arcrun — AI workflow execution engine (clean history)
Self-hosted 開源:WASM 零件 + recipe + cypher-executor,跑在你自己的 Cloudflare。 此為重建的乾淨歷史起點(移除曾誤 commit 的 GCP SA 金鑰,舊歷史保留在 richblack/arcrun 與本地 backup 分支)。含: - acr init --self-hosted installer(建 KV/R2 + codeload 拉預編譯 wasm + wrangler deploy + seed recipe) - recipe push 把關(資料外流提醒 + 打通檢查) - 19 個正當零件預編譯 wasm(claude_api/km_writer/kbdb_upsert_block 排除:違反 DECISIONS §1) - CLI / cypher-executor / registry / 完整 SDD Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,83 @@
|
||||
// 單元測試:sandboxAcceptance
|
||||
// Requirements: 2.1, 2.2
|
||||
|
||||
import { describe, it, expect } from 'vitest';
|
||||
import { runSandboxAcceptance } from '../src/actions/sandboxAcceptance';
|
||||
import type { ComponentContract } from '../src/types';
|
||||
|
||||
const BASE_CONTRACT: ComponentContract = {
|
||||
canonical_id: 'validate_json',
|
||||
display_name: 'JSON 格式驗證器',
|
||||
category: 'logic',
|
||||
version: 'v1',
|
||||
wasi_target: 'preview1',
|
||||
stability: 'floating',
|
||||
runtime_compat: ['cf-workers', 'wazero'],
|
||||
constraints: {
|
||||
max_size_kb: 100,
|
||||
max_cold_start_ms: 50,
|
||||
no_network_syscall: true,
|
||||
io_model: 'stdin_stdout_json',
|
||||
},
|
||||
input_schema: { type: 'object' },
|
||||
output_schema: { type: 'object' },
|
||||
gherkin_tests: [
|
||||
{ scenario: 'happy', given: '{}', then_contains: '{}' },
|
||||
{ scenario: 'error', given: '{}', then_contains: '{}' },
|
||||
],
|
||||
};
|
||||
|
||||
// 建立合法的小型 WASM(最小 WASM magic + version header)
|
||||
function makeMinimalWasm(extraBytes = 0): Uint8Array {
|
||||
const magic = [0x00, 0x61, 0x73, 0x6d]; // \0asm
|
||||
const version = [0x01, 0x00, 0x00, 0x00];
|
||||
const padding = new Array(extraBytes).fill(0x00);
|
||||
return new Uint8Array([...magic, ...version, ...padding]);
|
||||
}
|
||||
|
||||
describe('runSandboxAcceptance', () => {
|
||||
// 註:G4 Gherkin 真實作後,minimal wasm(只有 magic header)無法 instantiate,
|
||||
// 會在 gherkin_tests 步驟失敗。同步步驟(size/syscall/fake)的失敗測試仍有效,
|
||||
// 因為它們在 Gherkin 之前就擋下。「全通過」需真實零件 wasm,移至整合測試。
|
||||
|
||||
it('步驟 (a):體積超過上限時失敗(在 Gherkin 前擋下)', async () => {
|
||||
const contract = { ...BASE_CONTRACT, constraints: { ...BASE_CONTRACT.constraints, max_size_kb: 1 } };
|
||||
const wasm = makeMinimalWasm(2000); // > 1KB
|
||||
const result = await runSandboxAcceptance(wasm, contract);
|
||||
expect(result.success).toBe(false);
|
||||
expect(result.failed_step).toBe('size_check');
|
||||
expect(result.reason).toContain('超過上限');
|
||||
expect(result.guide_anchor).toBeDefined();
|
||||
expect(result.canonical_id).toBe('validate_json');
|
||||
expect(result.version).toBe('v1');
|
||||
});
|
||||
|
||||
it('步驟:含禁止 syscall 時失敗', async () => {
|
||||
const encoder = new TextEncoder();
|
||||
const syscallBytes = encoder.encode('sock_connect');
|
||||
const wasm = new Uint8Array([0x00, 0x61, 0x73, 0x6d, 0x01, 0x00, 0x00, 0x00, ...syscallBytes]);
|
||||
const result = await runSandboxAcceptance(wasm, BASE_CONTRACT);
|
||||
expect(result.success).toBe(false);
|
||||
expect(result.failed_step).toBe('syscall_scan');
|
||||
expect(result.reason).toContain('sock_connect');
|
||||
});
|
||||
|
||||
it('size_check 失敗後不執行後續步驟', async () => {
|
||||
const encoder = new TextEncoder();
|
||||
const syscallBytes = encoder.encode('sock_connect');
|
||||
const padding = new Uint8Array(2000);
|
||||
const wasm = new Uint8Array([0x00, 0x61, 0x73, 0x6d, 0x01, 0x00, 0x00, 0x00, ...syscallBytes, ...padding]);
|
||||
const contract = { ...BASE_CONTRACT, constraints: { ...BASE_CONTRACT.constraints, max_size_kb: 1 } };
|
||||
const result = await runSandboxAcceptance(wasm, contract);
|
||||
expect(result.failed_step).toBe('size_check');
|
||||
});
|
||||
|
||||
it('G1:contract 含外部 URL 的假零件被擋(最先擋)', async () => {
|
||||
const contract = { ...BASE_CONTRACT, canonical_id: 'fake_gmail', description: '打 https://gmail.googleapis.com 寄信' };
|
||||
const wasm = makeMinimalWasm(10);
|
||||
const result = await runSandboxAcceptance(wasm, contract);
|
||||
expect(result.success).toBe(false);
|
||||
expect(result.failed_step).toBe('fake_component_scan');
