Files
roboco/tests/unit/gateway/test_evidence_populates_files_changed.py
T
93739a9dca fix(notifications): stop tick-wide row locks + poisoned-session swallows behind the PendingRollbackError 500s (#743)
* fix(notifications): release re-escalation row locks per row; stop swallowing DB errors in notify_get

The re-escalation sweep ran one tick-wide transaction, so each CAS
claim's row lock was held across every remaining delivery until the
single commit — a concurrent mark-read UPDATE on a claimed row starved
into the 60s lock_timeout. The sweep now commits per row (claim commit
releases the lock before delivery and makes the burned slot durable),
re-fetches each row by snapshotted id so one row's rollback can't
expire the rest of the tick, and savepoints each recipient's delivery.

notify_get's bare except swallowed the resulting LockNotAvailableError
into a false "notification not found" and returned a poisoned session
to the commit-at-send middleware, which blew up with
PendingRollbackError; it now catches only the two domain outcomes.

defer_after_commit's listeners fire on SAVEPOINT release too, which
would have drained deferred telegram/bus work before real durability —
they now skip savepoint boundaries via get_nested_transaction() (the
root get_transaction() is non-None inside the listener even at a real
commit). acknowledge_for_recipient's Redis dedup-clear moved before the
flush so the row lock never spans a Redis round-trip. The five
best-effort CEO-notify swallows that persist notification rows are
savepointed.

* fix(services): contain swallowed best-effort DB write failures instead of poisoning the session

Sweep of the same class as the notify_get incident: broad
except-Exception handlers that swallow a failure whose try-body writes
through the shared session leave the session rollback-pending, and the
verb/request then dies later with PendingRollbackError at
commit-at-send. Confirmed-dangerous sites now run the write inside a
savepoint (safe since defer_after_commit skips savepoint boundaries):
ceo_approve's verified-stamp, completion/pitch/postmortem-style CEO
notifies, _inherit_upstream_base, _link_commit_to_task (covers every
commit route), board-program LEARN records, the QA/PR-gate/PM-merge
verified-stamps, and the documenter->PM handoff.
_ack_pending_wake_notifications gets the same treatment so a wake-ack
failure can't fail the A2A read. telegram_inbound's per-update loop and
intake confirm roll back explicitly instead (their success paths commit
mid-flow, so a savepoint doesn't fit).

A swallowed savepoint rollback fully expires any ORM object mutated
inside the block, and the next attribute read raises MissingGreenlet —
strictly worse than the original bug. The two paths that keep using the
object after the swallow (doc handoff's envelope build, base
inheritance's claim continuation) refresh it in the except path;
regression tests run against a real session and were verified to fail
with the refresh reverted.

* test: shape mocked session.execute results so sync accessors stop leaking unawaited coroutines

An AsyncMock's auto-created children are themselves AsyncMock, so
production code that correctly awaits session.execute() and then calls
sync accessors (.scalars().all(), .scalar_one_or_none()) on the result
was silently collecting unawaited coroutines in 22 test files — 80
RuntimeWarnings per unit run, and in test_flow_soup_guard one mock
raised a real TypeError that a coincidentally-matching invalid_state
envelope masked. Each affected fixture now returns a plain MagicMock
shaped like a real Result. Zero AsyncMock warnings remain.

* docs: document per-row sweep commits and the savepoint/refresh containment pattern

---------

Co-authored-by: Renn F <rennf93@users.noreply.github.com>
2026-07-30 16:35:42 +02:00

