Compare commits
36
Commits
master
..
bf7171924d
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
bf7171924d | ||
|
|
097c363fbc | ||
|
|
7dd8809e38 | ||
|
|
1749757036 | ||
|
|
5857e6121c | ||
|
|
a41147916b | ||
|
|
cabe38db1d | ||
|
|
f079479160 | ||
|
|
87e160a01a | ||
|
|
f94d829bf8 | ||
|
|
9a05bfa0c3 | ||
|
|
c1d46859a3 | ||
|
|
87ecbcb113 | ||
|
|
1fb2949561 | ||
|
|
11be777fc0 | ||
|
|
ff94161fc0 | ||
|
|
c2ab9a950f | ||
|
|
8e26a0f5a8 | ||
|
|
d1c15ee295 | ||
|
|
00a96234c6 | ||
|
|
fc3b663510 | ||
|
|
e4e045d059 | ||
|
|
436feaf33d | ||
|
|
29f450b962 | ||
|
|
db343893c8 | ||
|
|
554906ec02 | ||
|
|
18c37f4842 | ||
|
|
83382b824a | ||
|
|
6203316aa1 | ||
|
|
d57b4d1d5e | ||
|
|
379ae214fc | ||
|
|
163a403636 | ||
|
|
53edaadc3a | ||
|
|
3c2664c3ce | ||
|
|
d9048954a5 | ||
|
|
4f84dfd73f |
Generated
+2
@@ -6131,9 +6131,11 @@ dependencies = [
|
||||
"tokio-tungstenite 0.29.0",
|
||||
"toml",
|
||||
"tower",
|
||||
"url",
|
||||
"uuid",
|
||||
"workdir",
|
||||
"worker",
|
||||
"workspace-api",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
use serde::{Deserialize, Serialize};
|
||||
use std::fmt;
|
||||
use workspace_api::{RepositoryObservedStatus, RepositorySource};
|
||||
|
||||
const DEFAULT_WORKSPACE_LIMIT: usize = 200;
|
||||
|
||||
@@ -44,8 +45,13 @@ pub struct CreateBackendWorkspaceRepositoryRecord {
|
||||
pub repository_id: String,
|
||||
pub name: String,
|
||||
pub kind: String,
|
||||
pub uri: String,
|
||||
pub provider: Option<String>,
|
||||
pub source: RepositorySource,
|
||||
pub default_ref: Option<String>,
|
||||
pub source_revision: u64,
|
||||
pub source_fingerprint: String,
|
||||
pub observed_status: RepositoryObservedStatus,
|
||||
pub observed_at: Option<String>,
|
||||
}
|
||||
|
||||
#[derive(Debug, Clone, PartialEq, Eq)]
|
||||
|
||||
@@ -473,8 +473,12 @@ impl TicketBackend for BackendWorkspaceProductClient {
|
||||
.map_err(ticket_client_error)
|
||||
}
|
||||
|
||||
fn queue_ready(&self, id: TicketIdOrSlug, _queued_by: &str) -> ticket::Result<()> {
|
||||
self.send_unit::<()>(
|
||||
fn queue_ready(
|
||||
&self,
|
||||
id: TicketIdOrSlug,
|
||||
_queued_by: &str,
|
||||
) -> ticket::Result<ticket::TicketQueueOutcome> {
|
||||
self.send_json::<(), _>(
|
||||
Method::POST,
|
||||
&format!(
|
||||
"/tickets/{}/workflow/queue",
|
||||
|
||||
+1103
-198
File diff suppressed because it is too large
Load Diff
@@ -142,8 +142,8 @@ const INTAKE_READY_DESCRIPTION: &str = "Record a bounded intake summary and mark
|
||||
The backend applies the same target validation and lock as TicketMarkReady and commits the summary, \
|
||||
state_changed event, effective target, and planning -> ready transition atomically.";
|
||||
const QUEUE_DESCRIPTION: &str = "Queue a ready Ticket for Orchestrator routing through the typed \
|
||||
Ticket backend. The backend performs the gated ready -> queued transition, records queued_by/queued_at, \
|
||||
and rejects unresolved blocking relations.";
|
||||
Ticket backend. The backend rejects transitive planning dependencies and cycles, atomically queues the \
|
||||
requested Ticket plus every transitive ready dependency, and leaves queued or in-progress dependencies unchanged.";
|
||||
const WORKFLOW_STATE_DESCRIPTION: &str = "Transition Ticket `state` through the typed \
|
||||
Ticket backend with a bounded `state_changed` event. Treat `queued -> inprogress` \
|
||||
as the implementation acceptance step: implementation side effects should happen only after that \
|
||||
@@ -316,7 +316,11 @@ impl TicketBackend for TicketToolBackend {
|
||||
self.backend.mark_ready(id, request)
|
||||
}
|
||||
|
||||
fn queue_ready(&self, id: TicketIdOrSlug, queued_by: &str) -> TicketResult<()> {
|
||||
fn queue_ready(
|
||||
&self,
|
||||
id: TicketIdOrSlug,
|
||||
queued_by: &str,
|
||||
) -> TicketResult<crate::TicketQueueOutcome> {
|
||||
self.backend.queue_ready(id, queued_by)
|
||||
}
|
||||
|
||||
@@ -1219,12 +1223,22 @@ impl Tool for TicketQueueTool {
|
||||
) -> Result<ToolOutput, ToolError> {
|
||||
let params: TicketQueueParams = parse_input("TicketQueue", input_json)?;
|
||||
let queued_by = default_author();
|
||||
self.backend
|
||||
let outcome = self
|
||||
.backend
|
||||
.queue_ready(TicketIdOrSlug::Query(params.ticket.clone()), &queued_by)
|
||||
.map_err(|error| backend_error("TicketQueue", error))?;
|
||||
Ok(json_output(
|
||||
format!("Queued ticket {} for Orchestrator", params.ticket),
|
||||
json!({ "ticket": params.ticket, "state": "queued", "queued_by": queued_by, "ok": true }),
|
||||
format!(
|
||||
"Queued {} ticket(s) for Orchestrator",
|
||||
outcome.queued_tickets.len()
|
||||
),
|
||||
json!({
|
||||
"ticket": outcome.requested_ticket,
|
||||
"queued_tickets": outcome.queued_tickets,
|
||||
"state": "queued",
|
||||
"queued_by": queued_by,
|
||||
"ok": true
|
||||
}),
|
||||
))
|
||||
}
|
||||
}
|
||||
|
||||
+127
-31
@@ -4,6 +4,7 @@ use std::fmt;
|
||||
use std::io;
|
||||
use std::path::{Path, PathBuf};
|
||||
use std::process::Command;
|
||||
use std::sync::Arc;
|
||||
use std::time::{Duration, Instant, SystemTime, UNIX_EPOCH};
|
||||
|
||||
use client::ticket_role::{
|
||||
@@ -4125,7 +4126,10 @@ async fn dispatch_ticket_action(
|
||||
let config = TicketConfig::load_workspace(&request.workspace_root)
|
||||
.map_err(|error| TicketActionError::BackendConfig(error.to_string()))?;
|
||||
let backend = LocalTicketBackend::new(config.backend_root())
|
||||
.with_record_language(config.ticket_record_language());
|
||||
.with_record_language(config.ticket_record_language())
|
||||
.with_target_authority(Arc::new(DashboardTicketTargetAuthority {
|
||||
workspace_root: request.workspace_root.clone(),
|
||||
}));
|
||||
if request.action == NextUserAction::Close {
|
||||
return dispatch_panel_close(&backend, &request.ticket_id);
|
||||
}
|
||||
@@ -4201,17 +4205,32 @@ async fn dispatch_panel_queue(
|
||||
"root-ticket-state-after-orchestration-merge",
|
||||
&preflight.root_top_level,
|
||||
)?;
|
||||
backend
|
||||
let queue_outcome = backend
|
||||
.queue_ready(TicketIdOrSlug::Id(ticket_id.to_owned()), "workspace-panel")
|
||||
.map_err(|error| TicketActionError::Ticket(error.to_string()))?;
|
||||
let expected_queue_tickets = preflight
|
||||
.queue_tickets
|
||||
.iter()
|
||||
.cloned()
|
||||
.collect::<std::collections::BTreeSet<_>>();
|
||||
let actual_queue_tickets = queue_outcome
|
||||
.queued_tickets
|
||||
.iter()
|
||||
.cloned()
|
||||
.collect::<std::collections::BTreeSet<_>>();
|
||||
if actual_queue_tickets != expected_queue_tickets {
|
||||
return Err(TicketActionError::Stale(format!(
|
||||
"Queue dependency plan changed after confirmation for Ticket {ticket_id}; reload and retry"
|
||||
)));
|
||||
}
|
||||
let commit = commit_panel_queue_ticket_record(&preflight)?;
|
||||
let sync = sync_panel_queue_to_orchestration(&preflight, &commit)?;
|
||||
verify_panel_queue_synced(&preflight, &commit)?;
|
||||
let notification = notify_workspace_orchestrator(orchestrator, current_ticket).await;
|
||||
Ok(TicketActionOutcome {
|
||||
notice: format!(
|
||||
"Queued Ticket {}; root Queue commit {}; {}; orchestration sync {}; {}. Orchestrator routing is authorized; implementation side effects still require queued -> inprogress acceptance.",
|
||||
ticket_id,
|
||||
"Queued Ticket closure [{}]; root Queue commit {}; {}; orchestration sync {}; {}. Orchestrator routing is authorized; implementation side effects still require queued -> inprogress acceptance.",
|
||||
queue_outcome.queued_tickets.join(", "),
|
||||
commit.sha,
|
||||
root_merge.sentence(),
|
||||
sync.sentence(),
|
||||
@@ -4220,12 +4239,52 @@ async fn dispatch_panel_queue(
|
||||
})
|
||||
}
|
||||
|
||||
struct DashboardTicketTargetAuthority {
|
||||
workspace_root: PathBuf,
|
||||
}
|
||||
|
||||
impl ticket::TicketTargetAuthority for DashboardTicketTargetAuthority {
|
||||
fn resolve_target(
|
||||
&self,
|
||||
_workspace_id: &str,
|
||||
repository_id: Option<&str>,
|
||||
ref_selector: Option<&str>,
|
||||
) -> ticket::Result<ticket::ResolvedTicketTarget> {
|
||||
let repository_id = repository_id.unwrap_or("main");
|
||||
if repository_id != "main" {
|
||||
return Err(ticket::TicketError::UnknownTargetRepository(
|
||||
repository_id.to_string(),
|
||||
));
|
||||
}
|
||||
let ref_selector = ref_selector.unwrap_or("HEAD");
|
||||
git_capture(
|
||||
&self.workspace_root,
|
||||
&[
|
||||
"rev-parse",
|
||||
"--verify",
|
||||
&format!("{ref_selector}^{{commit}}"),
|
||||
],
|
||||
"resolve Queue Ticket target",
|
||||
)
|
||||
.map_err(|reason| ticket::TicketError::InvalidTargetSelector {
|
||||
repository_id: repository_id.to_string(),
|
||||
selector: ref_selector.to_string(),
|
||||
reason,
|
||||
})?;
|
||||
Ok(ticket::ResolvedTicketTarget {
|
||||
repository_id: repository_id.to_string(),
|
||||
ref_selector: ref_selector.to_string(),
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
#[derive(Debug, Clone, PartialEq, Eq)]
|
||||
struct PanelQueueHandoffPreflight {
|
||||
ticket_id: String,
|
||||
root_top_level: PathBuf,
|
||||
orchestration: OrchestrationWorktreeLayout,
|
||||
ticket_record_dir: PathBuf,
|
||||
queue_tickets: Vec<String>,
|
||||
ticket_record_dirs: Vec<PathBuf>,
|
||||
}
|
||||
|
||||
#[derive(Debug, Clone, PartialEq, Eq)]
|
||||
@@ -4393,27 +4452,53 @@ fn prepare_panel_queue_handoff(
|
||||
&root_top_level,
|
||||
)?;
|
||||
|
||||
let ticket_record_dir = backend.root().join(ticket_id);
|
||||
let dependency_check = backend
|
||||
.dependency_check(TicketIdOrSlug::Id(ticket_id.to_owned()))
|
||||
.map_err(|error| TicketActionError::Ticket(error.to_string()))?;
|
||||
if !dependency_check.queue_guard.can_queue_for_orchestrator {
|
||||
return Err(queue_check_failed(
|
||||
"dependency-queue-plan",
|
||||
ticket_id,
|
||||
&root_top_level,
|
||||
dependency_check
|
||||
.queue_guard
|
||||
.blocked_reason
|
||||
.or(dependency_check.queue_guard.reason)
|
||||
.unwrap_or_else(|| "Queue dependency validation failed".to_string()),
|
||||
));
|
||||
}
|
||||
let queue_tickets = dependency_check.queue_tickets;
|
||||
let mut ticket_record_dirs = Vec::with_capacity(queue_tickets.len());
|
||||
for queue_ticket in &queue_tickets {
|
||||
let ticket_record_dir = backend.root().join(queue_ticket);
|
||||
if !ticket_record_dir.join("item.md").is_file() {
|
||||
return Err(queue_check_failed(
|
||||
"target-ticket-record",
|
||||
ticket_id,
|
||||
&queue_ticket,
|
||||
&ticket_record_dir,
|
||||
"target Ticket item.md is missing".to_string(),
|
||||
"Queue Ticket item.md is missing".to_string(),
|
||||
));
|
||||
}
|
||||
let clean_stage = if queue_ticket == ticket_id {
|
||||
"root-ticket-clean"
|
||||
} else {
|
||||
"queue-dependency-clean"
|
||||
};
|
||||
ensure_git_path_clean(
|
||||
"root-ticket-clean",
|
||||
ticket_id,
|
||||
clean_stage,
|
||||
&queue_ticket,
|
||||
&root_top_level,
|
||||
&ticket_record_dir,
|
||||
)?;
|
||||
ticket_record_dirs.push(ticket_record_dir);
|
||||
}
|
||||
|
||||
Ok(PanelQueueHandoffPreflight {
|
||||
ticket_id: ticket_id.to_string(),
|
||||
root_top_level,
|
||||
orchestration,
|
||||
ticket_record_dir,
|
||||
queue_tickets,
|
||||
ticket_record_dirs,
|
||||
})
|
||||
}
|
||||
|
||||
@@ -4504,37 +4589,36 @@ fn sync_orchestration_to_root_before_queue(
|
||||
fn commit_panel_queue_ticket_record(
|
||||
preflight: &PanelQueueHandoffPreflight,
|
||||
) -> Result<PanelQueueCommit, TicketActionError> {
|
||||
let ticket_rel = path_relative_to_root(
|
||||
let ticket_rels = preflight
|
||||
.ticket_record_dirs
|
||||
.iter()
|
||||
.map(|ticket_record_dir| {
|
||||
path_relative_to_root(
|
||||
&preflight.root_top_level,
|
||||
&preflight.ticket_record_dir,
|
||||
ticket_record_dir,
|
||||
"target-ticket-record",
|
||||
&preflight.ticket_id,
|
||||
)?;
|
||||
)
|
||||
})
|
||||
.collect::<Result<Vec<_>, _>>()?;
|
||||
let mut add = Command::new("git");
|
||||
add.arg("-C")
|
||||
.arg(&preflight.root_top_level)
|
||||
.arg("add")
|
||||
.arg("--")
|
||||
.arg(&ticket_rel);
|
||||
run_git_command(add, "stage Queue Ticket record").map_err(|message| {
|
||||
.args(&ticket_rels);
|
||||
run_git_command(add, "stage Queue Ticket records").map_err(|message| {
|
||||
queue_check_failed(
|
||||
"queue-commit-stage",
|
||||
&preflight.ticket_id,
|
||||
&preflight.ticket_record_dir,
|
||||
&preflight.root_top_level,
|
||||
message,
|
||||
)
|
||||
})?;
|
||||
|
||||
let ticket_rel_string = git_path_string(&ticket_rel);
|
||||
let staged = git_capture(
|
||||
&preflight.root_top_level,
|
||||
&[
|
||||
"diff",
|
||||
"--cached",
|
||||
"--name-only",
|
||||
"--",
|
||||
ticket_rel_string.as_str(),
|
||||
],
|
||||
&["diff", "--cached", "--name-only"],
|
||||
"list staged Queue Ticket files",
|
||||
)
|
||||
.map_err(|message| {
|
||||
@@ -4545,19 +4629,31 @@ fn commit_panel_queue_ticket_record(
|
||||
message,
|
||||
)
|
||||
})?;
|
||||
let allowed = ticket_rels
|
||||
.iter()
|
||||
.map(|path| format!("{}/", git_path_string(path).trim_end_matches('/')))
|
||||
.collect::<Vec<_>>();
|
||||
let staged_paths = staged
|
||||
.lines()
|
||||
.filter(|line| !line.trim().is_empty())
|
||||
.collect::<Vec<_>>();
|
||||
if staged_paths.is_empty() {
|
||||
if staged_paths.is_empty()
|
||||
|| staged_paths
|
||||
.iter()
|
||||
.any(|path| !allowed.iter().any(|root| path.starts_with(root)))
|
||||
{
|
||||
return Err(queue_check_failed(
|
||||
"queue-commit-pathscope",
|
||||
&preflight.ticket_id,
|
||||
&preflight.ticket_record_dir,
|
||||
"Queue mutation produced no staged Ticket record changes".to_string(),
|
||||
&preflight.root_top_level,
|
||||
"Queue mutation staged no Ticket records or included files outside the confirmed dependency closure"
|
||||
.to_string(),
|
||||
));
|
||||
}
|
||||
let message = format!("ticket: queue {}", preflight.ticket_id);
|
||||
let message = format!(
|
||||
"chore: queue Ticket dependency closure {}",
|
||||
preflight.ticket_id
|
||||
);
|
||||
let mut commit = Command::new("git");
|
||||
commit
|
||||
.arg("-C")
|
||||
@@ -4567,8 +4663,8 @@ fn commit_panel_queue_ticket_record(
|
||||
.arg("-m")
|
||||
.arg(message)
|
||||
.arg("--")
|
||||
.arg(&ticket_rel);
|
||||
run_git_command(commit, "commit Queue Ticket record").map_err(|message| {
|
||||
.args(&ticket_rels);
|
||||
run_git_command(commit, "commit Queue Ticket records").map_err(|message| {
|
||||
queue_check_failed(
|
||||
"queue-commit-create",
|
||||
&preflight.ticket_id,
|
||||
|
||||
@@ -462,7 +462,7 @@ pub(super) fn panel_ticket_detail(row: &PanelRow) -> String {
|
||||
.as_ref()
|
||||
.and_then(|ticket| ticket.blocked_reason.as_deref())
|
||||
{
|
||||
parts.push(format!("Gate: waiting for {blocked_reason}"));
|
||||
parts.push(format!("Dependencies: {blocked_reason}"));
|
||||
} else {
|
||||
parts.push("Gate: clear".to_string());
|
||||
}
|
||||
|
||||
@@ -1846,24 +1846,23 @@ fn panel_orchestration_overlay_uses_compact_status_column_and_detail_line() {
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn ready_ticket_with_waiting_gate_shows_queue_disabled_reason() {
|
||||
fn ready_ticket_with_dependency_context_keeps_queue_action_available() {
|
||||
let mut row = panel_test_ticket_row(
|
||||
"00001WAITING",
|
||||
"Ready but gated",
|
||||
ActionPriority::Background,
|
||||
NextUserAction::Wait,
|
||||
"Ready with dependency context",
|
||||
ActionPriority::ReadyForQueue,
|
||||
NextUserAction::Queue,
|
||||
"ready",
|
||||
);
|
||||
row.disabled_reason = Some("Queue disabled: waiting for BLOCKER-1".to_string());
|
||||
row.ticket.as_mut().unwrap().blocked_reason = Some("BLOCKER-1 via depends_on".to_string());
|
||||
|
||||
let lines = panel_row_lines(&row, true, 160);
|
||||
let detail = &lines[1];
|
||||
let detail_line = plain_line(&detail);
|
||||
|
||||
assert!(detail_line.contains("Gate: waiting for BLOCKER-1 via depends_on"));
|
||||
assert!(detail_line.contains("Action: queue disabled"));
|
||||
assert!(detail_line.contains("Reason: Queue disabled: waiting for BLOCKER-1"));
|
||||
assert!(detail_line.contains("Dependencies: BLOCKER-1 via depends_on"));
|
||||
assert!(detail_line.contains("Action: Queue"));
|
||||
assert!(!detail_line.contains("Queue disabled"));
|
||||
}
|
||||
|
||||
#[test]
|
||||
|
||||
@@ -2203,7 +2203,7 @@ mod tests {
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn workspace_panel_marks_ready_ticket_with_unresolved_relation_waiting_gate() {
|
||||
fn workspace_panel_blocks_ready_ticket_with_planning_relation() {
|
||||
let temp = TempDir::new().unwrap();
|
||||
write_ticket_config(temp.path());
|
||||
let backend = LocalTicketBackend::new(temp.path().join(".yoi/tickets"));
|
||||
@@ -2235,12 +2235,7 @@ mod tests {
|
||||
assert_eq!(row.kind, PanelRowKind::Ticket);
|
||||
assert_eq!(row.next_action, Some(NextUserAction::Wait));
|
||||
assert_eq!(row.priority, ActionPriority::Background);
|
||||
assert!(
|
||||
row.disabled_reason
|
||||
.as_deref()
|
||||
.unwrap()
|
||||
.contains("Queue disabled: waiting for")
|
||||
);
|
||||
assert!(row.disabled_reason.is_some());
|
||||
assert!(
|
||||
row.ticket
|
||||
.as_ref()
|
||||
@@ -2253,7 +2248,7 @@ mod tests {
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn workspace_panel_allows_ready_ticket_when_relation_prerequisite_is_queued() {
|
||||
fn workspace_panel_queues_ready_ticket_when_relation_prerequisite_is_queued() {
|
||||
let temp = TempDir::new().unwrap();
|
||||
write_ticket_config(temp.path());
|
||||
let backend = LocalTicketBackend::new(temp.path().join(".yoi/tickets"));
|
||||
@@ -2286,13 +2281,16 @@ mod tests {
|
||||
assert_eq!(row.next_action, Some(NextUserAction::Queue));
|
||||
assert_eq!(row.priority, ActionPriority::ReadyForQueue);
|
||||
assert!(row.disabled_reason.is_none());
|
||||
assert!(row.ticket.as_ref().unwrap().blocked_reason.is_none());
|
||||
assert!(
|
||||
row.key_hint
|
||||
.as_deref()
|
||||
row.ticket
|
||||
.as_ref()
|
||||
.unwrap()
|
||||
.contains("Queue allowed: prerequisites are already queued/in progress")
|
||||
.blocked_reason
|
||||
.as_deref()
|
||||
.unwrap_or_default()
|
||||
.contains(&dependency.id)
|
||||
);
|
||||
assert!(row.key_hint.as_deref().unwrap().contains("Queue targets:"));
|
||||
assert!(row.key_hint.as_deref().unwrap().contains(&dependency.id));
|
||||
}
|
||||
|
||||
|
||||
@@ -311,7 +311,10 @@ impl DelegatingWorkdirSession {
|
||||
if !self.capabilities.supports(WorkdirSessionCapability::Read)
|
||||
|| (writable
|
||||
&& (!self.capabilities.supports(WorkdirSessionCapability::Write)
|
||||
|| !self.capabilities.supports(WorkdirSessionCapability::Edit)))
|
||||
|| !self.capabilities.supports(WorkdirSessionCapability::Edit)
|
||||
|| !self
|
||||
.capabilities
|
||||
.supports(WorkdirSessionCapability::Command)))
|
||||
{
|
||||
return Err(WorkdirError::Denied(
|
||||
"parent workdir session cannot delegate the requested capabilities".into(),
|
||||
@@ -342,6 +345,7 @@ impl DelegatingWorkdirSession {
|
||||
if writable {
|
||||
delegated.push(WorkdirSessionCapability::Write);
|
||||
delegated.push(WorkdirSessionCapability::Edit);
|
||||
delegated.push(WorkdirSessionCapability::Command);
|
||||
}
|
||||
Ok(WorkdirSessionCapabilities::from_capabilities(delegated))
|
||||
}
|
||||
@@ -929,6 +933,43 @@ mod tests {
|
||||
.delegate(request("leased", WorkdirDelegationPermission::Write))
|
||||
.await
|
||||
.unwrap();
|
||||
assert!(
|
||||
child
|
||||
.capabilities
|
||||
.supports(WorkdirSessionCapability::Command)
|
||||
);
|
||||
let command = child
|
||||
.scoped_session
|
||||
.start_command(CommandRequest {
|
||||
command: "printf child-command".into(),
|
||||
timeout_secs: 5,
|
||||
output_limit: 1024,
|
||||
tool_call_id: Some("delegated-child-command".into()),
|
||||
})
|
||||
.await
|
||||
.unwrap();
|
||||
let command_output = child
|
||||
.scoped_session
|
||||
.command_output(CommandOutputRequest {
|
||||
handle: command,
|
||||
cursor: 0,
|
||||
limit: 1024,
|
||||
wait: true,
|
||||
})
|
||||
.await
|
||||
.unwrap();
|
||||
assert_eq!(command_output.content, "child-command");
|
||||
assert!(
|
||||
parent
|
||||
.start_command(CommandRequest {
|
||||
command: "printf parent-command".into(),
|
||||
timeout_secs: 5,
|
||||
output_limit: 1024,
|
||||
tool_call_id: Some("blocked-parent-command".into()),
|
||||
})
|
||||
.await
|
||||
.is_err()
|
||||
);
|
||||
|
||||
assert!(matches!(
|
||||
parent.write(write("leased/file", "parent")).await,
|
||||
|
||||
@@ -211,6 +211,7 @@ pub struct WorkingDirectoryListResponse {
|
||||
#[serde(deny_unknown_fields)]
|
||||
pub struct WorkingDirectoryDetailResponse {
|
||||
pub workspace_id: String,
|
||||
pub runtime_id: String,
|
||||
pub item: WorkingDirectorySummary,
|
||||
pub diagnostics: Vec<WorkingDirectoryDiagnostic>,
|
||||
}
|
||||
@@ -306,6 +307,7 @@ mod tests {
|
||||
|
||||
let detail = WorkingDirectoryDetailResponse {
|
||||
workspace_id: decoded.workspace_id.clone(),
|
||||
runtime_id: "arcadia".to_string(),
|
||||
item: decoded.items[0].clone(),
|
||||
diagnostics: decoded.diagnostics.clone(),
|
||||
};
|
||||
|
||||
@@ -41,9 +41,11 @@ tar.workspace = true
|
||||
thiserror = { workspace = true }
|
||||
tokio = { workspace = true, features = ["net", "rt", "sync", "time"] }
|
||||
toml.workspace = true
|
||||
url.workspace = true
|
||||
uuid = { workspace = true, features = ["v7"] }
|
||||
