"""Downloading the models is the last step of every fresh install, and it ran into the one macOS trap nothing else here does. A python.org macOS build ships its own OpenSSL with NO trust store, and populates one only when somebody double-clicks `Install Certificates.command` in the Python folder. Measured on a colleague's Mac: the engine installed perfectly - numpy, onnxruntime, faiss, all of it - and then could not fetch a 230 KB model file, ending setup in forty lines of traceback about `_ssl.c`. """ import io import logging import ssl import urllib.request import pytest from behavision import model_assets class _Resp(io.BytesIO): """Enough of an http response for _fetch: read() and .headers.""" def __init__(self, payload: bytes): super().__init__(payload) self.headers = {"Content-Length": str(len(payload))} def __enter__(self): return self def __exit__(self, *exc): self.close() return False def _verify_error(): return ssl.SSLCertVerificationError( "[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: " "unable to get local issuer certificate") def test_a_machine_with_no_trust_store_falls_back_to_the_bundled_one(monkeypatch): calls = [] def fake(url, timeout=None, context=None): calls.append(context) if context is None: raise _verify_error() return _Resp(b"ok") monkeypatch.setattr(urllib.request, "urlopen", fake) with model_assets._urlopen("https://example.invalid/m.onnx") as resp: assert resp.read() == b"ok" assert len(calls) == 2, f"expected a retry, got {calls}" # Default FIRST, and that order is the point. On Windows and on a system # Python the default context reads the machine's own certificate store, # which is what makes a corporate proxy with its own root CA work. # Replacing it unconditionally would break every site that has one in # order to fix a different platform. assert calls[0] is None assert isinstance(calls[1], ssl.SSLContext) def test_a_working_trust_store_is_used_as_is(monkeypatch): calls = [] def fake(url, timeout=None, context=None): calls.append(context) return _Resp(b"ok") monkeypatch.setattr(urllib.request, "urlopen", fake) model_assets._urlopen("https://example.invalid/m.onnx").close() assert calls == [None], "the machine's own certificate store was bypassed" def test_a_real_network_failure_is_not_disguised_as_a_certificate_problem(monkeypatch): def fake(url, timeout=None, context=None): raise urllib.error.URLError("no route to host") monkeypatch.setattr(urllib.request, "urlopen", fake) with pytest.raises(urllib.error.URLError): model_assets._urlopen("https://example.invalid/m.onnx") def test_progress_lines_survive_the_rewrite(tmp_path, monkeypatch, caplog): """`download: