mirror of
https://github.com/callstack/agent-device.git
synced 2026-09-14 20:06:34 +08:00
05a1d76f2e
* test: gate daemon RPC wire compatibility against the last released tag (#1432) ADR 0006 fixes exactly when DAEMON_RPC_PROTOCOL_VERSION must be bumped, and nothing checked that it was. The runtime guard (readRemoteDaemonHealth) refuses a mismatched peer, but only fires when someone remembered the bump — a wire change that skipped it left both sides advertising protocol 2 while parsing different payloads, which is the failure ADR 0006 exists to prevent. Local daemons cannot skew (isReusableDaemonInfo takes over on any package version mismatch). Cross-machine is skewed by design — proxy, cloud/limrun, a remote macOS host — and ADR 0006 explicitly rules package version out as the compatibility gate there, so the one boundary where skew is intended was the one boundary with no gate. test/wire-compat/surface.ts declares the wire surface grouped by the ADR bullet each group serves, quoting it, with an `uncovered` note where a bullet is only partly digestible (the /health and /rpc literals inside http-server.ts stay reviewer-owned: a moved route 404s at connect time rather than misparsing). ledger.json records what each declaration hashes to, at which protocol version. Two gates, split for the same reason the replay-compat corpus splits: - unit-core holds the ledger to its source and prints the digest to paste; - Released-Surface Compatibility reads the ledger at the last RELEASED tag and requires the drift since then to carry a bump or a compatibleChanges ack. From one commit a bumped ledger and an unbumped one are both just an edited file, so only a released baseline can tell them apart. Acks are keyed by the digest they cover, so one "added an optional field" cannot launder later changes. Digests ignore comments and formatting; the manifest's closure is derived from the AST, so a field typed by an unlisted sibling fails rather than sitting outside the gate. CI cost: one added job (checkout + toolchain + two node scripts, ~1 min), mirroring the existing full-history replay-compat job. * test: close wire-surface overclaim and make the closure fail closed (#1432) Addresses both review P1s on #1717. P1 — the manifest materially overclaimed ADR 0006 coverage. It quoted all four bullets while digesting only the payload TYPES, so the producer and consumer seams could break a skewed peer without moving a listed digest. Now listed on both sides of every boundary: JSON-RPC method sets and the projections that turn each method's params into a DaemonRequest, createRpcError/sendJson/ writeRpcResponseEnvelope, resolveToken and the auth-hook types, upload preflight/finalize/308 handlers and the resumable ticket shape, artifact route and download/inventory framing, REST error mapping, and the client's own payload builder, lease-method mapping, response parser and error projection. 57 -> 117 declarations. What stays out is now named rather than implied: createDaemonHttpServer's dispatch wiring and the /health and /rpc literals inside it. Everything it dispatches WITH is digested individually, and a moved route 404s at connect time rather than misparsing — the loud failure, not the silent one. P1 — imported and re-exported payload shapes escaped the closure. declarationHomes() scanned only the manifest's own files and the walk continued silently when a name could not be placed, so a listed type could gain foo?: ImportedShape from a new module and stay green. Resolution is now explicit and fails closed: relative imports, workspace specifiers (through the owning package's own exports map, so a re-pointed export cannot drop a type), and facade re-export chains. Every referenced name must land on a listed declaration, a waiver with a written reason, a declared external module, or the TS/Node global set. Fixed two extractor blind spots the walk exposed: a declaration's own generic parameters and `as const` were being reported as references. Planted-red proofs (wire-mutations.test.ts): 13 cases independently mutate method naming, response serialization, response parsing, auth projection, upload ticket shape, 308 framing, artifact framing, REST error mapping, and progress framing, each asserting the digest moves; 3 probes prove the closure really reaches across a package boundary, a facade re-export, and a plain relative import. Mutations apply inside the declaration's own span — a whole-file replace silently hit a sibling sharing the substring, which is how the first draft of one case passed vacuously. The largest waiver pair (InternalRequestOptions, CommandFlags) rests on ADR 0006's own additive rule: they reach the peer inside DaemonRequest's untyped flags/input bags, and the decision says a new flag needs no bump. Digesting them would fire the gate on every new CLI flag and train reviewers to rubber-stamp acks. * test: list the consumer half of the auxiliary HTTP boundaries (#1432) Addresses the remaining review P1 on #1717. The manifest claimed both sides of response/upload/artifact framing while listing nothing from upload-client.ts, daemon-artifacts.ts, or the health consumer in daemon-client-transport.ts, so those parsers could narrow without moving a listed digest or protocol 2. Now listed (117 -> 141 declarations): - /health consumer: RemoteDaemonHealth, readHealthPayload, readDaemonHttpHealth, readRemoteDaemonHealth. This is the sharpest of the three — narrowing the reader or the comparison disables the very refusal ADR 0006 exists to guarantee, and nothing else in the repo would notice. - /upload consumer: UploadResponse, UploadPreflightResponse, UploadPreflightResult, parseUploadPreflightResult, requestUploadPreflight, uploadDirectArtifact, tryDirectUploadWithResume, shouldRetryDirectUpload, finalizeDirectUpload, uploadLegacyArtifact, ARTIFACT_HASH_ALGORITHM, isStringRecord, and PreparedUploadArtifact — whose sha256/sizeBytes/fileName/artifactType/ contentType fields ARE the preflight body the daemon parses. - /artifacts/* consumer: DaemonArtifactEndpoint, buildDaemonArtifactUrl, isRemoteDaemon, DownloadRemoteArtifactParams, downloadRemoteArtifact, materializeRemoteArtifacts, resolveMaterializedArtifactPath. Running the closure fail-closed over the new files surfaced three more stops, each decided rather than skipped: PreparedUploadArtifact listed (it is payload), UploadProgressSink waived (client-local rendering, never leaves the process), and src/daemon/types.ts#DaemonArtifact waived as a re-export alias of the listed kernel type, matching its DaemonRequest/DaemonResponse siblings. 10 more planted-red mutations cover the new seams: health version-read and mismatch-refusal defeated, RemoteDaemonHealth field dropped, preflight parser narrowed, preflight/legacy response shapes narrowed, finalize body key renamed, ticket field renamed, artifact tenant header dropped, artifact URL moved. A fourth closure probe proves the upload-consumer files are genuinely reached by the walk rather than merely listed. 22 -> 33 tests. The README now states the coverage as a producer/consumer table per boundary, so the claim is checkable at a glance instead of asserted in prose. * test: list the client half of the resumable 308 contract (#1432) Addresses the third review P1 on #1717. Listing the daemon's handleResumableUpload proved it still PRODUCES 308; nothing proved the client still CONSUMES the released one. src/remote/upload-stream.ts owns that half and was entirely outside the manifest, so a newer client could stop accepting `upload-offset`, change how it reads `Range: bytes=0-N`, or emit a different resumed `Content-Range` without moving one of the 141 listed digests. Now listed (141 -> 151): UploadStreamResponse, streamFileToHttpRequest, streamFileToHttpRequestAttempt, buildUploadRequestHeaders, isUploadResumeStatus, isUploadRedirectStatus, parseUploadResumeOffset, parseNonNegativeIntegerHeader, firstHeaderValue, MAX_UPLOAD_REDIRECTS. streamFileToHttpRequestAttempt is listed despite its size, unlike createDaemonHttpServer which stays in `uncovered`. The distinction is stated at the declaration: the HTTP server only dispatches to handlers that are each digested, while the attempt loop IS the resume state machine — it decides whether a 308 continues the upload and what the next request carries, so its sequencing alone can break a released daemon while every helper keeps its digest. 6 new planted-red mutations prove the client half moves the ledger: a dropped `upload-offset` fallback, narrowed Range parsing, a changed resumed Content-Range, 308 no longer treated as continue, a narrowed UploadStreamResponse, and dropped header-value coercion. 33 -> 39 tests. Closure fail-closed surfaced two more stops: UploadStreamProgressOptions waived (local byte-progress rendering) and URL/URLSearchParams added to the global set. README now carries a `/upload` resume row in the producer/consumer table, and names the pattern behind three rounds of review: the coverage sentence kept getting written ahead of the coverage, so the table and the `uncovered` notes are the claims to trust — they are checkable against surface.ts, prose is not. --------- Co-authored-by: Claude <noreply@anthropic.com>
140 lines
6.2 KiB
TypeScript
140 lines
6.2 KiB
TypeScript
/**
|
|
* Daemon RPC wire-surface gate, offline half (#1432).
