Files
orca/src/shared/protocol-compat.test.ts
T
Neil dcaef9dee5 test: retire relay, preload and shared cases that re-prove an owned contract (#24007)
Audit sweep over `src/relay`, `src/preload` and `src/shared` (1,087 test files
reviewed). 101 case declarations removed across 40 files, 6 test files deleted
outright, 1,143 lines gone. Executed-case count falls further, since several
removals were `it.each` tables.

Dominant patterns, by frequency:

- Self-comparisons that cannot fail: `expect(f(x)).toBe(f(x))`,
  `JSON.parse(JSON.stringify(literal))` deep-equalling the literal for a type
  with no codec, and `normalizeKeyToken(t) === normalizeKeyToken(t)` presented as
  proof of memoization.
- Object literals asserting their own fields back, where the guarantee comes from
  the type annotation and the runtime assertion cannot fail.
- Copied inventories: constants compared to their own initializers, and a
  function returning a copy of an exported constant checked against that
  constant's literal contents.
- Duplicate invocations of a contract owned at a stronger boundary, including
  provider-local replays of a shared helper.
- Table rows varying a field production never reads, so every row runs one path.
- Names promising more than the input exercises: a "Windows launch" case in a
  module with no platform input, and a case whose named branch is never entered.

Two production symbols go with them, each a test-only export whose sole caller
was a deleted case:

- `getGitHubProjectRefInputByteLength` — a one-line forward to
  `getClipboardTextByteLength`. The real bound
  (`GITHUB_PROJECT_REF_INPUT_MAX_BYTES`) and its guard stay.
- `GRAB_STYLE_PROPERTIES` — an intended shared source of truth that nothing ever
  consulted; the property set is hand-enumerated at three independent sites.

One case was deliberately restored and strengthened rather than dropped. The
relay integration suite is the only place the real `SshChannelMultiplexer` is
wired to `RelayDispatcher`, so it reaches transport behavior the handler suites
cannot (they use `createMockDispatcher`). Its `fs.writeFile` roundtrip is the one
case producing a void result, and `JSON.stringify` drops an absent `result`
member — a shape no other surviving case exercises. Restored with an assertion
pinning what the client actually observes: `null`, not `undefined`. That
assertion failed on first run, so the fact was previously unasserted anywhere.

One deletion was reverted mid-audit. A case asserting that optional fields stay
invisible to "old attach and ready decoders" builds those decoders from `z.object`
schemas declared in the test file, so it demonstrates zod's unknown-key stripping
rather than anything shipped. It is nonetheless the only forward-compatibility
coverage these envelopes have, and `reliability-gates.jsonc:6232` names it as
evidence verbatim, so it stays. Note that `check-reliability-gates.mjs` passed
both with and without it: the script resolves manifest paths and commands, and
does not check that a named assertion still corresponds to a live case.

Kept deliberately: everything a reliability gate cites as evidence; the three
`registers all expected handlers` RPC manifests (a dropped registration is a
silent wire break no type checker catches, and one carries the STA-4571
`pty.ackData` ratchet); the `child-process` direct-import ratchet; and
prototype-spy cases paired with a `.repeat(10_000)` input, which assert a real
memory bound rather than merely forbidding a technique.

Verified: `pnpm test src/shared src/relay src/preload` (1073 files, 11996
passed, 1 pre-existing `it.fails`, 131 skipped), `pnpm tc` after clearing
`.tsbuildinfo`, `check-reliability-gates.mjs` (140 gates),
`check:code-quality:changed` (0 new findings).
2026-09-29 22:17:13 -07:00

