Files
Michał Pierzchała e832325e87 refactor(substrate): split host mechanics into @agent-device/host-kit capability ports (#2088)
* refactor: split generic host mechanics into @agent-device/host-kit (#2082 W1)

The shared src/utils closure that blocked the platform-family moves lands
on declared owners: generic host mechanics form a new private
@agent-device/host-kit package between kernel and capture-kit, and
capture-kit keeps capture, snapshot, and recording behavior, depending on
host-kit for the mechanics it needs. tar-stream and yauzl move with the
archive code.

Every seam's exported subpaths are pinned in package-boundaries.test.ts,
the layering model ranks the new zone, R13's allow-list names it, and each
seam carries an exact eager-closure row. ADR-0019's substrate amendment
describes the layout.

Tests that mocked two of the moved modules separately became duplicate
same-seam vi.mock factories, where the second silently replaced the first;
those are merged, and the mocks that production code reaches past are
pinned at their injection points instead.

Co-Authored-By: Claude <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018VngeKZH6zBuJzNBk5YzUH

* refactor(host-kit): one narrow capability port per export

The four technical barrels (exec/fs/values/request) grouped by category
rather than by capability, so a consumer needing one mechanic evaluated
unrelated ones. Each export is now a single capability over the host
machine: command, process, diagnostics, retry, archive, file, request,
version. A port re-exports only what a consumer of that capability uses,
and every port carries its own eager-closure row.

Most of the old values barrel was never host mechanics. Pure record
readers, config-source values, result text, memoization, async scoping,
coordinate validation, and device-scope parsing touch no process, file, or
environment, so they join kernel's other primitives instead.

Closures fall accordingly: capture-kit's png-worker-client from 20 to 10,
png-resize from 28 to 18, session-teardown from 79 to 68, and the CLI from
386 to 380.

Co-Authored-By: Claude <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018VngeKZH6zBuJzNBk5YzUH

* chore: drop the migration inventories and trim the touched comments

Co-Authored-By: Claude <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018VngeKZH6zBuJzNBk5YzUH

* docs: trim the touched host-kit and mutation-lane comments

Co-Authored-By: Claude <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018VngeKZH6zBuJzNBk5YzUH

* docs: keep tool directives only in the touched files

Co-Authored-By: Claude <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018VngeKZH6zBuJzNBk5YzUH

* docs: keep tool directives only across the touched tree

Co-Authored-By: Claude <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018VngeKZH6zBuJzNBk5YzUH

* fix: point the Swift parity comment at the real TS twin and test

The W1 move rewrote this citation to packages/contracts/src/mobile-snapshot-semantics.ts,
which does not exist: the module went to capture-kit while isTapPointInsideViewport itself
went to packages/contracts/src/snapshot-visibility.ts. The TS test line was left pointing at
the pre-move path. Both now resolve.

Co-Authored-By: Claude <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018VngeKZH6zBuJzNBk5YzUH

* fix: repoint comment citations at the homes this refactor moved them to

The W1 move left ~20 comment citations pointing at src/utils/*.ts and
src/request/*.ts paths that no longer exist. Each now names the capability
port that owns the symbol, which survives further file moves:

  exec -> host-kit/command          host-process, owner-identity -> host-kit/process
  diagnostics -> host-kit/diagnostics   atomic-file, process-lock -> host-kit/file
  retry -> host-kit/retry           request progress/cancel -> host-kit/request
  version -> host-kit/version       ttl-memo, source-value, parsing, device-isolation,
                                    keyed-lock, success-text -> kernel subpaths

Comment-only; no closure, budget, or behavior change. ADR citations are left
as written, being dated records of the decision rather than live references.

