Something went wrong. Try again.
This repository has no description
Something went wrong. Try again.
JavaScript
123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418import assert from "node:assert/strict";import { createHash } from "node:crypto";import { test } from "node:test";import { setTimeout as sleep } from "node:timers/promises";import { build } from "esbuild";import { Miniflare, convertV4MiniflareOptions } from "miniflare";import { customerBindings } from "./fixtures/config.mjs";
const name = "private-diagnostic-skill";const version = "7.8.9-private-version";const hash = (value) => createHash("sha256").update(value).digest("hex");const identity = (skill) => ({ source: "installed", name: skill.name, fingerprint: skill.fingerprint, revision: skill.revision,});const packageOf = () => ({ formatVersion: 1, files: [ { path: "SKILL.md", content: `---\nname: ${name}\ndescription: PRIVATE_DESCRIPTION_CANARY\nmetadata:\n version: "${version}"\n---\nPRIVATE_INSTRUCTIONS_CANARY`, }, { path: "references/private.txt", content: "PRIVATE_RESOURCE_CANARY" }, { path: "scripts/run.js", content: 'export default async function(input) { console.log("PRIVATE_STDOUT_CANARY"); console.error("PRIVATE_STDERR_CANARY"); if(input.fail) throw new Error("PRIVATE_SCRIPT_ERROR_CANARY"); return {secret:"PRIVATE_RESULT_CANARY", echoed: input.secret}; }', }, ],});
test( "native Skill failures produce bounded metadata while owner export excludes package, auth and script content", { timeout: 60000 }, async (t) => { let worker; let disposal; const dispose = () => (disposal ??= (async () => { if (!worker) return; let timer; try { await Promise.race([ worker.dispose(), new Promise((_, reject) => { timer = setTimeout( () => reject(new Error("Diagnostic fixture disposal timed out")), 10000, ); }), ]); } finally { clearTimeout(timer); } })()); t.after(dispose); const bundle = await build({ entryPoints: ["tests/fixtures/skill-diagnostics-worker.ts"], alias: { path: "node:path", crypto: "node:crypto", async_hooks: "node:async_hooks", }, target: "es2022", keepNames: true, bundle: true, write: false, format: "esm", platform: "neutral", conditions: ["workerd", "worker", "browser"], mainFields: ["module", "main"], external: ["cloudflare:*", "node:*"], }); t.signal.throwIfAborted(); const sentHeaders = []; worker = new Miniflare( convertV4MiniflareOptions({ modules: true, script: bundle.outputFiles[0].text, compatibilityDate: "2026-09-04", compatibilityFlags: ["nodejs_compat"], durableObjects: { MODEL: { className: "PersonalAgent", useSQLite: true }, }, r2Buckets: ["ATTACHMENTS"], workerLoaders: { LOADER: {} }, bindings: customerBindings, outboundService: (request) => { sentHeaders.push(request.headers.get("X-Private-Header")); return new Response("PRIVATE_UPSTREAM_ERROR_CANARY", { status: 503 }); }, }), ); const request = async (path, body) => { const response = await worker.dispatchFetch( `https://fixture.example${path}`, { method: "POST", headers: { "Content-Type": "application/json", "X-Filename": "PRIVATE_FILENAME_CANARY.json", }, body: JSON.stringify(body), signal: t.signal, }, ); return { status: response.status, body: await response.json() }; }; const call = async (action, value) => (await request("/fixture", { action, value })).body; const exportEvents = async () => (await call("export")).runtime.events; const operation = async (kind, status) => { const events = await exportEvents(); const found = events.find( (event) => event.details.extensionOperation === kind && event.status === status, ); assert.ok(found, `${kind}/${status}: ${JSON.stringify(events)}`); assert.equal(found.phase, "finish"); assert.ok(Number.isFinite(found.durationMs) && found.durationMs >= 0); return found; }; const invalid = await request("/api/skills/review-upload", { formatVersion: 1, files: [ { path: "../PRIVATE_PATH_CANARY", content: "PRIVATE_INSTRUCTIONS_CANARY", }, ], }); assert.equal(invalid.status, 400); assert.equal( (await operation("skill-validation", "error")).details.extensionFailure, "validation", );
let review = await request("/api/skills/review-upload", packageOf()); assert.equal(review.status, 200, JSON.stringify(review)); await call("fault", { put: true }); const failedInstall = await request("/api/skills/install", { reviewId: review.body.reviewId, }); assert.ok(failedInstall.status >= 400, JSON.stringify(failedInstall)); assert.equal( (await operation("skill-install", "error")).details.extensionFailure, "storage", ); await call("fault", { put: false }); review = await request("/api/skills/review-upload", packageOf()); const installed = await request("/api/skills/install", { reviewId: review.body.reviewId, }); assert.equal(installed.status, 201, JSON.stringify(installed)); let skill = (await call("list")).find((skill) => skill.name === name); let id = identity(skill); assert.equal(await call("load", id), null); assert.equal( await call("resource", { skill: id, path: "references/private.txt" }), null, ); for (const kind of ["skill-activation", "skill-resource"]) { const event = await operation(kind, "error"); assert.equal(event.details.extensionFailure, "unavailable"); assert.equal(event.details.capabilitySourceId, hash(`installed:${name}`)); assert.equal(event.details.capabilityVersion, hash(version)); assert.equal( event.details.capabilityFingerprint, hash(skill.fingerprint), ); } assert.equal((await call("toggle", { ...id, enabled: true })).ok, true); skill = (await call("list")).find((skill) => skill.name === name); id = identity(skill); await call("fault", { get: true }); const previousSequence = (await exportEvents())[0].sequence; assert.equal( await call("resource", { skill: id, path: "references/private.txt" }), null, ); assert.ok( (await operation("skill-resource", "error")).sequence > previousSequence, ); assert.equal( (await operation("skill-resource", "error")).details.extensionFailure, "storage", ); assert.equal(await call("load", id), null); assert.equal( (await operation("skill-activation", "error")).details.extensionFailure, "storage", ); assert.equal(await call("load", { invalid: true }), null); const invalidRead = await operation("skill-activation", "error"); assert.equal(invalidRead.details.extensionFailure, "validation"); assert.equal(invalidRead.details.capabilityVersion, null); assert.equal( await call("resource", { skill: id, path: "../private" }), null, ); assert.equal( (await operation("skill-resource", "error")).details.extensionFailure, "validation", ); await call("fault", { get: false }); assert.ok(await call("load", id)); assert.ok( await call("resource", { skill: id, path: "references/private.txt" }), ); await operation("skill-activation", "completed"); await operation("skill-resource", "completed"); const permissions = await request("/api/skills/manage", { action: "permissions", skill: id, }); const set = await request("/api/skills/manage", { action: "set-permissions", skill: id, revision: permissions.body.permissions.revision, choices: { execute: "allow", network: "never", workspaceRead: "never", workspaceWrite: "never", externalCapabilities: "never", }, }); assert.equal(set.status, 200, JSON.stringify(set)); assert.equal( ( await call("policy", { revision: 0, defaultPolicy: "allow", sourceOverrides: [], }) ).ok, true, ); const definition = (await call("definitions")).find( (definition) => definition.skill.name === name, ); assert.ok(definition); const script = async (fail) => call("script", { request: { skill: id, path: definition.path, capability: { source: definition.metadata.source, id: definition.metadata.id, fingerprint: definition.metadata.fingerprint, }, conversationId: "PRIVATE_CONVERSATION_CANARY", toolCallId: crypto.randomUUID(), }, input: { input: { secret: "PRIVATE_INPUT_CANARY", fail }, workspace: [], }, approved: false, }); const success = await script(false); assert.equal(success.result.ok, true, JSON.stringify(success)); assert.match(success.result.stdout, /PRIVATE_STDOUT_CANARY/); assert.equal(success.result.result.secret, "PRIVATE_RESULT_CANARY"); const failure = await script(true); assert.equal(failure.result.ok, false); assert.equal( (await operation("skill-script", "error")).details.extensionFailure, "script", ); const scriptCompleted = await operation("skill-script", "completed"); assert.equal( scriptCompleted.details.capabilitySourceId, hash(`installed:${name}`), ); assert.equal(scriptCompleted.details.capabilityVersion, hash(version)); assert.equal( scriptCompleted.details.capabilityFingerprint, hash(skill.fingerprint), ); const