tower = { workspace = true, features = ["util"], optional = true }
|
||||
worker.workspace = true
|
||||
workspace-api = { path = "../workspace-api" }
|
||||
workdir.workspace = true
|
||||
|
||||
[dev-dependencies]
|
||||
|
||||
@@ -3,6 +3,7 @@ use base64::engine::general_purpose::URL_SAFE_NO_PAD;
|
||||
use ring::rand::{SecureRandom, SystemRandom};
|
||||
use ring::signature::{ED25519, Ed25519KeyPair, KeyPair, UnparsedPublicKey};
|
||||
use serde::{Deserialize, Serialize};
|
||||
use sha2::{Digest, Sha256};
|
||||
use std::fmt;
|
||||
use std::time::{SystemTime, UNIX_EPOCH};
|
||||
|
||||
@@ -14,6 +15,11 @@ pub const WORKER_MUTATION_SOURCE_PROOF_HEADER: &str = "x-yoi-worker-mutation-pro
|
||||
const WORKER_MUTATION_SOURCE_PROOF_PREFIX: &str = "yoi-worker-source-v1";
|
||||
const WORKER_MUTATION_SOURCE_SIGNING_INPUT_PREFIX: &str = "yoi-worker-source-v1.";
|
||||
pub const WORKER_REMOVE_PERMISSION: &str = "workspace:worker-remove";
|
||||
pub const RUNTIME_REQUEST_SOURCE_PROOF_HEADER: &str = "x-yoi-runtime-request-proof";
|
||||
pub const WORKSPACE_REQUEST_PERMISSION: &str = "workspace:request";
|
||||
pub const BACKEND_RESOURCE_FETCH_PERMISSION: &str = "workspace:resource-fetch";
|
||||
const RUNTIME_REQUEST_SOURCE_PROOF_PREFIX: &str = "yoi-runtime-request-v1";
|
||||
const RUNTIME_REQUEST_SOURCE_SIGNING_INPUT_PREFIX: &str = "yoi-runtime-request-v1.";
|
||||
|
||||
#[derive(Debug, thiserror::Error)]
|
||||
pub enum RuntimeAuthError {
|
||||
@@ -33,6 +39,10 @@ pub enum RuntimeAuthError {
|
||||
InvalidTokenFormat,
|
||||
#[error("malformed capability token claims: {0}")]
|
||||
MalformedClaims(#[from] serde_json::Error),
|
||||
#[error("runtime request proof contains an invalid `{0}` claim")]
|
||||
InvalidClaim(&'static str),
|
||||
#[error("runtime request proof does not match the HTTP request")]
|
||||
ClaimMismatch,
|
||||
#[error("unknown token issuer `{0}`")]
|
||||
UnknownIssuer(String),
|
||||
#[error("invalid token signature")]
|
||||
@@ -224,6 +234,162 @@ pub fn verify_capability_token(
|
||||
})
|
||||
}
|
||||
|
||||
#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
|
||||
pub struct RuntimeRequestSourceClaims {
|
||||
pub iss: String,
|
||||
pub aud: String,
|
||||
pub workspace_id: String,
|
||||
#[serde(skip_serializing_if = "Option::is_none")]
|
||||
pub worker_id: Option<String>,
|
||||
pub permission: String,
|
||||
pub method: String,
|
||||
pub path: String,
|
||||
pub body_digest: String,
|
||||
pub iat: i64,
|
||||
pub exp: i64,
|
||||
pub jti: String,
|
||||
}
|
||||
|
||||
#[derive(Clone, Debug, PartialEq, Eq)]
|
||||
pub struct RuntimeRequestSourceSigner {
|
||||
identity_id: String,
|
||||
private_key: String,
|
||||
}
|
||||
|
||||
#[derive(Clone, Debug, PartialEq, Eq)]
|
||||
pub struct RuntimeRequestSourceExpectation<'a> {
|
||||
pub identity_id: &'a str,
|
||||
pub audience: &'a str,
|
||||
pub workspace_id: &'a str,
|
||||
pub worker_id: Option<&'a str>,
|
||||
pub permission: &'a str,
|
||||
pub method: &'a str,
|
||||
pub path: &'a str,
|
||||
pub body_digest: &'a str,
|
||||
pub now_unix: i64,
|
||||
}
|
||||
|
||||
pub fn request_body_digest(body: &[u8]) -> String {
|
||||
URL_SAFE_NO_PAD.encode(Sha256::digest(body))
|
||||
}
|
||||
|
||||
impl RuntimeRequestSourceSigner {
|
||||
pub fn from_identity(identity: &RuntimeIdentityMaterial) -> Self {
|
||||
Self {
|
||||
identity_id: identity.identity_id.clone(),
|
||||
private_key: identity.private_key.clone(),
|
||||
}
|
||||
}
|
||||
|
||||
#[allow(clippy::too_many_arguments)]
|
||||
pub fn issue(
|
||||
&self,
|
||||
audience: &str,
|
||||
workspace_id: &str,
|
||||
worker_id: Option<&str>,
|
||||
permission: &str,
|
||||
method: &str,
|
||||
path: &str,
|
||||
body: &[u8],
|
||||
now_unix: i64,
|
||||
ttl_seconds: u64,
|
||||
) -> Result<String, RuntimeAuthError> {
|
||||
for (name, value) in [
|
||||
("audience", audience),
|
||||
("workspace_id", workspace_id),
|
||||
("permission", permission),
|
||||
("method", method),
|
||||
("path", path),
|
||||
] {
|
||||
if value.trim().is_empty() {
|
||||
return Err(RuntimeAuthError::InvalidClaim(name));
|
||||
}
|
||||
}
|
||||
if worker_id.is_some_and(str::is_empty) {
|
||||
return Err(RuntimeAuthError::InvalidClaim("worker_id"));
|
||||
}
|
||||
let ttl_seconds = i64::try_from(ttl_seconds).unwrap_or(i64::MAX);
|
||||
let claims = RuntimeRequestSourceClaims {
|
||||
iss: self.identity_id.clone(),
|
||||
aud: audience.to_owned(),
|
||||
workspace_id: workspace_id.to_owned(),
|
||||
worker_id: worker_id.map(str::to_owned),
|
||||
permission: permission.to_owned(),
|
||||
method: method.to_owned(),
|
||||
path: path.to_owned(),
|
||||
body_digest: request_body_digest(body),
|
||||
iat: now_unix,
|
||||
exp: now_unix.saturating_add(ttl_seconds),
|
||||
jti: new_token_id()?,
|
||||
};
|
||||
let payload = serde_json::to_vec(&claims)?;
|
||||
let payload = URL_SAFE_NO_PAD.encode(payload);
|
||||
let signing_input = format!("{RUNTIME_REQUEST_SOURCE_SIGNING_INPUT_PREFIX}{payload}");
|
||||
let private = decode_private_key(&self.private_key)?;
|
||||
let key_pair = Ed25519KeyPair::from_pkcs8(&private)
|
||||
.map_err(|_| RuntimeAuthError::InvalidPrivateKey)?;
|
||||
let signature = URL_SAFE_NO_PAD.encode(key_pair.sign(signing_input.as_bytes()).as_ref());
|
||||
Ok(format!(
|
||||
"{RUNTIME_REQUEST_SOURCE_PROOF_PREFIX}.{payload}.{signature}"
|
||||
))
|
||||
}
|
||||
}
|
||||
|
||||
pub fn decode_runtime_request_source_claims(
|
||||
proof: &str,
|
||||
) -> Result<RuntimeRequestSourceClaims, RuntimeAuthError> {
|
||||
let (prefix, payload, _signature) = split_runtime_request_source_proof(proof)?;
|
||||
if prefix != RUNTIME_REQUEST_SOURCE_PROOF_PREFIX {
|
||||
return Err(RuntimeAuthError::InvalidTokenFormat);
|
||||
}
|
||||
let payload = URL_SAFE_NO_PAD.decode(payload)?;
|
||||
serde_json::from_slice(&payload).map_err(RuntimeAuthError::from)
|
||||
}
|
||||
|
||||
pub fn verify_runtime_request_source(
|
||||
proof: &str,
|
||||
public_key: &str,
|
||||
expected: &RuntimeRequestSourceExpectation<'_>,
|
||||
) -> Result<RuntimeRequestSourceClaims, RuntimeAuthError> {
|
||||
let (prefix, payload, signature) = split_runtime_request_source_proof(proof)?;
|
||||
if prefix != RUNTIME_REQUEST_SOURCE_PROOF_PREFIX {
|
||||
return Err(RuntimeAuthError::InvalidTokenFormat);
|
||||
}
|
||||
let signature = URL_SAFE_NO_PAD.decode(signature)?;
|
||||
let signing_input = format!("{RUNTIME_REQUEST_SOURCE_SIGNING_INPUT_PREFIX}{payload}");
|
||||
let public_key = decode_public_key(public_key)?;
|
||||
UnparsedPublicKey::new(&ED25519, public_key)
|
||||
.verify(signing_input.as_bytes(), &signature)
|
||||
.map_err(|_| RuntimeAuthError::InvalidSignature)?;
|
||||
let claims = decode_runtime_request_source_claims(proof)?;
|
||||
if claims.iss != expected.identity_id
|
||||
|| claims.aud != expected.audience
|
||||
|| claims.workspace_id != expected.workspace_id
|
||||
|| claims.worker_id.as_deref() != expected.worker_id
|
||||
|| claims.permission != expected.permission
|
||||
|| claims.method != expected.method
|
||||
|| claims.path != expected.path
|
||||
|| claims.body_digest != expected.body_digest
|
||||
{
|
||||
return Err(RuntimeAuthError::ClaimMismatch);
|
||||
}
|
||||
if claims.iat > expected.now_unix || claims.exp < expected.now_unix {
|
||||
return Err(RuntimeAuthError::Expired);
|
||||
}
|
||||
Ok(claims)
|
||||
}
|
||||
|
||||
fn split_runtime_request_source_proof(proof: &str) -> Result<(&str, &str, &str), RuntimeAuthError> {
|
||||
let mut parts = proof.split('.');
|
||||
let prefix = parts.next().unwrap_or_default();
|
||||
let payload = parts.next().unwrap_or_default();
|
||||
let signature = parts.next().unwrap_or_default();
|
||||
if prefix.is_empty() || payload.is_empty() || signature.is_empty() || parts.next().is_some() {
|
||||
return Err(RuntimeAuthError::InvalidTokenFormat);
|
||||
}
|
||||
Ok((prefix, payload, signature))
|
||||
}
|
||||
|
||||
#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
|
||||
pub struct WorkerMutationSourceClaims {
|
||||
pub iss: String,
|
||||
@@ -592,6 +758,99 @@ mod tests {
|
||||
));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn runtime_request_source_proof_binds_request_and_rejects_spoofed_signature() {
|
||||
let trusted = RuntimeIdentityMaterial::generate("runtime-main").unwrap();
|
||||
let signer = RuntimeRequestSourceSigner::from_identity(&trusted);
|
||||
let body = br#"{"ticket":"T-1"}"#;
|
||||
let proof = signer
|
||||
.issue(
|
||||
"server-main",
|
||||
"workspace-a",
|
||||
Some("worker-7"),
|
||||
WORKSPACE_REQUEST_PERMISSION,
|
||||
"POST",
|
||||
"/api/w/workspace-a/tickets/comment",
|
||||
body,
|
||||
90,
|
||||
10,
|
||||
)
|
||||
.unwrap();
|
||||
let expected = RuntimeRequestSourceExpectation {
|
||||
identity_id: "runtime-main",
|
||||
audience: "server-main",
|
||||
workspace_id: "workspace-a",
|
||||
worker_id: Some("worker-7"),
|
||||
permission: WORKSPACE_REQUEST_PERMISSION,
|
||||
method: "POST",
|
||||
path: "/api/w/workspace-a/tickets/comment",
|
||||
body_digest: &request_body_digest(body),
|
||||
now_unix: 99,
|
||||
};
|
||||
let claims = verify_runtime_request_source(&proof, &trusted.public_key, &expected).unwrap();
|
||||
assert_eq!(claims.iss, "runtime-main");
|
||||
let changed_body = RuntimeRequestSourceExpectation {
|
||||
body_digest: &request_body_digest(br#"{"ticket":"T-2"}"#),
|
||||
..expected.clone()
|
||||
};
|
||||
assert!(matches!(
|
||||
verify_runtime_request_source(&proof, &trusted.public_key, &changed_body),
|
||||
Err(RuntimeAuthError::ClaimMismatch)
|
||||
));
|
||||
let spoofed = RuntimeIdentityMaterial::generate("runtime-main").unwrap();
|
||||
assert!(matches!(
|
||||
verify_runtime_request_source(&proof, &spoofed.public_key, &expected),
|
||||
Err(RuntimeAuthError::InvalidSignature)
|
||||
));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn runtime_request_source_proof_rejects_wrong_scope_and_expiry() {
|
||||
let runtime = RuntimeIdentityMaterial::generate("runtime-main").unwrap();
|
||||
let proof = RuntimeRequestSourceSigner::from_identity(&runtime)
|
||||
.issue(
|
||||
"server-main",
|
||||
"workspace-a",
|
||||
None,
|
||||
BACKEND_RESOURCE_FETCH_PERMISSION,
|
||||
"POST",
|
||||
"/api/runtime/v1/workspaces/workspace-a/resources/fetch",
|
||||
b"{}",
|
||||
90,
|
||||
10,
|
||||
)
|
||||
.unwrap();
|
||||
let digest = request_body_digest(b"{}");
|
||||
let expected = RuntimeRequestSourceExpectation {
|
||||
identity_id: "runtime-main",
|
||||
audience: "server-main",
|
||||
workspace_id: "workspace-a",
|
||||
worker_id: None,
|
||||
permission: BACKEND_RESOURCE_FETCH_PERMISSION,
|
||||
method: "POST",
|
||||
path: "/api/runtime/v1/workspaces/workspace-a/resources/fetch",
|
||||
body_digest: &digest,
|
||||
now_unix: 99,
|
||||
};
|
||||
assert!(verify_runtime_request_source(&proof, &runtime.public_key, &expected).is_ok());
|
||||
let wrong_workspace = RuntimeRequestSourceExpectation {
|
||||
workspace_id: "workspace-b",
|
||||
..expected.clone()
|
||||
};
|
||||
assert!(matches!(
|
||||
verify_runtime_request_source(&proof, &runtime.public_key, &wrong_workspace),
|
||||
Err(RuntimeAuthError::ClaimMismatch)
|
||||
));
|
||||
let expired = RuntimeRequestSourceExpectation {
|
||||
now_unix: 101,
|
||||
..expected
|
||||
};
|
||||
assert!(matches!(
|
||||
verify_runtime_request_source(&proof, &runtime.public_key, &expired),
|
||||
Err(RuntimeAuthError::Expired)
|
||||
));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn capability_token_verifies_signature_audience_expiry_and_permission() {
|
||||
let server = RuntimeIdentityMaterial::generate("server-main").unwrap();
|
||||
|
||||
@@ -2,7 +2,6 @@ use crate::identity::{RuntimeWorkerRef, WorkerId, WorkerRef};
|
||||
use crate::interaction::WorkerInput;
|
||||
use crate::profile_archive::{ProfileSourceArchive, ProfileSourceArchiveRef};
|
||||
use serde::{Deserialize, Serialize};
|
||||
use std::path::PathBuf;
|
||||
|
||||
fn is_false(value: &bool) -> bool {
|
||||
!*value
|
||||
@@ -85,9 +84,9 @@ impl std::ops::Deref for RepositorySelector {
|
||||
pub struct WorkingDirectoryRepository {
|
||||
pub id: String,
|
||||
pub provider: String,
|
||||
pub uri: String,
|
||||
#[serde(default, skip_serializing_if = "Option::is_none")]
|
||||
pub local_path: Option<PathBuf>,
|
||||
pub source: workspace_api::RepositorySource,
|
||||
pub source_revision: u64,
|
||||
pub source_fingerprint: String,
|
||||
#[serde(default, skip_serializing_if = "Option::is_none")]
|
||||
pub selector: Option<RepositorySelector>,
|
||||
}
|
||||
|
||||
@@ -160,15 +160,33 @@ fn build_runtime(config: &ProcessConfig) -> Result<Runtime, ProcessError> {
|
||||
};
|
||||
let mut factory = ProfileRuntimeWorkerFactory::new(fs_paths.worker_dir.join("worker-root"))
|
||||
.with_runtime_store_dir(runtime_store_dir);
|
||||
if let Some(identity) = read_runtime_auth_file(&runtime_auth_path(config))?.identity {
|
||||
let runtime_auth = read_runtime_auth_file(&runtime_auth_path(config))?;
|
||||
if let Some(identity) = runtime_auth.identity.clone() {
|
||||
if let [trusted_server] = runtime_auth.trusted_servers.as_slice() {
|
||||
factory =
|
||||
factory.with_runtime_request_identity(identity, trusted_server.server_id.clone());
|
||||
} else {
|
||||
factory = factory.with_remote_worker_mutation_identity(identity);
|
||||
}
|
||||
}
|
||||
if let Some(endpoint) = config.backend_resource_endpoint.clone() {
|
||||
let identity = runtime_auth.identity.as_ref().ok_or_else(|| {
|
||||
ProcessError::Auth(
|
||||
"--backend-resource-endpoint requires a configured Runtime identity".to_owned(),
|
||||
)
|
||||
})?;
|
||||
let [trusted_server] = runtime_auth.trusted_servers.as_slice() else {
|
||||
return Err(ProcessError::Auth(
|
||||
"--backend-resource-endpoint requires exactly one trusted Server identity"
|
||||
.to_owned(),
|
||||
));
|
||||
};
|
||||
factory = factory.with_resource_client(Arc::new(
|
||||
worker_runtime::resource::HttpBackendResourceClient::new(
|
||||
endpoint,
|
||||
config.backend_resource_token.clone(),
|
||||
),
|
||||
)
|
||||
.with_runtime_request_source(identity, trusted_server.server_id.clone()),
|
||||
));
|
||||
}
|
||||
let backend = Arc::new(
|
||||
|
||||
@@ -1,3 +1,7 @@
|
||||
use crate::auth::{
|
||||
BACKEND_RESOURCE_FETCH_PERMISSION, RUNTIME_REQUEST_SOURCE_PROOF_HEADER,
|
||||
RuntimeIdentityMaterial, RuntimeRequestSourceSigner, unix_now_seconds,
|
||||
};
|
||||
use crate::identity::WorkerId;
|
||||
use crate::profile_archive::{ProfileSourceArchive, ProfileSourceArchiveRef, sha256_hex};
|
||||
use async_trait::async_trait;
|
||||
@@ -108,6 +112,8 @@ pub trait BackendResourceClient: Send + Sync + 'static {
|
||||
pub struct HttpBackendResourceClient {
|
||||
endpoint: String,
|
||||
bearer_token: Option<String>,
|
||||
request_source_signer: Option<RuntimeRequestSourceSigner>,
|
||||
request_source_audience: Option<String>,
|
||||
client: reqwest::Client,
|
||||
}
|
||||
|
||||
@@ -117,9 +123,21 @@ impl HttpBackendResourceClient {
|
||||
Self {
|
||||
endpoint: endpoint.into(),
|
||||
bearer_token,
|
||||
request_source_signer: None,
|
||||
request_source_audience: None,
|
||||
client: reqwest::Client::new(),
|
||||
}
|
||||
}
|
||||
|
||||
pub fn with_runtime_request_source(
|
||||
mut self,
|
||||
identity: &RuntimeIdentityMaterial,
|
||||
audience: impl Into<String>,
|
||||
) -> Self {
|
||||
self.request_source_signer = Some(RuntimeRequestSourceSigner::from_identity(identity));
|
||||
self.request_source_audience = Some(audience.into());
|
||||
self
|
||||
}
|
||||
}
|
||||
|
||||
#[cfg(feature = "http-server")]
|
||||
@@ -129,7 +147,44 @@ impl BackendResourceClient for HttpBackendResourceClient {
|
||||
&self,
|
||||
request: BackendResourceFetchRequest,
|
||||
) -> Result<BackendResourceFetchResponse, BackendResourceError> {
|
||||
let builder = self.client.post(&self.endpoint).json(&request);
|
||||
let body = serde_json::to_vec(&request).map_err(|error| {
|
||||
BackendResourceError::InvalidResponse {
|
||||
message: error.to_string(),
|
||||
}
|
||||
})?;
|
||||
let endpoint = reqwest::Url::parse(&self.endpoint).map_err(|error| {
|
||||
BackendResourceError::Transport {
|
||||
message: error.to_string(),
|
||||
}
|
||||
})?;
|
||||
let mut builder = self
|
||||
.client
|
||||
.post(endpoint.clone())
|
||||
.header(reqwest::header::CONTENT_TYPE, "application/json")
|
||||
.body(body.clone());
|
||||
if let Some(signer) = self.request_source_signer.as_ref() {
|
||||
let audience = self.request_source_audience.as_deref().ok_or_else(|| {
|
||||
BackendResourceError::Unauthorized {
|
||||
message: "Runtime request proof audience is unavailable".to_owned(),
|
||||
}
|
||||
})?;
|
||||
let proof = signer
|
||||
.issue(
|
||||
audience,
|
||||
&request.handle.workspace_id,
|
||||
None,
|
||||
BACKEND_RESOURCE_FETCH_PERMISSION,
|
||||
"POST",
|
||||
endpoint.path(),
|
||||
&body,
|
||||
i64::try_from(unix_now_seconds()).unwrap_or(i64::MAX),
|
||||
30,
|
||||
)
|
||||
.map_err(|error| BackendResourceError::Unauthorized {
|
||||
message: error.to_string(),
|
||||
})?;
|
||||
builder = builder.header(RUNTIME_REQUEST_SOURCE_PROOF_HEADER, proof);
|
||||
}
|
||||
let builder = if let Some(token) = self.bearer_token.as_deref() {
|
||||
builder.bearer_auth(token)
|
||||
} else {
|
||||
|
||||
@@ -14,7 +14,10 @@ use std::sync::atomic::{AtomicBool, Ordering};
|
||||
use std::sync::{Arc, Mutex, mpsc};
|
||||
use std::time::Duration;
|
||||
|
||||
use crate::auth::RuntimeIdentityMaterial;
|
||||
use crate::auth::{
|
||||
BACKEND_RESOURCE_FETCH_PERMISSION, RUNTIME_REQUEST_SOURCE_PROOF_HEADER,
|
||||
RuntimeIdentityMaterial, RuntimeRequestSourceSigner, unix_now_seconds,
|
||||
};
|
||||
use crate::catalog::{
|
||||
CreateWorkerRequest, ProfileSourceArchiveHttpRef, ProfileSourceArchiveSource,
|
||||
WorkingDirectoryRequest, WorkingDirectoryStatus,
|
||||
@@ -295,6 +298,7 @@ pub struct ProfileRuntimeWorkerFactory {
|
||||
prompt_projection_cache: Arc<WorkspacePromptProjectionCache>,
|
||||
runtime_id: Option<String>,
|
||||
worker_mutation_identity: Option<RuntimeIdentityMaterial>,
|
||||
runtime_request_audience: Option<String>,
|
||||
embedded_worker_mutation_dispatcher: Option<Arc<dyn EmbeddedWorkerMutationDispatcher>>,
|
||||
controller_transport: WorkerControllerTransport,
|
||||
}
|
||||
@@ -311,6 +315,7 @@ impl ProfileRuntimeWorkerFactory {
|
||||
prompt_projection_cache: Arc::new(WorkspacePromptProjectionCache::default()),
|
||||
runtime_id: None,
|
||||
worker_mutation_identity: None,
|
||||
runtime_request_audience: None,
|
||||
embedded_worker_mutation_dispatcher: None,
|
||||
controller_transport: WorkerControllerTransport::UnixSocket,
|
||||
}
|
||||
@@ -331,6 +336,17 @@ impl ProfileRuntimeWorkerFactory {
|
||||
self
|
||||
}
|
||||
|
||||
pub fn with_runtime_request_identity(
|
||||
mut self,
|
||||
identity: RuntimeIdentityMaterial,
|
||||
audience: impl Into<String>,
|
||||
) -> Self {
|
||||
self.runtime_id = Some(identity.identity_id.clone());
|
||||
self.worker_mutation_identity = Some(identity);
|
||||
self.runtime_request_audience = Some(audience.into());
|
||||
self
|
||||
}
|
||||
|
||||
pub fn with_embedded_worker_mutation_dispatcher(
|
||||
mut self,
|
||||
runtime_id: impl Into<String>,
|
||||
@@ -457,13 +473,15 @@ impl ProfileRuntimeWorkerFactory {
|
||||
async fn resolve_profile_source_archive(
|
||||
&self,
|
||||
source: &ProfileSourceArchiveSource,
|
||||
request_audience: Option<&str>,
|
||||
) -> Result<crate::profile_archive::VerifiedProfileSourceArchive, String> {
|
||||
match source {
|
||||
ProfileSourceArchiveSource::Embedded { archive } => archive
|
||||
.verify()
|
||||
.map_err(|err| format!("failed to verify embedded profile source archive: {err}")),
|
||||
ProfileSourceArchiveSource::Http { location } => {
|
||||
self.fetch_profile_source_archive(location).await
|
||||
self.fetch_profile_source_archive(location, request_audience)
|
||||
.await
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -471,10 +489,18 @@ impl ProfileRuntimeWorkerFactory {
|
||||
async fn fetch_profile_source_archive(
|
||||
&self,
|
||||
location: &ProfileSourceArchiveHttpRef,
|
||||
request_audience: Option<&str>,
|
||||
) -> Result<crate::profile_archive::VerifiedProfileSourceArchive, String> {
|
||||
if let Some(cached) = self.profile_archive_cache.get(&location.archive.digest) {
|
||||
let response =
|
||||
fetch_profile_source_archive_http(location, Some(&location.archive.digest)).await?;
|
||||
let response = fetch_profile_source_archive_http(
|
||||
location,
|
||||
Some(&location.archive.digest),
|
||||
self.worker_mutation_identity.as_ref(),
|
||||
self.runtime_request_audience
|
||||
.as_deref()
|
||||
.or(request_audience),
|
||||
)
|
||||
.await?;
|
||||
if let Some(fetched) = response {
|
||||
self.profile_archive_cache.insert(fetched.clone());
|
||||
fetched.verify().map_err(|err| {
|
||||
@@ -486,7 +512,14 @@ impl ProfileRuntimeWorkerFactory {
|
||||
.map_err(|err| format!("failed to verify cached profile source archive: {err}"))
|
||||
}
|
||||
} else {
|
||||
let archive = fetch_profile_source_archive_http(location, None)
|
||||
let archive = fetch_profile_source_archive_http(
|
||||
location,
|
||||
None,
|
||||
self.worker_mutation_identity.as_ref(),
|
||||
self.runtime_request_audience
|
||||
.as_deref()
|
||||
.or(request_audience),
|
||||
)
|
||||
.await?