Co-Authored-By: Claude <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018VngeKZH6zBuJzNBk5YzUH

---------

Co-authored-by: Claude <noreply@anthropic.com>
2026-08-28 07:46:48 +02:00

88 lines
3.8 KiB
TypeScript

import test from 'node:test';
import assert from 'node:assert/strict';
import fs from 'node:fs';
import os from 'node:os';
import path from 'node:path';
import { runCmdSync } from '@agent-device/host-kit/command';
import { readProcessCommand, readProcessStartTime } from '@agent-device/host-kit/process';
// #1781 B1: the oracle's `after-close` checkpoint is only meaningful when it can
// name the sessions that closed — without them it would accept every unfinalized
// capture handle and report clean, which is the vacuous mode the type system now
// refuses in code. The standalone CLI is the one caller that builds options from
// strings rather than types, so it must refuse the same invocation at runtime
// instead of silently degrading to that mode.
const ORACLE_PATH = 'test/integration/support/daemon-leak-oracle.ts';
function runOracle(args: string[]) {
return runCmdSync(process.execPath, ['--experimental-strip-types', ORACLE_PATH, ...args], {
allowFailure: true,
timeoutMs: 60_000,
});
}
test('the leak oracle CLI refuses an after-close checkpoint that names no session', (t) => {
const stateDir = fs.mkdtempSync(path.join(os.tmpdir(), 'agent-device-leak-oracle-cli-'));
// A closed session that left an unfinalized capture handle: the exact residue
// the refused invocation would have reported clean.
const sessionDir = path.join(stateDir, 'sessions', 'closed-one');
fs.mkdirSync(sessionDir, { recursive: true });
fs.writeFileSync(
path.join(sessionDir, 'screen-recording.resource.json'),
`${JSON.stringify({ lifecycle: 'open' })}\n`,
);
t.after(() => fs.rmSync(stateDir, { recursive: true, force: true }));
const refused = runOracle(['--state-dir', stateDir, '--phase', 'after-close']);
assert.notEqual(refused.exitCode, 0, `expected a refusal, got:\n${refused.stdout}`);
assert.match(refused.stderr, /--phase after-close requires at least one --closed-session/);
// A refusal, not a leak report: the checkpoint never ran.
assert.doesNotMatch(refused.stdout, /daemon leak oracle:/);
// The same invocation, once it names the session, runs and finds the handle.
const named = runOracle([
'--state-dir',
stateDir,
'--phase',
'after-close',
'--closed-session',
'closed-one',
'--settle-ms',
'0',
]);
assert.equal(named.exitCode, 1, `expected a leak report, got:\n${named.stdout}${named.stderr}`);
assert.match(named.stdout, /LEAK \(after-close\)/);
assert.match(named.stdout, /sessions\/closed-one\/screen-recording\.resource\.json/);
// `after-shutdown` needs no session identity and is unaffected by the guard.
const shutdown = runOracle(['--state-dir', stateDir, '--settle-ms', '0']);
assert.equal(shutdown.exitCode, 1, shutdown.stderr);
assert.match(shutdown.stdout, /LEAK \(after-shutdown\)/);
});
test('the leak oracle CLI reads an exact daemon-owned process record', (t) => {
const stateDir = fs.mkdtempSync(path.join(os.tmpdir(), 'agent-device-leak-record-cli-'));
const startTime = readProcessStartTime(process.pid);
const command = readProcessCommand(process.pid);
if (!startTime || !command) {
t.skip('host process identity is unavailable in this sandbox');
fs.rmSync(stateDir, { recursive: true, force: true });
return;
}
fs.writeFileSync(
path.join(stateDir, 'owned-processes.json'),
`${JSON.stringify({
version: 1,
processes: [{ pid: process.pid, startTime, command, purpose: 'managed-web-browser' }],
})}\n`,
);
t.after(() => fs.rmSync(stateDir, { recursive: true, force: true }));
const result = runOracle(['--state-dir', stateDir, '--settle-ms', '0']);
assert.equal(result.exitCode, 1, `${result.stdout}\n${result.stderr}`);
assert.match(result.stdout, /managed-web-browser: pid/);
assert.match(result.stdout, /owned processes still alive: 1/);
});