|
||||
expect(result.reason).toContain('recipe');
|
||||
});
|
||||
});
|
||||
@@ -0,0 +1,113 @@
|
||||
// 單元測試:validateContract
|
||||
// Requirements: 1.1, 1.2, 11.5
|
||||
|
||||
import { describe, it, expect } from 'vitest';
|
||||
import { validateContract } from '../src/actions/validateContract';
|
||||
|
||||
const VALID_CONTRACT = {
|
||||
canonical_id: 'validate_json',
|
||||
display_name: 'JSON 格式驗證器',
|
||||
category: 'logic',
|
||||
version: 'v1',
|
||||
wasi_target: 'preview1',
|
||||
stability: 'floating',
|
||||
runtime_compat: ['cf-workers', 'wazero'],
|
||||
constraints: {
|
||||
max_size_kb: 2048,
|
||||
max_cold_start_ms: 50,
|
||||
no_network_syscall: true,
|
||||
io_model: 'stdin_stdout_json',
|
||||
},
|
||||
input_schema: { type: 'object', required: ['json_string'] },
|
||||
output_schema: { type: 'object', properties: { valid: { type: 'boolean' } } },
|
||||
gherkin_tests: [
|
||||
{ scenario: 'happy path', given: '{"json_string":"{}"}', then_contains: '{"valid":true}' },
|
||||
{ scenario: 'error path', given: '{"json_string":"bad"}', then_contains: '{"valid":false' },
|
||||
],
|
||||
};
|
||||
|
||||
describe('validateContract', () => {
|
||||
it('完整合約通過驗證', () => {
|
||||
const result = validateContract(VALID_CONTRACT);
|
||||
expect(result.valid).toBe(true);
|
||||
expect(result.missing_fields).toHaveLength(0);
|
||||
expect(result.errors).toHaveLength(0);
|
||||
});
|
||||
|
||||
it('缺少 canonical_id 時回傳 missing_fields', () => {
|
||||
const { canonical_id: _, ...rest } = VALID_CONTRACT;
|
||||
const result = validateContract(rest);
|
||||
expect(result.valid).toBe(false);
|
||||
expect(result.missing_fields).toContain('canonical_id');
|
||||
});
|
||||
|
||||
it('缺少 version 時回傳 missing_fields', () => {
|
||||
const { version: _, ...rest } = VALID_CONTRACT;
|
||||
const result = validateContract(rest);
|
||||
expect(result.valid).toBe(false);
|
||||
expect(result.missing_fields).toContain('version');
|
||||
});
|
||||
|
||||
it('缺少 constraints.io_model 時驗證失敗', () => {
|
||||
const contract = {
|
||||
...VALID_CONTRACT,
|
||||
constraints: {
|
||||
max_size_kb: 2048,
|
||||
max_cold_start_ms: 50,
|
||||
no_network_syscall: true,
|
||||
// io_model 缺失
|
||||
},
|
||||
};
|
||||
const result = validateContract(contract);
|
||||
expect(result.valid).toBe(false);
|
||||
// io_model 缺失時可能在 missing_fields 或 errors 中
|
||||
const allIssues = [...result.missing_fields, ...result.errors];
|
||||
expect(allIssues.some(f => f.includes('io_model'))).toBe(true);
|
||||
});
|
||||
|
||||
it('gherkin_tests 少於 2 個時驗證失敗', () => {
|
||||
const contract = {
|
||||
...VALID_CONTRACT,
|
||||
gherkin_tests: [
|
||||
{ scenario: 'only one', given: '{}', then_contains: '{}' },
|
||||
],
|
||||
};
|
||||
const result = validateContract(contract);
|
||||
expect(result.valid).toBe(false);
|
||||
});
|
||||
|
||||
it('category 不在允許集合時驗證失敗', () => {
|
||||
const contract = { ...VALID_CONTRACT, category: 'invalid_category' };
|
||||
const result = validateContract(contract);
|
||||
expect(result.valid).toBe(false);
|
||||
});
|
||||
|
||||
it('wasi_target 不是 preview1 時驗證失敗', () => {
|
||||
const contract = { ...VALID_CONTRACT, wasi_target: 'preview2' };
|
||||
const result = validateContract(contract);
|
||||
expect(result.valid).toBe(false);
|
||||
});
|
||||
|
||||
it('version 格式不符時驗證失敗', () => {
|
||||
const contract = { ...VALID_CONTRACT, version: '1.0.0' };
|
||||
const result = validateContract(contract);
|
||||
expect(result.valid).toBe(false);
|
||||
});
|
||||
|
||||
it('canonical_id 含大寫時驗證失敗', () => {
|
||||
const contract = { ...VALID_CONTRACT, canonical_id: 'ValidateJson' };
|
||||
const result = validateContract(contract);
|
||||
expect(result.valid).toBe(false);
|
||||
});
|
||||
|
||||
it('空物件回傳所有必填欄位', () => {
|
||||
const result = validateContract({});
|
||||
expect(result.valid).toBe(false);
|
||||
expect(result.missing_fields.length).toBeGreaterThan(0);
|
||||
});
|
||||
|
||||
it('null 輸入回傳驗證失敗', () => {
|
||||
const result = validateContract(null);
|
||||
expect(result.valid).toBe(false);
|
||||
});
|
||||
});
|
||||
Reference in New Issue
Block a user