Files
callstack__agent-device/scripts/fuzz/invariant.ts
devin-ai-integration[bot] 006c4cadc9 test: nightly parser fuzz lane — parser input fails as typed AppErrors, never hangs (#1414) (#1438)
* test: nightly parser fuzz lane with typed-AppError invariant (#1414)

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* test(fuzz): run envelope, artifact promotion, and harness self-check tests (#1414)

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* test(fuzz): shared scheduled-lane envelope on every terminal path, watchdog after ready (#1414)

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* test(fuzz): envelope for malformed options; add scheduled-lane health consumer (#1414, #1430)

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(lanes): actions:read scope, terminal error envelope, first-due grace (#1414, #1430)

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(lanes): anchor first-run grace to schedule registration, use exec helper in tests (#1414, #1430)

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(lanes): portable POSIX pickaxe pattern for schedule registration (#1414, #1430)

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* refactor(fuzz): fast-check generators over the shared hazard list, drop the bundled lane-health work (#1414)

- Strip scripts/scheduled-lane/* and scheduled-lane-health.yml: that watcher is #1430's own
  deliverable and collides with PR #1439's implementation of the same lane. What this lane owes
  (a per-run envelope) moves into scripts/fuzz/envelope.ts.
- Rebase onto #1437 and rebuild the generator layer on fast-check: cases come from arbitraries
  sharing SELECTOR_VALUE_HAZARDS with the property suite, and counterexamples are shrunk, so a
  failure names a minimal input plus fast-check's seed/path instead of a 20k-char random string.
- Route harness.test.ts into the serialized subprocess-stub project.
- Drop the AGENT_DEVICE_FUZZ_STARTUP_DELAY_MS test seam: the ready handshake is now proven by a
  case budget far below real worker startup.

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* test(fuzz): replay the regression corpus through the worker watchdog (#1414)

A promoted hang case used to wedge the unit job until the CI timeout, because corpus replay called
checkCase in-process. It now goes through the same worker-backed watchdog the nightly lane uses, so
such a case fails against a 5s per-case budget; the file moves to the serialized subprocess-stub
project with the rest of the worker-driven fuzz tests.

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* test(fuzz): let the watchdog outlive vitest's default case timeout (#1414)

A wedged parser was surfacing as a bare 'Test timed out in 5000ms' instead of the named hang:
failure that says which input wedged, because the file's vitest timeout was shorter than the
watchdog budget times the number of replayed cases.

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* test(fuzz): complete drift provenance in the lane envelope (#1414)

configHash now covers every input that decides what a seed generates (generate.ts and the shared property arbitraries, not just the arbitraries/targets/invariant), and tool records fast-check's installed version. A generation-loop edit or a fast-check upgrade previously changed the case set while the envelope looked unchanged. A test recomputes the hash with each input omitted so a future omission fails.

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

---------

Co-authored-by: Michał Pierzchała <thymikee@gmail.com>
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-07-28 11:29:25 +02:00

64 lines
2.1 KiB
TypeScript

// The single invariant the parser fuzz lane enforces (#1414).
//
// Parsers are the front door for agent-authored input, so the contract is not "parses
// correctly" (nobody can say what a mutated string should mean) but "fails well":
//
// 1. a rejection is an `AppError` — never a bare Error, TypeError, string, or undefined;
// 2. the normalized error carries a non-empty `hint`, so the caller is told what to do;
// 3. the case terminates — enforced by the harness watchdog, not by this module, because
// synchronous parsers cannot be interrupted from inside their own tick.
import { AppError, normalizeError } from '../../src/kernel/errors.ts';
import type { FuzzTarget, FuzzTargetName } from './target-types.ts';
export type FuzzFailureKind = 'untyped-throw' | 'empty-hint' | 'hang';
export type FuzzFailure = {
target: FuzzTargetName;
input: string;
kind: FuzzFailureKind;
detail: string;
};
/**
* Runs one case and returns the invariant violation it produced, or `null`.
* Accepting the parse is a pass: the lane judges rejections, not results.
*/
export function checkCase(target: FuzzTarget, input: string): FuzzFailure | null {
try {
target.run(input);
return null;
} catch (error) {
if (!(error instanceof AppError)) {
return {
target: target.name,
input,
kind: 'untyped-throw',
detail: describeThrown(error),
};
}
const hint = normalizeError(error).hint;
if (typeof hint !== 'string' || hint.trim().length === 0) {
return {
target: target.name,
input,
kind: 'empty-hint',
detail: `AppError ${error.code} has no hint: ${error.message}`,
};
}
return null;
}
}
function describeThrown(error: unknown): string {
if (error instanceof Error) {
const stackLine = error.stack?.split('\n')[1]?.trim();
return `${error.name}: ${error.message}${stackLine ? ` (at ${stackLine})` : ''}`;
}
return `non-Error throw: ${typeof error} ${String(error)}`;
}
export function describeFailure(failure: FuzzFailure): string {
return `[${failure.target}] ${failure.kind}: ${failure.detail}`;
}