With the version ceiling and the widened numpy pin in place, setup succeeded on the Mac that found them - Python 3.14 chosen and accepted, numpy 2.5.3, onnxruntime 1.30, faiss 1.15.1, the engine itself - and died on the last step, fetching the YuNet model: ssl.SSLCertVerificationError: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate A python.org macOS build ships its own OpenSSL with NO trust store, and populates one only when somebody double-clicks Install Certificates.command in the Python folder. Nobody installing face-recognition software has a reason to know that exists, and the failure is forty lines of traceback about _ssl.c at the end of a ten-minute install. _urlopen tries the default context first and retries with certifi's bundle on a verification failure. The order is the design: - Default first, because on Windows and on a system or Homebrew Python the default context reads the machine's own certificate store, which is what makes a corporate proxy with its own root CA work. Replacing it unconditionally would break every site that has one to fix a different platform. - certifi second, because it is already installed: requests is a hard dependency and brings it. - URLError is re-raised untouched. "No route to host" and "no trust store" are different problems, and retrying the first with a different CA list only delays the real message. urlretrieve had to go, since it offers no way to pass a context - exactly the kind of rewrite that silently drops something. The `download: <label> <n>%` lines are a contract: supervisor.go's progressRe parses them to put first-run progress in the tray, because the API is not up yet and a shop PC showing a stopped engine for five minutes looks broken. A test asserts them, and the rewritten fetch was checked against the real URL: 232,589 bytes, sha256 identical to the model already on disk. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01KGcjxF1cNLcuwc3DAPcnfj
106 lines
3.9 KiB
Python
106 lines
3.9 KiB
Python
"""Downloading the models is the last step of every fresh install, and it ran
|
|
into the one macOS trap nothing else here does.
|
|
|
|
A python.org macOS build ships its own OpenSSL with NO trust store, and
|
|
populates one only when somebody double-clicks `Install Certificates.command`
|
|
in the Python folder. Measured on a colleague's Mac: the engine installed
|
|
perfectly - numpy, onnxruntime, faiss, all of it - and then could not fetch a
|
|
230 KB model file, ending setup in forty lines of traceback about `_ssl.c`.
|
|
"""
|
|
import io
|
|
import logging
|
|
import ssl
|
|
import urllib.request
|
|
|
|
import pytest
|
|
|
|
from behavision import model_assets
|
|
|
|
|
|
class _Resp(io.BytesIO):
|
|
"""Enough of an http response for _fetch: read() and .headers."""
|
|
|
|
def __init__(self, payload: bytes):
|
|
super().__init__(payload)
|
|
self.headers = {"Content-Length": str(len(payload))}
|
|
|
|
def __enter__(self):
|
|
return self
|
|
|
|
def __exit__(self, *exc):
|
|
self.close()
|
|
return False
|
|
|
|
|
|
def _verify_error():
|
|
return ssl.SSLCertVerificationError(
|
|
"[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: "
|
|
"unable to get local issuer certificate")
|
|
|
|
|
|
def test_a_machine_with_no_trust_store_falls_back_to_the_bundled_one(monkeypatch):
|
|
calls = []
|
|
|
|
def fake(url, timeout=None, context=None):
|
|
calls.append(context)
|
|
if context is None:
|
|
raise _verify_error()
|
|
return _Resp(b"ok")
|
|
|
|
monkeypatch.setattr(urllib.request, "urlopen", fake)
|
|
with model_assets._urlopen("https://example.invalid/m.onnx") as resp:
|
|
assert resp.read() == b"ok"
|
|
|
|
assert len(calls) == 2, f"expected a retry, got {calls}"
|
|
# Default FIRST, and that order is the point. On Windows and on a system
|
|
# Python the default context reads the machine's own certificate store,
|
|
# which is what makes a corporate proxy with its own root CA work.
|
|
# Replacing it unconditionally would break every site that has one in
|
|
# order to fix a different platform.
|
|
assert calls[0] is None
|
|
assert isinstance(calls[1], ssl.SSLContext)
|
|
|
|
|
|
def test_a_working_trust_store_is_used_as_is(monkeypatch):
|
|
calls = []
|
|
|
|
def fake(url, timeout=None, context=None):
|
|
calls.append(context)
|
|
return _Resp(b"ok")
|
|
|
|
monkeypatch.setattr(urllib.request, "urlopen", fake)
|
|
model_assets._urlopen("https://example.invalid/m.onnx").close()
|
|
assert calls == [None], "the machine's own certificate store was bypassed"
|
|
|
|
|
|
def test_a_real_network_failure_is_not_disguised_as_a_certificate_problem(monkeypatch):
|
|
def fake(url, timeout=None, context=None):
|
|
raise urllib.error.URLError("no route to host")
|
|
|
|
monkeypatch.setattr(urllib.request, "urlopen", fake)
|
|
with pytest.raises(urllib.error.URLError):
|
|
model_assets._urlopen("https://example.invalid/m.onnx")
|
|
|
|
|
|
def test_progress_lines_survive_the_rewrite(tmp_path, monkeypatch, caplog):
|
|
"""`download: <label> <n>%` is a CONTRACT, not logging.
|
|
|
|
The supervisor parses it (progressRe) to put first-run progress in the
|
|
tray and the window, because the API is not up yet and a shop PC showing
|
|
a stopped engine for five minutes after install looks broken. Switching
|
|
off urlretrieve - needed because it offers no way to pass an SSL context -
|
|
is exactly the kind of change that drops it silently.
|
|
"""
|
|
payload = b"x" * (64 * 1024 * 8)
|
|
monkeypatch.setattr(urllib.request, "urlopen",
|
|
lambda url, timeout=None, context=None: _Resp(payload))
|
|
dest = tmp_path / "model.onnx"
|
|
with caplog.at_level(logging.INFO, logger="behavision.model_assets"):
|
|
model_assets._fetch("https://example.invalid/m.onnx", dest, "face detector")
|
|
|
|
assert dest.read_bytes() == payload
|
|
lines = [r.getMessage() for r in caplog.records]
|
|
pct = [ln for ln in lines if ln.startswith("download: face detector ")]
|
|
assert pct, f"no progress lines at all: {lines}"
|
|
assert "download: face detector 100%" in pct, pct
|