|
||||
.ok_or_else(|| {
|
||||
"profile source archive HTTP revalidation returned 304 without a cached archive"
|
||||
@@ -527,6 +560,7 @@ impl RuntimeWorkspaceBackendRef {
|
||||
worker_ref: &WorkerRef,
|
||||
workspace_scope: Option<&crate::runtime::RuntimeWorkspaceScope>,
|
||||
mutation_identity: Option<&RuntimeIdentityMaterial>,
|
||||
runtime_request_audience: Option<&str>,
|
||||
embedded_dispatcher: Option<&Arc<dyn EmbeddedWorkerMutationDispatcher>>,
|
||||
prompt_projection_cache: Option<Arc<WorkspacePromptProjectionCache>>,
|
||||
) -> WorkerWorkspaceContext {
|
||||
@@ -546,6 +580,13 @@ impl RuntimeWorkspaceBackendRef {
|
||||
if let Some(cache) = prompt_projection_cache {
|
||||
client = client.with_prompt_projection_cache(cache);
|
||||
}
|
||||
if let Some(identity) = mutation_identity {
|
||||
let audience = runtime_request_audience
|
||||
.or_else(|| workspace_scope.map(|scope| scope.server_id.as_str()));
|
||||
if let Some(audience) = audience {
|
||||
client = client.with_runtime_request_source(identity, audience.to_owned());
|
||||
}
|
||||
}
|
||||
if let (Some(scope), Some(identity)) = (workspace_scope, mutation_identity) {
|
||||
client = client.with_worker_remove(RuntimeWorkerMutationForwarder::remote(
|
||||
identity,
|
||||
@@ -576,9 +617,40 @@ impl RuntimeWorkspaceBackendRef {
|
||||
async fn fetch_profile_source_archive_http(
|
||||
location: &ProfileSourceArchiveHttpRef,
|
||||
cached_digest: Option<&str>,
|
||||
identity: Option<&RuntimeIdentityMaterial>,
|
||||
audience: Option<&str>,
|
||||
) -> Result<Option<crate::profile_archive::ProfileSourceArchive>, String> {
|
||||
let client = reqwest::Client::new();
|
||||
let mut request = client.get(&location.url);
|
||||
let url = reqwest::Url::parse(&location.url)
|
||||
.map_err(|error| format!("profile source archive URL is invalid: {error}"))?;
|
||||
let path = url.path().to_owned();
|
||||
let workspace_id = path
|
||||
.split('/')
|
||||
.collect::<Vec<_>>()
|
||||
.windows(2)
|
||||
.find_map(|parts| (parts[0] == "w").then_some(parts[1]))
|
||||
.filter(|value| !value.is_empty())
|
||||
.ok_or_else(|| "profile source archive URL is not workspace-scoped".to_owned())?;
|
||||
let mut request = client.get(url);
|
||||
if let Some(identity) = identity {
|
||||
let audience = audience.ok_or_else(|| {
|
||||
"profile source archive request proof audience is unavailable".to_owned()
|
||||
})?;
|
||||
let proof = RuntimeRequestSourceSigner::from_identity(identity)
|
||||
.issue(
|
||||
audience,
|
||||
workspace_id,
|
||||
None,
|
||||
BACKEND_RESOURCE_FETCH_PERMISSION,
|
||||
"GET",
|
||||
&path,
|
||||
b"",
|
||||
i64::try_from(unix_now_seconds()).unwrap_or(i64::MAX),
|
||||
30,
|
||||
)
|
||||
.map_err(|error| error.to_string())?;
|
||||
request = request.header(RUNTIME_REQUEST_SOURCE_PROOF_HEADER, proof);
|
||||
}
|
||||
if cached_digest == Some(location.archive.digest.as_str()) {
|
||||
if let Some(etag) = location.etag.as_deref() {
|
||||
request = request.header(reqwest::header::IF_NONE_MATCH, etag);
|
||||
@@ -620,6 +692,8 @@ async fn fetch_profile_source_archive_http(
|
||||
async fn fetch_profile_source_archive_http(
|
||||
_location: &ProfileSourceArchiveHttpRef,
|
||||
_cached_digest: Option<&str>,
|
||||
_identity: Option<&RuntimeIdentityMaterial>,
|
||||
_audience: Option<&str>,
|
||||
) -> Result<Option<crate::profile_archive::ProfileSourceArchive>, String> {
|
||||
Err(
|
||||
"HTTP profile source archive fetch requires the worker-runtime http-server feature"
|
||||
@@ -743,12 +817,19 @@ impl RuntimeWorkerFactory for ProfileRuntimeWorkerFactory {
|
||||
&request.worker_ref,
|
||||
request.workspace_scope.as_ref(),
|
||||
self.worker_mutation_identity.as_ref(),
|
||||
self.runtime_request_audience.as_deref(),
|
||||
self.embedded_worker_mutation_dispatcher.as_ref(),
|
||||
Some(self.prompt_projection_cache.clone()),
|
||||
);
|
||||
let selector = profile.as_ref();
|
||||
let archive = self
|
||||
.resolve_profile_source_archive(&request.request.profile_source)
|
||||
.resolve_profile_source_archive(
|
||||
&request.request.profile_source,
|
||||
request
|
||||
.workspace_scope
|
||||
.as_ref()
|
||||
.map(|scope| scope.server_id.as_str()),
|
||||
)
|
||||
.await?;
|
||||
let (mut manifest, mut loader) = {
|
||||
let manifest = archive
|
||||
@@ -909,6 +990,7 @@ impl RuntimeWorkerFactory for ProfileRuntimeWorkerFactory {
|
||||
&request.worker_ref,
|
||||
request.workspace_scope.as_ref(),
|
||||
self.worker_mutation_identity.as_ref(),
|
||||
self.runtime_request_audience.as_deref(),
|
||||
self.embedded_worker_mutation_dispatcher.as_ref(),
|
||||
Some(self.prompt_projection_cache.clone()),
|
||||
);
|
||||
@@ -2187,12 +2269,18 @@ mod tests {
|
||||
let scope = crate::runtime::RuntimeWorkspaceScope::new("workspace-a", "server-main");
|
||||
|
||||
let before_restart =
|
||||
backend.worker_context(&worker_ref, Some(&scope), Some(&identity), None, None);
|
||||
backend.worker_context(&worker_ref, Some(&scope), Some(&identity), None, None, None);
|
||||
let adapter = WorkerRuntimeExecutionBackend::new(FailingFactory).unwrap();
|
||||
let (after_restore_kind, after_restore_workspace_id) = adapter
|
||||
.run_on_adapter_runtime(async move {
|
||||
let after_restore =
|
||||
backend.worker_context(&worker_ref, Some(&scope), Some(&identity), None, None);
|
||||
let after_restore = backend.worker_context(
|
||||
&worker_ref,
|
||||
Some(&scope),
|
||||
Some(&identity),
|
||||
None,
|
||||
None,
|
||||
None,
|
||||
);
|
||||
let client = after_restore.client_handle();
|
||||
Ok((
|
||||
client.kind().to_string(),
|
||||
@@ -2383,6 +2471,7 @@ mod tests {
|
||||
None,
|
||||
None,
|
||||
None,
|
||||
None,
|
||||
);
|
||||
let workspace_client = workspace_context.client_handle();
|
||||
self.observed_workspace_clients.lock().unwrap().push((
|
||||
@@ -2631,8 +2720,12 @@ mod tests {
|
||||
repository: WorkingDirectoryRepository {
|
||||
id: "repo-main".to_string(),
|
||||
provider: "git".to_string(),
|
||||
uri: ".".to_string(),
|
||||
local_path: Some(repo.to_path_buf()),
|
||||
source: workspace_api::RepositorySource {
|
||||
kind: workspace_api::RepositorySourceKind::LocalPath,
|
||||
uri: repo.display().to_string(),
|
||||
},
|
||||
source_revision: 1,
|
||||
source_fingerprint: "sha256:test".to_string(),
|
||||
selector: Some(RepositorySelector::from("HEAD")),
|
||||
},
|
||||
materializer: MaterializerKind::LocalGitWorktree,
|
||||
@@ -2781,7 +2874,7 @@ mod tests {
|
||||
archive: bundle.profile_source_archive.clone().unwrap(),
|
||||
};
|
||||
factory
|
||||
.resolve_profile_source_archive(&source)
|
||||
.resolve_profile_source_archive(&source, None)
|
||||
.await
|
||||
.expect("embedded archive should resolve without Backend resource client");
|
||||
}
|
||||
|
||||
@@ -7,8 +7,9 @@ use worker::{
|
||||
};
|
||||
|
||||
use crate::auth::{
|
||||
RuntimeAuthError, RuntimeIdentityMaterial, RuntimeWorkerMutationSourceSigner,
|
||||
WORKER_REMOVE_PERMISSION, WorkerMutationActorKind, WorkerMutationOperation,
|
||||
RUNTIME_REQUEST_SOURCE_PROOF_HEADER, RuntimeAuthError, RuntimeIdentityMaterial,
|
||||
RuntimeRequestSourceSigner, RuntimeWorkerMutationSourceSigner, WORKER_REMOVE_PERMISSION,
|
||||
WORKSPACE_REQUEST_PERMISSION, WorkerMutationActorKind, WorkerMutationOperation,
|
||||
WorkerMutationSourceClaims, new_token_id,
|
||||
};
|
||||
use crate::runtime::RuntimeWorkspaceScope;
|
||||
@@ -289,6 +290,8 @@ pub struct RuntimeOwnedWorkspaceClient {
|
||||
worker_id: String,
|
||||
request_timeout: Option<Duration>,
|
||||
worker_remove: Option<RuntimeWorkerMutationForwarder>,
|
||||
request_source_signer: Option<RuntimeRequestSourceSigner>,
|
||||
request_source_audience: Option<String>,
|
||||
prompt_projection_cache: Option<Arc<WorkspacePromptProjectionCache>>,
|
||||
}
|
||||
|
||||
@@ -306,6 +309,8 @@ impl RuntimeOwnedWorkspaceClient {
|
||||
worker_id: worker_id.into(),
|
||||
request_timeout: None,
|
||||
worker_remove: None,
|
||||
request_source_signer: None,
|
||||
request_source_audience: None,
|
||||
prompt_projection_cache: None,
|
||||
}
|
||||
}
|
||||
@@ -315,6 +320,16 @@ impl RuntimeOwnedWorkspaceClient {
|
||||
self
|
||||
}
|
||||
|
||||
pub fn with_runtime_request_source(
|
||||
mut self,
|
||||
identity: &RuntimeIdentityMaterial,
|
||||
audience: impl Into<String>,
|
||||
) -> Self {
|
||||
self.request_source_signer = Some(RuntimeRequestSourceSigner::from_identity(identity));
|
||||
self.request_source_audience = Some(audience.into());
|
||||
self
|
||||
}
|
||||
|
||||
pub(crate) fn with_prompt_projection_cache(
|
||||
mut self,
|
||||
cache: Arc<WorkspacePromptProjectionCache>,
|
||||
@@ -363,15 +378,21 @@ impl WorkspaceClient for RuntimeOwnedWorkspaceClient {
|
||||
request: WorkspaceRequest,
|
||||
) -> Result<WorkspaceResponse, WorkspaceClientError> {
|
||||
let base_url = self.base_url.clone();
|
||||
let workspace_id = self.workspace_id.clone();
|
||||
let runtime_id = self.runtime_id.clone();
|
||||
let worker_id = self.worker_id.clone();
|
||||
let request_source_signer = self.request_source_signer.clone();
|
||||
let request_source_audience = self.request_source_audience.clone();
|
||||
let request_timeout = self.request_timeout;
|
||||
if tokio::runtime::Handle::try_current().is_ok() {
|
||||
std::thread::spawn(move || {
|
||||
execute_runtime_owned_workspace_http(
|
||||
&base_url,
|
||||
&workspace_id,
|
||||
&runtime_id,
|
||||
&worker_id,
|
||||
request_source_signer.as_ref(),
|
||||
request_source_audience.as_deref(),
|
||||
request_timeout,
|
||||
request,
|
||||
)
|
||||
@@ -383,8 +404,11 @@ impl WorkspaceClient for RuntimeOwnedWorkspaceClient {
|
||||
} else {
|
||||
execute_runtime_owned_workspace_http(
|
||||
&self.base_url,
|
||||
&self.workspace_id,
|
||||
&self.runtime_id,
|
||||
&self.worker_id,
|
||||
self.request_source_signer.as_ref(),
|
||||
self.request_source_audience.as_deref(),
|
||||
self.request_timeout,
|
||||
request,
|
||||
)
|
||||
@@ -484,8 +508,11 @@ impl WorkspaceClient for RuntimeOwnedWorkspaceClient {
|
||||
|
||||
fn execute_runtime_owned_workspace_http(
|
||||
base_url: &str,
|
||||
workspace_id: &str,
|
||||
runtime_id: &str,
|
||||
worker_id: &str,
|
||||
request_source_signer: Option<&RuntimeRequestSourceSigner>,
|
||||
request_source_audience: Option<&str>,
|
||||
request_timeout: Option<Duration>,
|
||||
request: WorkspaceRequest,
|
||||
) -> Result<WorkspaceResponse, WorkspaceClientError> {
|
||||
@@ -510,11 +537,33 @@ fn execute_runtime_owned_workspace_http(
|
||||
))
|
||||
})?;
|
||||
let request_label = format!("{method} {}", request.path);
|
||||
let body = request.body.unwrap_or_default();
|
||||
let mut request_builder = client
|
||||
.request(method, url)
|
||||
.request(method.clone(), url)
|
||||
.header("x-yoi-runtime-id", runtime_id)
|
||||
.header("x-yoi-worker-id", worker_id);
|
||||
if let Some(body) = request.body {
|
||||
if let Some(signer) = request_source_signer {
|
||||
let audience = request_source_audience.ok_or_else(|| {
|
||||
WorkspaceClientError::Request(
|
||||
"runtime request proof audience is unavailable".to_owned(),
|
||||
)
|
||||
})?;
|
||||
let proof = signer
|
||||
.issue(
|
||||
audience,
|
||||
workspace_id,
|
||||
Some(worker_id),
|
||||
WORKSPACE_REQUEST_PERMISSION,
|
||||
method.as_str(),
|
||||
&request.path,
|
||||
body.as_bytes(),
|
||||
i64::try_from(unix_now_seconds()).unwrap_or(i64::MAX),
|
||||
30,
|
||||
)
|
||||
.map_err(|error| WorkspaceClientError::Request(error.to_string()))?;
|
||||
request_builder = request_builder.header(RUNTIME_REQUEST_SOURCE_PROOF_HEADER, proof);
|
||||
}
|
||||
if !body.is_empty() {
|
||||
request_builder = request_builder
|
||||
.header(reqwest::header::CONTENT_TYPE, "application/json")
|
||||
.body(body);
|
||||
@@ -590,8 +639,8 @@ fn unix_now_seconds() -> u64 {
|
||||
mod tests {
|
||||
use super::*;
|
||||
use crate::auth::{
|
||||
WorkerMutationSourceExpectation, decode_worker_mutation_source_claims,
|
||||
verify_worker_mutation_source_proof,
|
||||
WorkerMutationSourceExpectation, decode_runtime_request_source_claims,
|
||||
decode_worker_mutation_source_claims, verify_worker_mutation_source_proof,
|
||||
};
|
||||
|
||||
#[test]
|
||||
@@ -797,7 +846,7 @@ mod tests {
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn ordinary_workspace_forwarding_stamps_legacy_source_only_inside_runtime() {
|
||||
fn ordinary_workspace_forwarding_stamps_runtime_identity_and_signs_path_and_query() {
|
||||
use std::io::{Read, Write};
|
||||
use std::net::TcpListener;
|
||||
use std::sync::Mutex;
|
||||
@@ -817,21 +866,41 @@ mod tests {
|
||||
.unwrap();
|
||||
});
|
||||
|
||||
let identity = RuntimeIdentityMaterial::generate("runtime-a").unwrap();
|
||||
let client = RuntimeOwnedWorkspaceClient::new(
|
||||
"workspace-a",
|
||||
format!("http://{address}"),
|
||||
"runtime-a",
|
||||
"worker-a",
|
||||
);
|
||||
)
|
||||
.with_runtime_request_source(&identity, "server-a");
|
||||
let response = client
|
||||
.execute(WorkspaceRequest::get("/api/w/workspace-a/tickets/search"))
|
||||
.execute(WorkspaceRequest::get(
|
||||
"/api/w/workspace-a/tickets/search?state=planning&limit=20",
|
||||
))
|
||||
.unwrap();
|
||||
assert_eq!(response.status, 200);
|
||||
server.join().unwrap();
|
||||
let request = received.lock().unwrap().to_ascii_lowercase();
|
||||
assert!(request.contains("x-yoi-runtime-id: runtime-a"));
|
||||
assert!(request.contains("x-yoi-worker-id: worker-a"));
|
||||
assert!(!request.contains("authorization:"));
|
||||
let request = received.lock().unwrap().clone();
|
||||
let lowercase_request = request.to_ascii_lowercase();
|
||||
assert!(lowercase_request.contains("x-yoi-runtime-id: runtime-a"));
|
||||
assert!(lowercase_request.contains("x-yoi-worker-id: worker-a"));
|
||||
assert!(lowercase_request.contains("x-yoi-runtime-request-proof: yoi-runtime-request-v1."));
|
||||
assert!(!lowercase_request.contains("authorization:"));
|
||||
let token = request
|
||||
.lines()
|
||||
.find_map(|line| {
|
||||
line.split_once(':').and_then(|(name, value)| {
|
||||
name.eq_ignore_ascii_case(RUNTIME_REQUEST_SOURCE_PROOF_HEADER)
|
||||
.then(|| value.trim())
|
||||
})
|
||||
})
|
||||
.expect("runtime proof header");
|
||||
let claims = decode_runtime_request_source_claims(token).unwrap();
|
||||
assert_eq!(
|
||||
claims.path,
|
||||
"/api/w/workspace-a/tickets/search?state=planning&limit=20"
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
|
||||
@@ -318,18 +318,36 @@ impl LocalGitWorktreeMaterializer {
|
||||
),
|
||||
));
|
||||
}
|
||||
if is_remote_uri(&request.repository.uri) {
|
||||
let source_path = match request.repository.source.kind {
|
||||
workspace_api::RepositorySourceKind::LocalPath => {
|
||||
PathBuf::from(&request.repository.source.uri)
|
||||
}
|
||||
workspace_api::RepositorySourceKind::File => {
|
||||
url::Url::parse(&request.repository.source.uri)
|
||||
.ok()
|
||||
.and_then(|uri| uri.to_file_path().ok())
|
||||
.ok_or_else(|| {
|
||||
WorkingDirectoryDiagnostic::new(
|
||||
"working_directory_repository_source_invalid",
|
||||
"configured file Repository source is invalid",
|
||||
)
|
||||
})?
