Align adversarial search rebuild assertion with the 202 API contract #520

Closed
opened 2026-09-30 14:02:03 +00:00 by kayg · 4 comments
Owner

Evidence

tests/adversarial/search_chaos.py asserts that the admin staged rebuild request returns HTTP 200. The checked-in OpenAPI contract for POST /api/v1/admin/search/rebuild declares HTTP 202 with a JobTriggerReceipt, and crates/calternal-server/src/wire.rs::rebuild_search_index returns StatusCode::ACCEPTED with that receipt.

The 2026-09-30 local hostile-input run observed HTTP 202 with job_id and inserted in the response body. The product route and contract agree, while the adversarial assertion disagrees. I left the existing test expectation unchanged for owner review. Please decide whether the probe should expect 202 or the route contract should change, then update the regression test in the approved direction.

## Evidence `tests/adversarial/search_chaos.py` asserts that the admin staged rebuild request returns HTTP 200. The checked-in OpenAPI contract for `POST /api/v1/admin/search/rebuild` declares HTTP 202 with a `JobTriggerReceipt`, and `crates/calternal-server/src/wire.rs::rebuild_search_index` returns `StatusCode::ACCEPTED` with that receipt. The 2026-09-30 local hostile-input run observed HTTP 202 with `job_id` and `inserted` in the response body. The product route and contract agree, while the adversarial assertion disagrees. I left the existing test expectation unchanged for owner review. Please decide whether the probe should expect 202 or the route contract should change, then update the regression test in the approved direction.
Author
Owner

Starting #520 in job/probe-520 from base cd3cea7575. I confirmed the server route and OpenAPI both specify 202 Accepted with a JobTriggerReceipt; I will update only the probe and run it against the local server.

Starting #520 in job/probe-520 from base cd3cea757508d9f581d00fb7d5d7973fbc0a75fd. I confirmed the server route and OpenAPI both specify 202 Accepted with a JobTriggerReceipt; I will update only the probe and run it against the local server.
Author
Owner

Implemented and committed on job/probe-520.

Changed tests/adversarial/search_chaos.py so the staged admin Search rebuild expects HTTP 202 Accepted. The route and OpenAPI contract both return a queued JobTriggerReceipt; no API code changed. Added doc comments that record the query/recovery checks and queued-rebuild behavior.

Base handling: fetched and fast-forwarded origin/dev from cd3cea757508d9f581d00fb7d5d7973fbc0a75fd to cc25c441b7a974185622a1dee853cf38686d2b67 before verification.

Head: 92f4558c69ff0a56e3e5462e93d66224ca709437

Verification output:

search chaos: passed (01a0f646, 32 concurrent renames, concurrent queries and rebuild)
...
----------------------------------------------------------------------
Ran 3 tests in 0.001s

OK

python3 -m py_compile tests/adversarial/search_chaos.py passed (exit 0). The fixture-backed helper test passed (3 tests). git diff --check passed (no output). cargo clean output: Removed 7469 files, 5.0GiB total.

The first harness launch skipped the frontend build and stopped before the live probe because the embedded apps/web/build directory was absent. I built the production frontend and reran the Search-only adversarial harness successfully. The generated web output was removed after the run.

Known gaps: none for this probe-only change. No Rust crate changed, so no Rust crate clippy or test gate applies.

Decisions: none beyond following the existing route and OpenAPI contract: keep the API unchanged and expect HTTP 202 for the queued rebuild receipt.

Implemented and committed on `job/probe-520`. Changed `tests/adversarial/search_chaos.py` so the staged admin Search rebuild expects HTTP 202 Accepted. The route and OpenAPI contract both return a queued `JobTriggerReceipt`; no API code changed. Added doc comments that record the query/recovery checks and queued-rebuild behavior. Base handling: fetched and fast-forwarded `origin/dev` from `cd3cea757508d9f581d00fb7d5d7973fbc0a75fd` to `cc25c441b7a974185622a1dee853cf38686d2b67` before verification. Head: `92f4558c69ff0a56e3e5462e93d66224ca709437` Verification output: ```text search chaos: passed (01a0f646, 32 concurrent renames, concurrent queries and rebuild) ... ---------------------------------------------------------------------- Ran 3 tests in 0.001s OK ``` `python3 -m py_compile tests/adversarial/search_chaos.py` passed (exit 0). The fixture-backed helper test passed (3 tests). `git diff --check` passed (no output). `cargo clean` output: `Removed 7469 files, 5.0GiB total`. The first harness launch skipped the frontend build and stopped before the live probe because the embedded `apps/web/build` directory was absent. I built the production frontend and reran the Search-only adversarial harness successfully. The generated web output was removed after the run. Known gaps: none for this probe-only change. No Rust crate changed, so no Rust crate clippy or test gate applies. Decisions: none beyond following the existing route and OpenAPI contract: keep the API unchanged and expect HTTP 202 for the queued rebuild receipt.
Author
Owner

Duplicate of #561: both report tests/adversarial/search_chaos.py expecting HTTP 200 from POST /api/v1/admin/search/rebuild while the route returns its documented HTTP 202 JobTriggerReceipt. Recommend keeping #561 as the tracking issue because it states the probe correction, and linking this run as repeated evidence.

Duplicate of #561: both report tests/adversarial/search_chaos.py expecting HTTP 200 from POST /api/v1/admin/search/rebuild while the route returns its documented HTTP 202 JobTriggerReceipt. Recommend keeping #561 as the tracking issue because it states the probe correction, and linking this run as repeated evidence.
Author
Owner

Duplicate of #561: both report the Search rebuild probe expecting the wrong status. Keep #561 as the active tracker.

Duplicate of #561: both report the Search rebuild probe expecting the wrong status. Keep #561 as the active tracker.
kayg closed this issue 2026-10-03 11:55:49 +00:00
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#520
No description provided.