fix(code-runtime): flatten worker JSON transport

This commit is contained in:
Tianyi Cui
2026-07-22 19:09:27 +08:00
parent d6f478488d
commit ef2de530ff
13 changed files with 352 additions and 58 deletions
@@ -22,14 +22,14 @@ Every field is validated and defaulted; `maxOutputBytes` is a safe integer of at
- **Type-strip host-side, in execution context** — the program is wrapped in an async-function shell, stripped with `node:module`'s `stripTypeScriptTypes` (erasable syntax only — `enum`/namespaces are rejected as a program `exception` and no worker spawns), and sliced back out byte-positioned; it then executes as the body of an `AsyncFunction`, so top-level `await`/`return` work.
- **The port assumes a hostile peer** — model code can reach `parentPort` and forge traffic, so every inbound message is shape-validated and REBUILT before anything reads it (`null`, primitives, junk types, and malformed payloads drop without a throw; forged extra fields never ride along), the host answers each call id at most once, resolves binding names as OWN properties only (a forged `constructor` cannot walk a prototype chain), drops post-settlement replies, and validates every binding resolution and completion as lossless JSON. Forged `log`/`done` messages cannot bypass the outer cap: the host repeats validation and accounts every admitted log plus the completion or diagnostic. Worker-side namespaces are null-prototype with `defineProperty`, so `__proto__`-shaped binding names are ordinary keys.
- **Two independent budgets, because the peer is hostile** — `computeMs` meters the worker's MEASURED busy time (`worker.performance.eventLoopUtilization()` polling): a hot loop cannot hide behind a pending decoy dispatch, and a program awaiting a slow tool accrues nothing. `maxWallMs` backstops what busy time cannot see (awaiting a promise nobody resolves). Both funnel into `worker.terminate()`, which ends hot synchronous loops too; heap overflow surfaces as the worker's OOM exit (`kind: 'worker-exit'`).
- **Intermediate binding values are complete JSON** — binding arguments and resolutions cross by structured clone after iterative lossless-JSON validation and have no byte or call-stack depth cap. They never enter the outer-output ledger or model context; provider/executor acquisition bounds and process/worker memory remain the limits.
- **Intermediate binding values are complete JSON** — binding arguments and resolutions undergo iterative lossless-JSON validation, flatten into a bounded-depth pre-order wire value for structured clone, and rebuild iteratively on the other side. They have no byte, JavaScript call-stack, or nested structured-clone depth cap. They never enter the outer-output ledger or model context; provider/executor acquisition bounds and process/worker memory remain the limits.
- **Logs stream eagerly into one outer ledger** — console/stdout/stderr text crosses the port in emission order, so a timed-out or killed program still shows what it printed. Native writes that bypass the patched stream slots arrive on pipes independent of the completion port; settlement therefore continues bounded pipe capture until worker termination completes before materializing the result. `maxOutputBytes` accounts the JSON serialization of the outer `logs` array plus the completion value or failure diagnostic. At or below the cap the exact value returns; a lossy completion is `invalid-output`, and a combined overflow is `output-limit` rather than a substituted inspected string. The failure retains the fitting captured prefix and later follows the normal outer `run_code` spill policy.
- **Empty environment** — the worker gets `env: {}` and `execArgv: []`: no ambient credentials (stronger than the scrubbed-env rule for spawned commands) and no inherited loader flags.
- **Dispose to quiescence** — teardown fails in-flight runs as `abort` and AWAITS each worker's exit before resolving.
## The worker entry, unbuilt and built
Source mode loads erasable-only `src/worker.ts` through Node's native type stripping. Its transitive runtime closure contains only Node built-ins and relative source modules, so a fresh checkout never requires a sibling workspace package's unbuilt `lib/` export. The worker-local JSON snapshotter is parity-tested against the session-owned canonical boundary; the host repeats canonical validation after structured clone. Built mode passes the sibling `lib/worker.cjs` as a filesystem path because pkg's VFS Worker hook expects CommonJS; the same path works under ordinary Node. `tests/built-lib.e2e.ts` pins the real load path required by [docs/testing.md](../../../docs/testing.md).
Source mode loads erasable-only `src/worker.ts` through Node's native type stripping. Its transitive runtime closure contains only Node built-ins and relative source modules, so a fresh checkout never requires a sibling workspace package's unbuilt `lib/` export. The worker-local JSON snapshotter is parity-tested against the session-owned canonical boundary; both sides flatten and rebuild validated values around the message port so application nesting never reaches structured clone. Built mode passes the sibling `lib/worker.cjs` as a filesystem path because pkg's VFS Worker hook expects CommonJS; the same path works under ordinary Node. `tests/built-lib.e2e.ts` pins the real load path required by [docs/testing.md](../../../docs/testing.md).
The SDK surface is the default/named `WorkerCodeRuntime` class plus `Config`. The operational `./worker` subpath exists only as the packaged spawn entry; the wire protocol and bootstrap helpers are source-private implementation details.
@@ -8,7 +8,7 @@
import { inspect } from 'node:util'
import type { DoneMessage, ReplyMessage, WorkerBootData, WorkerToHost } from './protocol.ts'
import { jsonValueBytesUpTo } from './output-json.ts'
import { snapshotCodeJsonValue } from './worker-json.ts'
import { decodeWorkerJson, encodeWorkerJson, snapshotCodeJsonValue } from './worker-json.ts'
/** The port surface the bootstrap needs — satisfied by `parentPort` and by the tests' fake. */
export interface BootstrapPort {
@@ -152,7 +152,7 @@ export function truncateUtf8Bytes(text: string, maxBytes: number): string {
*
* @param value - the program's completion value.
* @param maxOutputBytes - the byte cap for the outer result.
* @returns the done-message fragment: `{}` for `undefined`, else `{ value }`.
* @returns the done-message fragment: `{}` for `undefined`, else a flat wire `{ value }`.
*/
export function prepareCompletion(value: unknown, maxOutputBytes: number): Omit<DoneMessage, 'type'> {
if (value === undefined) return {}
@@ -168,7 +168,7 @@ export function prepareCompletion(value: unknown, maxOutputBytes: number): Omit<
if (jsonValueBytesUpTo(snapshot, maxOutputBytes) === undefined) {
return { error: { kind: 'output-limit', message: `outer output exceeded ${maxOutputBytes} bytes` } }
}
return { value: snapshot }
return { value: encodeWorkerJson(snapshot) }
}
/** One awaited binding call's settlement handles, keyed by call id in the pending map. */
@@ -208,8 +208,13 @@ export function wireReplies(port: BootstrapPort, pending: Map<number, PendingCal
const entry = pending.get(message.id)
if (!entry) return
pending.delete(message.id)
if (message.ok) entry.resolve(message.value)
else entry.reject(new Error(message.message))
if (message.ok) {
const value = decodeWorkerJson(message.value)
if (value === undefined) entry.reject(new Error('binding resolution must be lossless JSON'))
else entry.resolve(value)
} else {
entry.reject(new Error(message.message))
}
})
}
@@ -238,7 +243,7 @@ export function makeNamespaces(
Object.defineProperty(namespace, name, {
enumerable: true,
value: (args: unknown): Promise<unknown> => {
let detached: unknown
let detached: ReturnType<typeof snapshotCodeJsonValue>
try {
detached = snapshotCodeJsonValue(args)
} catch {
@@ -254,7 +259,7 @@ export function makeNamespaces(
},
})
try {
port.postMessage({ type: 'call', id, global, name, args: detached })
port.postMessage({ type: 'call', id, global, name, args: encodeWorkerJson(detached) })
} catch (error: unknown) {
pending.delete(id)
const message = `binding arguments must be structured-cloneable: ${error instanceof Error ? error.message : String(error)}`
@@ -17,6 +17,8 @@ import type { CodeBindingFunction, CodeJsonValue, CodeRunFailure, CodeRunRequest
import { snapshotJsonValue } from '@deepseek-ai/dsh-session'
import type { ReplyMessage, WorkerBootData, WorkerToHost } from './protocol.ts'
import { jsonStringBytesUpTo, jsonValueBytesUpTo, truncateJsonStringBytes } from './output-json.ts'
import { decodeWorkerJson, encodeWorkerJson } from './worker-json.ts'
import type { WorkerJsonWire } from './worker-json.ts'
/** Plugin config: every execution cap, changeable from `cordis.yml` (no hardcoded tunables). */
export interface Config {
@@ -142,7 +144,7 @@ function parseWorkerMessage(raw: unknown): WorkerToHost | undefined {
switch (m.type) {
case 'call': {
if (typeof m.id !== 'number' || typeof m.global !== 'string' || typeof m.name !== 'string') return undefined
return { type: 'call', id: m.id, global: m.global, name: m.name, args: m.args }
return { type: 'call', id: m.id, global: m.global, name: m.name, args: m.args as WorkerJsonWire }
}
case 'log': {
if (typeof m.text !== 'string') return undefined
@@ -150,7 +152,7 @@ function parseWorkerMessage(raw: unknown): WorkerToHost | undefined {
}
case 'output-limit': return { type: 'output-limit' }
case 'done': {
if (m.error === undefined) return { type: 'done', ...m.value !== undefined ? { value: m.value } : {} }
if (m.error === undefined) return { type: 'done', ...m.value !== undefined ? { value: m.value as WorkerJsonWire } : {} }
const error = m.error
if (typeof error !== 'object' || error === null) return undefined
const { kind, message } = error as Record<string, unknown>
@@ -409,10 +411,7 @@ export class WorkerCodeRuntime extends CodeRuntime {
finish(() => output.success([...logs, ...strayLogs]))
return
}
// The worker-thread boundary has already structured-cloned this
// hostile value, so accessors and proxies cannot survive to throw
// during the lossless-JSON snapshot.
const value = snapshotJsonValue(message.value) as CodeJsonValue | undefined
const value = decodeWorkerJson(message.value)
if (value === undefined) {
finish(() => output.failure([...logs, ...strayLogs], { kind: 'invalid-output', message: 'program completion must be lossless JSON' }))
} else {
@@ -442,9 +441,7 @@ export class WorkerCodeRuntime extends CodeRuntime {
reply({ type: 'reply', id: message.id, ok: false, message: `unknown binding ${JSON.stringify(`${message.global}.${message.name}`)}` })
return
}
// Structured clone has already removed accessors and proxies, so the
// host can repeat the lossless snapshot without a reflective throw.
const args = snapshotJsonValue(message.args) as CodeJsonValue | undefined
const args = decodeWorkerJson(message.args)
if (args === undefined) {
reply({ type: 'reply', id: message.id, ok: false, message: 'binding arguments must be lossless JSON' })
return
@@ -461,7 +458,7 @@ export class WorkerCodeRuntime extends CodeRuntime {
if (value === undefined) {
reply({ type: 'reply', id: message.id, ok: false, message: 'binding resolution must be lossless JSON' })
} else {
reply({ type: 'reply', id: message.id, ok: true, value })
reply({ type: 'reply', id: message.id, ok: true, value: encodeWorkerJson(value) })
}
} catch (error: unknown) {
reply({ type: 'reply', id: message.id, ok: false, message: messageOf(error) })
@@ -5,6 +5,8 @@
* @module @deepseek-ai/dsh-code-runtime-worker/src/protocol
*/
import type { WorkerJsonWire } from './worker-json.ts'
/** What the host hands the worker at spawn, via `workerData`. */
export interface WorkerBootData {
/** The type-stripped (plain JS) program body. */
@@ -24,8 +26,8 @@ interface CallMessage {
global: string
/** The function name within the namespace. */
name: string
/** The single argument, structured-clone-plain. */
args: unknown
/** The single argument as a flat lossless-JSON wire value. */
args: WorkerJsonWire
}
/** Worker → host: captured text, streamed eagerly so output survives a mid-run termination (timeout, abort, OOM). */
@@ -43,13 +45,13 @@ interface OutputLimitMessage {
* Worker → host: the program settled. `error` carries a program exception
* (the only failure the bootstrap itself can report — budgets, aborts, and
* substrate death are observed host-side). `value` is present only on a
* clean completion that produced one (already size-capped and
* clone-safe per the bootstrap's value preparation). Logs are NOT carried
* here — they streamed eagerly as {@link LogMessage}s.
* clean completion that produced one, as a flat wire value already
* size-capped and lossless per the bootstrap. Logs are NOT carried here —
* they streamed eagerly as {@link LogMessage}s.
*/
export interface DoneMessage {
type: 'done'
value?: unknown
value?: WorkerJsonWire
error?: { kind: 'exception' | 'invalid-output' | 'output-limit'; message: string }
}
@@ -58,5 +60,5 @@ export type WorkerToHost = CallMessage | LogMessage | OutputLimitMessage | DoneM
/** Host → worker: the answer to one {@link CallMessage}. */
export type ReplyMessage =
| { type: 'reply'; id: number; ok: true; value: unknown }
| { type: 'reply'; id: number; ok: true; value: WorkerJsonWire }
| { type: 'reply'; id: number; ok: false; message: string }
@@ -150,4 +150,185 @@ export function snapshotCodeJsonValue(value: unknown): CodeJsonValue | undefined
}
return root
}
interface ArrayWireToken {
kind: 'array'
length: number
}
interface ObjectWireToken {
kind: 'object'
keys: string[]
}
type WorkerJsonToken = null | boolean | number | string | ArrayWireToken | ObjectWireToken
/**
* A pre-order, bounded-depth transport for one lossless JSON value. Container
* markers and scalar leaves share one flat token array, so `worker_threads`
* never has to structured-clone the value's application nesting.
*/
export type WorkerJsonWire = WorkerJsonToken[]
/**
* Flatten one validated JSON value for the worker-thread message port.
* @param value - the lossless JSON value to transport.
* @returns a pre-order token stream whose own nesting is bounded.
*/
export function encodeWorkerJson(value: CodeJsonValue): WorkerJsonWire {
const wire: WorkerJsonWire = []
const pending: CodeJsonValue[] = [value]
for (let current = pending.pop(); current !== undefined; current = pending.pop()) {
if (current === null || typeof current === 'boolean' || typeof current === 'number' || typeof current === 'string') {
wire.push(current)
continue
}
if (Array.isArray(current)) {
wire.push({ kind: 'array', length: current.length })
for (let index = current.length - 1; index >= 0; index--) {
const item = current[index]
if (item === undefined) throw new Error('cannot encode a sparse JSON array')
pending.push(item)
}
continue
}
const keys = Object.keys(current)
wire.push({ kind: 'object', keys })
for (let index = keys.length - 1; index >= 0; index--) {
const key = keys[index]
/* v8 ignore next -- the loop is bounded by the captured key count. */
if (key === undefined) throw new Error('cannot encode a missing JSON object key')
const item = current[key]
if (item === undefined) throw new Error('cannot encode an undefined JSON object property')
pending.push(item)
}
}
return wire
}
type DecodeFrame =
| { kind: 'array'; target: CodeJsonValue[]; length: number; index: number }
| { kind: 'object'; target: Record<string, CodeJsonValue>; keys: string[]; index: number }
/** Whether an array contains exactly its dense indexed slots and `length`. */
function isDenseArray(value: unknown[]): boolean {
if (!hasPlainArrayPrototype(value) || Reflect.ownKeys(value).length !== value.length + 1) return false
for (let index = 0; index < value.length; index++) {
if (!Object.hasOwn(value, index)) return false
}
return true
}
/** Return one exact container marker, or reject any extra/missing fields. */
function containerToken(value: object): ArrayWireToken | ObjectWireToken | undefined {
if (Array.isArray(value) || !hasPlainObjectPrototype(value)) return undefined
const keys = enumerableStringKeys(value)
if (keys === undefined) return undefined
const token = value as Record<string, unknown>
if (token.kind === 'array') {
if (keys.length !== 2 || !keys.includes('kind') || !keys.includes('length')) return undefined
const length = token.length
return typeof length === 'number' && Number.isSafeInteger(length) && length >= 0
? { kind: 'array', length }
: undefined
}
if (token.kind === 'object') {
if (keys.length !== 2 || !keys.includes('kind') || !keys.includes('keys')) return undefined
const objectKeys = token.keys
if (!Array.isArray(objectKeys) || !isDenseArray(objectKeys)) return undefined
const unique = new Set<string>()
const normalizedKeys: string[] = []
for (const key of objectKeys as unknown[]) {
if (typeof key !== 'string' || unique.has(key)) return undefined
unique.add(key)
normalizedKeys.push(key)
}
return { kind: 'object', keys: normalizedKeys }
}
return undefined
}
/**
* Rebuild one lossless JSON value from the flat worker-thread wire format.
* Malformed or incomplete traffic returns `undefined`; traversal is iterative
* and therefore independent of the transported value's application depth.
* @param input - untrusted message-port payload.
* @returns the detached JSON value, or `undefined` when the wire is invalid.
*/
export function decodeWorkerJson(input: unknown): CodeJsonValue | undefined {
try {
if (!Array.isArray(input) || !isDenseArray(input) || input.length === 0) return undefined
const wire = input as unknown[]
const frames: DecodeFrame[] = []
let root: CodeJsonValue | undefined
let rootAssigned = false
const attach = (value: CodeJsonValue): boolean => {
const parent = frames.at(-1)
if (!parent) {
if (rootAssigned) return false
root = value
rootAssigned = true
return true
}
/* v8 ignore next -- completed frames are popped before another token can attach. */
if (parent.index >= (parent.kind === 'array' ? parent.length : parent.keys.length)) return false
if (parent.kind === 'array') {
parent.target.push(value)
} else {
const key = parent.keys[parent.index]
/* v8 ignore next -- object frames are built from validated keys and their exact length. */
if (key === undefined) return false
Object.defineProperty(parent.target, key, {
value,
enumerable: true,
configurable: true,
writable: true,
})
}
parent.index += 1
return true
}
for (let tokenIndex = 0; tokenIndex < wire.length; tokenIndex++) {
const token = wire[tokenIndex]
let value: CodeJsonValue
let frame: DecodeFrame | undefined
if (token === null || typeof token === 'boolean' || typeof token === 'string') {
value = token
} else if (typeof token === 'number') {
if (!Number.isFinite(token) || Object.is(token, -0)) return undefined
value = token
} else {
if (typeof token !== 'object') return undefined
const marker = containerToken(token)
if (!marker) return undefined
const remainingTokens = wire.length - tokenIndex - 1
if (marker.kind === 'array') {
if (marker.length > remainingTokens) return undefined
const target: CodeJsonValue[] = []
value = target
if (marker.length > 0) frame = { kind: 'array', target, length: marker.length, index: 0 }
} else {
if (marker.keys.length > remainingTokens) return undefined
const target: Record<string, CodeJsonValue> = {}
value = target
if (marker.keys.length > 0) frame = { kind: 'object', target, keys: marker.keys, index: 0 }
}
}
if (!attach(value)) return undefined
if (frame) frames.push(frame)
while (frames.length > 0) {
const current = frames.at(-1)
/* v8 ignore next -- the loop condition guarantees a final frame. */
if (current === undefined) break
if (current.index < (current.kind === 'array' ? current.length : current.keys.length)) break
frames.pop()
}
}
return frames.length === 0 ? root : undefined
} catch {
return undefined
}
}
/* jscpd:ignore-end */
@@ -3,6 +3,7 @@ import { EventEmitter } from 'node:events'
import { LogBuffer, makeConsoleShim, makeNamespaces, captureStreamWrites, prepareCompletion, runWorkerMain, ToolCallError, truncateUtf8Bytes, wireReplies } from '../src/bootstrap.ts'
import type { BootstrapPort, PatchableStream, PendingCall } from '../src/bootstrap.ts'
import type { ReplyMessage, WorkerToHost } from '../src/protocol.ts'
import { decodeWorkerJson, encodeWorkerJson } from '../src/worker-json.ts'
/**
* An in-process stand-in for the worker's parentPort: the test plays the
@@ -37,6 +38,11 @@ class FakePort implements BootstrapPort {
done(): WorkerToHost | undefined {
return this.sent.find(message => message.type === 'done')
}
doneValue(): unknown {
const done = this.done()
return done?.type === 'done' && done.value !== undefined ? decodeWorkerJson(done.value) : undefined
}
}
function fakeStreams(): { stdout: PatchableStream; stderr: PatchableStream } {
@@ -127,7 +133,7 @@ describe('captureStreamWrites', () => {
describe('prepareCompletion', () => {
it('omits undefined and passes lossless JSON values exactly', () => {
expect(prepareCompletion(undefined, 100)).toEqual({})
expect(prepareCompletion({ a: [1, 'two'] }, 100)).toEqual({ value: { a: [1, 'two'] } })
expect(prepareCompletion({ a: [1, 'two'] }, 100)).toEqual({ value: encodeWorkerJson({ a: [1, 'two'] }) })
})
it('turns every lossy completion shape into invalid-output', () => {
@@ -149,7 +155,7 @@ describe('prepareCompletion', () => {
})
it('measures the exact JSON serialization at and over the boundary', () => {
expect(prepareCompletion('€', 5)).toEqual({ value: '€' })
expect(prepareCompletion('€', 5)).toEqual({ value: encodeWorkerJson('€') })
expect(prepareCompletion('€', 4)).toEqual({
error: { kind: 'output-limit', message: 'outer output exceeded 4 bytes' },
})
@@ -178,9 +184,20 @@ describe('truncateUtf8Bytes', () => {
})
describe('makeNamespaces', () => {
it('rejects a malformed success reply instead of resolving a lossy binding value', async () => {
const port = new FakePort()
const pending = new Map<number, PendingCall>()
wireReplies(port, pending)
const result = new Promise<unknown>((resolve, reject) => { pending.set(1, { resolve, reject }) })
port.deliver({ type: 'reply', id: 1, ok: true, value: [undefined] as never })
await expect(result).rejects.toThrow('binding resolution must be lossless JSON')
})
it('exposes prototype-colliding names as ordinary own properties', async () => {
const port = new FakePort()
port.respond = message => message.type === 'call' ? { type: 'reply', id: message.id, ok: true, value: `${message.name}-ok` } : undefined
port.respond = message => message.type === 'call'
? { type: 'reply', id: message.id, ok: true, value: encodeWorkerJson(`${message.name}-ok`) }
: undefined
const pending = new Map<number, PendingCall>()
wireReplies(port, pending)
const [tools] = makeNamespaces({ namespaces: [{ global: 'tools', names: ['__proto__', 'constructor', 'toString'] }] }, port, pending, { value: 1 }) as [Record<string, (args: unknown) => Promise<unknown>>]
@@ -268,14 +285,18 @@ describe('makeNamespaces', () => {
describe('runWorkerMain', () => {
it('runs a program end-to-end: bindings, console, return value', async () => {
const port = new FakePort()
port.respond = message => message.type === 'call' ? { type: 'reply', id: message.id, ok: true, value: (message.args as { n: number }).n * 2 } : undefined
port.respond = (message) => {
if (message.type !== 'call') return undefined
const args = decodeWorkerJson(message.args) as { n: number }
return { type: 'reply', id: message.id, ok: true, value: encodeWorkerJson(args.n * 2) }
}
await runWorkerMain(port, {
...BOOT,
code: 'const doubled = await tools.double({ n: 21 }); console.log("got", doubled); return { doubled };',
namespaces: [{ global: 'tools', names: ['double'] }],
}, fakeStreams())
expect(port.logs()).toEqual(['got 42'])
expect(port.done()).toEqual({ type: 'done', value: { doubled: 42 } })
expect(port.doneValue()).toEqual({ doubled: 42 })
})
it('reports worker-side log capture overflow before completing', async () => {
@@ -287,7 +308,7 @@ describe('runWorkerMain', () => {
}, fakeStreams())
expect(port.sent).toContainEqual({ type: 'log', text: '1234' })
expect(port.sent).toContainEqual({ type: 'output-limit' })
expect(port.done()).toEqual({ type: 'done', value: null })
expect(port.doneValue()).toBeNull()
})
it('reports a thrown program error on the done message', async () => {
@@ -318,10 +339,7 @@ describe('runWorkerMain', () => {
code: 'try { await tools.x({}) } catch (error) { return { caught: error instanceof ToolCallError, name: error.name, toolName: error.toolName, message: error.message } }',
namespaces: [{ global: 'tools', names: ['x'] }],
}, fakeStreams())
expect(port.done()).toEqual({
type: 'done',
value: { caught: true, name: 'ToolCallError', toolName: 'x', message: 'denied by host' },
})
expect(port.doneValue()).toEqual({ caught: true, name: 'ToolCallError', toolName: 'x', message: 'denied by host' })
expect(new ToolCallError('x', 'nope')).toMatchObject({ name: 'ToolCallError', toolName: 'x', message: 'nope' })
})
@@ -330,15 +348,15 @@ describe('runWorkerMain', () => {
port.respond = (message) => {
if (message.type !== 'call') return undefined
// Deliver a stray reply first; the real one follows.
port.deliver({ type: 'reply', id: 9_999, ok: true, value: 'stray' })
return { type: 'reply', id: message.id, ok: true, value: 'real' }
port.deliver({ type: 'reply', id: 9_999, ok: true, value: encodeWorkerJson('stray') })
return { type: 'reply', id: message.id, ok: true, value: encodeWorkerJson('real') }
}
await runWorkerMain(port, {
...BOOT,
code: 'return await tools.x({})',
namespaces: [{ global: 'tools', names: ['x'] }],
}, fakeStreams())
expect(port.done()).toEqual({ type: 'done', value: 'real' })
expect(port.doneValue()).toBe('real')
})
it('captures raw stream writes through the patched process streams', async () => {
@@ -92,7 +92,7 @@ describe('WorkerCodeRuntime — programs and bindings (real workers)', () => {
cursor = Array.isArray(cursor) ? cursor[0] : undefined
}
expect(cursor).toBe('leaf')
}, 60_000)
}, 15_000)
it('reports non-erasable syntax as an exception without spawning a worker', async () => {
const { runtime } = await setup()
@@ -371,7 +371,7 @@ describe('WorkerCodeRuntime — budgets and containment (real workers)', () => {
const { parentPort } = await import('node:worker_threads');
const write = (text) => Object.getPrototypeOf(process.stdout).write.call(process.stdout, text);
write('late-pipe-' + 'x'.repeat(100_000));
parentPort.postMessage({ type: 'done', value: 'done' });
parentPort.postMessage({ type: 'done', value: ['done'] });
for (;;) {}
`,
bindings: [],
@@ -438,7 +438,7 @@ describe('WorkerCodeRuntime — hostile programs (real workers)', () => {
program: `
const { parentPort } = await import('node:worker_threads');
for (let i = 0; i < 50; i++) parentPort.postMessage({ type: 'log', text: 'F'.repeat(100), forged: true });
parentPort.postMessage({ type: 'done', value: 'V'.repeat(100000) });
parentPort.postMessage({ type: 'done', value: ['V'.repeat(100000)] });
for (;;) {}
`,
bindings: [],
@@ -482,8 +482,9 @@ describe('WorkerCodeRuntime — hostile programs (real workers)', () => {
const result = await runtime.run({
program: `
const { parentPort } = await import('node:worker_threads');
let value = null;
for (let depth = 0; depth < 3_000; depth++) value = [value];
const value = [];
for (let depth = 0; depth < 3_000; depth++) value.push({ kind: 'array', length: 1 });
value.push(null);
setTimeout(() => { parentPort.postMessage({ type: 'done', value }) }, 25);
// Prevent bootstrap's normal undefined completion from racing the forged terminal.
await new Promise(() => {});
@@ -500,7 +501,7 @@ describe('WorkerCodeRuntime — hostile programs (real workers)', () => {
}
expect(depth).toBe(3_000)
expect(value).toBeNull()
}, 60_000)
}, 15_000)
it('turns forged over-limit error text into output-limit at the host', async () => {
const { runtime } = await setup({ maxOutputBytes: 64 })
@@ -3,6 +3,7 @@ import { tmpdir } from 'node:os'
import { join } from 'node:path'
import { Worker } from 'node:worker_threads'
import { expect, it } from 'vitest'
import { decodeWorkerJson } from '../src/worker-json.ts'
/**
* Prove the unbuilt worker is a self-contained source closure. Copying it out
@@ -28,7 +29,9 @@ it('boots the source worker without workspace package outputs', async () => {
worker?.once('error', reject)
})
expect(message).toEqual({ type: 'done', value: { answer: 42 } })
expect(message).toMatchObject({ type: 'done' })
const value = typeof message === 'object' && message !== null ? (message as { value?: unknown }).value : undefined
expect(decodeWorkerJson(value)).toEqual({ answer: 42 })
} finally {
if (worker) await worker.terminate()
await rm(directory, { recursive: true, force: true })
@@ -1,7 +1,7 @@
import { runInNewContext } from 'node:vm'
import { describe, expect, it } from 'vitest'
import { snapshotJsonValue } from '@deepseek-ai/dsh-session'
import { snapshotCodeJsonValue } from '../src/worker-json.ts'
import { decodeWorkerJson, encodeWorkerJson, snapshotCodeJsonValue } from '../src/worker-json.ts'
describe('snapshotCodeJsonValue', () => {
it('matches the canonical scalar boundary', () => {
@@ -142,3 +142,90 @@ describe('snapshotCodeJsonValue', () => {
expect(snapshotCodeJsonValue({ after: true })).toEqual({ after: true })
})
})
describe('flat worker JSON wire', () => {
it('round-trips every JSON root while preserving object keys and container order', () => {
const withPrototypeKey = Object.create(null) as Record<string, unknown>
withPrototypeKey.__proto__ = { safe: true }
const values = [null, false, true, 1.25, 'text', [], {}, [1, { nested: [2] }], withPrototypeKey]
for (const value of values) {
const snapshot = snapshotCodeJsonValue(value)
expect(snapshot).not.toBeUndefined()
expect(decodeWorkerJson(encodeWorkerJson(snapshot!))).toEqual(snapshot)
}
const decoded = decodeWorkerJson(encodeWorkerJson(snapshotCodeJsonValue(withPrototypeKey)!)) as Record<string, unknown>
expect(Object.hasOwn(decoded, '__proto__')).toBe(true)
expect(decoded.__proto__).toEqual({ safe: true })
})
it('round-trips deep values through a bounded-depth token array', () => {
let value: unknown = 'leaf'
for (let depth = 0; depth < 5_000; depth++) value = [value]
const snapshot = snapshotCodeJsonValue(value)!
const wire = encodeWorkerJson(snapshot)
expect(wire).toHaveLength(5_001)
let cursor = decodeWorkerJson(wire)
for (let depth = 0; depth < 5_000; depth++) {
expect(Array.isArray(cursor)).toBe(true)
cursor = Array.isArray(cursor) ? cursor[0] : undefined
}
expect(cursor).toBe('leaf')
})
it('rejects malformed, incomplete, lossy, sparse, decorated, and throwing wire values', () => {
const sparse = new Array(1)
const compensatedSparse = new Array(1)
Object.defineProperty(compensatedSparse, 'extra', { value: true })
const decorated: unknown[] = [null]
Object.defineProperty(decorated, 'extra', { value: true })
const throwing: unknown[] = []
Object.defineProperty(throwing, 0, { enumerable: true, get: () => { throw new Error('wire getter') } })
const decoratedKeys: unknown[] = ['x']
Object.defineProperty(decoratedKeys, 'extra', { value: true })
const foreignMarker: Record<string, unknown> = { kind: 'array', length: 0 }
Object.setPrototypeOf(foreignMarker, {})
const hiddenMarker = Object.defineProperty({ kind: 'array', length: 0 }, 'hidden', { value: true })
for (const value of [
undefined,
null,
{},
[],
sparse,
compensatedSparse,
decorated,
throwing,
[undefined],
[-0],
[Number.NaN],
[Number.POSITIVE_INFINITY],
[1, 2],
[[]],
[foreignMarker],
[hiddenMarker],
[{ kind: 'unknown' }],
[{ kind: 'array' }],
[{ kind: 'array', length: '1' }],
[{ kind: 'array', length: -1 }],
[{ kind: 'array', length: Number.MAX_SAFE_INTEGER + 1 }],
[{ kind: 'array', length: 1 }],
[{ kind: 'array', length: 2 }, { kind: 'array', length: 1 }, null],
[{ kind: 'array', length: 0, extra: true }],
[{ kind: 'object' }],
[{ kind: 'object', keys: 'x' }],
[{ kind: 'object', keys: decoratedKeys }],
[{ kind: 'object', keys: [1] }],
[{ kind: 'object', keys: ['x', 'x'] }, 1, 2],
[{ kind: 'object', keys: ['x'] }],
[{ kind: 'object', keys: [], extra: true }],
]) {
expect(decodeWorkerJson(value)).toBeUndefined()
}
})
it('rejects invalid values passed through a forged static type', () => {
expect(() => encodeWorkerJson([undefined] as never)).toThrow(/sparse JSON array/)
expect(() => encodeWorkerJson({ value: undefined } as never)).toThrow(/undefined JSON object property/)
})
})