test(benchmark): preserve profile temp scope in app-server privacy guard - #5231
Conversation
…guard Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
huangruiteng
left a comment
There was a problem hiding this comment.
Approval conclusion (author-owned PR; GitHub blocks formal self-approval)
Reviewed exact head 5231@a2830bda87793de2dd43e27fe07d78db9a875050.
动机
1.2.2 候选源码的真实 Python CI 只有 widesearch 的现有隐私回归失败:#5226 已让原生 profile 的临时文件归属私有 HOME,但该测试仍断言旧环境字典,误把必需的 TMPDIR/TMP/TEMP 判为多余。旧测试在不可变合入基线上实际失败,其余三个 Python shard、全量公开 smoke 与隔离 PostgreSQL 验证已通过;最终新源码仍须全部重新验证。
改动思路
保留现有 app-server 完整字典断言和两个独立的上游 provider 权威拒绝用例。将继承环境中的三个标准临时变量设为外部合成目录,明确要求导出值全部由 profile HOME 覆盖;PATH、CODEX_HOME、无凭证 sentinel 及无关 token 排除仍是原规则。无需新增生产逻辑、状态、权限或 helper。
具体改动
仅改现有 benchmark/widesearch/tests/test_run_config.py,增加 7 行、删除 1 行,重命名该测试以准确覆盖临时目录归属。完整 widesearch 测试目录 11 项通过,旧断言单项在基线失败;相同合成输入经真实 runner 和原生 profile builder 在 base/head 导出完全一致的环境哈希,生产 runner 与 profile 模块也逐字节相同。Ruff、diff、公开边界、精确质量收据和全部 6 项原生选中检查通过,直接失败 0;原始 benchmark-sensitive 人工标记没有改写,本评审核实无评分、任务、runner、提交或模型作业变更。
对主干的风险
主要风险是为了恢复绿色 CI 而削弱凭证边界。这里仍用完整字典相等,新增外部临时变量污染输入反而使归属验证更强;已有 provider URL/key 注入拒绝用例和无关 token 排除保持。修改仅是已有 benchmark 专用测试的预期,不更改正式安装、CLI、App、权限、持久化、发布内容或首屏。GitHub PR CI 按目标配置不作为本次精确 review 等待项;合并后的不可变发行源码会重新跑完整 Python、全量公开 smoke、实际模型和发布产物读回。
我的整体评价
批准当前精确 head。该单项修复直接消除真实发布阻断,并强化而非删除既有隐私检查;相邻 owner 已复用,没有适合加入本 PR 的生产重构。人工 benchmark 分类由本次精确审查、无作业/评分变更的证据及维护者授权处理;整版发行资格仍属于当前发布任务。
English verdict: APPROVE - Exact head a2830bd; test-only privacy guard correction, 11 tests and 6 selected native checks pass; full merged-source release qualification follows.
The existing Widesearch app-server environment test blocks 1.2.2 Python CI because it still expects the pre-isolation environment, while the native profile now correctly exports HOME-scoped TMPDIR/TMP/TEMP. The corrected test retains strict full-dictionary equality and poisons inherited temporary settings to prove they cannot retarget the profile; upstream provider keys and unrelated tokens remain excluded.
Only one existing test file changes (7 insertions, 1 deletion); production runner and profile modules are byte-identical to the base. The original single test fails on the immutable base; all 11 Widesearch tests pass at the exact head. The same synthetic input through the real runner produces an identical exported environment hash at base and head. Ruff, diff, public-boundary scan, exact-scope change-quality receipt, and all six selected native premerge checks pass. The conservative benchmark-sensitive manual marker remains recorded and is addressed by exact-head review and owner authorization. Final merged-source full release qualification follows.