|
|
*
|
|
* ADR 0006 fixes when `DAEMON_RPC_PROTOCOL_VERSION` must be bumped and until
|
|
* now nothing checked it. This lane is the tripwire: it fails the moment a
|
|
* declaration the manifest calls wire surface changes shape, naming the symbol
|
|
* and printing the digest to paste. It needs no history and no network, so it
|
|
* runs in `unit-core` on every PR.
|
|
*
|
|
* It deliberately cannot tell a bump from an ack — both look like an edited
|
|
* ledger from a single commit. `pnpm check:daemon-wire-compat` answers that
|
|
* half against the last RELEASED tag, which is the only baseline ADR 0006 and
|
|
* #1432 accept.
|
|
*/
|
|
|
|
import assert from 'node:assert/strict';
|
|
import fs from 'node:fs';
|
|
import path from 'node:path';
|
|
import { test } from 'vitest';
|
|
import { DAEMON_RPC_PROTOCOL_VERSION } from '../../src/daemon/http-health.ts';
|
|
import { isExternalWireSpecifier, WIRE_CLOSURE_WAIVERS } from './closure-policy.ts';
|
|
import { findClosureGaps } from './closure.ts';
|
|
import { digestDeclaration } from './declaration-digest.ts';
|
|
import { digestWireSurface, readWireLedger, WIRE_LEDGER_PATH } from './ledger.ts';
|
|
import { WIRE_DECLARATIONS, WIRE_SURFACE, wireDeclarationKey } from './surface.ts';
|
|
|
|
const repoRoot = path.resolve(import.meta.dirname, '..', '..');
|
|
const ledger = readWireLedger(repoRoot);
|
|
const digests = digestWireSurface(repoRoot, WIRE_DECLARATIONS, digestDeclaration);
|
|
|
|
function readSource(file: string): string {
|
|
return fs.readFileSync(path.join(repoRoot, file), 'utf8');
|
|
}
|
|
|
|
test('the ledger records the protocol version the daemon advertises', () => {
|
|
assert.equal(
|
|
ledger.protocolVersion,
|
|
DAEMON_RPC_PROTOCOL_VERSION,
|
|
`${WIRE_LEDGER_PATH} says protocol ${ledger.protocolVersion} but DAEMON_RPC_PROTOCOL_VERSION is ` +
|
|
`${DAEMON_RPC_PROTOCOL_VERSION}. Bumping the constant means updating the ledger in the same ` +
|
|
`commit — see test/wire-compat/README.md.`,
|
|
);
|
|
});
|
|
|
|
test('the ledger covers exactly the declarations the manifest claims', () => {
|
|
const claimed = [...new Set(WIRE_DECLARATIONS.map(wireDeclarationKey))].sort();
|
|
const recorded = Object.keys(ledger.declarations).sort();
|
|
assert.deepEqual(
|
|
recorded,
|
|
claimed,
|
|
`${WIRE_LEDGER_PATH} and test/wire-compat/surface.ts disagree about which declarations are wire ` +
|
|
`surface. Add or drop the ledger entry in the same commit as the manifest change.`,
|
|
);
|
|
});
|
|
|
|
test('every wire declaration still hashes to its ledger digest', () => {
|
|
const drifted = [...digests].filter(([key, digest]) => ledger.declarations[key] !== digest);
|
|
assert.deepEqual(
|
|
drifted.map(([key]) => key),
|
|
[],
|
|
`Daemon RPC wire surface changed (ADR 0006). Each line below is a declaration whose shape ` +
|
|
`moved:\n${drifted
|
|
.map(
|
|
([key, digest]) =>
|
|
` ${key}\n now: ${digest}\n ledger: ${ledger.declarations[key]}`,
|
|
)
|
|
.join('\n')}\n` +
|
|
`Decide which ADR 0006 case this is, then follow test/wire-compat/README.md: a breaking ` +
|
|
`change bumps DAEMON_RPC_PROTOCOL_VERSION, an additive one adds a compatibleChanges entry. ` +
|
|
`Either way paste the "now" digest into ${WIRE_LEDGER_PATH}.`,
|
|
);
|
|
});
|
|
|
|
test('every compatible-change ack names a declaration at its current digest', () => {
|
|
const stale = ledger.compatibleChanges.filter(
|
|
(ack) => digests.get(ack.declaration) !== ack.digest,
|
|
);
|
|
assert.deepEqual(
|
|
stale.map((ack) => ack.declaration),
|
|
[],
|
|
`${WIRE_LEDGER_PATH} carries compatibleChanges entries whose digest is no longer current. An ` +
|
|
`ack covers one specific post-change shape so it cannot be recycled for the next change; ` +
|
|
`drop the stale entry — git history is the audit trail, the ledger is the gate.`,
|
|
);
|
|
for (const ack of ledger.compatibleChanges) {
|
|
assert.ok(
|
|
ack.rationale.trim().length > 0,
|
|
`The compatibleChanges entry for ${ack.declaration} needs a rationale saying why a peer on ` +
|
|
`the previous protocol version still parses this payload (ADR 0006, "additive changes").`,
|
|
);
|
|
}
|
|
});
|
|
|
|
// Without this, adding `foo?: NewShape` to a wire type would move only that
|
|
// type's digest and leave `NewShape` — the declaration that actually decides
|
|
// what the peer parses — outside the gate. The manifest's closure is therefore
|
|
// derived from the AST rather than trusted: "something enumerates N" (#1412).
|
|
//
|
|
// It FAILS CLOSED (review P1). The first version scanned only the manifest's
|
|
// own files and skipped any name it could not place, so an imported payload
|
|
// shape escaped entirely. Now every referenced name must land somewhere
|
|
// someone wrote down: a listed declaration, a closure-policy waiver, a
|
|
// declared external module, or the TypeScript global set.
|
|
test('the manifest is closed over the wire types it references', () => {
|
|
const { omitted, unresolved } = findClosureGaps({
|
|
repoRoot,
|
|
readSource,
|
|
declarations: WIRE_DECLARATIONS,
|
|
claimed: new Set(WIRE_DECLARATIONS.map(wireDeclarationKey)),
|
|
waivers: WIRE_CLOSURE_WAIVERS,
|
|
isExternalSpecifier: isExternalWireSpecifier,
|
|
});
|
|
|
|
assert.deepEqual(
|
|
omitted,
|
|
[],
|
|
`These declarations are referenced by the daemon RPC wire surface but are neither listed in ` +
|
|
`test/wire-compat/surface.ts nor waived in closure-policy.ts, so their shape is ungated. ` +
|
|
`List the ones that carry payload; waive the ones that cannot, with the reason.`,
|
|
);
|
|
assert.deepEqual(
|
|
unresolved,
|
|
[],
|
|
`The closure could not place these type names, and it fails closed rather than skipping them ` +
|
|
`— an unplaceable name is exactly how an imported payload shape escaped before. Either the ` +
|
|
`import is a module that belongs in WIRE_EXTERNAL_MODULES, or the resolver needs to learn ` +
|
|
`the specifier form (test/wire-compat/module-resolution.ts).`,
|
|
);
|
|
});
|
|
|
|
test('every manifest group cites the ADR 0006 bullet it covers', () => {
|
|
for (const group of WIRE_SURFACE) {
|
|
assert.ok(
|
|
group.adrBullet.trim().length > 0 && group.declarations.length > 0,
|
|
`Each wire-surface group quotes one ADR 0006 bullet and lists at least one declaration; a ` +
|
|
`bullet with nothing to digest belongs in "uncovered" with its reason instead.`,
|
|
);
|
|
}
|
|
});
|