwd: String = "", ) raises -> CommandOutput: """Run one bounded child command and capture its stdout/stderr. @@ -115,6 +117,8 @@ def run_capture( var stderr_write_fd = pipes.stderr_pipe.write_fd var command_ptr = elements[0].as_c_string_slice().unsafe_ptr() var argv_ptr = argv.unsafe_ptr() + var cwd_local = String(cwd) + var cwd_ptr = cwd_local.as_c_string_slice().unsafe_ptr() var pid = fork_owned_or_close3(pipes) if pid == 0: @@ -130,6 +134,9 @@ def run_capture( close_fd(stdout_write_fd) close_fd(stderr_read_fd) close_fd(stderr_write_fd) + if cwd != "": + if Int(external_call["chdir", c_int](cwd_ptr)) != 0: + child_exit(126) _ = set_alarm(MEASUREMENT_CHILD_ALARM_SECONDS) _ = external_call["execvp", c_int](command_ptr, argv_ptr) child_exit(127) @@ -321,6 +328,8 @@ struct MeasurementIdentity(Movable): """Exact source/binary/toolchain/host identity and launch profile.""" var source_root: String + var source_revision: String + var cwd: String var binary_path: String var binary_sha256: String var pixi_toml_sha256: String @@ -332,7 +341,11 @@ struct MeasurementIdentity(Movable): def describe(self) -> String: return ( - "binary_sha256=" + "source_revision=" + + self.source_revision + + " cwd=" + + self.cwd + + " binary_sha256=" + self.binary_sha256 + " pixi_toml_sha256=" + self.pixi_toml_sha256 @@ -376,15 +389,59 @@ def build_product_binary( return output^ +def source_revision( + source_root: String, mut guard: CleanupGuard +) raises -> String: + """Exact capsule source revision; a measurement must not guess it.""" + var args = List[String]() + args.append("rev-parse") + args.append("HEAD") + var out = run_capture( + "git", args^, MEASUREMENT_SAMPLE_DEADLINE_MS, guard, source_root + ) + var text = String(out.stdout.strip()) + if out.exit_code != 0 or text.byte_length() != 40: + raise Error( + "measurement: source revision unavailable in " + source_root + ) + return text^ + + +def working_directory(mut guard: CleanupGuard) raises -> String: + var args = List[String]() + var out = run_capture_simple("pwd", args^, guard) + if out.exit_code != 0: + raise Error("measurement: working directory unavailable") + return String(out.stdout.strip()) + + +def verified_environment_profile() -> String: + """The environment actually inherited by the measured child, read back. + + Recorded from the live process environment rather than asserted, so the + reproduced profile is truthful: the measured child inherits exactly these + values through ``execvp``. + """ + var profile = std.os.getenv("HYF_PATHS_PROFILE") + var root = std.os.getenv("HYF_PATHS_REPO_LOCAL_ROOT") + return ( + "HYF_PATHS_PROFILE=" + + (profile if profile != "" else "<unset>") + + " HYF_PATHS_REPO_LOCAL_ROOT=" + + (root if root != "" else "<unset>") + ) + + def measurement_identity( source_root: String, binary_path: String, argv_profile: String, - env_profile: String, mut guard: CleanupGuard, ) raises -> MeasurementIdentity: return MeasurementIdentity( source_root=source_root, + source_revision=source_revision(source_root, guard), + cwd=working_directory(guard), binary_path=binary_path, binary_sha256=file_sha256(binary_path, guard), pixi_toml_sha256=file_sha256(source_root + "/pixi.toml", guard), @@ -392,7 +449,7 @@ def measurement_identity( toolchain_version=toolchain_version(guard), host_platform=host_platform(guard), argv_profile=argv_profile, - env_profile=env_profile, + env_profile=verified_environment_profile(), ) @@ -748,7 +805,7 @@ def sample_fd_count( args.append("-F") args.append("f") var out = run_capture(command, args^, MEASUREMENT_SAMPLE_DEADLINE_MS, guard) - if out.exit_code != 0 and out.stdout.strip().byte_length() == 0: + if out.exit_code != 0: raise