Skip to content

Provider malformed-response corpus + era-jump migration test #105

Description

@hsliuustc0106

The provider lane (#75/#77/#81) parses external input at the only other egress site, but its contract tests use ideal shapes. Real APIs send dirty data. Two gaps, both offline:

A. Malformed-response corpus

Per adapter (openai_compat, anthropic), a parametrized corpus through the fake transport, each row asserting ProviderError (fail closed), no crash, and no credential material in the error text:

  • truncated JSON / empty body / non-JSON (HTML error pages)
  • wrong shape: missing expected fields (content, choices, message blocks), null fields, text block with non-string text
  • success status with an error-shaped body, and vice versa
  • 429 + Retry-After variants (integer, HTTP-date, missing, garbage) → bounded backoff semantics per Implement #46 P2: bounded provider retry with Retry-After semantics #81; garbage Retry-After never parses into an absurd wait
  • empty model output → ProviderError("empty"), never an empty notification summary

B. Migration jump test

  • A database created at the v0.1-era schema (tasks without digest/stale/flaky columns; permissions without content_hash/capabilities) opens under current TaskStore + PermissionCenter with every new dimension off, reads/writes round-trip, and the additive migrations are idempotent on reopen

Out of scope

Live per-vendor recorded fixtures (separate maintainer decision on #46); any behavior change — corpus rows pin fail-closed behavior, a failing row is triaged before code moves.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions