Repository navigation
feat(task): observation registry with read completeness (U3, #1375) #1912
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
easonLiangWorldedtech
wants to merge
35
commits into
Zoo-Code-Org:main
Choose a base branch
from
easonLiangWorldedtech:fws/u3-observation-completeness
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
Changes from all commits
Commits
Show all changes
35 commits
Select commit
Hold shift + click to select a range
d5f8a79
split unit U1 of PR 1833 (issue 1375)
aa0cdab
fix(file-safety): close the pre-merge findings on the publish primiti…
c4120b0
fix(file-safety): propagate a non-ENOENT lstat failure in resolvePubl…
97b599d
fix(file-safety): keep the rollback pair typed and the mock stand-ins…
435be8b
rebuild unit u2 on the fixed chain
625a976
chore(lint): prune the safeWriteJson suppression this unit earns
4e2de13
rebuild unit u3 on the fixed chain
60376ca
fix(task): declare the observation registry on Task in this unit
58a1f1c
test(task): pin the clock and restore real timers in the observation …
9e40ad3
test(utils): make the rollback-failure test name match what it asserts
1476213
fix(file-safety): inherit U1 committed-guard and exact rmdir assertion
761dec8
fix(file-safety): keep the publish error message in RollbackFailureError
e65efb0
test(file-safety): assert the exact staging directory removed after a…
5bfb81d
test: re-trigger required checks - the queued runs were cancelled by …
0d0ee7d
fix(file-safety): give the Windows DACL dump a per-write name
9c111ce
test(utils): assert the RollbackFailureError message, not only its fi…
d8b34b8
fix(file-safety): keep the target present by backing it up with a dur…
631bfd8
fix(file-safety): remove a partial backup when the backup copy or its…
10d2d97
fix(file-safety): report a failed DACL restore, and cover the primiti…
38f8a59
test(file-safety): drop the duplicated failed-commit case and cover t…
96b6024
fix(file-safety): remove the backup copy after a post-commit failure …
ee17f99
fix(file-safety): make the backup copy writable before fsyncing it
0574ad4
fix(file-safety): create the backup privately before its content exists
1b6ce40
feat(utils): let a caller confine a write to a directory
75fe4a4
fix(file-safety): do not read a failed target lstat as a missing target
ea5b3ce
fix(file-safety): compare staging and target identity with bigint stats
f74cac9
test(file-safety): pin the bigint options in the staging-identity tests
3486dc7
fix(file-safety): report a Windows replacement whose DACL was not pre…
fac2c7e
fix(file-safety): keep DACL warning delivery from failing the save
5f07a25
fix(utils): check confinement before taking the advisory lock
783d1dc
fix(file-safety): handle async warning sinks and confine before mkdir
256091d
fix(mcp): confine project MCP writes to the workspace root
ff6e864
test(utils): pin the fail-closed scope canonicalization in safeWriteJson
dd142c6
fix(file-safety): report a leftover backup copy instead of discarding…
799962b
fix(file-safety): report the exact orphan paths when post-failure cle…
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,120 @@ | ||
| import { describe, it, expect, vi } from "vitest" | ||
|
|
||
| import { ObservationRegistry } from "../observationRegistry" | ||
|
|
||
| describe("ObservationRegistry", () => { | ||
| it("observe → get returns the recorded version and observedAt", () => { | ||
| vi.useFakeTimers() | ||
| try { | ||
| vi.setSystemTime(new Date("2026-01-01T00:00:00.000Z")) | ||
| const reg = new ObservationRegistry() | ||
| reg.observe("/a/b/c.ts", "1:2:300:4000000000:5000000000") | ||
|
|
||
| const obs = reg.get("/a/b/c.ts") | ||
| expect(obs).toBeDefined() | ||
| expect(obs!.version).toBe("1:2:300:4000000000:5000000000") | ||
| // The clock is pinned, so this checks the recorded instant rather than | ||
| // merely that some number is present. | ||
| expect(obs!.observedAt).toBe(Date.parse("2026-01-01T00:00:00.000Z")) | ||
| } finally { | ||
| vi.useRealTimers() | ||
| } | ||
| }) | ||
|
|
||
| it("re-observe replaces the entry with a fresh observedAt", () => { | ||
| vi.useFakeTimers() | ||
| try { | ||
| vi.setSystemTime(new Date("2026-01-01T00:00:00.000Z")) | ||
| const reg = new ObservationRegistry() | ||
| reg.observe("/a/b/c.ts", "v1") | ||
| const first = reg.get("/a/b/c.ts")! | ||
| expect(first.version).toBe("v1") | ||
|
|
||
| vi.advanceTimersByTime(50) | ||
| reg.observe("/a/b/c.ts", "v2") | ||
| const second = reg.get("/a/b/c.ts")! | ||
| expect(second.version).toBe("v2") | ||
| expect(second.observedAt).toBeGreaterThan(first.observedAt) | ||
| } finally { | ||
| // A failed assertion must not leave fake timers for the next test. | ||
| vi.useRealTimers() | ||
| } | ||
| }) | ||
|
easonLiangWorldedtech marked this conversation as resolved.
|
||
|
|
||
| it("has returns true for observed paths, false otherwise", () => { | ||
| const reg = new ObservationRegistry() | ||
| reg.observe("/x.ts", "t1") | ||
| expect(reg.has("/x.ts")).toBe(true) | ||
| expect(reg.has("/y.ts")).toBe(false) | ||
| }) | ||
|
|
||
| it("size reflects the number of observed entries", () => { | ||
| const reg = new ObservationRegistry() | ||
| expect(reg.size).toBe(0) | ||
| reg.observe("/a.ts", "t1") | ||
| reg.observe("/b.ts", "t2") | ||
| expect(reg.size).toBe(2) | ||
| }) | ||
|
|
||
| it("clear removes all entries and resets size to 0", () => { | ||
| const reg = new ObservationRegistry() | ||
| reg.observe("/a.ts", "t1") | ||
| reg.observe("/b.ts", "t2") | ||
| reg.clear() | ||
| expect(reg.size).toBe(0) | ||
| expect(reg.get("/a.ts")).toBeUndefined() | ||
| expect(reg.has("/b.ts")).toBe(false) | ||
| }) | ||
|
|
||
| it("get on empty registry returns undefined", () => { | ||
| const reg = new ObservationRegistry() | ||
| expect(reg.get("/any.ts")).toBeUndefined() | ||
| }) | ||
|
|
||
| it("separate instances are independent — observing in one does not appear in the other", () => { | ||
| const regA = new ObservationRegistry() | ||
| const regB = new ObservationRegistry() | ||
| regA.observe("/shared.ts", "v1") | ||
| expect(regA.get("/shared.ts")).toBeDefined() | ||
| expect(regB.get("/shared.ts")).toBeUndefined() | ||
| regB.observe("/shared.ts", "v2") | ||
| expect(regA.get("/shared.ts")!.version).toBe("v1") | ||
| expect(regB.get("/shared.ts")!.version).toBe("v2") | ||
| }) | ||
|
|
||
| describe("completeness scope (S4b follow-up #46)", () => { | ||
| it("defaults to a complete observation when the read scope is not given", () => { | ||
| const reg = new ObservationRegistry() | ||
| reg.observe("/a/b/c.ts", "v1") | ||
|
|
||
| expect(reg.get("/a/b/c.ts")!.complete).toBe(true) | ||
| }) | ||
|
|
||
| it("records a partial observation when the read only returned a view of the file", () => { | ||
| const reg = new ObservationRegistry() | ||
| reg.observe("/a/b/c.ts", "v1", false) | ||
|
|
||
| expect(reg.get("/a/b/c.ts")!.complete).toBe(false) | ||
| }) | ||
|
|
||
| it("re-observing replaces the entry's completeness with the new read's scope", () => { | ||
| const reg = new ObservationRegistry() | ||
| reg.observe("/a/b/c.ts", "v1", false) | ||
| reg.observe("/a/b/c.ts", "v2") | ||
|
|
||
| const obs = reg.get("/a/b/c.ts")! | ||
| expect(obs.version).toBe("v2") | ||
| expect(obs.complete).toBe(true) | ||
| }) | ||
|
|
||
| it("re-observing with a partial scope downgrades a previously complete entry", () => { | ||
| const reg = new ObservationRegistry() | ||
| reg.observe("/a/b/c.ts", "v1") | ||
| reg.observe("/a/b/c.ts", "v2", false) | ||
|
|
||
| const obs = reg.get("/a/b/c.ts")! | ||
| expect(obs.version).toBe("v2") | ||
| expect(obs.complete).toBe(false) | ||
| }) | ||
| }) | ||
| }) | ||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,59 @@ | ||
| /** | ||
| * Per-task file observation registry (upstream epic #1375, phase A2). | ||
| * | ||
| * Each Task owns its own instance so parent and subtask observations are | ||
| * independent. The S4 guarded-write will compare these versions against the | ||
| * token recomputed pre-write to detect stale reads or file replacement. | ||
| * | ||
| * Pure in-memory — zero I/O, no dependencies. The S4 guarded-write consults | ||
| * these observations for the version check and for the completeness check that | ||
| * gates a full-file replacement. | ||
| */ | ||
|
|
||
| export interface FileObservation { | ||
| /** Version token derived from on-disk fs.stat (bigint mode). */ | ||
| version: string | ||
| /** Millisecond timestamp when the observation was recorded. */ | ||
| observedAt: number | ||
| /** | ||
| * Whether the read that produced this observation returned the complete | ||
| * file. A slice, line-range, truncated, or indentation-block read returns | ||
| * only a view of the file; such an observation authorizes targeted edits | ||
| * on the view the model saw, but never a full-file replacement. | ||
| */ | ||
| complete: boolean | ||
| } | ||
|
|
||
| export class ObservationRegistry { | ||
| private readonly entries = new Map<string, FileObservation>() | ||
|
|
||
| /** | ||
| * Record an observation for a file at its absolute path. | ||
| * | ||
| * Re-observing replaces the entry with a fresh observedAt timestamp, the | ||
| * new version token, and the read's completeness. `complete` defaults to | ||
| * true for callers that read the whole file themselves (spec doubles, | ||
| * WriteToFileTool). A caller whose read is internal to a targeted edit must | ||
| * carry the model's prior completeness instead, so the tool's own read cannot | ||
| * upgrade a partial read into authority for a full-file replacement. | ||
| */ | ||
| observe(absolutePath: string, version: string, complete: boolean = true): void { | ||
| this.entries.set(absolutePath, { version, observedAt: Date.now(), complete }) | ||
| } | ||
|
|
||
| get(absolutePath: string): FileObservation | undefined { | ||
| return this.entries.get(absolutePath) | ||
| } | ||
|
|
||
| has(absolutePath: string): boolean { | ||
| return this.entries.has(absolutePath) | ||
| } | ||
|
|
||
| clear(): void { | ||
| this.entries.clear() | ||
| } | ||
|
|
||
| get size(): number { | ||
| return this.entries.size | ||
| } | ||
| } |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
68 changes: 68 additions & 0 deletions
68
src/services/file-safety/__tests__/safeWriteText.integration.spec.ts
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,68 @@ | ||
| import * as fs from "fs/promises" | ||
| import * as os from "os" | ||
| import * as path from "path" | ||
|
|
||
| import { safeWriteText } from "../safeWriteText" | ||
|
|
||
| // No fs mocks in this file: the point is to assert what a real filesystem ends up | ||
| // holding after a publish attempt, which the mocked spec cannot show. The failure is | ||
| // provoked with real filesystem semantics rather than with a stubbed call. | ||
| describe("safeWriteText against a real filesystem", () => { | ||
| let dir: string | ||
|
|
||
| beforeEach(async () => { | ||
| dir = await fs.mkdtemp(path.join(os.tmpdir(), "safe-write-text-int-")) | ||
| }) | ||
|
|
||
| afterEach(async () => { | ||
| await fs.rm(dir, { recursive: true, force: true }) | ||
| }) | ||
|
|
||
| it("publishes the new bytes and leaves no staging or backup residue", async () => { | ||
| const targetPath = path.join(dir, "target.txt") | ||
| await fs.writeFile(targetPath, "old bytes") | ||
|
|
||
| // No platform override: the real platform's own durability and ACL steps run. | ||
| // A failed icacls restore in a throwaway temp directory is reported, not thrown, | ||
| // so the publish still lands. | ||
| await safeWriteText(targetPath, "new bytes", { backup: true }) | ||
|
|
||
| expect(await fs.readFile(targetPath, "utf8")).toBe("new bytes") | ||
| expect(await fs.readdir(dir)).toEqual(["target.txt"]) | ||
| }) | ||
|
|
||
| it("leaves the target bytes untouched when the backup copy of a directory target fails", async () => { | ||
| // A directory target makes the backup COPY fail first (a directory cannot be | ||
| // copied), so this covers the backup step, not the commit rename: the inner | ||
| // catch unlinks the partial backup and rethrows before the rename runs. | ||
| const targetPath = path.join(dir, "target-dir") | ||
| await fs.mkdir(targetPath) | ||
| const inside = path.join(targetPath, "payload.txt") | ||
| await fs.writeFile(inside, "original bytes") | ||
|
|
||
| await expect(safeWriteText(targetPath, "new data", { backup: true })).rejects.toThrow() | ||
|
|
||
| // The directory and its content are exactly as they were, and no backup copy | ||
| // or staging directory was left behind next to them. | ||
| expect(await fs.readFile(inside, "utf8")).toBe("original bytes") | ||
| expect(await fs.readdir(dir)).toEqual(["target-dir"]) | ||
| }) | ||
|
|
||
| it("leaves the target untouched when the commit rename itself cannot replace it", async () => { | ||
| // backup:false makes the commit rename the first operation that touches the | ||
| // target: a regular file cannot be renamed over a directory, so the failure | ||
| // under test is the commit, and the cleanup is the temp unlink plus the | ||
| // staging-directory removal. | ||
| const targetPath = path.join(dir, "target-dir") | ||
| await fs.mkdir(targetPath) | ||
| const inside = path.join(targetPath, "payload.txt") | ||
| await fs.writeFile(inside, "original bytes") | ||
|
|
||
| await expect(safeWriteText(targetPath, "new data", { backup: false })).rejects.toThrow() | ||
|
|
||
| // The directory and its content are exactly as they were, and neither the | ||
| // staged temp nor the staging directory was left behind. | ||
| expect(await fs.readFile(inside, "utf8")).toBe("original bytes") | ||
| expect(await fs.readdir(dir)).toEqual(["target-dir"]) | ||
| }) | ||
| }) |
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.