fix(core): font zip cache, monotonic timers, resolver back-off, and other core/common fixes (#654)

* fix(core): font zip cache, monotonic timers, resolver back-off, and other core/common fixes

- font_manager: a .zip font URL is served as its extracted font after a
  restart (the cached-file check returned the archive first); downloads
  use requests with a 30s timeout into a temp file + os.replace.
- api_helper / sync_manager: rate-limit and heartbeat/leader timeouts use
  time.monotonic(); last_request_time and the status file's ts stay
  wall-clock. set_on_new_cycle docstring no longer claims core uses it.
- logo_helper: the placeholder uses the same scaled box as a real logo.
- permission_utils: one _sudo_bash_candidates() helper (with the sudoers
  exact-argv rationale) shared by sudo_remove_directory, which now retries
  the next bash path on a sudo refusal, and install_requirements_file.
- dynamic_team_resolver: failed/empty fetch backs off 5 min; duplicate
  INFO log and contradictory docstring example fixed.
- element_style: scale default looked up through element aliases.
- background_data_service: cache-hit callback runs outside the lock.
- config_arrays: union-aware type check (["array","null"]); stale
  dotToNested() reference removed.
- auto_update_setup: non-dict auto_update reads as off; temp result file
  unlinked when the write fails.
- exceptions: constructors copy the caller's context dict.
- logging_config: StructuredFormatter json.dumps(default=str).
- error_aggregator: removed unused export_path/export_to_file/_auto_export.
- Docstrings: validate_file_upload max_size_mb, raise_on_errors.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(sync): retry the status-file rename like the other atomic writers

On Windows os.replace can fail with "Access is denied" while a scanner
briefly holds the target open; config_manager_atomic._replace already
retries that (and re-raises at once on other platforms). The sync status
writer called os.replace directly, which made
test_concurrent_writers_each_use_their_own_temp_file flaky on Windows.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
Chuck
2026-09-28 10:40:16 -04:00
committed by GitHub
co-authored by Claude Opus 5.5
parent 6f45ff5e63
commit f6c0fe55d9
28 changed files with 596 additions and 171 deletions
+37
View File
@@ -19,6 +19,7 @@ from src.common.permission_utils import (
_redact_url_credentials,
ensure_shared_group_ownership,
install_requirements_file,
sudo_remove_directory,
)
@@ -46,6 +47,42 @@ class TestRedactUrlCredentials:
assert _redact_url_credentials(text) == text
class TestSudoRemoveDirectory:
"""sudoers matches the exact argv, so the bash path the rule names has
to be found by trying each candidate, as install_requirements_file does."""
def _target(self, tmp_path):
target = tmp_path / "some-plugin"
target.mkdir()
return target
@patch('src.common.permission_utils.subprocess.run')
def test_tries_the_next_bash_path_when_sudo_refuses(self, mock_run, tmp_path):
target = self._target(tmp_path)
def fake_run(argv, **kwargs):
if mock_run.call_count == 1:
return MagicMock(returncode=1, stdout="",
stderr="sudo: a password is required")
target.rmdir()
return MagicMock(returncode=0, stdout="", stderr="")
mock_run.side_effect = fake_run
assert sudo_remove_directory(target, allowed_bases=[tmp_path]) is True
assert mock_run.call_count == 2
first, second = (c.args[0][2] for c in mock_run.call_args_list)
assert first != second
@patch('src.common.permission_utils.subprocess.run')
def test_stops_when_the_helper_itself_fails(self, mock_run, tmp_path):
target = self._target(tmp_path)
mock_run.return_value = MagicMock(returncode=1, stdout="",
stderr="refusing: not a plugin dir")
assert sudo_remove_directory(target, allowed_bases=[tmp_path]) is False
assert mock_run.call_count == 1
class TestInstallRequirementsFileRedaction:
@patch('src.common.permission_utils.subprocess.run')
def test_wrapper_path_redacts_stderr_and_stdout(self, mock_run, tmp_path):