A new capability family at packages/workflow/ in the bash seam shape,
modeled on Claude Code's dynamic workflows: the model writes a JavaScript
orchestration script (export const meta = {...} + plain-JS body), a runtime
executes it, and the script — not the conversation — holds the loop, the
branching, and the intermediate results.
- dsh-workflow (ctx.workflows): abstract WorkflowService + run vocabulary
(WorkflowRun whose result NEVER rejects) + observe-only workflow/* events
carrying data snapshots (id + meta, never the live run), per-listener
contained like subagent/*.
- dsh-workflow-vm: in-process node:vm engine. Meta extraction via a
string/comment-aware scanner (template interpolation rejected; literal
evaluated alone in an empty timed context; statement blanked line-
preservingly so stacks keep script line numbers). Hooks: agent(prompt,
{label, phase, schema, model}) over ctx.subagents, parallel(), pipeline()
(no cross-stage barrier), phase(), log(), args. Fatal-vs-null discipline:
hook misuse (unknown/deferred options, bad arguments, unsupported
schemas, tripped caps, seam start failures, cancellation) throws fatal
WorkflowErrors the combinators RE-THROW — never dissolved into the
per-item null reserved for child failures. Realm boundary: inbound values
materialized by descriptor walks that never invoke accessors (defineProperty
copies, __proto__-safe); outbound values rebuilt in-realm via the
context's own JSON.parse. Determinism bans (Date.now/Math.random/argless
new Date) kept so future resume support cannot break scripts. Caps and
timeouts are validated Config. Every hook promise carries a no-op
rejection consumer (app-boot exits on unhandled rejections).
- dsh-tool-workflow: the model-facing workflow tool, synchronous like
dsh-tool-subagent (start → await → try/finally dispose; abort bridged;
non-completed → isError). Generic render card titled by a textual
meta.name sniff. The tool description carries the authoring contract.
Wired into examples/{coding-agent,acp-agent} with explicit-ask-only
guidance. Coverage at every tier: unit (meta scanner, materializer incl.
counting-getter and __proto__ regressions, combinator semantics,
concurrency ceiling, caps, cancellation, no-unhandled-rejection abandon),
integration over the real spawn stack, with-key e2e (real two-phase run +
the tool through the registry pipeline), and a recorded ACP snapshot
scenario (workflow-run, 1 child session). RFC:
docs/rfc/implemented/feature/2026-07-05-dynamic-workflows.md (deferred
work explicitly listed). AGENTS.md budget 1575 → 1590 for the new group's
layout line.
115 lines
5.4 KiB
TypeScript
115 lines
5.4 KiB
TypeScript
import { describe, expect, it } from 'vitest'
|
|
import * as vm from 'node:vm'
|
|
import { materializeFromRealm, MaterializeError } from '../src/realm.ts'
|
|
|
|
/** Evaluate an expression inside a fresh vm realm and hand back the raw realm value. */
|
|
function inRealm(expression: string): unknown {
|
|
return vm.runInNewContext(`(${expression})`)
|
|
}
|
|
|
|
/** The MaterializeError message for a value that must be rejected (throws if accepted). */
|
|
function rejection(value: unknown): string {
|
|
try {
|
|
materializeFromRealm(value)
|
|
} catch (error: unknown) {
|
|
if (error instanceof MaterializeError) return error.message
|
|
throw error
|
|
}
|
|
throw new Error('expected the value to be rejected')
|
|
}
|
|
|
|
describe('materializeFromRealm', () => {
|
|
it('copies realm objects/arrays/scalars into host plain data', () => {
|
|
const value = inRealm("{ a: 1, b: 'x', c: true, d: null, list: [1, [2, { deep: 'y' }]] }")
|
|
const out = materializeFromRealm(value) as Record<string, unknown>
|
|
expect(out).toEqual({ a: 1, b: 'x', c: true, d: null, list: [1, [2, { deep: 'y' }]] })
|
|
// The copy is HOST data: prototypes are the host intrinsics.
|
|
expect(Object.getPrototypeOf(out)).toBe(Object.prototype)
|
|
expect(Array.isArray(out.list)).toBe(true)
|
|
// And it round-trips through JSON byte-identically (the whole point).
|
|
expect(JSON.parse(JSON.stringify(out))).toEqual(out)
|
|
})
|
|
|
|
it('accepts undefined ONLY at the root (a valueless script return)', () => {
|
|
expect(materializeFromRealm(undefined)).toBeUndefined()
|
|
expect(rejection(inRealm('{ a: undefined }'))).toContain('value.a')
|
|
})
|
|
|
|
it('never invokes accessors: a counting getter is rejected, not read', () => {
|
|
const counter = inRealm(`
|
|
(() => {
|
|
globalThis.reads = 0
|
|
return { get x() { globalThis.reads += 1; return 1 } }
|
|
})()
|
|
`)
|
|
expect(rejection(counter)).toContain('accessor properties cannot cross')
|
|
// The getter body never ran — descriptor inspection only.
|
|
expect((counter as { x?: unknown }).x).toBe(1) // sanity: reading DOES run it…
|
|
expect(rejection(counter)).toContain('accessor') // …but materialization still never did
|
|
})
|
|
|
|
it('a "__proto__" key becomes an OWN data property of the copy, never a prototype mutation', () => {
|
|
const value: unknown = vm.runInNewContext('JSON.parse(\'{"__proto__": {"polluted": 1}, "ok": 2}\')')
|
|
const out = materializeFromRealm(value) as Record<string, unknown>
|
|
expect(Object.getPrototypeOf(out)).toBe(Object.prototype)
|
|
expect(Object.prototype.hasOwnProperty.call(out, '__proto__')).toBe(true)
|
|
expect(out.ok).toBe(2)
|
|
// The host Object.prototype was NOT touched.
|
|
expect(({} as Record<string, unknown>).polluted).toBeUndefined()
|
|
})
|
|
|
|
it('rejects functions, symbols (keys and values), and bigints with path-qualified messages', () => {
|
|
expect(rejection(inRealm('{ fn: () => 1 }'))).toContain('value.fn')
|
|
expect(rejection(inRealm("{ [Symbol('k')]: 1 }"))).toContain('symbol-keyed')
|
|
expect(rejection(inRealm("{ s: Symbol('v') }"))).toContain('value.s')
|
|
expect(rejection(inRealm('{ big: 1n }'))).toContain('value.big')
|
|
expect(rejection(inRealm("[Symbol('x')]"))).toContain('value[0]')
|
|
const taggedArray = inRealm("(() => { const a = [1]; a[Symbol('t')] = 1; return a })()")
|
|
expect(rejection(taggedArray)).toContain('symbol-keyed')
|
|
})
|
|
|
|
it('rejects non-finite numbers and undefined values inside containers', () => {
|
|
expect(rejection(inRealm('{ n: NaN }'))).toContain('non-finite')
|
|
expect(rejection(inRealm('[Infinity]'))).toContain('non-finite')
|
|
})
|
|
|
|
it('rejects exotic prototypes (Date, Map, class instances) but accepts null-prototype data', () => {
|
|
expect(rejection(inRealm('{ d: new Date(0) }'))).toContain('exotic prototype')
|
|
expect(rejection(inRealm('new Map()'))).toContain('exotic prototype')
|
|
expect(rejection(inRealm('(() => { class C { constructor() { this.x = 1 } } return new C() })()')))
|
|
.toContain('exotic prototype')
|
|
expect(materializeFromRealm(inRealm('Object.assign(Object.create(null), { a: 1 })'))).toEqual({ a: 1 })
|
|
})
|
|
|
|
it('rejects cycles and accepts the same object reused as a sibling (a DAG)', () => {
|
|
expect(rejection(inRealm('(() => { const o = {}; o.self = o; return o })()'))).toContain('circular')
|
|
const dag = inRealm('(() => { const leaf = { v: 1 }; return { a: leaf, b: leaf } })()')
|
|
expect(materializeFromRealm(dag)).toEqual({ a: { v: 1 }, b: { v: 1 } })
|
|
})
|
|
|
|
it('rejects sparse arrays, accessor elements, and non-index array properties', () => {
|
|
expect(rejection(inRealm('[1, , 3]'))).toContain('sparse')
|
|
expect(rejection(inRealm('(() => { const a = [1]; Object.defineProperty(a, 0, { get: () => 1 }); return a })()')))
|
|
.toContain('accessor')
|
|
expect(rejection(inRealm('(() => { const a = [1]; a.total = 3; return a })()')))
|
|
.toContain('non-index')
|
|
})
|
|
|
|
it('skips non-enumerable own properties (matching JSON.stringify exactly)', () => {
|
|
const value = inRealm(`(() => {
|
|
const o = { visible: 1 }
|
|
Object.defineProperty(o, 'hidden', { value: () => 1, enumerable: false })
|
|
return o
|
|
})()`)
|
|
expect(materializeFromRealm(value)).toEqual({ visible: 1 })
|
|
})
|
|
|
|
it('works on plain host values too (the boundary is realm-agnostic)', () => {
|
|
expect(materializeFromRealm({ a: [1, 'x'] })).toEqual({ a: [1, 'x'] })
|
|
expect(materializeFromRealm('str')).toBe('str')
|
|
expect(materializeFromRealm(3)).toBe(3)
|
|
expect(materializeFromRealm(false)).toBe(false)
|
|
expect(materializeFromRealm(null)).toBeNull()
|
|
})
|
|
})
|