"""The window an operator declares, for a server that cannot be asked for one. `contextwindow`'s discovery speaks Ollama's native API. Nothing restricts `endpoint_url` to Ollama, so on vLLM, llama.cpp's own server, or anything else serving an OpenAI-compatible `/v1`, `/api/ps` and `/api/show` are not there: discovery fails as designed, the window is unknown, and the budget is left uncapped at whatever is configured. That is M11's own failure mode reached by a different route — the server drops the oldest tokens, which here are the narrator's rules and the campaign canon. `Settings.context_window_override` closes it. These tests pin the two properties that make it safe rather than merely useful: 1. it is used **only** where discovery left a hole, so it can never talk the application into a longer prompt than a server actually reported, and 2. it does not make `verified` true, because `verified` means the server answered and a declaration is a person's claim about a server. """ import asyncio import pytest from fastapi import Depends from fastapi.testclient import TestClient from app import auth, contextwindow, models from app.database import Base, SessionLocal, engine, get_db from app.main import app UNREACHABLE = "http://127.0.0.1:1/v1" @pytest.fixture(autouse=True) def _clear_window_cache(): contextwindow.cache_clear() yield contextwindow.cache_clear() @pytest.fixture() def client(): Base.metadata.create_all(bind=engine) setup = SessionLocal() user = models.User(is_guest=False, email="m11dw@example.com") setup.add(user) setup.flush() setup.add(models.Settings( user_id=user.id, model="some-model", endpoint_url=UNREACHABLE, embedding_model="", context_token_budget=16384, max_output_tokens=800, )) setup.commit() user_id = user.id setup.close() app.dependency_overrides[auth.get_current_user] = ( lambda db=Depends(get_db): db.get(models.User, user_id) ) try: yield TestClient(app) finally: app.dependency_overrides.clear() Base.metadata.drop_all(bind=engine) def probe(endpoint=UNREACHABLE, model="some-model", declared=None): contextwindow.cache_clear() return asyncio.run( contextwindow.probe(endpoint, model, declared=declared, use_cache=False)) # ------------------------------------------------------- filling the hole def test_without_a_declaration_an_unaskable_server_leaves_the_window_unknown(): window = probe() assert window.tokens is None assert not window.verified assert not window.enforceable assert window.source == contextwindow.UNKNOWN def test_a_declaration_becomes_the_ceiling_when_the_server_cannot_be_asked(): window = probe(declared=8192) assert window.tokens == 8192 assert window.source == contextwindow.DECLARED assert window.enforceable assert contextwindow.effective_budget(16384, window) == 8192 def test_a_declaration_does_not_claim_the_server_was_verified(): """`window_verified` travels in every turn's provenance and the M11 report counts it. A declaration must not inflate that count.""" window = probe(declared=8192) assert window.enforceable assert not window.verified def test_the_detail_says_the_number_came_from_settings(): assert "declared in settings" in probe(declared=8192).detail @pytest.mark.parametrize("declared", [None, 0, -1]) def test_a_missing_or_meaningless_declaration_changes_nothing(declared): window = probe(declared=declared) assert window.tokens is None assert window.source == contextwindow.UNKNOWN def test_a_declaration_still_applies_when_nothing_is_configured(): window = asyncio.run(contextwindow.probe("", "", declared=4096)) assert window.tokens == 4096 assert window.source == contextwindow.DECLARED def test_a_declaration_applies_to_a_refused_endpoint_without_reaching_it(): """A refused address is a discovery failure like any other (ADR 011, H12). The declaration caps the prompt; it does not make the endpoint usable, and the turn is still refused where endpoints are enforced.""" window = probe(endpoint="http://169.254.169.254/v1", declared=4096) assert window.source == contextwindow.DECLARED assert window.tokens == 4096 # ------------------------------------------- a verified answer always wins def test_a_verified_window_is_not_overridden(monkeypatch): """The safety property. An operator may lower an unknown ceiling into existence; they may never raise one the server reported.""" async def reported(endpoint, model): return contextwindow.Window(4096, contextwindow.LOADED, 32768, "real") monkeypatch.setattr(contextwindow, "_ask", reported) window = probe(declared=32768) assert window.tokens == 4096 assert window.source == contextwindow.LOADED assert window.verified assert contextwindow.effective_budget(16384, window) == 4096 def test_a_declared_window_larger_than_the_budget_does_not_raise_it(): window = probe(declared=200_000) assert contextwindow.effective_budget(16384, window) == 16384 # --------------------------------------------------------------- plumbing def test_the_override_is_readable_and_settable_through_the_api(client): assert client.get("/api/settings").json()["context_window_override"] is None body = client.put("/api/settings", json={"context_window_override": 8192}).json() assert body["context_window_override"] == 8192 # And can be taken back off, which `exclude_unset` makes a real distinction: # sending null clears it, sending nothing leaves it alone. body = client.put("/api/settings", json={"temperature": 0.5}).json() assert body["context_window_override"] == 8192 body = client.put("/api/settings", json={"context_window_override": None}).json() assert body["context_window_override"] is None @pytest.mark.parametrize("bad", [255, 200_001]) def test_the_override_is_bounded_like_the_budget_it_caps(client, bad): assert client.put("/api/settings", json={"context_window_override": bad}).status_code == 422