|
||||
}
|
||||
workspace_api::RepositorySourceKind::Ssh
|
||||
| workspace_api::RepositorySourceKind::Http
|
||||
| workspace_api::RepositorySourceKind::Https => {
|
||||
return Err(WorkingDirectoryDiagnostic::new(
|
||||
"working_directory_remote_repository_unsupported",
|
||||
"remote repository URI materialization is not implemented in v0",
|
||||
"working_directory_remote_repository_access_required",
|
||||
"remote Repository materialization requires an explicit authenticated access and trust handle",
|
||||
));
|
||||
}
|
||||
|
||||
let source_path = request
|
||||
.repository
|
||||
.local_path
|
||||
.clone()
|
||||
.unwrap_or_else(|| PathBuf::from(&request.repository.uri));
|
||||
workspace_api::RepositorySourceKind::Invalid => {
|
||||
return Err(WorkingDirectoryDiagnostic::new(
|
||||
"working_directory_repository_source_invalid",
|
||||
"configured Repository source is invalid and cannot be materialized",
|
||||
));
|
||||
}
|
||||
};
|
||||
let source_root = git_stdout(&source_path, ["rev-parse", "--show-toplevel"])
|
||||
.map(|value| PathBuf::from(value.trim()))
|
||||
.map_err(|_| {
|
||||
@@ -661,10 +679,6 @@ fn path_str(path: &Path) -> Result<String, WorkingDirectoryDiagnostic> {
|
||||
})
|
||||
}
|
||||
|
||||
fn is_remote_uri(uri: &str) -> bool {
|
||||
uri.contains("://") || uri.starts_with("git@") || uri.starts_with("ssh:")
|
||||
}
|
||||
|
||||
fn sanitize_path_component(value: &str) -> String {
|
||||
let sanitized = value
|
||||
.chars()
|
||||
@@ -793,8 +807,12 @@ mod tests {
|
||||
repository: WorkingDirectoryRepository {
|
||||
id: "repo-main".to_string(),
|
||||
provider: "git".to_string(),
|
||||
uri: ".".to_string(),
|
||||
local_path: Some(repo.to_path_buf()),
|
||||
source: workspace_api::RepositorySource {
|
||||
kind: workspace_api::RepositorySourceKind::LocalPath,
|
||||
uri: repo.display().to_string(),
|
||||
},
|
||||
source_revision: 1,
|
||||
source_fingerprint: "sha256:test".to_string(),
|
||||
selector: Some(RepositorySelector::from("HEAD")),
|
||||
},
|
||||
materializer: MaterializerKind::LocalGitWorktree,
|
||||
@@ -908,19 +926,21 @@ mod tests {
|
||||
let runtime_root = tempfile::tempdir().unwrap();
|
||||
let materializer = LocalGitWorktreeMaterializer::new(runtime_root.path());
|
||||
let mut remote = request(Path::new("."));
|
||||
remote.repository.local_path = None;
|
||||
remote.repository.uri = "https://example.invalid/repo.git".to_string();
|
||||
remote.repository.source = workspace_api::RepositorySource {
|
||||
kind: workspace_api::RepositorySourceKind::Https,
|
||||
uri: "https://example.invalid/repo.git".to_string(),
|
||||
};
|
||||
let error = materializer
|
||||
.materialize(&worker_ref(1), &remote)
|
||||
.unwrap_err();
|
||||
assert_eq!(
|
||||
error.code,
|
||||
"working_directory_remote_repository_unsupported"
|
||||
"working_directory_remote_repository_access_required"
|
||||
);
|
||||
|
||||
let mut non_git = remote;
|
||||
non_git.repository.provider = "archive".to_string();
|
||||
non_git.repository.uri = ".".to_string();
|
||||
non_git.repository.source.uri = ".".to_string();
|
||||
let error = materializer
|
||||
.materialize(&worker_ref(2), &non_git)
|
||||
.unwrap_err();
|
||||
|
||||
@@ -398,24 +398,35 @@ impl WorkspaceHttpWorkdirBackend {
|
||||
workdir_output(format!("Listed {count} Workdir(s)"), &response)
|
||||
}
|
||||
|
||||
fn create(&self, input: WorkdirCreateInput) -> Result<ToolOutput, ToolError> {
|
||||
let runtime_id = validate_identity(&input.runtime_id, CREATE_TOOL, "runtime_id")?;
|
||||
fn create(
|
||||
&self,
|
||||
input: WorkdirCreateInput,
|
||||
operation_id: String,
|
||||
) -> Result<ToolOutput, ToolError> {
|
||||
let runtime_id = input
|
||||
.runtime_id
|
||||
.as_deref()
|
||||
.map(|value| validate_identity(value, CREATE_TOOL, "runtime_id"))
|
||||
.transpose()?;
|
||||
let repository_id = validate_identity(&input.repository_id, CREATE_TOOL, "repository_id")?;
|
||||
let selector = validate_optional_selector(input.selector)?;
|
||||
let workspace_id = encode_path_segment(self.workspace_id()?);
|
||||
let runtime_path = encode_path_segment(runtime_id);
|
||||
let request = WorkdirCreateRequest {
|
||||
runtime_id: runtime_id.to_string(),
|
||||
runtime_id: runtime_id.map(str::to_string),
|
||||
repository_id: repository_id.to_string(),
|
||||
selector,
|
||||
operation_id,
|
||||
};
|
||||
let response = self.execute_json::<WorkdirDetailResponse>(WorkspaceRequest::json(
|
||||
WorkspaceRequestMethod::Post,
|
||||
format!("/api/w/{workspace_id}/runtimes/{runtime_path}/working-directories"),
|
||||
format!("/api/w/{workspace_id}/working-directories"),
|
||||
serde_json::to_string(&request).map_err(decode_error)?,
|
||||
))?;
|
||||
workdir_output(
|
||||
format!("Created Workdir {}", response.item.working_directory_id),
|
||||
format!(
|
||||
"Created Workdir {} on Runtime {}",
|
||||
response.item.working_directory_id, response.runtime_id
|
||||
),
|
||||
&response,
|
||||
)
|
||||
}
|
||||
@@ -518,16 +529,17 @@ impl Tool for WorkspaceHttpWorkdirTool {
|
||||
async fn execute(
|
||||
&self,
|
||||
input_json: &str,
|
||||
_ctx: ToolExecutionContext,
|
||||
ctx: ToolExecutionContext,
|
||||
) -> Result<ToolOutput, ToolError> {
|
||||
match self.operation {
|
||||
WorkdirOperation::List => {
|
||||
let _input = parse_input::<WorkdirListInput>(input_json)?;
|
||||
self.backend.list()
|
||||
}
|
||||
WorkdirOperation::Create => self
|
||||
.backend
|
||||
.create(parse_input::<WorkdirCreateInput>(input_json)?),
|
||||
WorkdirOperation::Create => self.backend.create(
|
||||
parse_input::<WorkdirCreateInput>(input_json)?,
|
||||
ctx.call_id.to_string(),
|
||||
),
|
||||
WorkdirOperation::Attach => self
|
||||
.backend
|
||||
.attach(parse_input::<WorkdirAttachInput>(input_json)?),
|
||||
@@ -635,9 +647,9 @@ fn create_schema() -> serde_json::Value {
|
||||
json!({
|
||||
"type": "object",
|
||||
"additionalProperties": false,
|
||||
"required": ["runtime_id", "repository_id"],
|
||||
"required": ["repository_id"],
|
||||
"properties": {
|
||||
"runtime_id": {"type": "string", "minLength": 1},
|
||||
"runtime_id": {"type": ["string", "null"], "minLength": 1},
|
||||
"repository_id": {"type": "string", "minLength": 1},
|
||||
"selector": {"type": ["string", "null"], "minLength": 1}
|
||||
}
|
||||
@@ -677,7 +689,8 @@ struct WorkdirListInput {}
|
||||
#[derive(Debug, Deserialize)]
|
||||
#[serde(deny_unknown_fields)]
|
||||
struct WorkdirCreateInput {
|
||||
runtime_id: String,
|
||||
#[serde(default)]
|
||||
runtime_id: Option<String>,
|
||||
repository_id: String,
|
||||
#[serde(default)]
|
||||
selector: Option<String>,
|
||||
@@ -685,10 +698,12 @@ struct WorkdirCreateInput {
|
||||
|
||||
#[derive(Debug, Serialize)]
|
||||
struct WorkdirCreateRequest {
|
||||
runtime_id: String,
|
||||
#[serde(skip_serializing_if = "Option::is_none")]
|
||||
runtime_id: Option<String>,
|
||||
repository_id: String,
|
||||
#[serde(skip_serializing_if = "Option::is_none")]
|
||||
selector: Option<String>,
|
||||
operation_id: String,
|
||||
}
|
||||
|
||||
#[derive(Debug, Deserialize)]
|
||||
@@ -916,7 +931,11 @@ mod tests {
|
||||
#[test]
|
||||
fn schemas_expose_identities_without_paths_or_session_handles() {
|
||||
let create = create_schema();
|
||||
assert_eq!(create["required"], json!(["runtime_id", "repository_id"]));
|
||||
assert_eq!(create["required"], json!(["repository_id"]));
|
||||
assert_eq!(
|
||||
create["properties"]["runtime_id"]["type"],
|
||||
json!(["string", "null"])
|
||||
);
|
||||
assert!(create["properties"].get("path").is_none());
|
||||
assert!(create["properties"].get("session_id").is_none());
|
||||
assert_eq!(attach_schema()["required"], json!(["workdir_id"]));
|
||||
@@ -946,6 +965,7 @@ mod tests {
|
||||
})),
|
||||
response(json!({
|
||||
"workspace_id": "workspace/test",
|
||||
"runtime_id": "runtime/one",
|
||||
"item": workdir_json("wd-created"),
|
||||
"diagnostics": []
|
||||
})),
|
||||
@@ -961,6 +981,7 @@ mod tests {
|
||||
})),
|
||||
response(json!({
|
||||
"workspace_id": "workspace/test",
|
||||
"runtime_id": "runtime/one",
|
||||
"item": {
|
||||
"working_directory_id": "wd-created",
|
||||
"repository_id": "main",
|
||||
@@ -985,13 +1006,19 @@ mod tests {
|
||||
.is_none()
|
||||
);
|
||||
let created = backend
|
||||
.create(WorkdirCreateInput {
|
||||
runtime_id: "runtime/one".to_string(),
|
||||
.create(
|
||||
WorkdirCreateInput {
|
||||
runtime_id: Some("runtime/one".to_string()),
|
||||
repository_id: "main".to_string(),
|
||||
selector: Some("refs/heads/topic".to_string()),
|
||||
})
|
||||
},
|
||||
"call-create-1".to_string(),
|
||||
)
|
||||
.unwrap();
|
||||
assert_eq!(created.summary, "Created Workdir wd-created");
|
||||
assert_eq!(
|
||||
created.summary,
|
||||
"Created Workdir wd-created on Runtime runtime/one"
|
||||
);
|
||||
let created: serde_json::Value =
|
||||
serde_json::from_str(created.content.as_deref().unwrap()).unwrap();
|
||||
assert_eq!(created["item"]["working_directory_id"], "wd-created");
|
||||
@@ -1017,12 +1044,14 @@ mod tests {
|
||||
assert_eq!(requests[0].method, WorkspaceRequestMethod::Get);
|
||||
assert_eq!(
|
||||
requests[1].path,
|
||||
"/api/w/workspace%2Ftest/runtimes/runtime%2Fone/working-directories"
|
||||
"/api/w/workspace%2Ftest/working-directories"
|
||||
);
|
||||
assert_eq!(requests[1].method, WorkspaceRequestMethod::Post);
|
||||
let body: serde_json::Value =
|
||||
serde_json::from_str(requests[1].body.as_deref().unwrap()).unwrap();
|
||||
assert_eq!(body["repository_id"], "main");
|
||||
assert_eq!(body["runtime_id"], "runtime/one");
|
||||
assert_eq!(body["operation_id"], "call-create-1");
|
||||
assert_eq!(body["selector"], "refs/heads/topic");
|
||||
assert_eq!(
|
||||
requests[2].path,
|
||||
@@ -1216,16 +1245,50 @@ mod tests {
|
||||
assert_eq!(body["operation"]["request"]["path"], "file");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn create_omits_runtime_for_backend_default_resolution() {
|
||||
let client = Arc::new(RecordingWorkspaceClient::new(vec![response(json!({
|
||||
"workspace_id": "workspace/test",
|
||||
"runtime_id": "arcadia",
|
||||
"item": workdir_json("wd-default"),
|
||||
"diagnostics": []
|
||||
}))]));
|
||||
let backend = WorkspaceHttpWorkdirBackend::new(client.clone());
|
||||
|
||||
let created = backend
|
||||
.create(
|
||||
WorkdirCreateInput {
|
||||
runtime_id: None,
|
||||
repository_id: "main".to_string(),
|
||||
selector: None,
|
||||
},
|
||||
"call-default".to_string(),
|
||||
)
|
||||
.unwrap();
|
||||
assert_eq!(
|
||||
created.summary,
|
||||
"Created Workdir wd-default on Runtime arcadia"
|
||||
);
|
||||
let requests = client.requests();
|
||||
let body: serde_json::Value =
|
||||
serde_json::from_str(requests[0].body.as_deref().unwrap()).unwrap();
|
||||
assert!(body.get("runtime_id").is_none());
|
||||
assert_eq!(body["operation_id"], "call-default");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn invalid_or_extra_inputs_are_rejected_before_workspace_request() {
|
||||
let client = Arc::new(RecordingWorkspaceClient::new(Vec::new()));
|
||||
let backend = WorkspaceHttpWorkdirBackend::new(client.clone());
|
||||
let error = backend
|
||||
.create(WorkdirCreateInput {
|
||||
runtime_id: " ".to_string(),
|
||||
.create(
|
||||
WorkdirCreateInput {
|
||||
runtime_id: Some(" ".to_string()),
|
||||
repository_id: "main".to_string(),
|
||||
selector: None,
|
||||
})
|
||||
},
|
||||
"call-invalid".to_string(),
|
||||
)
|
||||
.unwrap_err();
|
||||
assert!(matches!(error, ToolError::InvalidArgument(_)));
|
||||
assert!(client.requests().is_empty());
|
||||
|
||||
@@ -873,12 +873,13 @@ impl WorkspaceHttpTicketBackend {
|
||||
})?),
|
||||
)
|
||||
.map(TicketBackendOperationResult::Ticket),
|
||||
TicketBackendOperation::QueueReady { id, .. } => Self::request_unit(
|
||||
TicketBackendOperation::QueueReady { id, .. } => Self::request(
|
||||
client,
|
||||
WorkspaceRequestMethod::Post,
|
||||
format!("{base}/{}/workflow/queue", Self::ticket_path(&id)),
|
||||
None,
|
||||
),
|
||||
)
|
||||
.map(TicketBackendOperationResult::QueueOutcome),
|
||||
TicketBackendOperation::Close { id, resolution } => Self::request_unit(
|
||||
client,
|
||||
WorkspaceRequestMethod::Post,
|
||||
@@ -1099,16 +1100,18 @@ impl TicketBackend for WorkspaceHttpTicketBackend {
|
||||
)
|
||||
}
|
||||
|
||||
fn queue_ready(&self, id: TicketIdOrSlug, queued_by: &str) -> TicketResult<()> {
|
||||
match self.invoke(TicketBackendOperation::QueueReady {
|
||||
fn queue_ready(
|
||||
&self,
|
||||
id: TicketIdOrSlug,
|
||||
queued_by: &str,
|
||||
) -> TicketResult<ticket::TicketQueueOutcome> {
|
||||
expect_ticket_result!(
|
||||
self.invoke(TicketBackendOperation::QueueReady {
|
||||
id,
|
||||
queued_by: queued_by.to_string(),
|
||||
})? {
|
||||
TicketBackendOperationResult::Unit => Ok(()),
|
||||
other => Err(TicketError::Conflict(format!(
|
||||
"unexpected ticket backend response: {other:?}"
|
||||
))),
|
||||
}
|
||||
}),
|
||||
TicketBackendOperationResult::QueueOutcome
|
||||
)
|
||||
}
|
||||
|
||||
fn close(&self, id: TicketIdOrSlug, resolution: MarkdownText) -> TicketResult<()> {
|
||||
|
||||
@@ -329,13 +329,13 @@ fn validate_reviewer_handoff(input: &SubWorkerSpawnInput) -> Result<(), ToolErro
|
||||
"reviewer handoff requires the explicit effective profile builtin:reviewer".to_string(),
|
||||
));
|
||||
}
|
||||
if input
|
||||
if !input
|
||||
.scope
|
||||
.iter()
|
||||
.any(|rule| matches!(rule.permission, PermissionInput::Write))
|
||||
{
|
||||
return Err(ToolError::InvalidArgument(
|
||||
"Merge Request Reviewer SubWorkers must have read-only delegated scope".to_string(),
|
||||
"Merge Request Reviewer SubWorkers must include writable delegated scope".to_string(),
|
||||
));
|
||||
}
|
||||
Ok(())
|
||||
@@ -1008,28 +1008,28 @@ mod tests {
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn reviewer_handoff_requires_explicit_builtin_profile_and_read_only_scope() {
|
||||
fn reviewer_handoff_requires_explicit_builtin_profile_and_writable_scope() {
|
||||
let valid: SubWorkerSpawnInput = serde_json::from_value(serde_json::json!({
|
||||
"name":"reviewer","task":"review","profile":"builtin:reviewer",
|
||||
"scope":[{"target":"work","permission":"read"}],
|
||||
"scope":[{"target":"work","permission":"write"}],
|
||||
"review":{"ticket_id":"T1"}
|
||||
}))
|
||||
.unwrap();
|
||||
assert!(validate_reviewer_handoff(&valid).is_ok());
|
||||
let wrong_profile: SubWorkerSpawnInput = serde_json::from_value(serde_json::json!({
|
||||
"name":"reviewer","task":"review","profile":"builtin:coder",
|
||||
"scope":[{"target":"work","permission":"read"}],
|
||||
"review":{"ticket_id":"T1"}
|
||||
}))
|
||||
.unwrap();
|
||||
assert!(validate_reviewer_handoff(&wrong_profile).is_err());
|
||||
let writable: SubWorkerSpawnInput = serde_json::from_value(serde_json::json!({
|
||||
"name":"reviewer","task":"review","profile":"builtin:reviewer",
|
||||
"scope":[{"target":"work","permission":"write"}],
|
||||
"review":{"ticket_id":"T1"}
|
||||
}))
|
||||
.unwrap();
|
||||
assert!(validate_reviewer_handoff(&writable).is_err());
|
||||
assert!(validate_reviewer_handoff(&wrong_profile).is_err());
|
||||
let read_only: SubWorkerSpawnInput = serde_json::from_value(serde_json::json!({
|
||||
"name":"reviewer","task":"review","profile":"builtin:reviewer",
|
||||
"scope":[{"target":"work","permission":"read"}],
|
||||
"review":{"ticket_id":"T1"}
|
||||
}))
|
||||
.unwrap();
|
||||
assert!(validate_reviewer_handoff(&read_only).is_err());
|
||||
}
|
||||
|
||||
fn abs_rule(path: &Path, permission: Permission) -> ScopeRule {
|
||||
@@ -1079,7 +1079,7 @@ extract_threshold = 4000
|
||||
}
|
||||
|
||||
#[tokio::test]
|
||||
async fn reviewer_profile_spawns_and_notifies_parent_controller() {
|
||||
async fn reviewer_profile_write_scope_exposes_command_tools_and_notifies_parent_controller() {
|
||||
let runtime = TempDir::new().unwrap();
|
||||
let workspace_root = runtime.path().join("project");
|
||||
let available_profiles = write_project_profile_registry(
|
||||
@@ -1140,7 +1140,7 @@ extract_threshold = 4000
|
||||
"task": "review immutable commit",
|
||||
"scope": [{
|
||||
"target": ".",
|
||||
"permission": "read",
|
||||
"permission": "write",
|
||||
"recursive": true
|
||||
}]
|
||||
});
|
||||
@@ -1171,11 +1171,10 @@ extract_threshold = 4000
|
||||
let record = registry
|
||||
.get_internal("reviewer-child")
|
||||
.expect("Internal reviewer registry record");
|
||||
assert!(record.installed_tools.iter().any(|name| name == "Read"));
|
||||
for denied in ["Write", "Edit", "Bash"] {
|
||||
for required in ["Read", "Write", "Edit", "Glob", "Grep", "Bash"] {
|
||||
assert!(
|
||||
!record.installed_tools.iter().any(|name| name == denied),
|
||||
"read-only child unexpectedly received {denied}: {:?}",
|
||||
record.installed_tools.iter().any(|name| name == required),
|
||||
"write-scoped child is missing {required}: {:?}",
|
||||
record.installed_tools
|
||||
);
|
||||
}
|
||||
|
||||
@@ -7,6 +7,88 @@
|
||||
use serde::{Deserialize, Serialize};
|
||||
use workdir::workspace::WorkingDirectorySummary;
|
||||
|
||||
/// Provider-neutral classification of an authoritative Repository source.
|
||||
///
|
||||
/// Local paths remain distinct from network Git transports so callers cannot
|
||||
/// accidentally treat an unmaterialized remote as a server-local filesystem path.
|
||||
#[derive(Debug, Clone, Copy, PartialEq, Eq, Serialize, Deserialize)]
|
||||
#[serde(rename_all = "snake_case")]
|
||||
pub enum RepositorySourceKind {
|
||||
LocalPath,
|
||||
File,
|
||||
Ssh,
|
||||
Http,
|
||||
Https,
|
||||
/// A legacy value that could not be classified during migration. It remains
|
||||
/// inspectable but every provider operation must fail closed.
|
||||
Invalid,
|
||||
}
|
||||
|
||||
impl RepositorySourceKind {
|
||||
pub const fn is_remote(self) -> bool {
|
||||
matches!(self, Self::Ssh | Self::Http | Self::Https)
|
||||
}
|
||||
|
||||
pub const fn as_str(self) -> &'static str {
|
||||
match self {
|
||||
Self::LocalPath => "local_path",
|
||||
Self::File => "file",
|
||||
Self::Ssh => "ssh",
|
||||
Self::Http => "http",
|
||||
Self::Https => "https",
|
||||
Self::Invalid => "invalid",
|
||||
}
|
||||
}
|
||||
|
||||
pub fn parse(value: &str) -> Option<Self> {
|
||||
Some(match value {
|
||||
"local_path" => Self::LocalPath,
|
||||
"file" => Self::File,
|
||||
"ssh" => Self::Ssh,
|
||||
"http" => Self::Http,
|
||||
"https" => Self::Https,
|
||||
"invalid" => Self::Invalid,
|
||||
_ => return None,
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
/// Stable Repository source identity stored by Workspace authority.
|
||||
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
|
||||
pub struct RepositorySource {
|
||||
pub kind: RepositorySourceKind,
|
||||
/// Canonical source representation. This is an absolute local path for
|
||||
/// `local_path`, and a normalized URI/remote specification otherwise.
|
||||
pub uri: String,
|
||||
}
|
||||
|
||||
#[derive(Debug, Clone, Copy, PartialEq, Eq, Serialize, Deserialize)]
|
||||
#[serde(rename_all = "snake_case")]
|
||||
pub enum RepositoryObservedStatus {
|
||||
Unverified,
|
||||
Ready,
|
||||
Invalid,
|
||||
}
|
||||
|
||||
impl RepositoryObservedStatus {
|
||||
pub const fn as_str(self) -> &'static str {
|
||||
match self {
|
||||
Self::Unverified => "unverified",
|
||||
Self::Ready => "ready",
|
||||
Self::Invalid => "invalid",
|
||||
}
|
||||
}
|
||||
|
||||
pub fn parse(value: &str) -> Option<Self> {
|
||||
Some(match value {
|
||||
"unverified" => Self::Unverified,
|
||||
"ready" => Self::Ready,
|
||||
"invalid" => Self::Invalid,
|
||||
_ => return None,
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
pub const TICKET_RELATIONS_QUERY_PATH: &str = "/tickets/relations/search";
|
||||
pub const TICKET_ORCHESTRATION_PLANS_QUERY_PATH: &str = "/tickets/orchestration-plans/search";
|
||||
|
||||
|
||||
@@ -176,8 +176,28 @@ fn actor_for_user<S: ControlPlaneStore + ?Sized>(
|
||||
}))
|
||||
}
|
||||
|
||||
pub fn session_set_cookie(cookie_name: &str, token: &str, max_age_seconds: i64) -> String {
|
||||
format!("{cookie_name}={token}; Max-Age={max_age_seconds}; Path=/; HttpOnly; SameSite=Lax")
|
||||
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
|
||||
pub struct SessionCookiePolicy<'a> {
|
||||
pub cookie_name: &'a str,
|
||||
pub path: &'a str,
|
||||
pub domain: Option<&'a str>,
|
||||
pub secure: bool,
|
||||
}
|
||||
|
||||
pub fn session_set_cookie(
|
||||
policy: SessionCookiePolicy<'_>,
|
||||
token: &str,
|
||||
max_age_seconds: i64,
|
||||
) -> String {
|
||||
let domain = policy
|
||||
.domain
|
||||
.map(|domain| format!("; Domain={domain}"))
|
||||
.unwrap_or_default();
|
||||
let secure = if policy.secure { "; Secure" } else { "" };
|
||||
format!(
|
||||
"{}={token}; Max-Age={max_age_seconds}; Path={}; HttpOnly; SameSite=Lax{domain}{secure}",
|
||||
policy.cookie_name, policy.path
|
||||
)
|
||||
}
|
||||
|
||||
pub fn auth_error(code: &str, message: &str) -> Error {
|
||||
|
||||
@@ -704,6 +704,15 @@ impl SqliteWorkspaceAuthority {
|
||||
&self,
|
||||
reference: &str,
|
||||
request: TicketShowRequest,
|
||||
) -> Result<TicketDetail> {
|
||||
self.read_ticket_detail_with_backend(reference, request, &self.ticket_backend)
|
||||
}
|
||||
|
||||
pub(crate) fn read_ticket_detail_with_backend(
|
||||
&self,
|
||||
reference: &str,
|
||||
request: TicketShowRequest,
|
||||
backend: &SqliteTicketBackend,
|
||||
) -> Result<TicketDetail> {
|
||||
let id = self
|
||||
.store
|
||||
@@ -713,16 +722,19 @@ impl SqliteWorkspaceAuthority {
|
||||
reference,
|
||||
)?
|
||||
.ok_or_else(|| Error::Ticket(ticket::TicketError::NotFound(reference.to_string())))?;
|
||||
let ticket = self.ticket_backend.show(TicketIdOrSlug::Id(id))?;
|
||||
self.ticket_detail_from_ticket(ticket, request)
|
||||
let ticket = backend.show(TicketIdOrSlug::Id(id))?;
|
||||
self.ticket_detail_from_ticket(ticket, request, backend)
|
||||
}
|
||||
|
||||
fn ticket_detail_from_ticket(
|
||||
&self,
|
||||
ticket: ticket::Ticket,
|
||||
request: TicketShowRequest,
|
||||
dependency_backend: &SqliteTicketBackend,
|
||||
) -> Result<TicketDetail> {
|
||||
let id = ticket.meta.id.as_str();
|
||||
let dependency_check =
|
||||
dependency_backend.dependency_check(TicketIdOrSlug::Id(id.to_string()))?;
|
||||
let (body, body_truncated) =
|
||||
truncate_body(ticket.document.body.as_str(), DETAIL_BODY_LIMIT);
|
||||
let event_limit = request
|
||||
@@ -822,6 +834,27 @@ impl SqliteWorkspaceAuthority {
|
||||
.any(|assignment| assignment.role == TicketAssignmentRole::Coder);
|
||||
let has_target = ticket.meta.repository_id.is_some() && ticket.meta.ref_selector.is_some();
|
||||
let has_blockers = !ticket.relations.blockers.is_empty();
|
||||
let mut queue_assignment_blockers = Vec::new();
|
||||
for ticket_id in &dependency_check.queue_tickets {
|
||||
let assignments = self
|
||||
.store
|
||||
.list_current_ticket_role_assignments(&self.workspace_id, ticket_id)?;
|
||||
if !assignments
|
||||
.iter()
|
||||
.any(|assignment| assignment.role == TicketAssignmentRole::Orchestrator)
|
||||
{
|
||||
queue_assignment_blockers.push(format!(
|
||||
"Ticket {ticket_id} requires an active Orchestrator assignment"
|
||||
));
|
||||
}
|
||||
if assignments
|
||||
.iter()
|
||||
.any(|assignment| assignment.role == TicketAssignmentRole::Coder)
|
||||
{
|
||||
queue_assignment_blockers
|
||||
.push(format!("Ticket {ticket_id} has an active Coder assignment"));
|
||||
}
|
||||
}
|
||||
let mut assignment_diagnostics = Vec::new();
|
||||
if let Some(legacy_assignee) = ticket
|
||||
.meta
|
||||
@@ -833,6 +866,19 @@ impl SqliteWorkspaceAuthority {
|
||||
"legacy Ticket assignee `{legacy_assignee}` is not assignment authority"
|
||||
));
|
||||
}
|
||||
let mut action_blockers = Vec::new();
|
||||
if !has_target {
|
||||
action_blockers.push("Ticket target is required".to_string());
|
||||
}
|
||||
if !dependency_check.queue_guard.can_queue_for_orchestrator {
|
||||
if let Some(reason) = dependency_check.queue_guard.blocked_reason.clone() {
|
||||
action_blockers.push(reason);
|
||||
} else if let Some(reason) = dependency_check.queue_guard.reason.clone() {
|
||||
action_blockers.push(reason);
|
||||
}
|
||||
}
|
||||
let queue_assignments_valid = queue_assignment_blockers.is_empty();
|
||||
action_blockers.extend(queue_assignment_blockers);
|
||||
let action_eligibility = TicketActionEligibility {
|
||||
can_assign_orchestrator: matches!(
|
||||
ticket.meta.workflow_state,
|
||||
@@ -848,19 +894,15 @@ impl SqliteWorkspaceAuthority {
|
||||
&& has_orchestrator
|
||||
&& !has_coder
|
||||
&& has_target
|
||||
&& !has_blockers,
|
||||
&& dependency_check.queue_guard.can_queue_for_orchestrator
|
||||
&& queue_assignments_valid,
|
||||
can_start_manual_coder: ticket.meta.workflow_state == TicketWorkflowState::Ready
|
||||
&& !has_orchestrator
|
||||
&& !has_coder
|
||||
&& has_target
|
||||
&& !has_blockers,
|
||||
blockers: [
|
||||
(!has_target).then_some("Ticket target is required".to_string()),
|
||||
has_blockers.then_some("unresolved blocking relations remain".to_string()),
|
||||
]
|
||||
.into_iter()
|
||||
.flatten()
|
||||
.collect(),
|
||||
queue_tickets: dependency_check.queue_tickets.clone(),
|
||||
blockers: action_blockers,
|
||||
};
|
||||
let merge_request = match self.merge_request_store.get(&self.workspace_id, id) {
|
||||
Ok(request) => {
|
||||
@@ -1084,6 +1126,7 @@ impl TicketAuthority for SqliteWorkspaceAuthority {
|
||||
event_limit: Some(TICKET_EVENT_LIMIT),
|
||||
event_cursor: None,
|
||||
},
|
||||
&self.ticket_backend,
|
||||
)?;
|
||||
if ticket_matches_query(
|
||||
&summary,
|
||||
@@ -2927,7 +2970,7 @@ mod tests {
|
||||
async fn sqlite_workspace_authority_reads_sqlite_records_without_filesystem_authority() {
|
||||
let dir = tempfile::tempdir().unwrap();
|
||||
write_ticket(dir.path(), "00000000001J2", "Read bridge", "ready");
|
||||
write_ticket(dir.path(), "00000000001J5", "Second ticket", "planning");
|
||||
write_ticket(dir.path(), "00000000001J5", "Second ticket", "queued");
|
||||
write_ticket(dir.path(), "00000000001J6", "Third ticket", "planning");
|
||||
let db_path = dir.path().join("workspace.db");
|
||||
let store = SqliteWorkspaceStore::open(&db_path).unwrap();
|
||||
@@ -3038,10 +3081,22 @@ VALUES ('workspace-test', 'ticket', 4);
|
||||
.ticket_backend
|
||||
.add_ticket_relation(
|
||||
TicketIdOrSlug::Id("00000000001J2".to_string()),
|
||||
ticket::NewTicketRelation {
|
||||
kind: ticket::TicketRelationKind::DependsOn,
|
||||
target: "00000000001J5".to_string(),
|
||||
note: Some("queued dependency with a transitive blocker".to_string()),
|
||||
author: Some("tester".to_string()),
|
||||
},
|
||||
)
|
||||
.unwrap();
|
||||
authority
|
||||
.ticket_backend
|
||||
.add_ticket_relation(
|
||||
TicketIdOrSlug::Id("00000000001J5".to_string()),
|
||||
ticket::NewTicketRelation {
|
||||
kind: ticket::TicketRelationKind::DependsOn,
|
||||
target: "00000000001J6".to_string(),
|
||||
note: Some("separate dependency relation".to_string()),
|
||||
note: Some("transitive planning dependency".to_string()),
|
||||
author: Some("tester".to_string()),
|
||||
},
|
||||
)
|
||||
@@ -3056,6 +3111,14 @@ VALUES ('workspace-test', 'ticket', 4);
|
||||
assert_eq!(ticket_by_key.id, tickets.items[0].id);
|
||||
|
||||
let ticket = authority.ticket("00000000001J2").unwrap();
|
||||
assert!(!ticket.action_eligibility.can_queue);
|
||||
assert!(
|
||||
ticket
|
||||
.action_eligibility
|
||||
.blockers
|
||||
.iter()
|
||||
.any(|reason| reason.contains("00000000001J6"))
|
||||
);
|
||||
assert!(ticket.body.contains("Ticket body"));
|
||||
assert!(ticket.body_truncated);
|
||||
assert!(!ticket.body.contains("Deep Ticket marker"));
|
||||
@@ -3139,8 +3202,8 @@ VALUES ('workspace-test', 'ticket', 4);
|
||||
assert!(note_only_kind.items.is_empty());
|
||||
let crossed_relation_filters = authority
|
||||
.query_tickets(TicketQueryRequest {
|
||||
related_ticket_id: Some("00000000001J5".to_string()),
|
||||
relation_kind: Some("depends_on".to_string()),
|
||||
related_ticket_id: Some("00000000001J6".to_string()),
|
||||
relation_kind: Some("related".to_string()),
|
||||
..TicketQueryRequest::default()
|
||||
})
|
||||
.unwrap();
|
||||
|
||||
@@ -471,14 +471,18 @@ fn resolve_repository(
|
||||
let provider =
|
||||
normalize_required_string("repository provider", &config.provider)?.to_ascii_lowercase();
|
||||
let uri = normalize_required_string("repository uri", &config.uri)?;
|
||||
let path = resolve_repository_uri(workspace_root, &id, &uri)?;
|
||||
let (source, path) = resolve_repository_source(workspace_root, &id, &uri)?;
|
||||
let display_name = normalize_optional_string(config.display_name.as_deref());
|
||||
let default_selector = normalize_optional_string(config.default_selector.as_deref());
|
||||
|
||||
Ok(ConfiguredRepository {
|
||||
id,
|
||||
provider,
|
||||
uri,
|
||||
source_fingerprint: crate::repository_source::repository_source_fingerprint(&source),
|
||||
source,
|
||||
source_revision: 1,
|
||||
observed_status: workspace_api::RepositoryObservedStatus::Unverified,
|
||||
observed_at: None,
|
||||
path,
|
||||
display_name,
|
||||
default_selector,
|
||||
@@ -517,13 +521,41 @@ fn validate_repository_id(id: &str) -> Result<()> {
|
||||
}
|
||||
}
|
||||
|
||||
fn resolve_repository_uri(workspace_root: &Path, id: &str, uri: &str) -> Result<PathBuf> {
|
||||
if uri.contains("://") {
|
||||
fn resolve_repository_source(
|
||||
workspace_root: &Path,
|
||||
id: &str,
|
||||
uri: &str,
|
||||
) -> Result<(workspace_api::RepositorySource, Option<PathBuf>)> {
|
||||
match crate::repository_source::parse_repository_source(uri) {
|
||||
Ok(source) => {
|
||||
let path = match source.kind {
|
||||
workspace_api::RepositorySourceKind::LocalPath => Some(PathBuf::from(&source.uri)),
|
||||
workspace_api::RepositorySourceKind::File => url::Url::parse(&source.uri)
|
||||
.ok()
|
||||
.and_then(|uri| uri.to_file_path().ok()),
|
||||
workspace_api::RepositorySourceKind::Ssh
|
||||
| workspace_api::RepositorySourceKind::Http
|
||||
| workspace_api::RepositorySourceKind::Https => None,
|
||||
workspace_api::RepositorySourceKind::Invalid => {
|
||||
return Err(Error::Config(format!(
|
||||
"repository `{id}` uses a remote URI, but remote repository materialization is not implemented"
|
||||
"repository `{id}` has an invalid source"
|
||||
)));
|
||||
}
|
||||
Ok(resolve_workspace_path(workspace_root, Path::new(uri)))
|
||||
};
|
||||
Ok((source, path))
|
||||
}
|
||||
Err(_) if !Path::new(uri).is_absolute() && !uri.contains("://") => {
|
||||
let path = resolve_workspace_path(workspace_root, Path::new(uri));
|
||||
let source = workspace_api::RepositorySource {
|
||||
kind: workspace_api::RepositorySourceKind::LocalPath,
|
||||
uri: path.to_string_lossy().into_owned(),
|
||||
};
|
||||
Ok((source, Some(path)))
|
||||
}
|
||||
Err(error) => Err(Error::Config(format!(
|
||||
"repository `{id}` has an invalid source: {error}"
|
||||
))),
|
||||
}
|
||||
}
|
||||
|
||||
pub(crate) fn resolve_remote_runtime(
|
||||
@@ -741,13 +773,13 @@ default_selector = "HEAD"
|
||||
|
||||
assert_eq!(repository.id, "main");
|
||||
assert_eq!(repository.provider, "git");
|
||||
assert_eq!(repository.path, dir.path());
|
||||
assert_eq!(repository.path.as_deref(), Some(dir.path()));
|
||||
assert_eq!(repository.display_name.as_deref(), Some("Main"));
|
||||
assert_eq!(repository.default_selector.as_deref(), Some("HEAD"));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn remote_repository_uri_fails_closed() {
|
||||
fn remote_repository_source_is_preserved_without_a_local_path() {
|
||||
let dir = tempfile::tempdir().unwrap();
|
||||
let config = WorkspaceBackendConfigFile::parse_str(
|
||||
r#"
|
||||
@@ -759,17 +791,15 @@ uri = "https://example.com/org/repo.git"
|
||||
"test",
|
||||
)
|
||||
.unwrap();
|
||||
let error = match config.resolve(dir.path(), identity()) {
|
||||
Ok(_) => panic!("remote repository URI should fail closed"),
|
||||
Err(error) => error,
|
||||
};
|
||||
let resolved = config.resolve(dir.path(), identity()).unwrap();
|
||||
let repository = &resolved.server.repositories[0];
|
||||
|
||||
assert!(
|
||||
error
|
||||
.to_string()
|
||||
.contains("remote repository materialization is not implemented"),
|
||||
"unexpected error: {error}"
|
||||
assert_eq!(
|
||||
repository.source.kind,
|
||||
workspace_api::RepositorySourceKind::Https
|
||||
);
|
||||
assert_eq!(repository.source.uri, "https://example.com/org/repo.git");
|
||||
assert!(repository.path.is_none());
|
||||
}
|
||||
|
||||
#[test]
|
||||
|
||||
@@ -20,12 +20,15 @@ pub mod records;
|
||||
#[cfg(feature = "typescript")]
|
||||
pub use records::ticket_api_typescript;
|
||||
pub mod repositories;
|
||||
pub mod repository_source;
|
||||
pub mod resource_broker;
|
||||
pub mod retention;
|
||||
pub mod runtime_settings;
|
||||
pub mod runtime_subscription;
|
||||
pub mod server;
|
||||
pub mod skills;
|
||||
pub mod store;
|
||||
pub mod workdir_create_operations;
|
||||
pub mod worker_source;
|
||||
pub mod workspace_catalog;
|
||||
mod workspace_subscription;
|
||||
|
||||
@@ -711,14 +711,15 @@ fn infer_workspace_root_from_repositories(
|
||||
)));
|
||||
};
|
||||
|
||||
let repository_path = PathBuf::from(&repository.uri);
|
||||
if !repository_path.is_absolute() {
|
||||
if repository.source.kind == workspace_api::RepositorySourceKind::Invalid {
|
||||
return Err(CliError(format!(
|
||||
"repository `{}` has relative URI `{}`; repository records used by serve must be absolute paths",
|
||||
repository.repository_id, repository.uri
|
||||
"repository `{}` has an invalid migrated source and cannot be used by serve",
|
||||
repository.repository_id
|
||||
)));
|
||||
}
|
||||
Ok(repository_path)
|
||||
Ok(ServerConfig::default_workspace_backend_data_root(
|
||||
&workspace.workspace_id,
|
||||
))
|
||||
}
|
||||
|
||||
fn parse_config_command(args: &[String]) -> Result<Command, CliError> {
|
||||
|
||||
@@ -296,6 +296,7 @@ pub struct TicketActionEligibility {
|
||||
pub can_unassign_orchestrator: bool,
|
||||
pub can_queue: bool,
|
||||
pub can_start_manual_coder: bool,
|
||||
pub queue_tickets: Vec<String>,
|
||||
pub blockers: Vec<String>,
|
||||
}
|
||||
|
||||
|
||||
@@ -5,6 +5,7 @@ use std::{
|
||||
};
|
||||
|
||||
use serde::{Deserialize, Serialize};
|
||||
use workspace_api::{RepositoryObservedStatus, RepositorySource};
|
||||
|
||||
pub type RepositoryId = String;
|
||||
pub type RepositorySelector = String;
|
||||
@@ -13,8 +14,12 @@ pub type RepositorySelector = String;
|
||||
pub struct ConfiguredRepository {
|
||||
pub id: RepositoryId,
|
||||
pub provider: String,
|
||||
pub uri: String,
|
||||
pub path: PathBuf,
|
||||
pub source: RepositorySource,
|
||||
pub source_revision: u64,
|
||||
pub source_fingerprint: String,
|
||||
pub observed_status: RepositoryObservedStatus,
|
||||
pub observed_at: Option<String>,
|
||||
pub path: Option<PathBuf>,
|
||||
pub display_name: Option<String>,
|
||||
pub default_selector: Option<RepositorySelector>,
|
||||
}
|
||||
@@ -25,6 +30,12 @@ pub struct RepositorySummary {
|
||||
pub display_name: String,
|
||||
pub kind: String,
|
||||
pub provider: String,
|
||||
pub source: RepositorySource,
|
||||
pub source_revision: u64,
|
||||
pub source_fingerprint: String,
|
||||
pub observed_status: RepositoryObservedStatus,
|
||||
#[serde(skip_serializing_if = "Option::is_none")]
|
||||
pub observed_at: Option<String>,
|
||||
#[serde(skip_serializing_if = "Option::is_none")]
|
||||
pub default_selector: Option<RepositorySelector>,
|
||||
pub record_authority: String,
|
||||
@@ -262,9 +273,17 @@ impl RepositoryRegistryReader {
|
||||
descendant: &str,
|
||||
) -> Result<(), RepositoryLookupError> {
|
||||
let repository = self.merge_repository(id)?;
|
||||
let repository_path =
|
||||
repository
|
||||
.path
|
||||
.as_ref()
|
||||
.ok_or_else(|| RepositoryLookupError::ProviderFailure {
|
||||
id: id.into(),
|
||||
operation: "repository source is not materialized for local Git access".into(),
|
||||
})?;
|
||||
let status = Command::new("git")
|
||||
.arg("-C")
|
||||
.arg(&repository.path)
|
||||
.arg(repository_path)
|
||||
.args(["merge-base", "--is-ancestor", ancestor, descendant])
|
||||
.status()
|
||||
.map_err(|_| RepositoryLookupError::ProviderFailure {
|
||||
@@ -306,7 +325,24 @@ impl RepositoryRegistryReader {
|
||||
.clone()
|
||||
.unwrap_or_else(|| repository.id.clone());
|
||||
let mut diagnostics = Vec::new();
|
||||
if repository.source.kind == workspace_api::RepositorySourceKind::Http {
|
||||
diagnostics.push(RepositoryDiagnostic {
|
||||
severity: "warning".to_string(),
|
||||
code: "repository_source_insecure_http".to_string(),
|
||||
message:
|
||||
"HTTP Repository source is unencrypted; prefer HTTPS or SSH when available."
|
||||
.to_string(),
|
||||
});
|
||||
}
|
||||
let git = match repository.provider.as_str() {
|
||||
"git" if repository.path.is_none() => {
|
||||
diagnostics.push(RepositoryDiagnostic {
|
||||
severity: "info".to_string(),
|
||||
code: "repository_source_unverified".to_string(),
|
||||
message: "Remote Repository source is registered but is not materialized for server-local inspection.".to_string(),
|
||||
});
|
||||
None
|
||||
}
|
||||
"git" => match self.inspect_git(repository) {
|
||||
Ok(git) => Some(git),
|
||||
Err(message) => {
|
||||
@@ -335,6 +371,11 @@ impl RepositoryRegistryReader {
|
||||
display_name,
|
||||
kind: repository.provider.clone(),
|
||||
provider: repository.provider.clone(),
|
||||
source: repository.source.clone(),
|
||||
source_revision: repository.source_revision,
|
||||
source_fingerprint: repository.source_fingerprint.clone(),
|
||||
observed_status: repository.observed_status,
|
||||
observed_at: repository.observed_at.clone(),
|
||||
default_selector: repository.default_selector.clone(),
|
||||
record_authority: "workspace-control-plane".to_string(),
|
||||
git,
|
||||
@@ -346,12 +387,15 @@ impl RepositoryRegistryReader {
|
||||
&self,
|
||||
repository: &ConfiguredRepository,
|
||||
) -> Result<GitRepositorySummary, String> {
|
||||
let head = git_stdout(&repository.path, ["rev-parse", "HEAD"])?;
|
||||
let branch = git_stdout(&repository.path, ["branch", "--show-current"])
|
||||
let path = repository.path.as_ref().ok_or_else(|| {
|
||||
"Repository source is not materialized for local Git inspection.".to_string()
|
||||
})?;
|
||||
let head = git_stdout(path, ["rev-parse", "HEAD"])?;
|
||||
let branch = git_stdout(path, ["branch", "--show-current"])
|
||||
.ok()
|
||||
.and_then(|value| non_empty_string(value.trim()));
|
||||
let status = git_stdout(&repository.path, ["status", "--porcelain"])?;
|
||||
let remotes = git_stdout(&repository.path, ["remote", "-v"])
|
||||
let status = git_stdout(path, ["status", "--porcelain"])?;
|
||||
let remotes = git_stdout(path, ["remote", "-v"])
|
||||
.map(|raw| parse_remotes(&raw))
|
||||
.unwrap_or_default();
|
||||
Ok(GitRepositorySummary {
|
||||
@@ -369,8 +413,11 @@ impl RepositoryRegistryReader {
|
||||
limit: usize,
|
||||
) -> Result<Vec<GitCommitSummary>, String> {
|
||||
let limit_arg = format!("-{limit}");
|
||||
let path = repository.path.as_ref().ok_or_else(|| {
|
||||
"Repository source is not materialized for local Git log access.".to_string()
|
||||
})?;
|
||||
let output = git_stdout(
|
||||
&repository.path,
|
||||
path,
|
||||
[
|
||||
"log",
|
||||
"--date=iso-strict",
|
||||
@@ -419,11 +466,16 @@ fn merge_git_stdout(
|
||||
operation: &str,
|
||||
args: &[&str],
|
||||
) -> Result<String, RepositoryLookupError> {
|
||||
git_stdout(&repository.path, args.iter().copied()).map_err(|_| {
|
||||
RepositoryLookupError::ProviderFailure {
|
||||
let path = repository
|
||||
.path
|
||||
.as_ref()
|
||||
.ok_or_else(|| RepositoryLookupError::ProviderFailure {
|
||||
id: repository.id.clone(),
|
||||
operation: "repository source is not materialized for local Git access".into(),
|
||||
})?;
|
||||
git_stdout(path, args.iter().copied()).map_err(|_| RepositoryLookupError::ProviderFailure {
|
||||
id: repository.id.clone(),
|
||||
operation: operation.into(),
|
||||
}
|
||||
})
|
||||
}
|
||||
|
||||
@@ -593,6 +645,47 @@ mod tests {
|
||||
assert_eq!(projection.diagnostics[0].code, "repository_config_empty");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn remote_source_is_visible_but_local_provider_operations_fail_closed() {
|
||||
let source = RepositorySource {
|
||||
kind: workspace_api::RepositorySourceKind::Ssh,
|
||||
uri: "git@example.test:org/repository.git".to_string(),
|
||||
};
|
||||
let reader = RepositoryRegistryReader::new(vec![ConfiguredRepository {
|
||||
id: "remote".into(),
|
||||
display_name: Some("Remote".into()),
|
||||
provider: "git".into(),
|
||||
source_fingerprint: crate::repository_source::repository_source_fingerprint(&source),
|
||||
source,
|
||||
source_revision: 1,
|
||||
observed_status: RepositoryObservedStatus::Unverified,
|
||||
observed_at: None,
|
||||
path: None,
|
||||
default_selector: Some("main".into()),
|
||||
}]);
|
||||
|
||||
let projection = reader.list();
|
||||
let summary = &projection.items[0];
|
||||
assert_eq!(
|
||||
summary.source.kind,
|
||||
workspace_api::RepositorySourceKind::Ssh
|
||||
);
|
||||
assert_eq!(
|
||||
summary.observed_status,
|
||||
RepositoryObservedStatus::Unverified
|
||||
);
|
||||
assert!(summary.git.is_none());
|
||||
assert_eq!(summary.diagnostics[0].code, "repository_source_unverified");
|
||||
|
||||
let repository = reader.merge_repository("remote").unwrap();
|
||||
let error = merge_git_stdout(&repository, "inspect", &["rev-parse", "HEAD"]).unwrap_err();
|
||||
assert!(matches!(
|
||||
error,
|
||||
RepositoryLookupError::ProviderFailure { operation, .. }
|
||||
if operation.contains("not materialized")
|
||||
));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn merge_evidence_is_resolved_by_repository_identity() {
|
||||
let temp = tempfile::tempdir().unwrap();
|
||||
@@ -675,12 +768,22 @@ mod tests {
|
||||
.success()
|
||||
);
|
||||
|
||||
let source_descriptor = RepositorySource {
|
||||
kind: workspace_api::RepositorySourceKind::LocalPath,
|
||||
uri: path.display().to_string(),
|
||||
};
|
||||
let reader = RepositoryRegistryReader::new(vec![ConfiguredRepository {
|
||||
id: "main".into(),
|
||||
display_name: Some("Main".into()),
|
||||
provider: "git".into(),
|
||||
path: path.to_path_buf(),
|
||||
uri: path.display().to_string(),
|
||||
source_fingerprint: crate::repository_source::repository_source_fingerprint(
|
||||
&source_descriptor,
|
||||
),
|
||||
source: source_descriptor,
|
||||
source_revision: 1,
|
||||
observed_status: RepositoryObservedStatus::Unverified,
|
||||
observed_at: None,
|
||||
path: Some(path.to_path_buf()),
|
||||
default_selector: Some("main".into()),
|
||||
}]);
|
||||
let target = reader.observe_merge_target("main", Some("main")).unwrap();
|
||||
|
||||
@@ -0,0 +1,230 @@
|
||||
use std::path::Path;
|
||||
|
||||
use sha2::{Digest, Sha256};
|
||||
use url::Url;
|
||||
use workspace_api::{RepositorySource, RepositorySourceKind};
|
||||
|
||||
use crate::{Error, Result};
|
||||
|
||||
const MAX_REPOSITORY_SOURCE_BYTES: usize = 4096;
|
||||
|
||||
/// Parse and canonicalize a user-authored Git source without accessing the
|
||||
/// filesystem or network.
|
||||
pub fn parse_repository_source(value: &str) -> Result<RepositorySource> {
|
||||
let value = value.trim();
|
||||
if value.is_empty() || value.len() > MAX_REPOSITORY_SOURCE_BYTES {
|
||||
return Err(Error::InvalidInput(format!(
|
||||
"initial repository source must be between 1 and {MAX_REPOSITORY_SOURCE_BYTES} bytes"
|
||||
)));
|
||||
}
|
||||
if value.chars().any(char::is_control) {
|
||||
return Err(Error::InvalidInput(
|
||||
"initial repository source must not contain control characters".to_string(),
|
||||
));
|
||||
}
|
||||
|
||||
if Path::new(value).is_absolute() {
|
||||
return Ok(RepositorySource {
|
||||
kind: RepositorySourceKind::LocalPath,
|
||||
uri: value.to_string(),
|
||||
});
|
||||
}
|
||||
|
||||
if is_scp_like_ssh(value) {
|
||||
validate_scp_like_ssh(value)?;
|
||||
return Ok(RepositorySource {
|
||||
kind: RepositorySourceKind::Ssh,
|
||||
uri: value.to_string(),
|
||||
});
|
||||
}
|
||||
|
||||
let parsed = Url::parse(value).map_err(|_| {
|
||||
Error::InvalidInput(
|
||||
"initial repository source must be an absolute local path or a supported Git URI"
|
||||
.to_string(),
|
||||
)
|
||||
})?;
|
||||
if parsed.query().is_some() || parsed.fragment().is_some() {
|
||||
return Err(Error::InvalidInput(
|
||||
"initial repository source must not contain query parameters or fragments".to_string(),
|
||||
));
|
||||
}
|
||||
if parsed.password().is_some() {
|
||||
return Err(Error::InvalidInput(
|
||||
"initial repository source must not embed a password or token".to_string(),
|
||||
));
|
||||
}
|
||||
|
||||
let kind = match parsed.scheme() {
|
||||
"file" => {
|
||||
if !parsed.username().is_empty() {
|
||||
return Err(Error::InvalidInput(
|
||||
"file repository URI must not contain user information".to_string(),
|
||||
));
|
||||
}
|
||||
if parsed.host_str().is_some_and(|host| host != "localhost") {
|
||||
return Err(Error::InvalidInput(
|
||||
"file repository URI host must be empty or localhost".to_string(),
|
||||
));
|
||||
}
|
||||
parsed.to_file_path().map_err(|_| {
|
||||
Error::InvalidInput("file repository URI must contain an absolute path".to_string())
|
||||
})?;
|
||||
RepositorySourceKind::File
|
||||
}
|
||||
"ssh" => {
|
||||
require_remote_host_and_path(&parsed)?;
|
||||
RepositorySourceKind::Ssh
|
||||
}
|
||||
"http" | "https" => {
|
||||
if !parsed.username().is_empty() {
|
||||
return Err(Error::InvalidInput(
|
||||
"HTTP repository URI must not contain user information".to_string(),
|
||||
));
|
||||
}
|
||||
require_remote_host_and_path(&parsed)?;
|
||||
if parsed.scheme() == "http" {
|
||||
RepositorySourceKind::Http
|
||||
} else {
|
||||
RepositorySourceKind::Https
|
||||
}
|
||||
}
|
||||
scheme => {
|
||||
return Err(Error::InvalidInput(format!(
|
||||
"unsupported initial repository source scheme `{scheme}`"
|
||||
)));
|
||||
}
|
||||
};
|
||||
|
||||
Ok(RepositorySource {
|
||||
kind,
|
||||
uri: parsed.to_string(),
|
||||
})
|
||||
}
|
||||
|
||||
/// Classify persisted pre-source-contract rows without guessing a usable remote
|
||||
/// when the legacy value is malformed. No filesystem or network access occurs.
|
||||
pub fn classify_legacy_repository_source(value: &str) -> RepositorySource {
|
||||
parse_repository_source(value).unwrap_or_else(|_| RepositorySource {
|
||||
kind: RepositorySourceKind::Invalid,
|
||||
uri: value.trim().to_string(),
|
||||
})
|
||||
}
|
||||
|
||||
pub fn repository_source_fingerprint(source: &RepositorySource) -> String {
|
||||
let payload = serde_json::to_vec(source).expect("Repository source serializes");
|
||||
let mut hasher = Sha256::new();
|
||||
hasher.update(b"yoi.repository-source.v1\0");
|
||||
hasher.update(payload);
|
||||
let digest = hasher.finalize();
|
||||
let mut encoded = String::with_capacity(digest.len() * 2);
|
||||
for byte in digest {
|
||||
use std::fmt::Write as _;
|
||||
write!(&mut encoded, "{byte:02x}").expect("writing to String cannot fail");
|
||||
}
|
||||
format!("sha256:{encoded}")
|
||||
}
|
||||
|
||||
fn require_remote_host_and_path(parsed: &Url) -> Result<()> {
|
||||
if parsed.host_str().is_none() || parsed.path().is_empty() || parsed.path() == "/" {
|
||||
return Err(Error::InvalidInput(
|
||||
"remote repository URI must contain a host and repository path".to_string(),
|
||||
));
|
||||
}
|
||||
Ok(())
|
||||
}
|
||||
|
||||
fn is_scp_like_ssh(value: &str) -> bool {
|
||||
!value.contains("://")
|
||||
&& value
|
||||
.split_once(':')
|
||||
.is_some_and(|(identity, _)| identity.contains('@'))
|
||||
}
|
||||
|
||||
fn validate_scp_like_ssh(value: &str) -> Result<()> {
|
||||
let (identity, path) = value.split_once(':').ok_or_else(|| {
|
||||
Error::InvalidInput("scp-like SSH source must contain `host:path`".to_string())
|
||||
})?;
|
||||
let (username, host) = identity.split_once('@').ok_or_else(|| {
|
||||
Error::InvalidInput("scp-like SSH source must contain `user@host:path`".to_string())
|
||||
})?;
|
||||
if username.is_empty()
|
||||
|| host.is_empty()
|
||||
|| path.is_empty()
|
||||
|| username.contains('@')
|
||||
|| username.contains(':')
|
||||
|| host.contains('@')
|
||||
|| path.starts_with('-')
|
||||
|| value.contains('?')
|
||||
|| value.contains('#')
|
||||
|| value.chars().any(char::is_whitespace)
|
||||
{
|
||||
return Err(Error::InvalidInput(
|
||||
"scp-like SSH source must use `user@host:path` without credentials or parameters"
|
||||
.to_string(),
|
||||
));
|
||||
}
|
||||
Ok(())
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
|
||||
#[test]
|
||||
fn parses_local_file_ssh_http_and_https_sources_without_io() {
|
||||
let cases = [
|
||||
("/runtime/repos/project", RepositorySourceKind::LocalPath),
|
||||
("file:///runtime/repos/project", RepositorySourceKind::File),
|
||||
(
|
||||
"ssh://git@example.test/org/project.git",
|
||||
RepositorySourceKind::Ssh,
|
||||
),
|
||||
(
|
||||
"git@example.test:org/project.git",
|
||||
RepositorySourceKind::Ssh,
|
||||
),
|
||||
(
|
||||
"http://git.test/org/project.git",
|
||||
RepositorySourceKind::Http,
|
||||
),
|
||||
(
|
||||
"https://git.test/org/project.git",
|
||||
RepositorySourceKind::Https,
|
||||
),
|
||||
];
|
||||
for (source, expected_kind) in cases {
|
||||
assert_eq!(parse_repository_source(source).unwrap().kind, expected_kind);
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn rejects_relative_unsupported_and_credential_bearing_sources() {
|
||||
for source in [
|
||||
"relative/project",
|
||||
"ftp://git.test/project.git",
|
||||
"https://user@git.test/project.git",
|
||||
"https://git.test/project.git?token=secret",
|
||||
"ssh://git:secret@git.test/project.git",
|
||||
"git@example.test:",
|
||||
"git:secret@example.test:org/project.git",
|
||||
"https://git.test/project.git\nother",
|
||||
] {
|
||||
assert!(
|
||||
parse_repository_source(source).is_err(),
|
||||
"accepted {source:?}"
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn fingerprint_uses_canonical_source_identity() {
|
||||
let first = parse_repository_source(" https://EXAMPLE.test/a/../project.git ").unwrap();
|
||||
let second = parse_repository_source("https://example.test/project.git").unwrap();
|
||||
assert_eq!(first, second);
|
||||
assert_eq!(
|
||||
repository_source_fingerprint(&first),
|
||||
repository_source_fingerprint(&second)
|
||||
);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,229 @@
|
||||
use config_source::ConfigSchemaContribution;
|
||||
use serde::Deserialize;
|
||||
|
||||
use crate::config_source::{
|
||||
WorkspaceConfigSchemaProvider, WorkspaceConfigState, evaluate_workspace_config_state,
|
||||
};
|
||||
use crate::{Error, Result};
|
||||
|
||||
const RUNTIME_SCHEMA_SOURCE: &str = r#"{
|
||||
runtime = {
|
||||
default_runtime_id = String default "";
|
||||
};
|
||||
}"#;
|
||||
|
||||
#[derive(Debug, Default)]
|
||||
pub struct RuntimeConfigSchemaProvider;
|
||||
|
||||
impl WorkspaceConfigSchemaProvider for RuntimeConfigSchemaProvider {
|
||||
fn contribution(&self) -> Result<ConfigSchemaContribution> {
|
||||
ConfigSchemaContribution::new("builtin:runtime", "runtime", "1", RUNTIME_SCHEMA_SOURCE)
|
||||
.map_err(|error| Error::Config(error.to_string()))
|
||||
}
|
||||
}
|
||||
|
||||
#[derive(Debug, Clone, PartialEq, Eq)]
|
||||
pub struct RuntimeConfigProjection {
|
||||
pub config_revision: u64,
|
||||
pub projection_digest: String,
|
||||
pub default_runtime_id: Option<String>,
|
||||
}
|
||||
|
||||
#[derive(Debug, Deserialize)]
|
||||
struct VirtualRuntimeConfig {
|
||||
runtime: VirtualRuntimeSection,
|
||||
}
|
||||
|
||||
#[derive(Debug, Deserialize)]
|
||||
#[serde(deny_unknown_fields)]
|
||||
struct VirtualRuntimeSection {
|
||||
default_runtime_id: String,
|
||||
}
|
||||
|
||||
pub fn project_runtime_from_workspace_config(
|
||||
workspace_id: &str,
|
||||
state: &WorkspaceConfigState,
|
||||
) -> Result<RuntimeConfigProjection> {
|
||||
let has_runtime_schema = state
|
||||
.contract
|
||||
.schema_bundle
|
||||
.contributions
|
||||
.iter()
|
||||
.any(|entry| entry.provider_id == "builtin:runtime");
|
||||
if !has_runtime_schema {
|
||||
return Ok(RuntimeConfigProjection {
|
||||
config_revision: state.snapshot.revision,
|
||||
projection_digest: state.projection_digest.clone(),
|
||||
default_runtime_id: None,
|
||||
});
|
||||
}
|
||||
|
||||
let evaluation = evaluate_workspace_config_state(state, state.contract.schema_bundle.clone())?;
|
||||
if evaluation.projection_digest != state.projection_digest {
|
||||
return Err(Error::RegistryInconsistency(format!(
|
||||
"Runtime projection digest mismatch for Workspace {workspace_id}"
|
||||
)));
|
||||
}
|
||||
let projected = evaluation.projections.first().ok_or_else(|| {
|
||||
Error::RegistryInconsistency("Workspace config has no active projection".to_string())
|
||||
})?;
|
||||
let config: VirtualRuntimeConfig = serde_json::from_value(projected.data_json.clone())
|
||||
.map_err(|error| Error::RegistryInconsistency(error.to_string()))?;
|
||||
let default_runtime_id = normalize_runtime_id(&config.runtime.default_runtime_id)?;
|
||||
Ok(RuntimeConfigProjection {
|
||||
config_revision: state.snapshot.revision,
|
||||
projection_digest: evaluation.projection_digest,
|
||||
default_runtime_id,
|
||||
})
|
||||
}
|
||||
|
||||
fn normalize_runtime_id(value: &str) -> Result<Option<String>> {
|
||||
let value = value.trim();
|
||||
if value.is_empty() {
|
||||
return Ok(None);
|
||||
}
|
||||
if value.chars().any(char::is_control) {
|
||||
return Err(Error::InvalidRuntimeIdentifier {
|
||||
kind: "runtime_id".to_string(),
|
||||
value: "[redacted invalid value]".to_string(),
|
||||
});
|
||||
}
|
||||
Ok(Some(value.to_string()))
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use config_source::{ConfigContentType, ConfigEntry, ConfigTreeSnapshot, VirtualPath};
|
||||
|
||||
use super::*;
|
||||
|
||||
fn state(source: &str) -> WorkspaceConfigState {
|
||||
let bundle =
|
||||
config_source::WorkspaceConfigSchemaBundle::compose([RuntimeConfigSchemaProvider
|
||||
.contribution()
|
||||
.unwrap()])
|
||||
.unwrap();
|
||||
let snapshot = ConfigTreeSnapshot::from_entries(
|
||||
7,
|
||||
[ConfigEntry::new(
|
||||
VirtualPath::parse("main.dcdl").unwrap(),
|
||||
ConfigContentType::Decodal,
|
||||
source,
|
||||
)
|
||||
.unwrap()],
|
||||
)
|
||||
.unwrap();
|
||||
let contract = config_source::ToolchainContract::with_schema_bundle(
|
||||
config_source::DEFAULT_SCHEMA_VERSION,
|
||||
vec![VirtualPath::parse("main.dcdl").unwrap()],
|
||||
config_source::DEFAULT_IMPORT_POLICY_VERSION,
|
||||
bundle,
|
||||
);
|
||||
let projection_digest = config_source::SnapshotEnvironment::new(snapshot.clone())
|
||||
.evaluate_contract(&contract)
|
||||
.unwrap()
|
||||
.projection_digest;
|
||||
WorkspaceConfigState {
|
||||
snapshot,
|
||||
contract,
|
||||
projection_digest,
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn runtime_projection_reads_default_and_preserves_revision_evidence() {
|
||||
let projection = project_runtime_from_workspace_config(
|
||||
"workspace",
|
||||
&state(
|
||||
r#"{ runtime = { default_runtime_id = "arcadia"; }; } as WorkspaceConfigSchema"#,
|
||||
),
|
||||
)
|
||||
.unwrap();
|
||||
assert_eq!(projection.default_runtime_id.as_deref(), Some("arcadia"));
|
||||
assert_eq!(projection.config_revision, 7);
|
||||
assert!(!projection.projection_digest.is_empty());
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn runtime_projection_treats_missing_default_as_unconfigured() {
|
||||
let projection = project_runtime_from_workspace_config(
|
||||
"workspace",
|
||||
&state("{} as WorkspaceConfigSchema"),
|
||||
)
|
||||
.unwrap();
|
||||
assert_eq!(projection.default_runtime_id, None);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn runtime_projection_treats_pre_runtime_schema_bundle_as_unconfigured() {
|
||||
let bundle =
|
||||
config_source::WorkspaceConfigSchemaBundle::compose([ConfigSchemaContribution::new(
|
||||
"builtin:legacy",
|
||||
"legacy",
|
||||
"1",
|
||||
"{ legacy = { enabled = Bool default false; }; }",
|
||||
)
|
||||
.unwrap()])
|
||||
.unwrap();
|
||||
let snapshot = ConfigTreeSnapshot::from_entries(
|
||||
6,
|
||||
[ConfigEntry::new(
|
||||
VirtualPath::parse("main.dcdl").unwrap(),
|
||||
ConfigContentType::Decodal,
|
||||
"{ legacy = { enabled = true; }; } as WorkspaceConfigSchema",
|
||||
)
|
||||
.unwrap()],
|
||||
)
|
||||
.unwrap();
|
||||
let contract = config_source::ToolchainContract::with_schema_bundle(
|
||||
config_source::DEFAULT_SCHEMA_VERSION,
|
||||
vec![VirtualPath::parse("main.dcdl").unwrap()],
|
||||
config_source::DEFAULT_IMPORT_POLICY_VERSION,
|
||||
bundle,
|
||||
);
|
||||
let projection_digest = config_source::SnapshotEnvironment::new(snapshot.clone())
|
||||
.evaluate_contract(&contract)
|
||||
.unwrap()
|
||||
.projection_digest;
|
||||
let state = WorkspaceConfigState {
|
||||
snapshot,
|
||||
contract,
|
||||
projection_digest: projection_digest.clone(),
|
||||
};
|
||||
|
||||
let projection = project_runtime_from_workspace_config("workspace", &state).unwrap();
|
||||
assert_eq!(projection.default_runtime_id, None);
|
||||
assert_eq!(projection.config_revision, 6);
|
||||
assert_eq!(projection.projection_digest, projection_digest);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn runtime_schema_rejects_non_string_default() {
|
||||
let bundle =
|
||||
config_source::WorkspaceConfigSchemaBundle::compose([RuntimeConfigSchemaProvider
|
||||
.contribution()
|
||||
.unwrap()])
|
||||
.unwrap();
|
||||
let snapshot = ConfigTreeSnapshot::from_entries(
|
||||
1,
|
||||
[ConfigEntry::new(
|
||||
VirtualPath::parse("main.dcdl").unwrap(),
|
||||
ConfigContentType::Decodal,
|
||||
"{ runtime = { default_runtime_id = 42; }; } as WorkspaceConfigSchema",
|
||||
)
|
||||
.unwrap()],
|
||||
)
|
||||
.unwrap();
|
||||
let contract = config_source::ToolchainContract::with_schema_bundle(
|
||||
config_source::DEFAULT_SCHEMA_VERSION,
|
||||
vec![VirtualPath::parse("main.dcdl").unwrap()],
|
||||
config_source::DEFAULT_IMPORT_POLICY_VERSION,
|
||||
bundle,
|
||||
);
|
||||
assert!(
|
||||
config_source::SnapshotEnvironment::new(snapshot)
|
||||
.evaluate_contract(&contract)
|
||||
.is_err()
|
||||
);
|
||||
}
|
||||
}
|
||||
+2546
-224
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,246 @@
|
||||
use rusqlite::{OptionalExtension, params};
|
||||
use sha2::{Digest, Sha256};
|
||||
|
||||
use crate::store::WorkdirCreateOperationRecord;
|
||||
use crate::{Error, Result, SqliteWorkspaceStore};
|
||||
|
||||
pub fn request_fingerprint(
|
||||
repository_id: &str,
|
||||
selector: Option<&str>,
|
||||
requested_runtime_id: Option<&str>,
|
||||
) -> String {
|
||||
let mut hasher = Sha256::new();
|
||||
for value in [Some(repository_id), selector, requested_runtime_id] {
|
||||
match value {
|
||||
Some(value) => {
|
||||
hasher.update([1]);
|
||||
hasher.update((value.len() as u64).to_be_bytes());
|
||||
hasher.update(value.as_bytes());
|
||||
}
|
||||
None => hasher.update([0]),
|
||||
}
|
||||
}
|
||||
let digest = hasher.finalize();
|
||||
let mut encoded = String::with_capacity(digest.len() * 2);
|
||||
for byte in digest {
|
||||
use std::fmt::Write as _;
|
||||
write!(&mut encoded, "{byte:02x}").expect("writing to String cannot fail");
|
||||
}
|
||||
format!("sha256:{encoded}")
|
||||
}
|
||||
|
||||
impl SqliteWorkspaceStore {
|
||||
pub fn reserve_workdir_create_operation(
|
||||
&self,
|
||||
record: &WorkdirCreateOperationRecord,
|
||||
) -> Result<WorkdirCreateOperationRecord> {
|
||||
self.with_conn_mut(|conn| {
|
||||
let tx = conn.transaction()?;
|
||||
tx.execute(
|
||||
r#"INSERT OR IGNORE INTO workdir_create_operations (
|
||||
workspace_id, operation_id, request_fingerprint, repository_id, selector,
|
||||
requested_runtime_id, resolved_runtime_id, config_revision,
|
||||
config_projection_digest, working_directory_id, state, failure,
|
||||
created_at, updated_at
|
||||
) VALUES (?1, ?2, ?3, ?4, ?5, ?6, ?7, ?8, ?9, ?10, ?11, ?12, ?13, ?14)"#,
|
||||
params![
|
||||
record.workspace_id,
|
||||
record.operation_id,
|
||||
record.request_fingerprint,
|
||||
record.repository_id,
|
||||
record.selector,
|
||||
record.requested_runtime_id,
|
||||
record.resolved_runtime_id,
|
||||
record.config_revision as i64,
|
||||
record.config_projection_digest,
|
||||
record.working_directory_id,
|
||||
record.state,
|
||||
record.failure,
|
||||
record.created_at,
|
||||
record.updated_at,
|
||||
],
|
||||
)?;
|
||||
let persisted =
|
||||
read_workdir_create_operation(&tx, &record.workspace_id, &record.operation_id)?
