import assert from "node:assert/strict"; import { createHash } from "node:crypto"; import { readFile } from "node:fs/promises"; import { test } from "node:test"; import * as Effect from "effect/Effect"; import { parse } from "jsonc-parser"; import { loadArtifact } from "../control-plane/artifact.ts"; const digest = (bytes) => createHash("sha256").update(new Uint8Array(bytes)).digest("hex"); const encode = (value) => new TextEncoder().encode(value).buffer; const source = parse(await readFile("wrangler.jsonc", "utf8")); function fixture(edit = () => {}) { const deployment = { main: "./worker/index.js", no_bundle: true, assets: { directory: "./assets", binding: "ASSETS" }, ...Object.fromEntries( [ "compatibility_date", "compatibility_flags", "durable_objects", "exports", "containers", "ai", "browser", "worker_loaders", "observability", "keep_vars", ].map((key) => [key, source[key]]), ), }; deployment.ai = { binding: source.ai.binding }; const bytes = { "deployment.json": encode(JSON.stringify(deployment)), "worker/index.js": encode("export default {};"), ...Object.fromEntries( Array.from({ length: 8 }, (_, i) => [ `assets/${i}.html`, encode(`

${i}

`), ]), ), }; const files = Object.entries(bytes).map(([path, value]) => ({ path, size: value.byteLength, sha256: digest(value), mime: path.endsWith(".js") ? "application/javascript" : path.endsWith(".html") ? "text/html" : "application/json", ...(path.startsWith("assets/") ? { assetHash: "a".repeat(32) } : {}), })); edit(files); const manifest = { schemaVersion: 1, kind: "flarebot-customer-runtime", configurationVersion: 1, release: "0.1.0-fixture", sourceRevision: "a".repeat(40), sourceDirty: false, deployment: "deployment.json", shell: { image: source.containers[0].image }, compatibility: { applicationSchema: 1, agentIdentity: "personal/PersonalAgent/Conversation/Sandbox", fromArtifacts: [], }, files, }; bytes["manifest.json"] = encode(JSON.stringify(manifest)); return { entry: { identity: { version: manifest.release, sourceRevision: manifest.sourceRevision, artifactDigest: digest(bytes["manifest.json"]), }, development: false, files, }, bytes, }; } const pathFor = (key) => key.replace(/^releases\/[a-f0-9]{64}\//, ""); test( "artifact loading overlaps four complete reads, bounds concurrency and preserves verified bytes", { timeout: 5000 }, async () => { const { entry, bytes } = fixture(); let release; const gate = new Promise((resolve) => { release = resolve; }); let ready; const firstWave = new Promise((resolve) => { ready = resolve; }); let active = 0; let maximum = 0; const reads = []; const storage = { async get(key) { const path = pathFor(key); reads.push(path); if (path === "manifest.json") return { arrayBuffer: async () => bytes[path] }; active++; maximum = Math.max(maximum, active); if (active === 4) ready(); return { async arrayBuffer() { await gate; active--; return bytes[path]; }, }; }, }; const running = Effect.runPromise(loadArtifact(entry, storage)); let timer; try { await Promise.race([ firstWave, new Promise((_, reject) => { timer = setTimeout( () => reject(new Error("file reads remained serial")), 1000, ); }), ]); assert.equal(active, 4); assert.equal(reads.length, 5, "manifest plus four in-flight files"); } finally { clearTimeout(timer); release(); await running; } const result = await running; assert.equal(maximum, 4); assert.deepEqual(result.bytes, bytes); assert.deepEqual(reads.toSorted(), Object.keys(bytes).toSorted()); }, ); test("every load rejects missing or changed pinned objects, including after a successful load", async () => { for (const path of ["manifest.json", "worker/index.js", "assets/7.html"]) { for (const missing of [false, true]) { const { entry, bytes } = fixture(); const storage = { async get(key) { const value = bytes[pathFor(key)]; return value ? { arrayBuffer: async () => value } : null; }, }; await Effect.runPromise(loadArtifact(entry, storage)); if (missing) delete bytes[path]; else { const changed = new Uint8Array(bytes[path].slice(0)); changed[0] ^= 1; bytes[path] = changed.buffer; } await assert.rejects( Effect.runPromise(loadArtifact(entry, storage)), /artifact_unavailable/, ); } } }); test("invalid inventory and aggregate size fail before any file reads", async () => { for (const edit of [ (files) => { files.push(files[0]); }, (files) => { files[2].path = "assets/../private.html"; }, (files) => { files[1].size = 17 * 1024 * 1024; }, (files) => { files[2].size = 25 * 1024 * 1024; }, (files) => { delete files[2].assetHash; }, ]) { const { entry, bytes } = fixture(edit); const reads = []; await assert.rejects( Effect.runPromise( loadArtifact(entry, { async get(key) { const path = pathFor(key); reads.push(path); return { arrayBuffer: async () => bytes[path] }; }, }), ), /artifact_unavailable/, ); assert.deepEqual(reads, ["manifest.json"]); } });