Files
orca/tests/e2e/cross-version-wire/terminal-wire-link.ts
Jinwoo Hong 06780260c0 test(remote-runtime): run an old client and an old server against current code (#12682)
Mixed versions are the normal state of the remote-server feature: users update clients and servers independently. Until now nothing tested that. Every cross-version claim was made by code reading plus unit tests with hand-written old/new shapes — enough to catch design problems, not enough to catch a real skew regression.

This runs the REAL protocol implementations from two builds against each other in one process: the actual host methods and RPC dispatcher on one side, the actual renderer multiplexer on the other, with a transport that reproduces the production asymmetry — each side decodes with its OWN codec and drops frames whose opcode it does not know. A frame survives only if the RECEIVING build understands it, which is what makes this level sufficient without launching two apps. The old side is a genuine checkout extracted from the release tag; the extracted client was confirmed to lack a symbol that exists only on main.

Journey: subscribe, first snapshot, input reaching the process, live output, hide/reveal snapshot, transport drop, resubscribe, input landing again — across old->new, new->old, and a current/current control. Every step ends on an observed-state barrier; no sleeps. The oracle asserts the recorded step list, the exact 16-frame named sequence, negotiated capabilities, the exact input the host wrote to the PTY, rendered content, and zero decoder-rejected frames. A host method the stub lacks is recorded by name and asserted empty, so a harness gap cannot masquerade as a wire break.

Detection is proven per violation shape, and it attributes each to the correct side: an unnegotiated opcode goes red only where a decoder would reject it, a removed published field goes red only where an old client consumes it, and a legal additive field stays green in all three pairings so the harness will not cry wolf on safe changes.

It also documents the three compatibility rules in docs/reference/remote-wire-compatibility.md, linked from AGENTS.md, since they previously existed only as folklore — notably that "decoders reject unknown opcodes" is true for the desktop decoder but NOT for mobile, which silently drops them.

Deliberately scoped: terminal stream only. The session-tab sync channel is not covered, nor agent-session publications, file/Git RPCs, mobile E2EE framing, or the relay transport. Two version points, so a regression introduced and reverted between them is invisible.

CI selection was verified rather than assumed — `vitest list` confirms 0 matches under the shard's exclude and 4 under the dedicated job — because a lane silently running zero tests is precisely how a host-side defect escaped CI earlier in this series. Closes STA-3469.
2026-08-05 01:31:29 -07:00

226 lines
7.0 KiB
TypeScript

import { vi } from 'vitest'
import type { HostTerminalRuntimeStub } from './host-terminal-runtime-stub'
import type { TerminalStreamFrame, TerminalWireBuild } from './versioned-terminal-wire'
export type ObservedFrame = {
direction: 'host-to-client' | 'client-to-host'
opcode: number
streamId: number
seq: number
/** JSON payload when the receiving side could parse one. */
json: Record<string, unknown> | null
text: string
}
export type RejectedFrame = {
direction: 'host-to-client' | 'client-to-host'
/** Opcode byte as written by the sender, even though the receiver refused it. */
rawOpcode: number
byteLength: number
}
export type HostConnection = {
connectionId: string
events: Record<string, unknown>[]
alive: boolean
}
export type TerminalWireLink = {
/** Frames each side accepted, in delivery order. */
observed: ObservedFrame[]
/** Frames the receiving build's decoder refused — the unknown-opcode failure mode. */
rejected: RejectedFrame[]
connections: HostConnection[]
/** Drop the live transport the way a socket close would. */
disconnect: () => void
dispose: () => Promise<void>
}
function rawOpcodeOf(bytes: Uint8Array): number {
return bytes.length > 2 ? bytes[2]! : -1
}
function describeFrame(
direction: ObservedFrame['direction'],
frame: TerminalStreamFrame,
codec: TerminalWireBuild['codec']
): ObservedFrame {
const json = codec.decodeTerminalStreamJson<Record<string, unknown>>(frame.payload)
return {
direction,
opcode: frame.opcode,
streamId: frame.streamId,
seq: frame.seq,
json: json && typeof json === 'object' ? json : null,
text: codec.decodeTerminalStreamText(frame.payload)
}
}
/**
* Pair one client build to one host build over an in-process transport that copies
* the production routing exactly:
*
* - client -> host: the HOST decodes with its own codec and drops the frame when
* the opcode is unknown (`runtime-rpc.ts` `handleWebSocketBinaryMessage`);
* - host -> client: raw bytes reach the client, which decodes with ITS codec.
*
* That asymmetry is the whole point: a frame only survives if the receiving build
* understands it, so a new opcode against an old peer disappears silently.
*/
export function createTerminalWireLink(args: {
hostBuild: TerminalWireBuild
clientBuild: TerminalWireBuild
hostStub: HostTerminalRuntimeStub
}): TerminalWireLink {
const { hostBuild, clientBuild, hostStub } = args
const observed: ObservedFrame[] = []
const rejected: RejectedFrame[] = []
const connections: HostConnection[] = []
const dispatchPromises: Promise<unknown>[] = []
let connectionCounter = 0
type LiveConnection = {
record: HostConnection
handlers: Map<number, (frame: TerminalStreamFrame) => void>
clientCallbacks: {
onResponse: (response: unknown) => void
onBinary: (bytes: Uint8Array) => void
onError?: (error: { code?: string; message: string }) => void
onClose?: () => void
}
}
let live: LiveConnection | null = null
const closeHostSideByConnection = new Map<string, () => void>()
const subscribe = async (
_args: unknown,
clientCallbacks: LiveConnection['clientCallbacks']
): Promise<{ unsubscribe: () => void; sendBinary: (bytes: Uint8Array) => void }> => {
connectionCounter++
const connectionId = `cross-version-conn-${connectionCounter}`
const record: HostConnection = { connectionId, events: [], alive: true }
const handlers = new Map<number, (frame: TerminalStreamFrame) => void>()
const connection: LiveConnection = { record, handlers, clientCallbacks }
connections.push(record)
live = connection
const abort = new AbortController()
const closeHostSide = (): void => {
record.alive = false
if (live === connection) {
live = null
}
abort.abort()
// The socket layer runs the host's registered teardown on close; without it
// the multiplex handler never settles and the harness would hang, not fail.
hostStub.closeConnection(connectionId)
}
closeHostSideByConnection.set(connectionId, closeHostSide)
const dispatch = new hostBuild.host.RpcDispatcher({
runtime: hostStub.runtime,
methods: hostBuild.host.TERMINAL_METHODS
}).dispatchStreaming(
{
id: `req-${connectionCounter}`,
authToken: 'cross-version-token',
method: 'terminal.multiplex',
params: {}
},
(message) => {
if (!record.alive) {
return
}
const envelope = JSON.parse(message) as Record<string, unknown>
const result = envelope.result
if (result && typeof result === 'object') {
record.events.push(result as Record<string, unknown>)
}
clientCallbacks.onResponse(envelope)
},
{
connectionId,
sendBinary: (bytes) => {
if (!record.alive) {
return false
}
const asClientSees = clientBuild.codec.decodeTerminalStreamFrame(bytes)
if (!asClientSees) {
rejected.push({
direction: 'host-to-client',
rawOpcode: rawOpcodeOf(bytes),
byteLength: bytes.byteLength
})
} else {
observed.push(describeFrame('host-to-client', asClientSees, clientBuild.codec))
}
// Bytes always go out; only the receiving decoder decides survival.
clientCallbacks.onBinary(bytes)
return true
},
registerBinaryStreamHandler: (streamId, handler) => {
handlers.set(streamId, handler)
return () => {
if (handlers.get(streamId) === handler) {
handlers.delete(streamId)
}
}
},
signal: abort.signal
}
)
dispatchPromises.push(dispatch.catch(() => {}))
return {
unsubscribe: closeHostSide,
sendBinary: (bytes) => {
if (!record.alive) {
return
}
const frame = hostBuild.codec.decodeTerminalStreamFrame(bytes)
if (!frame) {
rejected.push({
direction: 'client-to-host',
rawOpcode: rawOpcodeOf(bytes),
byteLength: bytes.byteLength
})
return
}
observed.push(describeFrame('client-to-host', frame, hostBuild.codec))
handlers.get(frame.streamId)?.(frame)
}
}
}
vi.stubGlobal('window', {
api: {
runtimeEnvironments: {
subscribe: vi.fn(subscribe)
}
},
location: { search: '' }
})
return {
observed,
rejected,
connections,
disconnect: () => {
const connection = live
if (!connection) {
return
}
closeHostSideByConnection.get(connection.record.connectionId)?.()
connection.clientCallbacks.onClose?.()
},
dispose: async () => {
for (const record of connections) {
closeHostSideByConnection.get(record.connectionId)?.()
}
live = null
clientBuild.client.resetRemoteRuntimeTerminalMultiplexersForTests()
vi.unstubAllGlobals()
await Promise.all(dispatchPromises)
}
}
}