226 lines
8.3 KiB
Python

"""Task #154: evidence() must populate files_changed + use full PR diff.
Bug:
ContentActions.evidence() hard-coded ``files_changed=[]`` and called
``git.diff(branch_name=..., base="HEAD~1")``. Result: QA / reviewers
inspecting a real PR saw an empty change list and only the latest
commit's delta, even when GitHub showed a multi-commit change set.
Fix:
Pull files via ``git.list_changed_files(branch_name=...)`` (no base
→ full diff vs parent branch). Pull diff with ``base=None`` so the
full PR diff comes through. Both use git as the authoritative source
instead of the legacy ``work_session.files_modified`` field, which
the gateway ``commit()`` does not populate.
"""
from __future__ import annotations
from unittest.mock import AsyncMock, MagicMock
from uuid import uuid4
import pytest
from roboco.services.gateway.content_actions import ContentActions, ContentActionsDeps
def _deps_for_evidence(
task_svc: AsyncMock,
git_svc: AsyncMock,
workspace_svc: AsyncMock,
evidence_repo: AsyncMock,
) -> ContentActionsDeps:
# Findings-ledger reads (ReviewFindingsRepository.list_for_task) go
# through session.execute — an unconfigured AsyncMock's awaited result
# is itself an AsyncMock, so a plain sync `.scalars()` call on it leaks
# an unawaited coroutine. Empty scalars result (no findings).
task_svc.session.execute = AsyncMock(
return_value=MagicMock(
scalars=MagicMock(return_value=MagicMock(all=MagicMock(return_value=[])))
)
)
return ContentActionsDeps(
task=task_svc,
git=git_svc,
a2a=AsyncMock(),
journal=AsyncMock(),
workspace=workspace_svc,
notifications=AsyncMock(),
notification_delivery=AsyncMock(),
evidence_repo=evidence_repo,
)
def _task_with_pr(task_id: object, *, commits: list[str]) -> MagicMock:
return MagicMock(
id=task_id,
status="awaiting_qa",
assigned_to=None,
branch_name="feature/backend/abc12345--def67890",
work_session_id=uuid4(),
commits=commits,
pr_number=20,
pr_url="https://github.com/org/repo/pull/20",
dev_notes="see PR description",
acceptance_criteria_status=[],
)
@pytest.mark.asyncio
async def test_evidence_populates_files_changed_from_git() -> None:
"""The smoke-9 regression: PR #20 has README change on GitHub but
evidence() reports files_changed=[]. The fix queries git directly."""
agent_id = uuid4()
task_id = uuid4()
task_svc = AsyncMock()
task_svc.get.return_value = _task_with_pr(task_id, commits=["abc", "def"])
git_svc = AsyncMock()
git_svc.diff.return_value = "diff --git a/README.md b/README.md\n+added line\n"
git_svc.list_changed_files.return_value = ["README.md", "docs/guide.md"]
workspace_svc = AsyncMock()
evidence_repo = AsyncMock()
evidence_repo.journal_highlights_for_task.return_value = []
ca = ContentActions(
_deps_for_evidence(task_svc, git_svc, workspace_svc, evidence_repo)
)
env = await ca.evidence(agent_id=agent_id, task_id=task_id)
body = env.as_dict()
assert body["error"] is None
assert body["evidence"]["files_changed"] == ["README.md", "docs/guide.md"]
assert "diff --git" in body["evidence"]["pr_diff_summary"]
git_svc.list_changed_files.assert_awaited_once()
@pytest.mark.asyncio
async def test_evidence_uses_full_pr_diff_not_head_minus_one() -> None:
"""git.diff must be called with base=None (full PR diff vs parent),
not base='HEAD~1' (only the last commit)."""
agent_id = uuid4()
task_id = uuid4()
task_svc = AsyncMock()
# Multi-commit branch — the pre-fix code passed base='HEAD~1' when
# task.commits was non-empty, masking earlier commits' changes.
task_svc.get.return_value = _task_with_pr(task_id, commits=["sha1", "sha2", "sha3"])
git_svc = AsyncMock()
git_svc.diff.return_value = "full diff"
git_svc.list_changed_files.return_value = []
workspace_svc = AsyncMock()
evidence_repo = AsyncMock()
evidence_repo.journal_highlights_for_task.return_value = []
ca = ContentActions(