mcp = await call("mcp-add", { name: "PRIVATE_MCP_NAME_CANARY", endpoint: "https://private-mcp.example.com/mcp", authMode: "headers", }); assert.equal(mcp.ok, true); const deadline = Date.now() + 5000; let connection; do { t.signal.throwIfAborted(); connection = (await call("mcp-list"))[0]; if (connection.state === "authenticating") break; await sleep(20, undefined, { signal: t.signal }); } while (Date.now() < deadline); assert.equal(connection.state, "authenticating"); const headers = await call("mcp-headers", { id: connection.id, revision: connection.revision, headers: [ { name: "X-Private-Header", value: "PRIVATE_HEADER_TOKEN_CANARY" }, ], }); assert.equal(headers.ok, true, JSON.stringify(headers)); const headerDeadline = Date.now() + 5000; while (!sentHeaders.includes("PRIVATE_HEADER_TOKEN_CANARY")) { t.signal.throwIfAborted(); assert.ok( Date.now() < headerDeadline, "Configured private header reached native MCP transport", ); await sleep(20, undefined, { signal: t.signal }); } const exported = await call("export"); const serialized = JSON.stringify(exported); for (const canary of [ name, version, "PRIVATE_", "X-Private-Header", "x-private-header", "private-mcp.example.com", skill.fingerprint, ]) assert.equal(serialized.includes(canary), false, canary); assert.ok( exported.runtime.events.some( (event) => event.details.capabilityFingerprint === hash(skill.fingerprint), ), );
const currentHealth = await call("health"); assert.equal(currentHealth.available, true); const historical = currentHealth.events.find( (event) => event.sequence === scriptCompleted.sequence, ); assert.ok(historical, "The real completed script appears in owner health"); assert.equal(historical.sourceId, hash(`installed:${name}`)); assert.equal(historical.sourceName, name); assert.equal(historical.version, version);
const replacementVersion = "8.9.0-private-replacement"; const replacementPackage = packageOf(); replacementPackage.files[0].content = replacementPackage.files[0].content.replace(version, replacementVersion); const replacementReview = await request( "/api/skills/review-upload", replacementPackage, ); assert.equal(replacementReview.status, 200); const replacement = await request("/api/skills/install", { reviewId: replacementReview.body.reviewId, }); assert.equal(replacement.status, 201, JSON.stringify(replacement)); assert.notEqual(replacement.body.fingerprint, skill.fingerprint); assert.equal(replacement.body.name, name); const replacedHealth = await call("health"); const oldAfterReplacement = replacedHealth.events.find( (event) => event.sequence === historical.sequence, ); assert.ok(oldAfterReplacement); assert.equal(oldAfterReplacement.sourceId, historical.sourceId); assert.equal(oldAfterReplacement.sourceName, name); assert.equal( oldAfterReplacement.version, null, "An old package event must not inherit the replacement's version label", ); assert.ok( replacedHealth.events.some( (event) => event.operation === "skill-install" && event.status === "completed" && event.sourceName === name && event.version === replacementVersion, ), );
const removed = await request("/api/skills/manage", { action: "remove", skill: identity(replacement.body), }); assert.equal(removed.status, 200, JSON.stringify(removed)); assert.deepEqual(removed.body, { action: "remove" }); const removedHealth = await call("health"); const oldAfterRemoval = removedHealth.events.find( (event) => event.sequence === historical.sequence, ); assert.ok(oldAfterRemoval); assert.equal(oldAfterRemoval.sourceId, historical.sourceId); assert.equal(oldAfterRemoval.sourceName, null); assert.equal(oldAfterRemoval.version, null); const historicalExport = await call("export"); const oldExport = historicalExport.runtime.events.find( (event) => event.sequence === historical.sequence, ); assert.equal(oldExport.details.capabilitySourceId, historical.sourceId); assert.equal(oldExport.details.capabilityVersion, hash(version)); assert.equal( oldExport.details.capabilityFingerprint, hash(skill.fingerprint), ); const historicalSerialized = JSON.stringify(historicalExport); for (const canary of [ name, version, replacementVersion, "PRIVATE_", replacement.body.fingerprint, ]) assert.equal(historicalSerialized.includes(canary), false, canary); },);