|
||||
.ok_or_else(|| {
|
||||
Error::RegistryInconsistency(format!(
|
||||
"Workdir create operation `{}` was not persisted",
|
||||
record.operation_id
|
||||
))
|
||||
})?;
|
||||
if persisted.request_fingerprint != record.request_fingerprint {
|
||||
return Err(Error::InvalidInput(format!(
|
||||
"Workdir create operation `{}` was reused with different input",
|
||||
record.operation_id
|
||||
)));
|
||||
}
|
||||
tx.commit()?;
|
||||
Ok(persisted)
|
||||
})
|
||||
}
|
||||
|
||||
pub fn finish_workdir_create_operation(
|
||||
&self,
|
||||
workspace_id: &str,
|
||||
operation_id: &str,
|
||||
request_fingerprint: &str,
|
||||
succeeded: bool,
|
||||
failure: Option<&str>,
|
||||
updated_at: &str,
|
||||
) -> Result<WorkdirCreateOperationRecord> {
|
||||
self.with_conn_mut(|conn| {
|
||||
let changed = conn.execute(
|
||||
r#"UPDATE workdir_create_operations
|
||||
SET state = ?1, failure = ?2, updated_at = ?3
|
||||
WHERE workspace_id = ?4 AND operation_id = ?5
|
||||
AND request_fingerprint = ?6"#,
|
||||
params![
|
||||
if succeeded { "succeeded" } else { "failed" },
|
||||
failure,
|
||||
updated_at,
|
||||
workspace_id,
|
||||
operation_id,
|
||||
request_fingerprint,
|
||||
],
|
||||
)?;
|
||||
if changed != 1 {
|
||||
return Err(Error::RegistryInconsistency(format!(
|
||||
"Workdir create operation `{operation_id}` could not be finalized"
|
||||
)));
|
||||
}
|
||||
read_workdir_create_operation(conn, workspace_id, operation_id)?.ok_or_else(|| {
|
||||
Error::RegistryInconsistency(format!(
|
||||
"Workdir create operation `{operation_id}` disappeared"
|
||||
))
|
||||
})
|
||||
})
|
||||
}
|
||||
|
||||
pub fn load_workdir_create_operation(
|
||||
&self,
|
||||
workspace_id: &str,
|
||||
operation_id: &str,
|
||||
) -> Result<Option<WorkdirCreateOperationRecord>> {
|
||||
self.with_conn(|conn| read_workdir_create_operation(conn, workspace_id, operation_id))
|
||||
}
|
||||
}
|
||||
|
||||
fn read_workdir_create_operation(
|
||||
conn: &rusqlite::Connection,
|
||||
workspace_id: &str,
|
||||
operation_id: &str,
|
||||
) -> Result<Option<WorkdirCreateOperationRecord>> {
|
||||
conn.query_row(
|
||||
r#"SELECT workspace_id, operation_id, request_fingerprint, repository_id, selector,
|
||||
requested_runtime_id, resolved_runtime_id, config_revision,
|
||||
config_projection_digest, working_directory_id, state, failure,
|
||||
created_at, updated_at
|
||||
FROM workdir_create_operations
|
||||
WHERE workspace_id = ?1 AND operation_id = ?2"#,
|
||||
params![workspace_id, operation_id],
|
||||
|row| {
|
||||
Ok(WorkdirCreateOperationRecord {
|
||||
workspace_id: row.get(0)?,
|
||||
operation_id: row.get(1)?,
|
||||
request_fingerprint: row.get(2)?,
|
||||
repository_id: row.get(3)?,
|
||||
selector: row.get(4)?,
|
||||
requested_runtime_id: row.get(5)?,
|
||||
resolved_runtime_id: row.get(6)?,
|
||||
config_revision: row.get::<_, i64>(7)? as u64,
|
||||
config_projection_digest: row.get(8)?,
|
||||
working_directory_id: row.get(9)?,
|
||||
state: row.get(10)?,
|
||||
failure: row.get(11)?,
|
||||
created_at: row.get(12)?,
|
||||
updated_at: row.get(13)?,
|
||||
})
|
||||
},
|
||||
)
|
||||
.optional()
|
||||
.map_err(Error::from)
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
use crate::store::{ControlPlaneStore, RepositoryRecord, WorkspaceRecord};
|
||||
|
||||
#[test]
|
||||
fn retry_keeps_resolved_config_evidence_and_rejects_changed_input() {
|
||||
let store = SqliteWorkspaceStore::in_memory().unwrap();
|
||||
futures::executor::block_on(store.upsert_workspace(&WorkspaceRecord {
|
||||
workspace_id: "workspace".to_string(),
|
||||
owner_account_id: None,
|
||||
display_name: "Workspace".to_string(),
|
||||
state: "active".to_string(),
|
||||
created_at: "2026-08-24T00:00:00Z".to_string(),
|
||||
updated_at: "2026-08-24T00:00:00Z".to_string(),
|
||||
}))
|
||||
.unwrap();
|
||||
store
|
||||
.upsert_repository(&RepositoryRecord {
|
||||
workspace_id: "workspace".to_string(),
|
||||
repository_id: "main".to_string(),
|
||||
name: "main".to_string(),
|
||||
kind: "git".to_string(),
|
||||
provider: Some("git".to_string()),
|
||||
source: workspace_api::RepositorySource {
|
||||
kind: workspace_api::RepositorySourceKind::LocalPath,
|
||||
uri: "/tmp/main".to_string(),
|
||||
},
|
||||
default_ref: Some("develop".to_string()),
|
||||
source_revision: 1,
|
||||
source_fingerprint: "sha256:test".to_string(),
|
||||
observed_status: workspace_api::RepositoryObservedStatus::Unverified,
|
||||
observed_at: None,
|
||||
created_at: "2026-08-24T00:00:00Z".to_string(),
|
||||
updated_at: "2026-08-24T00:00:00Z".to_string(),
|
||||
})
|
||||
.unwrap();
|
||||
let record = WorkdirCreateOperationRecord {
|
||||
workspace_id: "workspace".to_string(),
|
||||
operation_id: "call-1".to_string(),
|
||||
request_fingerprint: request_fingerprint("main", Some("develop"), None),
|
||||
repository_id: "main".to_string(),
|
||||
selector: Some("develop".to_string()),
|
||||
requested_runtime_id: None,
|
||||
resolved_runtime_id: "arcadia".to_string(),
|
||||
config_revision: 7,
|
||||
config_projection_digest: "sha256:projection".to_string(),
|
||||
working_directory_id: "wd-1".to_string(),
|
||||
state: "pending".to_string(),
|
||||
failure: None,
|
||||
created_at: "2026-08-24T00:00:00Z".to_string(),
|
||||
updated_at: "2026-08-24T00:00:00Z".to_string(),
|
||||
};
|
||||
assert_eq!(
|
||||
store.reserve_workdir_create_operation(&record).unwrap(),
|
||||
record
|
||||
);
|
||||
let mut changed_resolution = record.clone();
|
||||
changed_resolution.resolved_runtime_id = "other".to_string();
|
||||
changed_resolution.config_revision = 8;
|
||||
assert_eq!(
|
||||
store
|
||||
.reserve_workdir_create_operation(&changed_resolution)
|
||||
.unwrap(),
|
||||
record
|
||||
);
|
||||
assert_eq!(
|
||||
store
|
||||
.load_workdir_create_operation("workspace", "call-1")
|
||||
.unwrap(),
|
||||
Some(record.clone())
|
||||
);
|
||||
let mut changed_input = record.clone();
|
||||
changed_input.request_fingerprint = request_fingerprint("main", Some("main"), None);
|
||||
assert!(
|
||||
store
|
||||
.reserve_workdir_create_operation(&changed_input)
|
||||
.unwrap_err()
|
||||
.to_string()
|
||||
.contains("reused with different input")
|
||||
);
|
||||
}
|
||||
}
|
||||
@@ -3,14 +3,118 @@ use std::time::{SystemTime, UNIX_EPOCH};
|
||||
|
||||
use axum::http::HeaderMap;
|
||||
use worker_runtime::auth::{
|
||||
WorkerMutationActorKind, WorkerMutationOperation, WorkerMutationSourceClaims,
|
||||
WorkerMutationSourceExpectation, decode_worker_mutation_source_claims,
|
||||
verify_worker_mutation_source_proof,
|
||||
RuntimeRequestSourceExpectation, WorkerMutationActorKind, WorkerMutationOperation,
|
||||
WorkerMutationSourceClaims, WorkerMutationSourceExpectation,
|
||||
decode_runtime_request_source_claims, decode_worker_mutation_source_claims,
|
||||
verify_runtime_request_source, verify_worker_mutation_source_proof,
|
||||
};
|
||||
use worker_runtime::worker_source::InProcessWorkerMutationProof;
|
||||
|
||||
use crate::hosts::RemoteRuntimeConfig;
|
||||
use crate::server::WorkspaceApi;
|
||||
use crate::server::{ServerConfig, WorkspaceApi};
|
||||
use crate::store::ControlPlaneStore;
|
||||
|
||||
#[derive(Clone, Debug, PartialEq, Eq)]
|
||||
pub struct VerifiedRuntimeRequestSource {
|
||||
pub runtime_id: String,
|
||||
pub worker_id: Option<String>,
|
||||
}
|
||||
|
||||
pub async fn verify_runtime_request_source_proof(
|
||||
api: &WorkspaceApi,
|
||||
proof: &str,
|
||||
workspace_id: &str,
|
||||
permission: &str,
|
||||
method: &str,
|
||||
path: &str,
|
||||
body_digest: &str,
|
||||
) -> Result<VerifiedRuntimeRequestSource, WorkerMutationSourceProofError> {
|
||||
verify_runtime_request_source_proof_with_store(
|
||||
api.store.as_ref(),
|
||||
&api.config,
|
||||
proof,
|
||||
workspace_id,
|
||||
permission,
|
||||
method,
|
||||
path,
|
||||
body_digest,
|
||||
)
|
||||
.await
|
||||
}
|
||||
|
||||
#[allow(clippy::too_many_arguments)]
|
||||
pub async fn verify_runtime_request_source_proof_with_store(
|
||||
store: &dyn ControlPlaneStore,
|
||||
config: &ServerConfig,
|
||||
proof: &str,
|
||||
workspace_id: &str,
|
||||
permission: &str,
|
||||
method: &str,
|
||||
path: &str,
|
||||
body_digest: &str,
|
||||
) -> Result<VerifiedRuntimeRequestSource, WorkerMutationSourceProofError> {
|
||||
let unverified = decode_runtime_request_source_claims(proof)
|
||||
.map_err(|_| WorkerMutationSourceProofError::Invalid)?;
|
||||
let audience = remote_audience(config, &unverified.iss, workspace_id)?;
|
||||
let trusted = store
|
||||
.get_trusted_runtime(&unverified.iss)
|
||||
.await
|
||||
.map_err(|error| WorkerMutationSourceProofError::Authority(error.to_string()))?
|
||||
.filter(|record| record.revoked_at.is_none())
|
||||
.ok_or(WorkerMutationSourceProofError::RevokedRuntimeTrust)?;
|
||||
let trusted_for_workspace = trusted.workspace_id.as_deref() == Some(workspace_id)
|
||||
|| (unverified.iss == crate::hosts::EMBEDDED_RUNTIME_ID && trusted.workspace_id.is_none());
|
||||
if !trusted_for_workspace {
|
||||
return Err(WorkerMutationSourceProofError::WrongWorkspace);
|
||||
}
|
||||
let expected = RuntimeRequestSourceExpectation {
|
||||
identity_id: &unverified.iss,
|
||||
audience: audience.as_ref(),
|
||||
workspace_id,
|
||||
worker_id: unverified.worker_id.as_deref(),
|
||||
permission,
|
||||
method,
|
||||
path,
|
||||
body_digest,
|
||||
now_unix: i64::try_from(unix_now_seconds()).unwrap_or(i64::MAX),
|
||||
};
|
||||
let claims = verify_runtime_request_source(proof, &trusted.public_key, &expected)
|
||||
.map_err(map_auth_error)?;
|
||||
let now_seconds = u64::try_from(expected.now_unix).unwrap_or(u64::MAX);
|
||||
let expires_at = u64::try_from(claims.exp).unwrap_or(0);
|
||||
let consumed_at = chrono::DateTime::from_timestamp(expected.now_unix, 0)
|
||||
.ok_or(WorkerMutationSourceProofError::Expired)?
|
||||
.to_rfc3339();
|
||||
if !store
|
||||
.consume_worker_mutation_source_jti(
|
||||
&claims.iss,
|
||||
&claims.jti,
|
||||
expires_at,
|
||||
now_seconds,
|
||||
&consumed_at,
|
||||
)
|
||||
.await
|
||||
.map_err(|error| WorkerMutationSourceProofError::Authority(error.to_string()))?
|
||||
{
|
||||
return Err(WorkerMutationSourceProofError::Replay);
|
||||
}
|
||||
if let Some(worker_id) = claims.worker_id.as_deref() {
|
||||
let worker = worker_runtime::identity::RuntimeWorkerRef {
|
||||
runtime_id: claims.iss.clone(),
|
||||
worker_id: worker_id.to_owned(),
|
||||
};
|
||||
let member = store
|
||||
.get_worker_registry(workspace_id, &worker)
|
||||
.map_err(|error| WorkerMutationSourceProofError::Authority(error.to_string()))?;
|
||||
if member.is_none() {
|
||||
return Err(WorkerMutationSourceProofError::WorkerCatalogMembership);
|
||||
}
|
||||
}
|
||||
Ok(VerifiedRuntimeRequestSource {
|
||||
runtime_id: claims.iss,
|
||||
worker_id: claims.worker_id,
|
||||
})
|
||||
}
|
||||
|
||||
#[derive(Clone, Debug, PartialEq, Eq)]
|
||||
pub enum PresentedWorkerMutationSourceProof<'a> {
|
||||
@@ -97,16 +201,19 @@ async fn verify_worker_remove_source_with(
|
||||
PresentedWorkerMutationSourceProof::Remote(token) => {
|
||||
let unverified = decode_worker_mutation_source_claims(token)
|
||||
.map_err(|_| WorkerMutationSourceProofError::Invalid)?;
|
||||
let audience = remote_audience(config, &unverified.iss)?;
|
||||
let audience = remote_audience(config, &unverified.iss, &config.workspace_id)?;
|
||||
let trusted = store
|
||||
.get_trusted_runtime(&unverified.iss)
|
||||
.await
|
||||
.map_err(|error| WorkerMutationSourceProofError::Authority(error.to_string()))?