_deps_for_evidence(task_svc, git_svc, workspace_svc, evidence_repo)
)
await ca.evidence(agent_id=agent_id, task_id=task_id)
git_svc.diff.assert_awaited_once()
call_kwargs = git_svc.diff.await_args.kwargs
# Pre-fix bug: kwargs['base'] would be 'HEAD~1' for any multi-commit
# branch. Post-fix: base is omitted (or explicitly None).
base = call_kwargs.get("base")
assert base in (None, ""), (
f"git.diff must use full-PR diff (base=None), got base={base!r}"
)
assert call_kwargs.get("branch_name") == "feature/backend/abc12345--def67890"
@pytest.mark.asyncio
async def test_evidence_populates_journal_highlights() -> None:
"""evidence() must return journal_highlights so QA gets the dev's
decision/reflection context — same as qa.py's claim_review evidence."""
agent_id = uuid4()
task_id = uuid4()
task_svc = AsyncMock()
task_svc.get.return_value = _task_with_pr(task_id, commits=["abc"])
git_svc = AsyncMock()
git_svc.diff.return_value = ""
git_svc.list_changed_files.return_value = []
workspace_svc = AsyncMock()
evidence_repo = AsyncMock()
highlights = [
{"scope": "decision", "title": "Use README format X", "content": "..."},
{"scope": "reflect", "title": "Lesson learned", "content": "..."},
]
evidence_repo.journal_highlights_for_task.return_value = highlights
ca = ContentActions(
_deps_for_evidence(task_svc, git_svc, workspace_svc, evidence_repo)
)
env = await ca.evidence(agent_id=agent_id, task_id=task_id)
body = env.as_dict()
assert body["evidence"]["journal_highlights"] == highlights
evidence_repo.journal_highlights_for_task.assert_awaited_once_with(
task_id, include_ancestors=True
)
@pytest.mark.asyncio
async def test_evidence_commits_session_before_git_work() -> None:
"""2026-07-29 pool exhaustion: evidence() must release its DB transaction
(commit) BEFORE the fetch/diff git work — those can run for minutes on a
cold workspace, and an open transaction pins a pool connection for the
whole duration."""
order: list[str] = []
agent_id = uuid4()
task_id = uuid4()
task_svc = AsyncMock()
task_svc.get.return_value = _task_with_pr(task_id, commits=["abc"])
task_svc.session.commit = AsyncMock(side_effect=lambda: order.append("commit"))
git_svc = AsyncMock()
git_svc.diff.return_value = ""
git_svc.list_changed_files.return_value = []
workspace_svc = AsyncMock()
workspace_svc.fetch_branch_for_inspection = AsyncMock(
side_effect=lambda **_kw: order.append("fetch")
)
evidence_repo = AsyncMock()
evidence_repo.journal_highlights_for_task.return_value = []
ca = ContentActions(
_deps_for_evidence(task_svc, git_svc, workspace_svc, evidence_repo)
)
env = await ca.evidence(agent_id=agent_id, task_id=task_id)
assert env.as_dict()["error"] is None
assert order == ["commit", "fetch"], (
f"session must be committed before git work, got order={order}"
)
@pytest.mark.asyncio
async def test_evidence_no_branch_skips_git_calls() -> None:
"""A task without a branch_name has no PR yet — skip git entirely,
still return a valid envelope with empty files_changed."""
agent_id = uuid4()
task_id = uuid4()
task_svc = AsyncMock()
no_branch = MagicMock(
id=task_id,
status="claimed",
assigned_to=agent_id,
branch_name=None,
work_session_id=None,
commits=[],
pr_number=None,
pr_url=None,
dev_notes=None,
acceptance_criteria_status=[],
)
task_svc.get.return_value = no_branch
git_svc = AsyncMock()
workspace_svc = AsyncMock()
evidence_repo = AsyncMock()
evidence_repo.journal_highlights_for_task.return_value = []
ca = ContentActions(
_deps_for_evidence(task_svc, git_svc, workspace_svc, evidence_repo)
)
env = await ca.evidence(agent_id=agent_id, task_id=task_id)
body = env.as_dict()
assert body["error"] is None
assert body["evidence"]["files_changed"] == []
assert body["evidence"]["pr_diff_summary"] == ""
git_svc.diff.assert_not_awaited()
git_svc.list_changed_files.assert_not_awaited()