feat(write-skill): GED attach op — upload the source document onto its invoice (erp#43)

document-attach.sh uploads a source piece (the supplier's own PDF) onto an
invoice's GED via POST /documents/upload — idempotent by (object, filename,
sha256): before any POST the object's GED is listed and a same-named entry is
downloaded back and sha256-compared. Identical → deduped no-op; different
content → ABORT (refuse-never-repair, overwriteifexists always 0, never
Dolibarr's overwrite flag). Read-back after upload: re-list + download +
sha256-verify. Module-relative download paths are derived from the listing's
fullname (supplier invoices carry an id-derived get_exdir prefix like
9/2/FAF2026013/…, so reconstruction would be wrong).

Promote integration: new `attach` op in promote-plan/promote-apply (OP_SCRIPT),
object_id resolvable via @ref and #supplierinvoice lookups; a relative `file`
resolves against the manifest's directory (replay packs carry pdfs/ beside the
manifest, gitignored — README documents the books@ re-fetch message ids).
promote-plan prints each file's sha256 (or a loud MISSING) at review time.
CLI: `arcodange sandbox attach`.

Proof: offline case 12 in tests/run-tests.sh (upload body, dedupe, conflict
abort, field refusal, manifest-relative resolution via stubbed /documents);
live: manifest-C-ged-attach.json applied twice on the sandbox — run 1 four
created, run 2 four deduped, one GED file per FAF2026010-013, stored sha256s
equal to the re-fetched sources; tests/replay-idempotency.sh extended with an
attach op (4 created → 4 deduped, ged_files count unchanged) and a live
same-name/different-bytes abort verified.

Closes erp#43

Co-Authored-By: Claude Fable 5 <[email protected]>
Claude-Session: https://claude.ai/code/session_01VRShc4QhLLU73FLHx9vskh
This commit is contained in:
2026-07-19 00:11:59 +02:00
co-authored by Claude Fable 5
parent e54b2f0f5d
commit fb13bdcc4f
11 changed files with 587 additions and 31 deletions
@@ -10,7 +10,7 @@
set -euo pipefail
MANIFEST="${1:?usage: promote-plan.sh <manifest.json>}"
python3 - "$MANIFEST" <<'PY'
import json, sys
import hashlib, json, os, sys
ops = json.load(open(sys.argv[1]))
print("Promote plan — %d operation(s) (symbolic refs resolve at apply time):\n" % len(ops))
for i, op in enumerate(ops, 1):
@@ -46,6 +46,23 @@ for i, op in enumerate(ops, 1):
flds = inp.get("fields") or {}
print(" socid=%s update %d dossier field(s): %s" % (inp.get("socid"), len(flds),
", ".join(sorted(flds)) if flds else "NONE (will be refused)"))
elif t == "attach":
obj = inp.get("object_id") or inp.get("ref")
f = inp.get("file")
# A relative file resolves against the MANIFEST (same rule as apply).
resolved = None
if isinstance(f, str):
resolved = f if os.path.isabs(f) else os.path.normpath(
os.path.join(os.path.dirname(os.path.abspath(sys.argv[1])), f))
print(" object=%s modulepart=%s file=%s" % (obj, inp.get("modulepart"), f))
if resolved and os.path.isfile(resolved):
data = open(resolved, "rb").read()
print(" sha256=%s (%d bytes) (idempotent: dedupe by object+filename+sha256; "
"same name + different content aborts)"
% (hashlib.sha256(data).hexdigest(), len(data)))
else:
print(" !! FILE MISSING at plan time: %s — apply WILL fail; "
"re-fetch the source first" % resolved)
elif t == "contact":
name = " ".join(x for x in (inp.get("firstname"), inp.get("lastname")) if x) or "?"
print(" socid=%s contact %s%s%s (idempotent: dedupe by email, then lastname+firstname)"