|
||||
.filter(|record| record.revoked_at.is_none())
|
||||
.ok_or(WorkerMutationSourceProofError::RevokedRuntimeTrust)?;
|
||||
if trusted.workspace_id.as_deref() != Some(config.workspace_id.as_str()) {
|
||||
return Err(WorkerMutationSourceProofError::WrongWorkspace);
|
||||
}
|
||||
let expected = WorkerMutationSourceExpectation {
|
||||
runtime_id: &unverified.iss,
|
||||
audience,
|
||||
audience: audience.as_ref(),
|
||||
workspace_id: &config.workspace_id,
|
||||
worker_id: None,
|
||||
actor_kind: WorkerMutationActorKind::Worker,
|
||||
@@ -247,13 +354,17 @@ impl worker_runtime::worker_source::EmbeddedWorkerMutationDispatcher
|
||||
fn remote_audience<'a>(
|
||||
config: &'a crate::server::ServerConfig,
|
||||
runtime_id: &str,
|
||||
) -> Result<&'a str, WorkerMutationSourceProofError> {
|
||||
workspace_id: &str,
|
||||
) -> Result<std::borrow::Cow<'a, str>, WorkerMutationSourceProofError> {
|
||||
if runtime_id == crate::hosts::EMBEDDED_RUNTIME_ID {
|
||||
return Ok(std::borrow::Cow::Owned(format!("embedded:{workspace_id}")));
|
||||
}
|
||||
config
|
||||
.remote_runtime_sources
|
||||
.iter()
|
||||
.find(|runtime| runtime.runtime_id == runtime_id)
|
||||
.and_then(|runtime: &RemoteRuntimeConfig| runtime.auth.as_ref())
|
||||
.map(|auth| auth.server_id.as_str())
|
||||
.map(|auth| std::borrow::Cow::Borrowed(auth.server_id.as_str()))
|
||||
.ok_or(WorkerMutationSourceProofError::RevokedRuntimeTrust)
|
||||
}
|
||||
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
use std::path::{Path, PathBuf};
|
||||
use std::sync::Arc;
|
||||
|
||||
use chrono::{SecondsFormat, Utc};
|
||||
@@ -6,6 +5,9 @@ use serde::{Deserialize, Serialize};
|
||||
use sha2::{Digest, Sha256};
|
||||
use uuid::Uuid;
|
||||
|
||||
use workspace_api::{RepositoryObservedStatus, RepositorySource};
|
||||
|
||||
use crate::repository_source::{parse_repository_source, repository_source_fingerprint};
|
||||
use crate::store::{
|
||||
ControlPlaneStore, RepositoryRecord, WorkspaceBootstrapRecord, WorkspaceRecord,
|
||||
};
|
||||
@@ -109,8 +111,8 @@ impl WorkspaceCatalogService {
|
||||
)?;
|
||||
let display_name =
|
||||
normalize_required("display_name", request.display_name, MAX_DISPLAY_NAME_BYTES)?;
|
||||
let repository_path = validate_repository_uri(&request.repository.uri)?;
|
||||
let repository_uri = repository_path.to_string_lossy().into_owned();
|
||||
let repository_source = validate_repository_source(&request.repository.uri)?;
|
||||
let repository_uri = repository_source.uri.clone();
|
||||
let repository_name = request
|
||||
.repository
|
||||
.display_name
|
||||
@@ -166,10 +168,12 @@ impl WorkspaceCatalogService {
|
||||
name: repository_name,
|
||||
kind: "git".to_string(),
|
||||
provider: Some("git".to_string()),
|
||||
uri: repository_uri,
|
||||
source: repository_source.clone(),
|
||||
default_ref: Some(default_ref),
|
||||
auth_ref_kind: None,
|
||||
auth_ref_key: None,
|
||||
source_revision: 1,
|
||||
source_fingerprint: repository_source_fingerprint(&repository_source),
|
||||
observed_status: RepositoryObservedStatus::Unverified,
|
||||
observed_at: None,
|
||||
created_at: now.clone(),
|
||||
updated_at: now,
|
||||
},
|
||||
@@ -194,35 +198,8 @@ fn normalize_required(field: &str, value: String, max_bytes: usize) -> Result<St
|
||||
Ok(value.to_string())
|
||||
}
|
||||
|
||||
fn validate_repository_uri(uri: &str) -> Result<PathBuf> {
|
||||
let uri = uri.trim();
|
||||
if uri.is_empty() || uri.contains("://") {
|
||||
return Err(Error::InvalidInput(
|
||||
"initial repository uri must be an absolute server-local path".to_string(),
|
||||
));
|
||||
}
|
||||
let path = Path::new(uri);
|
||||
if !path.is_absolute() {
|
||||
return Err(Error::InvalidInput(
|
||||
"initial repository uri must be an absolute server-local path".to_string(),
|
||||
));
|
||||
}
|
||||
let path = path.canonicalize().map_err(|error| {
|
||||
Error::InvalidInput(format!("initial repository path is unavailable: {error}"))
|
||||
})?;
|
||||
if !path.is_dir() {
|
||||
return Err(Error::InvalidInput(
|
||||
"initial repository path must be a directory".to_string(),
|
||||
));
|
||||
}
|
||||
let normal_git = path.join(".git").exists();
|
||||
let bare_git = path.join("HEAD").is_file() && path.join("objects").is_dir();
|
||||
if !normal_git && !bare_git {
|
||||
return Err(Error::InvalidInput(
|
||||
"initial repository path is not a Git repository".to_string(),
|
||||
));
|
||||
}
|
||||
Ok(path)
|
||||
fn validate_repository_source(uri: &str) -> Result<RepositorySource> {
|
||||
parse_repository_source(uri)
|
||||
}
|
||||
|
||||
fn workspace_create_fingerprint(
|
||||
@@ -259,6 +236,7 @@ fn workspace_create_fingerprint(
|
||||
mod tests {
|
||||
use super::*;
|
||||
use crate::store::SqliteWorkspaceStore;
|
||||
use workspace_api::RepositorySourceKind;
|
||||
|
||||
fn git_repository() -> tempfile::TempDir {
|
||||
let dir = tempfile::tempdir().unwrap();
|
||||
@@ -383,12 +361,53 @@ mod tests {
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn repository_intent_rejects_remote_and_non_git_paths() {
|
||||
let remote = validate_repository_uri("https://example.test/repo.git").unwrap_err();
|
||||
assert!(remote.to_string().contains("server-local path"));
|
||||
fn repository_intent_accepts_unavailable_local_sources_without_server_io() {
|
||||
let remote = validate_repository_source("https://example.test/repo.git").unwrap();
|
||||
assert_eq!(remote.kind, RepositorySourceKind::Https);
|
||||
|
||||
let dir = tempfile::tempdir().unwrap();
|
||||
let non_git = validate_repository_uri(&dir.path().display().to_string()).unwrap_err();
|
||||
assert!(non_git.to_string().contains("not a Git repository"));
|
||||
let local = validate_repository_source("/runtime-only/missing/repository").unwrap();
|
||||
assert_eq!(local.kind, RepositorySourceKind::LocalPath);
|
||||
assert_eq!(local.uri, "/runtime-only/missing/repository");
|
||||
|
||||
let file = validate_repository_source("file:///runtime-only/missing/repository").unwrap();
|
||||
assert_eq!(file.kind, RepositorySourceKind::File);
|
||||
|
||||
assert!(validate_repository_source("relative/repository").is_err());
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn remote_repository_creation_persists_typed_source_without_auth_metadata() {
|
||||
let store = Arc::new(SqliteWorkspaceStore::in_memory().unwrap());
|
||||
let service = WorkspaceCatalogService::new(store.clone());
|
||||
let result = service
|
||||
.create_first_ownerless(WorkspaceCreateRequest {
|
||||
operation_key: "remote-create".to_string(),
|
||||
display_name: "Remote Workspace".to_string(),
|
||||
repository: InitialRepositoryIntent {
|
||||
uri: "ssh://git@example.test/org/repository.git".to_string(),
|
||||
display_name: Some("Remote Repository".to_string()),
|
||||
default_ref: Some("main".to_string()),
|
||||
},
|
||||
})
|
||||
.unwrap();
|
||||
|
||||
let persisted = store
|
||||
.get_repository(
|
||||
&result.workspace.workspace_id,
|
||||
&result.repository.repository_id,
|
||||
)
|
||||
.unwrap()
|
||||
.unwrap();
|
||||
assert_eq!(persisted.source.kind, RepositorySourceKind::Ssh);
|
||||
assert_eq!(persisted.source_revision, 1);
|
||||
assert!(persisted.source_fingerprint.starts_with("sha256:"));
|
||||
assert_eq!(
|
||||
persisted.observed_status,
|
||||
RepositoryObservedStatus::Unverified
|
||||
);
|
||||
let json = serde_json::to_value(&persisted).unwrap();
|
||||
assert!(json.get("source").is_some());
|
||||
assert!(json.get("auth_ref_kind").is_none());
|
||||
assert!(json.get("auth_ref_key").is_none());
|
||||
}
|
||||
}
|
||||
|
||||
@@ -242,7 +242,7 @@ Implementation normally happens in a child git worktree created by the Orchestra
|
||||
|
||||
### 5. Review
|
||||
|
||||
The assigned Coder launches the Reviewer as an actual direct-child `builtin:reviewer` SubWorker with read-only scope and a structured handoff bound to the current immutable Merge Request revision. Server authority revalidates the parent assignment, Runtime-owned child session, effective profile, one-shot review attempt, and revision; prose output is not approval.
|
||||
The assigned Coder launches the Reviewer as an actual direct-child `builtin:reviewer` SubWorker with write scope, so it can use the Workdir command tools required for inspection and validation, and a structured handoff bound to the current immutable Merge Request revision. Server authority revalidates the parent assignment, Runtime-owned child session, effective profile, one-shot review attempt, and revision; prose output is not approval.
|
||||
|
||||
The Reviewer records the structured result with `MergeRequestReview`. Request changes requires a new immutable revision and a fresh child attempt. The Orchestrator uses `MergeRequestReadinessCheck` and then `MergeRequestComplete` for guarded integration with operation-id dedupe/CAS semantics; Flow transitions are not completion authority.
|
||||
|
||||
|
||||
@@ -15,7 +15,7 @@
|
||||
};
|
||||
|
||||
review = {
|
||||
instructions = "Use the current Ticket Merge Request as review authority. Confirm its immutable source selector resolves to the exact committed implementation HEAD, then spawn one actual direct-child SubWorker with profile builtin:reviewer, read-only scope, and a structured review handoff bound to the current immutable Merge Request revision. The trusted spawn layer records `ReviewRequested`; do not place commit/ref identity, capability material, or a prewritten verdict in model input. The child must commit MergeRequestReview; prose output and Worker observation are not approval authority. After the structured current-revision result exists, request a Flow transition.";
|
||||
instructions = "Use the current Ticket Merge Request as review authority. Confirm its immutable source selector resolves to the exact committed implementation HEAD, then spawn one actual direct-child SubWorker with profile builtin:reviewer, write scope for Workdir inspection and command validation, and a structured review handoff bound to the current immutable Merge Request revision. The trusted spawn layer records `ReviewRequested`; do not place commit/ref identity, capability material, or a prewritten verdict in model input. The child must commit MergeRequestReview; prose output and Worker observation are not approval authority. After the structured current-revision result exists, request a Flow transition.";
|
||||
transitions = {
|
||||
approved = {
|
||||
target = "complete";
|
||||
@@ -29,7 +29,7 @@
|
||||
};
|
||||
|
||||
fix = {
|
||||
instructions = "Resolve every open Reviewer finding on the same Ticket work branch, rerun the validation affected by the fixes, commit the corrected implementation as a new revision, and preserve concrete evidence. Publish only the updated Ticket work branch with a normal non-force push, verify that the configured repository provider resolves the published source ref to the exact new HEAD, and update the linked Merge Request so its current revision records that same subject. Request review from a fresh read-only Reviewer child so the trusted spawn layer captures the new immutable subject. Do not rewrite the previously reviewed commit, claim approval from the prior request_changes review, push the target branch, push tags or unrelated refs, force-push, merge, delete branches, or discard pre-existing changes. Request a Flow transition only after the corrected committed revision is published and ready for a new independent review.";
|
||||
instructions = "Resolve every open Reviewer finding on the same Ticket work branch, rerun the validation affected by the fixes, commit the corrected implementation as a new revision, and preserve concrete evidence. Publish only the updated Ticket work branch with a normal non-force push, verify that the configured repository provider resolves the published source ref to the exact new HEAD, and update the linked Merge Request so its current revision records that same subject. Request review from a fresh Reviewer child with write scope so it can use the Workdir command tools required for inspection and validation while the trusted spawn layer captures the new immutable subject. Do not rewrite the previously reviewed commit, claim approval from the prior request_changes review, push the target branch, push tags or unrelated refs, force-push, merge, delete branches, or discard pre-existing changes. Request a Flow transition only after the corrected committed revision is published and ready for a new independent review.";
|
||||
transitions = {
|
||||
review = {
|
||||
target = "review";
|
||||
|
||||
@@ -6,6 +6,6 @@ Before opening a Merge Request, publish only the committed Ticket work branch wi
|
||||
|
||||
{% include "common.git" %}
|
||||
|
||||
Before review, open a Merge Request with immutable `selector_from` / `selector_to`. Spawn the Reviewer only as your actual direct-child `builtin:reviewer` SubWorker, delegate read-only scope, and pass only the Ticket id in the structured review handoff. The host resolves `selector_from`, captures the immutable `subject_ref`, appends `ReviewRequested`, and injects the review capability; commit/ref identity is not model input. Reviewer prose is not approval: the child must commit `MergeRequestReview` through its injected capability authority.
|
||||
Before review, open a Merge Request with immutable `selector_from` / `selector_to`. Spawn the Reviewer only as your actual direct-child `builtin:reviewer` SubWorker, delegate write scope so it can use the Workdir command tools required for inspection and validation, and pass only the Ticket id in the structured review handoff. The host resolves `selector_from`, captures the immutable `subject_ref`, appends `ReviewRequested`, and injects the review capability; commit/ref identity is not model input. Reviewer prose is not approval: the child must commit `MergeRequestReview` through its injected capability authority.
|
||||
|
||||
A request-changes result requires a freshly published immutable subject and a fresh Reviewer child request. Flow terminal state is not Ticket completion authority. After the exact current Merge Request subject has authoritative approval, keep that source ref immutable, leave concise implementation evidence on the Ticket when useful, and hand off integration to the Orchestrator. Do not update the target selector. Do not call `MergeRequestComplete`.
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
You are the Ticket Reviewer role running as an actual Runtime-owned direct child of the assigned Coder.
|
||||
|
||||
Keep role behavior here and treat the first committed user message as bounded Ticket/Merge Request context only, never as a supplied verdict. Review the host-captured `ReviewRequested.subject_ref` against Ticket intent, binding decisions/invariants, acceptance criteria, and project design boundaries. Use read-only inspection and focused validation; do not merge, close, mutate the Workdir, update a repository ref, or take over implementation.
|
||||
Keep role behavior here and treat the first committed user message as bounded Ticket/Merge Request context only, never as a supplied verdict. Review the host-captured `ReviewRequested.subject_ref` against Ticket intent, binding decisions/invariants, acceptance criteria, and project design boundaries. Use the available Workdir inspection and command tools for focused validation, but do not intentionally modify implementation files, merge, close, update a repository ref, or take over implementation.
|
||||
|
||||
Your prose response is not review authority. Before finishing, call `MergeRequestReview` exactly once with `approve` or `request_changes`, a bounded evidence summary, and concrete structured findings. Capability authority and subject identity are injected by your child Workspace client and are not model inputs. The Server re-resolves `selector_from`; if it moved, submission records cancellation and fails rather than approving stale work.
|
||||
|
||||
|
||||
@@ -21,7 +21,7 @@ export type TicketRoleAssignmentSummary = { assignment_id: string, role: string,
|
||||
|
||||
export type TicketAssignmentPrincipalSummary = { "kind": "user", account_id: string, } | { "kind": "worker", runtime_id: string, worker_id: string, } | { "kind": "workspace_agent", agent_key: string, };
|
||||
|
||||
export type TicketActionEligibility = { can_assign_orchestrator: boolean, can_unassign_orchestrator: boolean, can_queue: boolean, can_start_manual_coder: boolean, blockers: Array<string>, };
|
||||
export type TicketActionEligibility = { can_assign_orchestrator: boolean, can_unassign_orchestrator: boolean, can_queue: boolean, can_start_manual_coder: boolean, queue_tickets: Array<string>, blockers: Array<string>, };
|
||||
|
||||
export type TicketMergeRequestSummary = { merge_request_id: string, repository_id: string, state: string, review_status: string, selector_from: string | null, selector_to: string, updated_at: string, current_subject_ref: string | null, review_subject_ref: string | null, review_requested_at: string | null, review_submitted_at: string | null, review_excerpt: string | null, };
|
||||
|
||||
|
||||
@@ -7,13 +7,29 @@ export type WorkspaceCatalogRecord = {
|
||||
updated_at: string;
|
||||
};
|
||||
|
||||
export type RepositorySourceKind =
|
||||
| "local_path"
|
||||
| "file"
|
||||
| "ssh"
|
||||
| "http"
|
||||
| "https"
|
||||
| "invalid";
|
||||
|
||||
export type WorkspaceRepositoryRecord = {
|
||||
workspace_id: string;
|
||||
repository_id: string;
|
||||
name: string;
|
||||
kind: string;
|
||||
provider: string | null;
|
||||
source: {
|
||||
kind: RepositorySourceKind;
|
||||
uri: string;
|
||||
};
|
||||
default_ref: string | null;
|
||||
source_revision: number;
|
||||
source_fingerprint: string;
|
||||
observed_status: "unverified" | "ready" | "invalid";
|
||||
observed_at: string | null;
|
||||
};
|
||||
|
||||
export type WorkspaceCatalogItem = WorkspaceCatalogRecord & {
|
||||
|
||||
@@ -269,6 +269,14 @@ export type RepositorySummary = {
|
||||
display_name: string;
|
||||
kind: string;
|
||||
provider: string;
|
||||
source: {
|
||||
kind: "local_path" | "file" | "ssh" | "http" | "https" | "invalid";
|
||||
uri: string;
|
||||
};
|
||||
source_revision: number;
|
||||
source_fingerprint: string;
|
||||
observed_status: "unverified" | "ready" | "invalid";
|
||||
observed_at?: string | null;
|
||||
default_selector?: string | null;
|
||||
record_authority: string;
|
||||
git?: GitRepositorySummary | null;
|
||||
|
||||
@@ -119,6 +119,14 @@ Deno.test("ticket detail uses server-derived role assignment actions", async ()
|
||||
);
|
||||
|
||||
assertEquals(source.includes("ticket.action_eligibility.can_queue"), true);
|
||||
assertEquals(source.includes("ticket.relations.blockers.length > 0"), true);
|
||||
assertEquals(source.includes("ticket.action_eligibility.queue_tickets"), true);
|
||||
assertEquals(source.includes("This operation queues:"), true);
|
||||
assertEquals(source.includes("outcome.queued_tickets.join"), true);
|
||||
assertEquals(
|
||||
source.includes("resolve the listed blockers before Queue"),
|
||||
false,
|
||||
);
|
||||
assertEquals(
|
||||
source.includes("ticket.action_eligibility.can_assign_orchestrator"),
|
||||
true,
|
||||
|
||||
@@ -155,8 +155,7 @@
|
||||
<p class="workspace-catalog-eyebrow">New team space</p>
|
||||
<h2 id="workspace-create-title">Create Workspace</h2>
|
||||
<p>
|
||||
Repository paths and URIs are interpreted by the Backend. Browser-local paths are
|
||||
not authority.
|
||||
Repository sources are interpreted by Backend authority. Supported Git sources are absolute local paths, file://, ssh://, http(s)://, and user@host:path; Browser-local paths and embedded credentials are not authority. Plain HTTP is unencrypted, so prefer HTTPS or SSH.
|
||||
</p>
|
||||
</div>
|
||||
<form onsubmit={submitCreation}>
|
||||
|
||||
@@ -16,7 +16,7 @@
|
||||
<div>
|
||||
<h3>{data.repository.item.display_name}</h3>
|
||||
</div>
|
||||
<span class="status-pill" class:warn={data.repository.item.git?.status !== 'clean'}>{data.repository.item.git?.status ?? 'not observed'}</span>
|
||||
<span class="status-pill" class:warn={data.repository.item.observed_status !== 'ready'}>{data.repository.item.observed_status}</span>
|
||||
</div>
|
||||
<dl>
|
||||
<div>
|
||||
@@ -27,6 +27,18 @@
|
||||
<dt>Provider</dt>
|
||||
<dd>{data.repository.item.provider}</dd>
|
||||
</div>
|
||||
<div>
|
||||
<dt>Source</dt>
|
||||
<dd>{data.repository.item.source.kind} · {data.repository.item.source.uri}</dd>
|
||||
</div>
|
||||
<div>
|
||||
<dt>Source revision</dt>
|
||||
<dd>{data.repository.item.source_revision} · {data.repository.item.source_fingerprint}</dd>
|
||||
</div>
|
||||
<div>
|
||||
<dt>Observed</dt>
|
||||
<dd>{data.repository.item.observed_at ?? 'not observed'}</dd>
|
||||
</div>
|
||||
<div>
|
||||
<dt>Record authority</dt>
|
||||
<dd>{data.repository.item.record_authority}</dd>
|
||||
|
||||
@@ -38,6 +38,11 @@
|
||||
if (!loadedTicket) throw new Error(initialData.ticket.error ?? "ticket load failed");
|
||||
const loadedRepositories = initialData.repositories.data;
|
||||
|
||||
type QueueOutcome = {
|
||||
requested_ticket: string;
|
||||
queued_tickets: string[];
|
||||
};
|
||||
|
||||
let ticket = $state<TicketDetail>(loadedTicket);
|
||||
const mergeRequest = $derived(ticket.merge_request);
|
||||
let editing = $state(false);
|
||||
@@ -52,9 +57,14 @@
|
||||
let resolution = $state("");
|
||||
let busy = $state<string | null>(null);
|
||||
let errorMessage = $state<string | null>(null);
|
||||
let queueMessage = $state<string | null>(null);
|
||||
let readyOperationKey = $state<string | null>(null);
|
||||
let manualRuntimeId = $state("");
|
||||
let manualWorkerId = $state("");
|
||||
let cancellationReason = $state("");
|
||||
const coderAssignment = $derived(
|
||||
ticket.assignments.find((assignment) => assignment.role === "coder") ?? null,
|
||||
);
|
||||
const selectedRepository = $derived(
|
||||
(loadedRepositories?.items ?? []).find((repository: RepositorySummary) => repository.id === repositoryId) ?? null,
|
||||
);
|
||||
@@ -117,6 +127,25 @@
|
||||
}
|
||||
}
|
||||
|
||||
async function queueTicket(): Promise<void> {
|
||||
if (busy) return;
|
||||
busy = "queue";
|
||||
errorMessage = null;
|
||||
queueMessage = null;
|
||||
try {
|
||||
const outcome = await workspaceApiJsonWithBody<QueueOutcome>(
|
||||
`${ticketPath}/queue`,
|
||||
{ method: "POST", body: JSON.stringify({}) },
|
||||
);
|
||||
queueMessage = `Queued ${outcome.queued_tickets.length} Ticket(s): ${outcome.queued_tickets.join(", ")}`;
|
||||
applyTicket(await workspaceApiJson<TicketDetail>(ticketPath));
|
||||
} catch (error) {
|
||||
errorMessage = error instanceof Error ? error.message : String(error);
|
||||
} finally {
|
||||
busy = null;
|
||||
}
|
||||
}
|
||||
|
||||
async function mutateAssignment(
|
||||
action: string,
|
||||
role: "orchestrator" | "coder",
|
||||
@@ -162,6 +191,18 @@
|
||||
});
|
||||
}
|
||||
|
||||
async function cancelImplementation(event: SubmitEvent): Promise<void> {
|
||||
event.preventDefault();
|
||||
if (!coderAssignment || !cancellationReason.trim()) return;
|
||||
if (
|
||||
await mutate("cancel-implementation", "/implementation-cancellations", {
|
||||
operation_id: crypto.randomUUID(),
|
||||
assignment_id: coderAssignment.assignment_id,
|
||||
reason: cancellationReason.trim(),
|
||||
})
|
||||
) cancellationReason = "";
|
||||
}
|
||||
|
||||
async function saveEdit(event: SubmitEvent) {
|
||||
event.preventDefault();
|
||||
if (
|
||||
@@ -272,6 +313,10 @@
|
||||
<div class="workspace-callout is-error" role="alert">{errorMessage}</div>
|
||||
{/if}
|
||||
|
||||
{#if queueMessage}
|
||||
<div class="workspace-callout" role="status">{queueMessage}</div>
|
||||
{/if}
|
||||
|
||||
{#if editing}
|
||||
<form class="ticket-editor" onsubmit={saveEdit}>
|
||||
<label>Title<input bind:value={editTitle} required /></label>
|
||||
@@ -416,6 +461,24 @@
|
||||
</button>
|
||||
</form>
|
||||
{/if}
|
||||
{#if ticket.state === "inprogress" && coderAssignment}
|
||||
<details class="ticket-cancel-implementation">
|
||||
<summary>Cancel implementation</summary>
|
||||
<form class="ticket-control-form" onsubmit={cancelImplementation}>
|
||||
<p class="workspace-empty-copy">
|
||||
Cancel the assigned Coder, remove its assignment, and return this Ticket to ready.
|
||||
</p>
|
||||
<label>Reason<textarea bind:value={cancellationReason} rows="3" required></textarea></label>
|
||||
<button
|
||||
class="workspace-danger-button"
|
||||
type="submit"
|
||||
disabled={busy !== null || !cancellationReason.trim()}
|
||||
>
|
||||
{busy === "cancel-implementation" ? "Cancelling…" : "Cancel and return to ready"}
|
||||
</button>
|
||||
</form>
|
||||
</details>
|
||||
{/if}
|
||||
{#if ticket.assignment_diagnostics.length > 0}
|
||||
{#each ticket.assignment_diagnostics as diagnostic}
|
||||
<p class="workspace-callout">{diagnostic}</p>
|
||||
@@ -462,11 +525,16 @@
|
||||
<p class="workspace-empty-copy">Choose a healthy repository and an effective ref selector before marking ready.</p>
|
||||
{/if}
|
||||
{:else if ticket.state === "ready"}
|
||||
<button class="workspace-primary-button ticket-queue-button" type="button" disabled={busy === "queue" || !ticket.action_eligibility.can_queue} onclick={() => mutate("queue", "/queue", {})}>
|
||||
{busy === "queue" ? "Queueing…" : "Queue ticket"}
|
||||
<button class="workspace-primary-button ticket-queue-button" type="button" disabled={busy === "queue" || !ticket.action_eligibility.can_queue} onclick={() => void queueTicket()}>
|
||||
{busy === "queue" ? "Queueing…" : `Queue ${ticket.action_eligibility.queue_tickets.length} Ticket(s)`}
|
||||
</button>
|
||||
{#if !ticket.action_eligibility.can_queue}
|
||||
<p class="workspace-empty-copy">Assign the Orchestrator role and resolve the listed blockers before Queue.</p>
|
||||
<p class="workspace-empty-copy">Queue requires a valid target, an active Orchestrator assignment, no active Coder assignment, and no dependency still in planning.</p>
|
||||
{:else if ticket.action_eligibility.queue_tickets.length > 0}
|
||||
<p class="workspace-empty-copy">This operation queues: {ticket.action_eligibility.queue_tickets.join(", ")}.</p>
|
||||
{#if ticket.relations.blockers.length > 0}
|
||||
<p class="workspace-empty-copy">Ready dependencies are queued atomically. Queued or in-progress dependencies remain unchanged for the Orchestrator to schedule.</p>
|
||||
{/if}
|
||||
{/if}
|
||||
{/if}
|
||||
</section>
|
||||
|
||||
Reference in New Issue
Block a user