208 lines
6.8 KiB
TypeScript

import { describe, expect, it } from 'vitest'
import {
describeRuntimeCompatBlock,
evaluateCompat,
evaluateRuntimeCompat
} from './protocol-compat'
import {
DESKTOP_PROTOCOL_VERSION,
MIN_COMPATIBLE_MOBILE_VERSION,
MIN_COMPATIBLE_RUNTIME_CLIENT_VERSION,
MIN_COMPATIBLE_RUNTIME_SERVER_VERSION,
RUNTIME_PROTOCOL_VERSION
} from './protocol-version'
const MOBILE_V = 1
describe('evaluateCompat', () => {
it('returns ok when both desktop fields are undefined and constants are wide-open', () => {
const verdict = evaluateCompat({
mobileProtocolVersion: MOBILE_V,
minCompatibleDesktopVersion: 0,
desktopProtocolVersion: undefined,
desktopMinCompatibleMobileVersion: undefined
})
expect(verdict).toEqual({ kind: 'ok' })
})
it('allows desktop protocol 3 to roll out before mobile protocol 2 updates', () => {
const verdict = evaluateCompat({
mobileProtocolVersion: 2,
minCompatibleDesktopVersion: 2,
desktopProtocolVersion: 3,
desktopMinCompatibleMobileVersion: 2
})
expect(verdict).toEqual({ kind: 'ok' })
})
it('allows mobile protocol 3 to roll out before desktop protocol 2 updates', () => {
const verdict = evaluateCompat({
mobileProtocolVersion: 3,
minCompatibleDesktopVersion: 2,
desktopProtocolVersion: 2,
desktopMinCompatibleMobileVersion: 2
})
expect(verdict).toEqual({ kind: 'ok' })
})
it('blocks with mobile-too-old when desktop requires a newer mobile', () => {
const verdict = evaluateCompat({
mobileProtocolVersion: MOBILE_V,
minCompatibleDesktopVersion: 0,
desktopProtocolVersion: 5,
desktopMinCompatibleMobileVersion: MOBILE_V + 1
})
expect(verdict).toEqual({
kind: 'blocked',
reason: 'mobile-too-old',
desktopVersion: 5,
requiredMobileVersion: MOBILE_V + 1
})
})
it('coerces undefined desktopVersion to 0 in the verdict payload', () => {
const verdict = evaluateCompat({
mobileProtocolVersion: MOBILE_V,
minCompatibleDesktopVersion: 0,
desktopProtocolVersion: undefined,
desktopMinCompatibleMobileVersion: MOBILE_V + 1
})
expect(verdict).toMatchObject({
kind: 'blocked',
reason: 'mobile-too-old',
desktopVersion: 0
})
})
it('blocks with desktop-too-old when desktop reports below the local minimum', () => {
const verdict = evaluateCompat({
mobileProtocolVersion: MOBILE_V,
minCompatibleDesktopVersion: 5,
desktopProtocolVersion: 3,
desktopMinCompatibleMobileVersion: 0
})
expect(verdict).toEqual({
kind: 'blocked',
reason: 'desktop-too-old',
desktopVersion: 3,
requiredDesktopVersion: 5
})
})
it('mobile-too-old wins precedence when both constraints would fire', () => {
// Why: documents the intended kill-switch precedence — desktop's
// refusal of a too-old mobile takes priority over mobile's local
// refusal of a too-old desktop.
const verdict = evaluateCompat({
mobileProtocolVersion: MOBILE_V,
minCompatibleDesktopVersion: 99,
desktopProtocolVersion: -1,
desktopMinCompatibleMobileVersion: MOBILE_V + 1
})
expect(verdict.kind).toBe('blocked')
expect((verdict as { reason: string }).reason).toBe('mobile-too-old')
})
it('with minCompatibleDesktopVersion = 0 every reported desktop passes', () => {
for (const v of [0, 1, 2, 99]) {
expect(
evaluateCompat({
mobileProtocolVersion: MOBILE_V,
minCompatibleDesktopVersion: 0,
desktopProtocolVersion: v,
desktopMinCompatibleMobileVersion: 0
})
).toEqual({ kind: 'ok' })
}
})
it('hard-blocks protocol-1 mobile for the binary terminal stream cutover', () => {
const verdict = evaluateCompat({
mobileProtocolVersion: 1,
minCompatibleDesktopVersion: DESKTOP_PROTOCOL_VERSION,
desktopProtocolVersion: DESKTOP_PROTOCOL_VERSION,
desktopMinCompatibleMobileVersion: MIN_COMPATIBLE_MOBILE_VERSION
})
expect(verdict).toEqual({
kind: 'blocked',
reason: 'mobile-too-old',
desktopVersion: DESKTOP_PROTOCOL_VERSION,
requiredMobileVersion: MIN_COMPATIBLE_MOBILE_VERSION
})
})
})
describe('evaluateRuntimeCompat', () => {
it('keeps the current client and current server self-compatible', () => {
const verdict = evaluateRuntimeCompat({
clientProtocolVersion: RUNTIME_PROTOCOL_VERSION,
minCompatibleServerProtocolVersion: MIN_COMPATIBLE_RUNTIME_SERVER_VERSION,
serverProtocolVersion: RUNTIME_PROTOCOL_VERSION,
serverMinCompatibleClientProtocolVersion: MIN_COMPATIBLE_RUNTIME_CLIENT_VERSION
})
expect(verdict).toMatchObject({ kind: 'ok' })
})
it('allows client and server app versions to skew when protocol ranges overlap', () => {
const verdict = evaluateRuntimeCompat({
clientProtocolVersion: RUNTIME_PROTOCOL_VERSION,
minCompatibleServerProtocolVersion: MIN_COMPATIBLE_RUNTIME_SERVER_VERSION,
serverProtocolVersion: RUNTIME_PROTOCOL_VERSION + 3,
serverMinCompatibleClientProtocolVersion: RUNTIME_PROTOCOL_VERSION - 1
})
expect(verdict).toMatchObject({ kind: 'ok' })
})
it('blocks when the server requires a newer client protocol', () => {
const verdict = evaluateRuntimeCompat({
clientProtocolVersion: RUNTIME_PROTOCOL_VERSION,
minCompatibleServerProtocolVersion: MIN_COMPATIBLE_RUNTIME_SERVER_VERSION,
serverProtocolVersion: RUNTIME_PROTOCOL_VERSION + 1,
serverMinCompatibleClientProtocolVersion: RUNTIME_PROTOCOL_VERSION + 1
})
expect(verdict).toMatchObject({
kind: 'blocked',
reason: 'client-too-old',
requiredClientProtocolVersion: RUNTIME_PROTOCOL_VERSION + 1
})
expect(describeRuntimeCompatBlock(verdict)).toContain('client is too old')
})
it('blocks when the server protocol is below the client minimum', () => {
const verdict = evaluateRuntimeCompat({
clientProtocolVersion: RUNTIME_PROTOCOL_VERSION,
minCompatibleServerProtocolVersion: RUNTIME_PROTOCOL_VERSION,
serverProtocolVersion: RUNTIME_PROTOCOL_VERSION - 1,
serverMinCompatibleClientProtocolVersion: 0
})
expect(verdict).toMatchObject({
kind: 'blocked',
reason: 'server-too-old',
requiredServerProtocolVersion: RUNTIME_PROTOCOL_VERSION
})
expect(describeRuntimeCompatBlock(verdict)).toContain('server is too old')
})
it('treats missing server fields as protocol 0', () => {
const verdict = evaluateRuntimeCompat({
clientProtocolVersion: RUNTIME_PROTOCOL_VERSION,
minCompatibleServerProtocolVersion: 1,
serverProtocolVersion: undefined,
serverMinCompatibleClientProtocolVersion: undefined
})
expect(verdict).toMatchObject({
kind: 'blocked',
reason: 'server-too-old',
serverProtocolVersion: 0
})
})
})