"""mumble — RESTORE overlay (Phase 1e HC3 / Phase 2 P4): data-integrity, assertion-only + additive. ops.pre_restore dropped the ci_marker table (diverge from the backup); the orchestrator restored once (generic tier asserted healthy/serving; the recipe's restore.post-hook `mv`s the backed-up sqlite back over /data/mumble-server.sqlite). This overlay ADDS: the restored DB carries the pre-mutation 'original' marker — proving the seeded data actually survived backup→restore, not just that the service came back up. Read via a fresh sqlite3 CLI in the app container (reads the restored on-disk file). """ import os import sys sys.path.insert(0, os.path.join(os.path.dirname(__file__), "..", "..", "runner")) from harness import lifecycle # noqa: E402 DB = "/data/mumble-server.sqlite" def _sqlite(domain, sql): # Set the busy timeout via the SILENT `.timeout` dot-command (-cmd), NOT an inline # `PRAGMA busy_timeout=...` (which emits its own result row and would pollute read-backs). cmd = f'sqlite3 -cmd ".timeout 20000" {DB} "{sql}"' return lifecycle.exec_in_app(domain, ["sh", "-c", cmd], service="app").strip() def test_restore_returns_state(live_app): assert _sqlite(live_app, "SELECT v FROM ci_marker;") == "original", ( "restore did not return the pre-mutation mumble sqlite marker (data-integrity failure)" )