Error( "measurement: descriptor sampling unavailable (" + command @@ -862,8 +919,9 @@ def measure_persistent_process( """ if warmup_frames < 0 or measured_frames < 1: raise Error("measurement: invalid warmup/measured frame counts") + _ = env_profile var identity = measurement_identity( - source_root, binary_path, argv_profile, env_profile, guard + source_root, binary_path, argv_profile, guard ) var process = spawn_measurement_process( identity.binary_path, argv^, deadline_ms, guard diff --git a/tests/measurement_runner.mojo b/tests/measurement_runner.mojo @@ -12,6 +12,11 @@ from std.collections import List from safe_tempdir import SafeTempDir from parent_lifecycle import CleanupGuard +from stdio_process_helper import ( + HYF_PATHS_PROFILE_ENV, + HYF_PATHS_REPO_LOCAL_ROOT_ENV, + ScopedEnvVar, +) from measurement_process_helper import ( build_product_binary, measure_persistent_process, @@ -26,22 +31,27 @@ comptime MEASURED_FRAMES = 1000 def main() raises: var guard = CleanupGuard() with SafeTempDir() as temp_dir: - var binary = build_product_binary(temp_dir, guard) - var argv = List[String]() - var measured = measure_persistent_process( - ".", - binary, - "argv=[<hyfd>]", - "env=HYF_PATHS_PROFILE=repo_local HYF_PATHS_REPO_LOCAL_ROOT=<temp>", - argv^, - WARMUP_FRAMES, - MEASURED_FRAMES, - MEASUREMENT_DEADLINE_MS, - guard, - ) - print("h005a.identity", measured.identity.describe()) - print("h005a.measurement", measured.summary()) - print("h005a.sampling_method", measured.sampling_method) - print("h005a.stderr_bytes", measured.stderr_excerpt.byte_length()) + with ScopedEnvVar(HYF_PATHS_PROFILE_ENV, "repo_local"): + with ScopedEnvVar(HYF_PATHS_REPO_LOCAL_ROOT_ENV, temp_dir): + var binary = build_product_binary(temp_dir, guard) + var argv = List[String]() + var measured = measure_persistent_process( + ".", + binary, + "argv=[<hyfd>]", + "env=verified at run time", + argv^, + WARMUP_FRAMES, + MEASURED_FRAMES, + MEASUREMENT_DEADLINE_MS, + guard, + ) + print("h005a.identity", measured.identity.describe()) + print("h005a.measurement", measured.summary()) + print("h005a.sampling_method", measured.sampling_method) + print( + "h005a.stderr_bytes", + measured.stderr_excerpt.byte_length(), + ) guard.assert_clean() print("h005a_measurement: ok") diff --git a/tests/test_measurement_contract.mojo b/tests/test_measurement_contract.mojo @@ -88,59 +88,72 @@ def _run_sh_measurement( def test_persistent_measurement_validates_every_frame() raises: # D29: one process serves warmup and measured frames; every frame has a # parsed envelope, matching correlation and expected outcome, with numeric - # RSS/FD samples, a checked child exit and proved cleanup. + # RSS/FD samples, a checked child exit and proved cleanup. The recorded + # environment profile is the verified live profile of the measured child. var guard = CleanupGuard() with SafeTempDir() as temp_dir: - var binary = build_product_binary(temp_dir, guard) - assert_true(file_sha256(binary, guard).byte_length() == 64) - var argv = List[String]() - var session = measure_persistent_process( - ".", - binary, - "argv=[<hyfd>]", - "env=HYF_PATHS_PROFILE=repo_local HYF_PATHS_REPO_LOCAL_ROOT=<temp>", - argv^, - WARMUP_FRAMES, - MEASURED_FRAMES, - MEASUREMENT_DEADLINE_MS, - guard, - ) - assert_equal(session.ok_frames, WARMUP_FRAMES + MEASURED_FRAMES) - assert_equal(session.failed_frames, 0) - assert_equal(session.first_failure, "") - # Startup, warmup and measured timing are recorded separately (ms). - assert_true(session.startup_ms >= 0) - assert_true(session.measured_ms >= 0) - # Numeric sampling with recorded units and method. - assert_true(session.rss_kb_before_warmup > 0) - assert_true(session.rss_kb_after_warmup > 0) - assert_true(session.rss_kb_after_measured > 0) - assert_true(session.rss_kb_peak >= session.rss_kb_after_warmup) - assert_true(session.fd_before_warmup > 0) - assert_true(session.fd_after_measured > 0) - assert_true(session.fd_peak >= session.fd_after_measured) - assert_true(session.sampling_method.find("kB") >= 0) - assert_true(session.sampling_method.find("-F f") >= 0) - # The declared per-process request policy is characterized, not assumed: - # it is a declared limit that the persistent loop does not enforce. - assert_equal(session.declared_max_requests_per_process, 1) - assert_true(session.child_exit.find("exited=0") >= 0) - assert_true(session.stderr_excerpt == "") - # Identity is exact and reproducible. - assert_equal(len(session.identity.binary_sha256), 64) - assert_equal(len(session.identity.pixi_lock_sha256), 64) - assert_equal(len(session.identity.pixi_toml_sha256), 64) - assert_true(session.identity.toolchain_version != "") - assert_true( - session.identity.host_platform.find("Darwin") >= 0 - or session.identity.host_platform.find("Linux") >= 0 - ) - assert_true( - session.summary().find( - "frames=" + String(WARMUP_FRAMES + MEASURED_FRAMES) - ) - >= 0 - ) + with ScopedEnvVar(HYF_PATHS_PROFILE_ENV, "repo_local"): + with ScopedEnvVar(HYF_PATHS_REPO_LOCAL_ROOT_ENV, temp_dir): + var binary = build_product_binary(temp_dir, guard) + assert_true(file_sha256(binary, guard).byte_length() == 64) + var argv = List[String]() + var session = measure_persistent_process( + ".", + binary, + "argv=[<hyfd>]", + "env=verified at run time", + argv^, + WARMUP_FRAMES, + MEASURED_FRAMES, + MEASUREMENT_DEADLINE_MS, + guard, + ) + assert_equal(session.ok_frames, WARMUP_FRAMES + MEASURED_FRAMES) + assert_equal(session.failed_frames, 0) + assert_equal(session.first_failure, "") + # Startup, warmup and measured timing are recorded separately (ms). + assert_true(session.startup_ms >= 0) + assert_true(session.measured_ms >= 0) + # Numeric sampling with recorded units and method. + assert_true(session.rss_kb_before_warmup > 0) + assert_true(session.rss_kb_after_warmup > 0) + assert_true(session.rss_kb_after_measured > 0) + assert_true(session.rss_kb_peak >= session.rss_kb_after_warmup) + assert_true(session.fd_before_warmup > 0) + assert_true(session.fd_after_measured > 0) + assert_true(session.fd_peak >= session.fd_after_measured) + assert_true(session.sampling_method.find("kB") >= 0) + assert_true(session.sampling_method.find("-F f") >= 0) + # The declared per-process request policy is characterized, not + # assumed: the persistent loop does not enforce it. + assert_equal(session.declared_max_requests_per_process, 1) + assert_true(session.child_exit.find("exited=0") >= 0) + assert_true(session.stderr_excerpt == "") + # Exact, truthful identity: source revision, cwd, binary, pixi + # files, toolchain, host and the verified environment profile. + assert_equal(len(session.identity.binary_sha256), 64) + assert_equal(len(session.identity.pixi_lock_sha256), 64) + assert_equal(len(session.identity.pixi_toml_sha256), 64) + assert_equal(len(session.identity.source_revision), 40) + assert_true(session.identity.cwd.find("oss/hyf") >= 0) + assert_true( + session.identity.env_profile.find( + "HYF_PATHS_PROFILE=repo_local" + ) + >= 0 + ) + assert_true(session.identity.env_profile.find(temp_dir) >= 0) + assert_true(session.identity.toolchain_version != "") + assert_true( + session.identity.host_platform.find("Darwin") >= 0 + or session.identity.host_platform.find("Linux") >= 0 + ) + assert_true( + session.summary().find( + "frames=" + String(WARMUP_FRAMES + MEASURED_FRAMES) + ) + >= 0 + ) guard.assert_clean()