"""Downloading the models is the last step of every fresh install, and it ran into the one macOS trap nothing else here does. A python.org macOS build ships its own OpenSSL with NO trust store, and populates one only when somebody double-clicks `Install Certificates.command` in the Python folder. Measured on a colleague's Mac: the engine installed perfectly - numpy, onnxruntime, faiss, all of it - and then could not fetch a 230 KB model file, ending setup in forty lines of traceback about `_ssl.c`. """ import io import logging import os import ssl import urllib.request import pytest from behavision import model_assets class _Resp(io.BytesIO): """Enough of an http response for _fetch: read() and .headers.""" def __init__(self, payload: bytes): super().__init__(payload) self.headers = {"Content-Length": str(len(payload))} def __enter__(self): return self def __exit__(self, *exc): self.close() return False def _verify_error(): """What urlopen ACTUALLY raises, which is not what it looks like. urllib catches ssl.SSLCertVerificationError and re-raises urllib.error.URLError(err), carrying the original on `.reason`. The first version of this test raised the bare SSL error - a shape real urllib never produces - so it passed against a fallback that could never fire, and the fix shipped and failed on the machine it was written for with the exact traceback it was meant to prevent. """ return urllib.error.URLError(ssl.SSLCertVerificationError( "[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: " "unable to get local issuer certificate")) def test_a_machine_with_no_trust_store_falls_back_to_the_bundled_one(monkeypatch): calls = [] def fake(url, timeout=None, context=None): calls.append(context) if context is None: raise _verify_error() return _Resp(b"ok") monkeypatch.setattr(urllib.request, "urlopen", fake) with model_assets._urlopen("https://example.invalid/m.onnx") as resp: assert resp.read() == b"ok" assert len(calls) == 2, f"expected a retry, got {calls}" # Default FIRST, and that order is the point. On Windows and on a system # Python the default context reads the machine's own certificate store, # which is what makes a corporate proxy with its own root CA work. # Replacing it unconditionally would break every site that has one in # order to fix a different platform. assert calls[0] is None assert isinstance(calls[1], ssl.SSLContext) def test_a_working_trust_store_is_used_as_is(monkeypatch): calls = [] def fake(url, timeout=None, context=None): calls.append(context) return _Resp(b"ok") monkeypatch.setattr(urllib.request, "urlopen", fake) model_assets._urlopen("https://example.invalid/m.onnx").close() assert calls == [None], "the machine's own certificate store was bypassed" def test_a_real_network_failure_is_not_disguised_as_a_certificate_problem(monkeypatch): """A URLError is not automatically a certificate problem. "No route to host" and "connection refused" arrive as URLError too, and retrying those with a different CA list changes nothing except how long the operator waits for the real message. """ calls = [] def fake(url, timeout=None, context=None): calls.append(context) raise urllib.error.URLError("no route to host") monkeypatch.setattr(urllib.request, "urlopen", fake) with pytest.raises(urllib.error.URLError): model_assets._urlopen("https://example.invalid/m.onnx") assert calls == [None], f"a dead network was retried as a CA problem: {calls}" def test_progress_lines_survive_the_rewrite(tmp_path, monkeypatch, caplog): """`download: