fix(code-runtime): flatten worker JSON transport
This commit is contained in:
@@ -22,14 +22,14 @@ Every field is validated and defaulted; `maxOutputBytes` is a safe integer of at
|
||||
- **Type-strip host-side, in execution context** — the program is wrapped in an async-function shell, stripped with `node:module`'s `stripTypeScriptTypes` (erasable syntax only — `enum`/namespaces are rejected as a program `exception` and no worker spawns), and sliced back out byte-positioned; it then executes as the body of an `AsyncFunction`, so top-level `await`/`return` work.
|
||||
- **The port assumes a hostile peer** — model code can reach `parentPort` and forge traffic, so every inbound message is shape-validated and REBUILT before anything reads it (`null`, primitives, junk types, and malformed payloads drop without a throw; forged extra fields never ride along), the host answers each call id at most once, resolves binding names as OWN properties only (a forged `constructor` cannot walk a prototype chain), drops post-settlement replies, and validates every binding resolution and completion as lossless JSON. Forged `log`/`done` messages cannot bypass the outer cap: the host repeats validation and accounts every admitted log plus the completion or diagnostic. Worker-side namespaces are null-prototype with `defineProperty`, so `__proto__`-shaped binding names are ordinary keys.
|
||||
- **Two independent budgets, because the peer is hostile** — `computeMs` meters the worker's MEASURED busy time (`worker.performance.eventLoopUtilization()` polling): a hot loop cannot hide behind a pending decoy dispatch, and a program awaiting a slow tool accrues nothing. `maxWallMs` backstops what busy time cannot see (awaiting a promise nobody resolves). Both funnel into `worker.terminate()`, which ends hot synchronous loops too; heap overflow surfaces as the worker's OOM exit (`kind: 'worker-exit'`).
|
||||
- **Intermediate binding values are complete JSON** — binding arguments and resolutions cross by structured clone after iterative lossless-JSON validation and have no byte or call-stack depth cap. They never enter the outer-output ledger or model context; provider/executor acquisition bounds and process/worker memory remain the limits.
|
||||
- **Intermediate binding values are complete JSON** — binding arguments and resolutions undergo iterative lossless-JSON validation, flatten into a bounded-depth pre-order wire value for structured clone, and rebuild iteratively on the other side. They have no byte, JavaScript call-stack, or nested structured-clone depth cap. They never enter the outer-output ledger or model context; provider/executor acquisition bounds and process/worker memory remain the limits.
|
||||
- **Logs stream eagerly into one outer ledger** — console/stdout/stderr text crosses the port in emission order, so a timed-out or killed program still shows what it printed. Native writes that bypass the patched stream slots arrive on pipes independent of the completion port; settlement therefore continues bounded pipe capture until worker termination completes before materializing the result. `maxOutputBytes` accounts the JSON serialization of the outer `logs` array plus the completion value or failure diagnostic. At or below the cap the exact value returns; a lossy completion is `invalid-output`, and a combined overflow is `output-limit` rather than a substituted inspected string. The failure retains the fitting captured prefix and later follows the normal outer `run_code` spill policy.
|
||||
- **Empty environment** — the worker gets `env: {}` and `execArgv: []`: no ambient credentials (stronger than the scrubbed-env rule for spawned commands) and no inherited loader flags.
|
||||
- **Dispose to quiescence** — teardown fails in-flight runs as `abort` and AWAITS each worker's exit before resolving.
|
||||
|
||||
## The worker entry, unbuilt and built
|
||||
|
||||
Source mode loads erasable-only `src/worker.ts` through Node's native type stripping. Its transitive runtime closure contains only Node built-ins and relative source modules, so a fresh checkout never requires a sibling workspace package's unbuilt `lib/` export. The worker-local JSON snapshotter is parity-tested against the session-owned canonical boundary; the host repeats canonical validation after structured clone. Built mode passes the sibling `lib/worker.cjs` as a filesystem path because pkg's VFS Worker hook expects CommonJS; the same path works under ordinary Node. `tests/built-lib.e2e.ts` pins the real load path required by [docs/testing.md](../../../docs/testing.md).
|
||||
Source mode loads erasable-only `src/worker.ts` through Node's native type stripping. Its transitive runtime closure contains only Node built-ins and relative source modules, so a fresh checkout never requires a sibling workspace package's unbuilt `lib/` export. The worker-local JSON snapshotter is parity-tested against the session-owned canonical boundary; both sides flatten and rebuild validated values around the message port so application nesting never reaches structured clone. Built mode passes the sibling `lib/worker.cjs` as a filesystem path because pkg's VFS Worker hook expects CommonJS; the same path works under ordinary Node. `tests/built-lib.e2e.ts` pins the real load path required by [docs/testing.md](../../../docs/testing.md).
|
||||
|
||||
The SDK surface is the default/named `WorkerCodeRuntime` class plus `Config`. The operational `./worker` subpath exists only as the packaged spawn entry; the wire protocol and bootstrap helpers are source-private implementation details.
|
||||
|
||||
|
||||
@@ -8,7 +8,7 @@
|
||||
import { inspect } from 'node:util'
|
||||
import type { DoneMessage, ReplyMessage, WorkerBootData, WorkerToHost } from './protocol.ts'
|
||||
import { jsonValueBytesUpTo } from './output-json.ts'
|
||||
import { snapshotCodeJsonValue } from './worker-json.ts'
|
||||
import { decodeWorkerJson, encodeWorkerJson, snapshotCodeJsonValue } from './worker-json.ts'
|
||||
|
||||
/** The port surface the bootstrap needs — satisfied by `parentPort` and by the tests' fake. */
|
||||
export interface BootstrapPort {
|
||||
@@ -152,7 +152,7 @@ export function truncateUtf8Bytes(text: string, maxBytes: number): string {
|
||||
*
|
||||
* @param value - the program's completion value.
|
||||
* @param maxOutputBytes - the byte cap for the outer result.
|
||||
* @returns the done-message fragment: `{}` for `undefined`, else `{ value }`.
|
||||
* @returns the done-message fragment: `{}` for `undefined`, else a flat wire `{ value }`.
|
||||
*/
|
||||
export function prepareCompletion(value: unknown, maxOutputBytes: number): Omit<DoneMessage, 'type'> {
|
||||
if (value === undefined) return {}
|
||||
@@ -168,7 +168,7 @@ export function prepareCompletion(value: unknown, maxOutputBytes: number): Omit<
|
||||
if (jsonValueBytesUpTo(snapshot, maxOutputBytes) === undefined) {
|
||||
return { error: { kind: 'output-limit', message: `outer output exceeded ${maxOutputBytes} bytes` } }
|
||||
}
|
||||
return { value: snapshot }
|
||||
return { value: encodeWorkerJson(snapshot) }
|
||||
}
|
||||
|
||||
/** One awaited binding call's settlement handles, keyed by call id in the pending map. */
|
||||
@@ -208,8 +208,13 @@ export function wireReplies(port: BootstrapPort, pending: Map<number, PendingCal
|
||||
const entry = pending.get(message.id)
|
||||
if (!entry) return
|
||||
pending.delete(message.id)
|
||||
if (message.ok) entry.resolve(message.value)
|
||||
else entry.reject(new Error(message.message))
|
||||
if (message.ok) {
|
||||
const value = decodeWorkerJson(message.value)
|
||||
if (value === undefined) entry.reject(new Error('binding resolution must be lossless JSON'))
|
||||
else entry.resolve(value)
|
||||
} else {
|
||||
entry.reject(new Error(message.message))
|
||||
}
|
||||
})
|
||||
}
|
||||
|
||||
@@ -238,7 +243,7 @@ export function makeNamespaces(
|
||||
Object.defineProperty(namespace, name, {
|
||||
enumerable: true,
|
||||
value: (args: unknown): Promise<unknown> => {
|
||||
let detached: unknown
|
||||
let detached: ReturnType<typeof snapshotCodeJsonValue>
|
||||
try {
|
||||
detached = snapshotCodeJsonValue(args)
|
||||
} catch {
|
||||
@@ -254,7 +259,7 @@ export function makeNamespaces(
|
||||
},
|
||||
})
|
||||
try {
|
||||
port.postMessage({ type: 'call', id, global, name, args: detached })
|
||||
port.postMessage({ type: 'call', id, global, name, args: encodeWorkerJson(detached) })
|
||||
} catch (error: unknown) {
|
||||
pending.delete(id)
|
||||
const message = `binding arguments must be structured-cloneable: ${error instanceof Error ? error.message : String(error)}`
|
||||
|
||||
@@ -17,6 +17,8 @@ import type { CodeBindingFunction, CodeJsonValue, CodeRunFailure, CodeRunRequest
|
||||
import { snapshotJsonValue } from '@deepseek-ai/dsh-session'
|
||||
import type { ReplyMessage, WorkerBootData, WorkerToHost } from './protocol.ts'
|
||||
import { jsonStringBytesUpTo, jsonValueBytesUpTo, truncateJsonStringBytes } from './output-json.ts'
|
||||
import { decodeWorkerJson, encodeWorkerJson } from './worker-json.ts'
|
||||
import type { WorkerJsonWire } from './worker-json.ts'
|
||||
|
||||
/** Plugin config: every execution cap, changeable from `cordis.yml` (no hardcoded tunables). */
|
||||
export interface Config {
|
||||
@@ -142,7 +144,7 @@ function parseWorkerMessage(raw: unknown): WorkerToHost | undefined {
|
||||
switch (m.type) {
|
||||
case 'call': {
|
||||
if (typeof m.id !== 'number' || typeof m.global !== 'string' || typeof m.name !== 'string') return undefined
|
||||
return { type: 'call', id: m.id, global: m.global, name: m.name, args: m.args }
|
||||
return { type: 'call', id: m.id, global: m.global, name: m.name, args: m.args as WorkerJsonWire }
|
||||
}
|
||||
case 'log': {
|
||||
if (typeof m.text !== 'string') return undefined
|
||||
@@ -150,7 +152,7 @@ function parseWorkerMessage(raw: unknown): WorkerToHost | undefined {
|
||||
}
|
||||
case 'output-limit': return { type: 'output-limit' }
|
||||
case 'done': {
|
||||
if (m.error === undefined) return { type: 'done', ...m.value !== undefined ? { value: m.value } : {} }
|
||||
if (m.error === undefined) return { type: 'done', ...m.value !== undefined ? { value: m.value as WorkerJsonWire } : {} }
|
||||
const error = m.error
|
||||
if (typeof error !== 'object' || error === null) return undefined
|
||||
const { kind, message } = error as Record<string, unknown>
|
||||
@@ -409,10 +411,7 @@ export class WorkerCodeRuntime extends CodeRuntime {
|
||||
finish(() => output.success([...logs, ...strayLogs]))
|
||||
return
|
||||
}
|
||||
// The worker-thread boundary has already structured-cloned this
|
||||
// hostile value, so accessors and proxies cannot survive to throw
|
||||
// during the lossless-JSON snapshot.
|
||||
const value = snapshotJsonValue(message.value) as CodeJsonValue | undefined
|
||||
const value = decodeWorkerJson(message.value)
|
||||
if (value === undefined) {
|
||||
finish(() => output.failure([...logs, ...strayLogs], { kind: 'invalid-output', message: 'program completion must be lossless JSON' }))
|
||||
} else {
|
||||
@@ -442,9 +441,7 @@ export class WorkerCodeRuntime extends CodeRuntime {
|
||||
reply({ type: 'reply', id: message.id, ok: false, message: `unknown binding ${JSON.stringify(`${message.global}.${message.name}`)}` })
|
||||
return
|
||||
}
|
||||
// Structured clone has already removed accessors and proxies, so the
|
||||
// host can repeat the lossless snapshot without a reflective throw.
|
||||
const args = snapshotJsonValue(message.args) as CodeJsonValue | undefined
|
||||
const args = decodeWorkerJson(message.args)
|
||||
if (args === undefined) {
|
||||
reply({ type: 'reply', id: message.id, ok: false, message: 'binding arguments must be lossless JSON' })
|
||||
return
|
||||
@@ -461,7 +458,7 @@ export class WorkerCodeRuntime extends CodeRuntime {
|
||||
if (value === undefined) {
|
||||
reply({ type: 'reply', id: message.id, ok: false, message: 'binding resolution must be lossless JSON' })
|
||||
} else {
|
||||
reply({ type: 'reply', id: message.id, ok: true, value })
|
||||
reply({ type: 'reply', id: message.id, ok: true, value: encodeWorkerJson(value) })
|
||||
}
|
||||
} catch (error: unknown) {
|
||||
reply({ type: 'reply', id: message.id, ok: false, message: messageOf(error) })
|
||||
|
||||
@@ -5,6 +5,8 @@
|
||||
* @module @deepseek-ai/dsh-code-runtime-worker/src/protocol
|
||||
*/
|
||||
|
||||
import type { WorkerJsonWire } from './worker-json.ts'
|
||||
|
||||
/** What the host hands the worker at spawn, via `workerData`. */
|
||||
export interface WorkerBootData {
|
||||
/** The type-stripped (plain JS) program body. */
|
||||
@@ -24,8 +26,8 @@ interface CallMessage {
|
||||
global: string
|
||||
/** The function name within the namespace. */
|
||||
name: string
|
||||
/** The single argument, structured-clone-plain. */
|
||||
args: unknown
|
||||
/** The single argument as a flat lossless-JSON wire value. */
|
||||
args: WorkerJsonWire
|
||||
}
|
||||
|
||||
/** Worker → host: captured text, streamed eagerly so output survives a mid-run termination (timeout, abort, OOM). */
|
||||
@@ -43,13 +45,13 @@ interface OutputLimitMessage {
|
||||
* Worker → host: the program settled. `error` carries a program exception
|
||||
* (the only failure the bootstrap itself can report — budgets, aborts, and
|
||||
* substrate death are observed host-side). `value` is present only on a
|
||||
* clean completion that produced one (already size-capped and
|
||||
* clone-safe per the bootstrap's value preparation). Logs are NOT carried
|
||||
* here — they streamed eagerly as {@link LogMessage}s.
|
||||
* clean completion that produced one, as a flat wire value already
|
||||
* size-capped and lossless per the bootstrap. Logs are NOT carried here —
|
||||
* they streamed eagerly as {@link LogMessage}s.
|
||||
*/
|
||||
export interface DoneMessage {
|
||||
type: 'done'
|
||||
value?: unknown
|
||||
value?: WorkerJsonWire
|
||||
error?: { kind: 'exception' | 'invalid-output' | 'output-limit'; message: string }
|
||||
}
|
||||
|
||||
@@ -58,5 +60,5 @@ export type WorkerToHost = CallMessage | LogMessage | OutputLimitMessage | DoneM
|
||||
|
||||
/** Host → worker: the answer to one {@link CallMessage}. */
|
||||
export type ReplyMessage =
|
||||
| { type: 'reply'; id: number; ok: true; value: unknown }
|
||||
| { type: 'reply'; id: number; ok: true; value: WorkerJsonWire }
|
||||
| { type: 'reply'; id: number; ok: false; message: string }
|
||||
@@ -150,4 +150,185 @@ export function snapshotCodeJsonValue(value: unknown): CodeJsonValue | undefined
|
||||
}
|
||||
return root
|
||||
}
|
||||
|
||||
interface ArrayWireToken {
|
||||
kind: 'array'
|
||||
length: number
|
||||
}
|
||||
|
||||
interface ObjectWireToken {
|
||||
kind: 'object'
|
||||
keys: string[]
|
||||
}
|
||||
|
||||
type WorkerJsonToken = null | boolean | number | string | ArrayWireToken | ObjectWireToken
|
||||
|
||||
/**
|
||||
* A pre-order, bounded-depth transport for one lossless JSON value. Container
|
||||
* markers and scalar leaves share one flat token array, so `worker_threads`
|
||||
* never has to structured-clone the value's application nesting.
|
||||
*/
|
||||
export type WorkerJsonWire = WorkerJsonToken[]
|
||||
|
||||
/**
|
||||
* Flatten one validated JSON value for the worker-thread message port.
|
||||
* @param value - the lossless JSON value to transport.
|
||||
* @returns a pre-order token stream whose own nesting is bounded.
|
||||
*/
|
||||
export function encodeWorkerJson(value: CodeJsonValue): WorkerJsonWire {
|
||||
const wire: WorkerJsonWire = []
|
||||
const pending: CodeJsonValue[] = [value]
|
||||
for (let current = pending.pop(); current !== undefined; current = pending.pop()) {
|
||||
if (current === null || typeof current === 'boolean' || typeof current === 'number' || typeof current === 'string') {
|
||||
wire.push(current)
|
||||
continue
|
||||
}
|
||||
if (Array.isArray(current)) {
|
||||
wire.push({ kind: 'array', length: current.length })
|
||||
for (let index = current.length - 1; index >= 0; index--) {
|
||||
const item = current[index]
|
||||
if (item === undefined) throw new Error('cannot encode a sparse JSON array')
|
||||
pending.push(item)
|
||||
}
|
||||
continue
|
||||
}
|
||||
const keys = Object.keys(current)
|
||||
wire.push({ kind: 'object', keys })
|
||||
for (let index = keys.length - 1; index >= 0; index--) {
|
||||
const key = keys[index]
|
||||
/* v8 ignore next -- the loop is bounded by the captured key count. */
|
||||
if (key === undefined) throw new Error('cannot encode a missing JSON object key')
|
||||
const item = current[key]
|
||||
if (item === undefined) throw new Error('cannot encode an undefined JSON object property')
|
||||
pending.push(item)
|
||||
}
|
||||
}
|
||||
return wire
|
||||
}
|
||||
|
||||
type DecodeFrame =
|
||||
| { kind: 'array'; target: CodeJsonValue[]; length: number; index: number }
|
||||
| { kind: 'object'; target: Record<string, CodeJsonValue>; keys: string[]; index: number }
|
||||
|
||||
/** Whether an array contains exactly its dense indexed slots and `length`. */
|
||||
function isDenseArray(value: unknown[]): boolean {
|
||||
if (!hasPlainArrayPrototype(value) || Reflect.ownKeys(value).length !== value.length + 1) return false
|
||||
for (let index = 0; index < value.length; index++) {
|
||||
if (!Object.hasOwn(value, index)) return false
|
||||
}
|
||||
return true
|
||||
}
|
||||
|
||||
/** Return one exact container marker, or reject any extra/missing fields. */
|
||||
function containerToken(value: object): ArrayWireToken | ObjectWireToken | undefined {
|
||||
if (Array.isArray(value) || !hasPlainObjectPrototype(value)) return undefined
|
||||
const keys = enumerableStringKeys(value)
|
||||
if (keys === undefined) return undefined
|
||||
const token = value as Record<string, unknown>
|
||||
if (token.kind === 'array') {
|
||||
if (keys.length !== 2 || !keys.includes('kind') || !keys.includes('length')) return undefined
|
||||
const length = token.length
|
||||
return typeof length === 'number' && Number.isSafeInteger(length) && length >= 0
|
||||
? { kind: 'array', length }
|
||||
: undefined
|
||||
}
|
||||
if (token.kind === 'object') {
|
||||
if (keys.length !== 2 || !keys.includes('kind') || !keys.includes('keys')) return undefined
|
||||
const objectKeys = token.keys
|
||||
if (!Array.isArray(objectKeys) || !isDenseArray(objectKeys)) return undefined
|
||||
const unique = new Set<string>()
|
||||
const normalizedKeys: string[] = []
|
||||
for (const key of objectKeys as unknown[]) {
|
||||
if (typeof key !== 'string' || unique.has(key)) return undefined
|
||||
unique.add(key)
|
||||
normalizedKeys.push(key)
|
||||
}
|
||||
return { kind: 'object', keys: normalizedKeys }
|
||||
}
|
||||
return undefined
|
||||
}
|
||||
|
||||
/**
|
||||
* Rebuild one lossless JSON value from the flat worker-thread wire format.
|
||||
* Malformed or incomplete traffic returns `undefined`; traversal is iterative
|
||||
* and therefore independent of the transported value's application depth.
|
||||
* @param input - untrusted message-port payload.
|
||||
* @returns the detached JSON value, or `undefined` when the wire is invalid.
|
||||
*/
|
||||
export function decodeWorkerJson(input: unknown): CodeJsonValue | undefined {
|
||||
try {
|
||||
if (!Array.isArray(input) || !isDenseArray(input) || input.length === 0) return undefined
|
||||
const wire = input as unknown[]
|
||||
const frames: DecodeFrame[] = []
|
||||
let root: CodeJsonValue | undefined
|
||||
let rootAssigned = false
|
||||
|
||||
const attach = (value: CodeJsonValue): boolean => {
|
||||
const parent = frames.at(-1)
|
||||
if (!parent) {
|
||||
if (rootAssigned) return false
|
||||
root = value
|
||||
rootAssigned = true
|
||||
return true
|
||||
}
|
||||
/* v8 ignore next -- completed frames are popped before another token can attach. */
|
||||
if (parent.index >= (parent.kind === 'array' ? parent.length : parent.keys.length)) return false
|
||||
if (parent.kind === 'array') {
|
||||
parent.target.push(value)
|
||||
} else {
|
||||
const key = parent.keys[parent.index]
|
||||
/* v8 ignore next -- object frames are built from validated keys and their exact length. */
|
||||
if (key === undefined) return false
|
||||
Object.defineProperty(parent.target, key, {
|
||||
value,
|
||||
enumerable: true,
|
||||
configurable: true,
|
||||
writable: true,
|
||||
})
|
||||
}
|
||||
parent.index += 1
|
||||
return true
|
||||
}
|
||||
|
||||
for (let tokenIndex = 0; tokenIndex < wire.length; tokenIndex++) {
|
||||
const token = wire[tokenIndex]
|
||||
let value: CodeJsonValue
|
||||
let frame: DecodeFrame | undefined
|
||||
if (token === null || typeof token === 'boolean' || typeof token === 'string') {
|
||||
value = token
|
||||
} else if (typeof token === 'number') {
|
||||
if (!Number.isFinite(token) || Object.is(token, -0)) return undefined
|
||||
value = token
|
||||
} else {
|
||||
if (typeof token !== 'object') return undefined
|
||||
const marker = containerToken(token)
|
||||
if (!marker) return undefined
|
||||
const remainingTokens = wire.length - tokenIndex - 1
|
||||
if (marker.kind === 'array') {
|
||||
if (marker.length > remainingTokens) return undefined
|
||||
const target: CodeJsonValue[] = []
|
||||
value = target
|
||||
if (marker.length > 0) frame = { kind: 'array', target, length: marker.length, index: 0 }
|
||||
} else {
|
||||
if (marker.keys.length > remainingTokens) return undefined
|
||||
const target: Record<string, CodeJsonValue> = {}
|
||||
value = target
|
||||
if (marker.keys.length > 0) frame = { kind: 'object', target, keys: marker.keys, index: 0 }
|
||||
}
|
||||
}
|
||||
if (!attach(value)) return undefined
|
||||
if (frame) frames.push(frame)
|
||||
while (frames.length > 0) {
|
||||
const current = frames.at(-1)
|
||||
/* v8 ignore next -- the loop condition guarantees a final frame. */
|
||||
if (current === undefined) break
|
||||
if (current.index < (current.kind === 'array' ? current.length : current.keys.length)) break
|
||||
frames.pop()
|
||||
}
|
||||
}
|
||||
return frames.length === 0 ? root : undefined
|
||||
} catch {
|
||||
return undefined
|
||||
}
|
||||
}
|
||||
/* jscpd:ignore-end */
|
||||
@@ -3,6 +3,7 @@ import { EventEmitter } from 'node:events'
|
||||
import { LogBuffer, makeConsoleShim, makeNamespaces, captureStreamWrites, prepareCompletion, runWorkerMain, ToolCallError, truncateUtf8Bytes, wireReplies } from '../src/bootstrap.ts'
|
||||
import type { BootstrapPort, PatchableStream, PendingCall } from '../src/bootstrap.ts'
|
||||
import type { ReplyMessage, WorkerToHost } from '../src/protocol.ts'
|
||||
import { decodeWorkerJson, encodeWorkerJson } from '../src/worker-json.ts'
|
||||
|
||||
/**
|
||||
* An in-process stand-in for the worker's parentPort: the test plays the
|
||||
@@ -37,6 +38,11 @@ class FakePort implements BootstrapPort {
|
||||
done(): WorkerToHost | undefined {
|
||||
return this.sent.find(message => message.type === 'done')
|
||||
}
|
||||
|
||||
doneValue(): unknown {
|
||||
const done = this.done()
|
||||
return done?.type === 'done' && done.value !== undefined ? decodeWorkerJson(done.value) : undefined
|
||||
}
|
||||
}
|
||||
|
||||
function fakeStreams(): { stdout: PatchableStream; stderr: PatchableStream } {
|
||||
@@ -127,7 +133,7 @@ describe('captureStreamWrites', () => {
|
||||
describe('prepareCompletion', () => {
|
||||
it('omits undefined and passes lossless JSON values exactly', () => {
|
||||
expect(prepareCompletion(undefined, 100)).toEqual({})
|
||||
expect(prepareCompletion({ a: [1, 'two'] }, 100)).toEqual({ value: { a: [1, 'two'] } })
|
||||
expect(prepareCompletion({ a: [1, 'two'] }, 100)).toEqual({ value: encodeWorkerJson({ a: [1, 'two'] }) })
|
||||
})
|
||||
|
||||
it('turns every lossy completion shape into invalid-output', () => {
|
||||
@@ -149,7 +155,7 @@ describe('prepareCompletion', () => {
|
||||
})
|
||||
|
||||
it('measures the exact JSON serialization at and over the boundary', () => {
|
||||
expect(prepareCompletion('€', 5)).toEqual({ value: '€' })
|
||||
expect(prepareCompletion('€', 5)).toEqual({ value: encodeWorkerJson('€') })
|
||||
expect(prepareCompletion('€', 4)).toEqual({
|
||||
error: { kind: 'output-limit', message: 'outer output exceeded 4 bytes' },
|
||||
})
|
||||
@@ -178,9 +184,20 @@ describe('truncateUtf8Bytes', () => {
|
||||
})
|
||||
|
||||
describe('makeNamespaces', () => {
|
||||
it('rejects a malformed success reply instead of resolving a lossy binding value', async () => {
|
||||
const port = new FakePort()
|
||||
const pending = new Map<number, PendingCall>()
|
||||
wireReplies(port, pending)
|
||||
const result = new Promise<unknown>((resolve, reject) => { pending.set(1, { resolve, reject }) })
|
||||
port.deliver({ type: 'reply', id: 1, ok: true, value: [undefined] as never })
|
||||
await expect(result).rejects.toThrow('binding resolution must be lossless JSON')
|
||||
})
|
||||
|
||||
it('exposes prototype-colliding names as ordinary own properties', async () => {
|
||||
const port = new FakePort()
|
||||
port.respond = message => message.type === 'call' ? { type: 'reply', id: message.id, ok: true, value: `${message.name}-ok` } : undefined
|
||||
port.respond = message => message.type === 'call'
|
||||
? { type: 'reply', id: message.id, ok: true, value: encodeWorkerJson(`${message.name}-ok`) }
|
||||
: undefined
|
||||
const pending = new Map<number, PendingCall>()
|
||||
wireReplies(port, pending)
|
||||
const [tools] = makeNamespaces({ namespaces: [{ global: 'tools', names: ['__proto__', 'constructor', 'toString'] }] }, port, pending, { value: 1 }) as [Record<string, (args: unknown) => Promise<unknown>>]
|
||||
@@ -268,14 +285,18 @@ describe('makeNamespaces', () => {
|
||||
describe('runWorkerMain', () => {
|
||||
it('runs a program end-to-end: bindings, console, return value', async () => {
|
||||
const port = new FakePort()
|
||||
port.respond = message => message.type === 'call' ? { type: 'reply', id: message.id, ok: true, value: (message.args as { n: number }).n * 2 } : undefined
|
||||
port.respond = (message) => {
|
||||
if (message.type !== 'call') return undefined
|
||||
const args = decodeWorkerJson(message.args) as { n: number }
|
||||
return { type: 'reply', id: message.id, ok: true, value: encodeWorkerJson(args.n * 2) }
|
||||
}
|
||||
await runWorkerMain(port, {
|
||||
...BOOT,
|
||||
code: 'const doubled = await tools.double({ n: 21 }); console.log("got", doubled); return { doubled };',
|
||||
namespaces: [{ global: 'tools', names: ['double'] }],
|
||||
}, fakeStreams())
|
||||
expect(port.logs()).toEqual(['got 42'])
|
||||
expect(port.done()).toEqual({ type: 'done', value: { doubled: 42 } })
|
||||
expect(port.doneValue()).toEqual({ doubled: 42 })
|
||||
})
|
||||
|
||||
it('reports worker-side log capture overflow before completing', async () => {
|
||||
@@ -287,7 +308,7 @@ describe('runWorkerMain', () => {
|
||||
}, fakeStreams())
|
||||
expect(port.sent).toContainEqual({ type: 'log', text: '1234' })
|
||||
expect(port.sent).toContainEqual({ type: 'output-limit' })
|
||||
expect(port.done()).toEqual({ type: 'done', value: null })
|
||||
expect(port.doneValue()).toBeNull()
|
||||
})
|
||||
|
||||
it('reports a thrown program error on the done message', async () => {
|
||||
@@ -318,10 +339,7 @@ describe('runWorkerMain', () => {
|
||||
code: 'try { await tools.x({}) } catch (error) { return { caught: error instanceof ToolCallError, name: error.name, toolName: error.toolName, message: error.message } }',
|
||||
namespaces: [{ global: 'tools', names: ['x'] }],
|
||||
}, fakeStreams())
|
||||
expect(port.done()).toEqual({
|
||||
type: 'done',
|
||||
value: { caught: true, name: 'ToolCallError', toolName: 'x', message: 'denied by host' },
|
||||
})
|
||||
expect(port.doneValue()).toEqual({ caught: true, name: 'ToolCallError', toolName: 'x', message: 'denied by host' })
|
||||
expect(new ToolCallError('x', 'nope')).toMatchObject({ name: 'ToolCallError', toolName: 'x', message: 'nope' })
|
||||
})
|
||||
|
||||
@@ -330,15 +348,15 @@ describe('runWorkerMain', () => {
|
||||
port.respond = (message) => {
|
||||
if (message.type !== 'call') return undefined
|
||||
// Deliver a stray reply first; the real one follows.
|
||||
port.deliver({ type: 'reply', id: 9_999, ok: true, value: 'stray' })
|
||||
return { type: 'reply', id: message.id, ok: true, value: 'real' }
|
||||
port.deliver({ type: 'reply', id: 9_999, ok: true, value: encodeWorkerJson('stray') })
|
||||
return { type: 'reply', id: message.id, ok: true, value: encodeWorkerJson('real') }
|
||||
}
|
||||
await runWorkerMain(port, {
|
||||
...BOOT,
|
||||
code: 'return await tools.x({})',
|
||||
namespaces: [{ global: 'tools', names: ['x'] }],
|
||||
}, fakeStreams())
|
||||
expect(port.done()).toEqual({ type: 'done', value: 'real' })
|
||||
expect(port.doneValue()).toBe('real')
|
||||
})
|
||||
|
||||
it('captures raw stream writes through the patched process streams', async () => {
|
||||
|
||||
@@ -92,7 +92,7 @@ describe('WorkerCodeRuntime — programs and bindings (real workers)', () => {
|
||||
cursor = Array.isArray(cursor) ? cursor[0] : undefined
|
||||
}
|
||||
expect(cursor).toBe('leaf')
|
||||
}, 60_000)
|
||||
}, 15_000)
|
||||
|
||||
it('reports non-erasable syntax as an exception without spawning a worker', async () => {
|
||||
const { runtime } = await setup()
|
||||
@@ -371,7 +371,7 @@ describe('WorkerCodeRuntime — budgets and containment (real workers)', () => {
|
||||
const { parentPort } = await import('node:worker_threads');
|
||||
const write = (text) => Object.getPrototypeOf(process.stdout).write.call(process.stdout, text);
|
||||
write('late-pipe-' + 'x'.repeat(100_000));
|
||||
parentPort.postMessage({ type: 'done', value: 'done' });
|
||||
parentPort.postMessage({ type: 'done', value: ['done'] });
|
||||
for (;;) {}
|
||||
`,
|
||||
bindings: [],
|
||||
@@ -438,7 +438,7 @@ describe('WorkerCodeRuntime — hostile programs (real workers)', () => {
|
||||
program: `
|
||||
const { parentPort } = await import('node:worker_threads');
|
||||
for (let i = 0; i < 50; i++) parentPort.postMessage({ type: 'log', text: 'F'.repeat(100), forged: true });
|
||||
parentPort.postMessage({ type: 'done', value: 'V'.repeat(100000) });
|
||||
parentPort.postMessage({ type: 'done', value: ['V'.repeat(100000)] });
|
||||
for (;;) {}
|
||||
`,
|
||||
bindings: [],
|
||||
@@ -482,8 +482,9 @@ describe('WorkerCodeRuntime — hostile programs (real workers)', () => {
|
||||
const result = await runtime.run({
|
||||
program: `
|
||||
const { parentPort } = await import('node:worker_threads');
|
||||
let value = null;
|
||||
for (let depth = 0; depth < 3_000; depth++) value = [value];
|
||||
const value = [];
|
||||
for (let depth = 0; depth < 3_000; depth++) value.push({ kind: 'array', length: 1 });
|
||||
value.push(null);
|
||||
setTimeout(() => { parentPort.postMessage({ type: 'done', value }) }, 25);
|
||||
// Prevent bootstrap's normal undefined completion from racing the forged terminal.
|
||||
await new Promise(() => {});
|
||||
@@ -500,7 +501,7 @@ describe('WorkerCodeRuntime — hostile programs (real workers)', () => {
|
||||
}
|
||||
expect(depth).toBe(3_000)
|
||||
expect(value).toBeNull()
|
||||
}, 60_000)
|
||||
}, 15_000)
|
||||
|
||||
it('turns forged over-limit error text into output-limit at the host', async () => {
|
||||
const { runtime } = await setup({ maxOutputBytes: 64 })
|
||||
|
||||
@@ -3,6 +3,7 @@ import { tmpdir } from 'node:os'
|
||||
import { join } from 'node:path'
|
||||
import { Worker } from 'node:worker_threads'
|
||||
import { expect, it } from 'vitest'
|
||||
import { decodeWorkerJson } from '../src/worker-json.ts'
|
||||
|
||||
/**
|
||||
* Prove the unbuilt worker is a self-contained source closure. Copying it out
|
||||
@@ -28,7 +29,9 @@ it('boots the source worker without workspace package outputs', async () => {
|
||||
worker?.once('error', reject)
|
||||
})
|
||||
|
||||
expect(message).toEqual({ type: 'done', value: { answer: 42 } })
|
||||
expect(message).toMatchObject({ type: 'done' })
|
||||
const value = typeof message === 'object' && message !== null ? (message as { value?: unknown }).value : undefined
|
||||
expect(decodeWorkerJson(value)).toEqual({ answer: 42 })
|
||||
} finally {
|
||||
if (worker) await worker.terminate()
|
||||
await rm(directory, { recursive: true, force: true })
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
import { runInNewContext } from 'node:vm'
|
||||
import { describe, expect, it } from 'vitest'
|
||||
import { snapshotJsonValue } from '@deepseek-ai/dsh-session'
|
||||
import { snapshotCodeJsonValue } from '../src/worker-json.ts'
|
||||
import { decodeWorkerJson, encodeWorkerJson, snapshotCodeJsonValue } from '../src/worker-json.ts'
|
||||
|
||||
describe('snapshotCodeJsonValue', () => {
|
||||
it('matches the canonical scalar boundary', () => {
|
||||
@@ -142,3 +142,90 @@ describe('snapshotCodeJsonValue', () => {
|
||||
expect(snapshotCodeJsonValue({ after: true })).toEqual({ after: true })
|
||||
})
|
||||
})
|
||||
|
||||
describe('flat worker JSON wire', () => {
|
||||
it('round-trips every JSON root while preserving object keys and container order', () => {
|
||||
const withPrototypeKey = Object.create(null) as Record<string, unknown>
|
||||
withPrototypeKey.__proto__ = { safe: true }
|
||||
const values = [null, false, true, 1.25, 'text', [], {}, [1, { nested: [2] }], withPrototypeKey]
|
||||
for (const value of values) {
|
||||
const snapshot = snapshotCodeJsonValue(value)
|
||||
expect(snapshot).not.toBeUndefined()
|
||||
expect(decodeWorkerJson(encodeWorkerJson(snapshot!))).toEqual(snapshot)
|
||||
}
|
||||
const decoded = decodeWorkerJson(encodeWorkerJson(snapshotCodeJsonValue(withPrototypeKey)!)) as Record<string, unknown>
|
||||
expect(Object.hasOwn(decoded, '__proto__')).toBe(true)
|
||||
expect(decoded.__proto__).toEqual({ safe: true })
|
||||
})
|
||||
|
||||
it('round-trips deep values through a bounded-depth token array', () => {
|
||||
let value: unknown = 'leaf'
|
||||
for (let depth = 0; depth < 5_000; depth++) value = [value]
|
||||
const snapshot = snapshotCodeJsonValue(value)!
|
||||
const wire = encodeWorkerJson(snapshot)
|
||||
expect(wire).toHaveLength(5_001)
|
||||
|
||||
let cursor = decodeWorkerJson(wire)
|
||||
for (let depth = 0; depth < 5_000; depth++) {
|
||||
expect(Array.isArray(cursor)).toBe(true)
|
||||
cursor = Array.isArray(cursor) ? cursor[0] : undefined
|
||||
}
|
||||
expect(cursor).toBe('leaf')
|
||||
})
|
||||
|
||||
it('rejects malformed, incomplete, lossy, sparse, decorated, and throwing wire values', () => {
|
||||
const sparse = new Array(1)
|
||||
const compensatedSparse = new Array(1)
|
||||
Object.defineProperty(compensatedSparse, 'extra', { value: true })
|
||||
const decorated: unknown[] = [null]
|
||||
Object.defineProperty(decorated, 'extra', { value: true })
|
||||
const throwing: unknown[] = []
|
||||
Object.defineProperty(throwing, 0, { enumerable: true, get: () => { throw new Error('wire getter') } })
|
||||
const decoratedKeys: unknown[] = ['x']
|
||||
Object.defineProperty(decoratedKeys, 'extra', { value: true })
|
||||
const foreignMarker: Record<string, unknown> = { kind: 'array', length: 0 }
|
||||
Object.setPrototypeOf(foreignMarker, {})
|
||||
const hiddenMarker = Object.defineProperty({ kind: 'array', length: 0 }, 'hidden', { value: true })
|
||||
|
||||
for (const value of [
|
||||
undefined,
|
||||
null,
|
||||
{},
|
||||
[],
|
||||
sparse,
|
||||
compensatedSparse,
|
||||
decorated,
|
||||
throwing,
|
||||
[undefined],
|
||||
[-0],
|
||||
[Number.NaN],
|
||||
[Number.POSITIVE_INFINITY],
|
||||
[1, 2],
|
||||
[[]],
|
||||
[foreignMarker],
|
||||
[hiddenMarker],
|
||||
[{ kind: 'unknown' }],
|
||||
[{ kind: 'array' }],
|
||||
[{ kind: 'array', length: '1' }],
|
||||
[{ kind: 'array', length: -1 }],
|
||||
[{ kind: 'array', length: Number.MAX_SAFE_INTEGER + 1 }],
|
||||
[{ kind: 'array', length: 1 }],
|
||||
[{ kind: 'array', length: 2 }, { kind: 'array', length: 1 }, null],
|
||||
[{ kind: 'array', length: 0, extra: true }],
|
||||
[{ kind: 'object' }],
|
||||
[{ kind: 'object', keys: 'x' }],
|
||||
[{ kind: 'object', keys: decoratedKeys }],
|
||||
[{ kind: 'object', keys: [1] }],
|
||||
[{ kind: 'object', keys: ['x', 'x'] }, 1, 2],
|
||||
[{ kind: 'object', keys: ['x'] }],
|
||||
[{ kind: 'object', keys: [], extra: true }],
|
||||
]) {
|
||||
expect(decodeWorkerJson(value)).toBeUndefined()
|
||||
}
|
||||
})
|
||||
|
||||
it('rejects invalid values passed through a forged static type', () => {
|
||||
expect(() => encodeWorkerJson([undefined] as never)).toThrow(/sparse JSON array/)
|
||||
expect(() => encodeWorkerJson({ value: undefined } as never)).toThrow(/undefined JSON object property/)
|
||||
})
|
||||
})
|
||||
Reference in New Issue
Block a user