Files
windy-git/api/app/providers/base.py
Grant Whitmer 659991b2bd G0: cell substrate — invariants made executable
Strand G0 complete and VERIFIED against real Postgres, not asserted.

  - FastAPI plane, fail-closed provider seams, repair-pointer error taxonomy
  - migration 001: all 10 tables incl. repo_type NOT NULL and model_cards (I-7)
  - 17 invariant tests, ruff clean, vocabulary audit clean

Two bugs found by RUNNING it that review would not have caught:

  1. SQLAlchemy Enum persists .name, not .value — so RepoState.deleted_soft
     and CreatedVia.imported would have written labels migration 001 never
     declared, failing at runtime rather than at review. Pinned via
     values_callable.
  2. op.create_table asks each Enum to emit its own CREATE TYPE with no
     checkfirst, so the second reference raised DuplicateObject and the
     migration died halfway. Types are now created once, referenced with
     create_type=False.

Proven live, with the hostile env var set:
  - I-12: COMMIT_SHA=deadbeef... in the environment, /version reports real HEAD.
    That env pin is the documented root cause of nine sibling services
    misreporting their commit; here it is structurally ignored.
  - I-8: three unconfigured providers -> status degraded, HTTP 503, each saying
    'refusing to report healthy'. No mock, no false green.
  - G0.4: upgrade -> downgrade -> upgrade round-trip clean (10 -> 0 -> 10).

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-11 14:19:28 -04:00

56 lines
1.9 KiB
Python

"""Provider seams — all of them fail CLOSED (I-8).
`windy-cloud-sites` ships an `edge_live` gate whose whole job is "never claim
live while the provider is mock" (commit a8ff948). `windy-cloud-domains` has a
registrar seam that literally raises `RuntimeError("Refusing to pretend")` — and
then shipped its public portal without wiring the equivalent gate on the quote
route, which is why production told anyone who asked that google.com was
available for $18.00 a year.
The lesson those two cells paid for: a fail-closed seam is worth nothing if a
route can reach the data without passing through it. So here the probe and the
gate are the SAME object, and `healthy()` can never return True for a provider
that `configured` reports False.
"""
from __future__ import annotations
import abc
from dataclasses import dataclass
@dataclass(frozen=True)
class ProbeResult:
ok: bool
detail: str
# True only when we actually reached the real dependency. A provider that is
# merely "not configured" is ok=False, reachable=False — never ok=True.
reachable: bool = False
class Provider(abc.ABC):
"""A dependency outside this process."""
name: str
@property
@abc.abstractmethod
def configured(self) -> bool:
"""Do we hold every credential needed to talk to the real thing?"""
@abc.abstractmethod
async def probe(self) -> ProbeResult:
"""Reach the real dependency. Never simulate."""
async def healthy(self) -> ProbeResult:
if not self.configured:
return ProbeResult(
ok=False,
detail=f"{self.name} is not configured; refusing to report healthy",
reachable=False,
)
try:
return await self.probe()
except Exception as exc: # noqa: BLE001 - a probe must never raise upward
return ProbeResult(ok=False, detail=f"{self.name} probe failed: {exc}")