ouroboros/tests/system_e2e/conftest.py
Ouroboros d1ed1e2fb1 tests(system_e2e): F4 wave 2 - subagent tree, cancellation, managed-update core
Five scenarios on the wave-1 skeleton (manifest rows S6-S10, keyless mock
lane, durable-artifact assertions, durable-event polling):

- S6 subagent tree: ReplayModel parent drives schedule_subagent ->
  wait_tasks -> exact-hash tree_note disposition -> final; the child runs
  on its own stub slot (slot binder = model id x tool-bearing shape) so
  every fixture ordinal is deterministic under parent/child concurrency.
  Pins lineage truth in the durable rows, the swarm_fanout receipt in the
  parent's forked drive, quiescence (child task_done precedes parent's;
  clean, not children_unabsorbed), the child result reaching the parent
  verbatim, the tree-ledger disposition row, root with-children cost keys,
  and full fixture consumption.
- S7 cancellation single: typed cancelled terminal with an owed answer
  (outbox delivery or the typed no_lineage_chat handoff row), honest cost
  names, self-draining cancel intent with the requested->claimed->settled
  forensic trail, terminal task_done, and a /proc no-orphans scan of the
  live server tree.
- S8 cancellation cascade: live child, cascade teardown; root intent
  minted scope=cascade at the ingress and settled only on the cascade
  postcondition, descendant carries its own cascade_descendant intent,
  the subtree snapshot lists the child, no orphan processes.
- S9 managed update ff core: a real managed install with a LOCAL managed
  upstream (official update URL redirected via git url.insteadOf - install
  config, not patched runtime), dirty-tree fast-forward applied over the
  live HTTP surface; stash-first insurance carries the owner's work, the
  server re-execs, boot-finalize consumes both markers, writes
  managed_update_finalized head==target, restores the dirty work and
  keeps the durable rescue-local stash pin.
- S10 rollback contracts (subprocess driver on a second isolated install):
  absent marker and explicit null stamp refuse typed (no pre_update_sha;
  strict corrupt) with marker bytes intact; a FUTURE-schema stamp refuses
  typed from both rollback_managed_update and
  finalize_managed_update_on_boot with the marker byte-identical; a
  half-applied update rolls back to a byte-for-byte identical worktree
  with the candidate preserved on failed-update-* and the durable
  managed_update_rolled_back receipt.

Harness: callable script/fixture steps (dynamic server-minted arguments),
ReplayModel model_ids override, pids_with_env_value no-orphans oracle,
terminal_deliveries / child_task_ids / tree_blackboard oracle readers;
manifest gen/verify + marker pins now scan every module of the package;
shared session clone moved to the package conftest. ARCHITECTURE System
E2E subsection extended; ledger carries the wave section including the
E2E findings table (W2-F1..F4) and lane timings (full mock lane 31 passed
in ~219s).
2026-09-01 12:04:53 +00:00

21 lines
774 B
Python

"""Shared fixtures of the system_e2e scenario package.
One throwaway clone serves every scenario server of a session (cloning the
checkout is the expensive step); scenarios that MOVE the clone's HEAD or add
remotes (the managed-update wave) must build their own private clone instead —
sharing a mutated clone would couple scenario outcomes to execution order.
"""
from __future__ import annotations
import pytest
from tests.system_e2e.harness import LANE_MOCK, clone_repo, require_lane
@pytest.fixture(scope="session")
def e2e_clone(tmp_path_factory):
"""One throwaway clone of the checkout under test, shared by every scenario
server that leaves HEAD alone."""
require_lane(LANE_MOCK)
return clone_repo(tmp_path_factory.mktemp("system_e2e_clone"))