Merge remote-tracking branch 'origin/master' into codex/simp-share-loader-smoke-harness
# Conflicts: # examples/AGENTS.md # examples/coding-agent/tests/code-mode-keyless-smoke.e2e.ts # examples/coding-agent/tests/keyless-smoke.e2e.ts # examples/cordis-agent/tests/keyless-smoke.e2e.ts # examples/echo-agent/tests/echo.e2e.ts
This commit is contained in:
@@ -30,4 +30,4 @@ Ask for `cordis_inspect` with `what: "api"` or `what: "events"` to see the gener
|
||||
|
||||
## End-to-end tests
|
||||
|
||||
`tests/keyless-smoke.e2e.ts` boots the real `cordis.yml` through the Loader with a dummy key and asserts the banner + clean EOF exit (the export-shape / real-load-path guard, now across the package-name resolution). `tests/cordis-tools.e2e.ts` is the with-key smoke: a real model mounts a status listener (asserting the tagged console line actually fires — the world, not the agent's claim), builds itself a `reverse_text` tool and uses it, and composes two mounts via provide/inject. The tool logic itself is unit-tested in [`packages/cordis/tool-cordis`](../../packages/cordis/tool-cordis) under the per-file 100% coverage gate.
|
||||
`tests/keyless-smoke.e2e.ts` boots the real `cordis.yml` through the Loader with a dummy key and asserts the banner, package-name resolution, and clean EOF exit. `tests/cordis-tools.e2e.ts` is the with-key smoke: a real model mounts a status listener and the test verifies its tagged console line, creates and uses a `reverse_text` tool, and composes two mounts through provide/inject. [`packages/cordis/tool-cordis`](../../packages/cordis/tool-cordis) carries the unit coverage under the per-file 100% gate.
|
||||
|
||||
@@ -1,17 +1,11 @@
|
||||
# The cordis-agent plugin tree: the SELF-REFERENTIAL harness demo. Same spine
|
||||
# as coding-agent (DeepSeek V4 + local bash on @deepseek-ai/dsh-stdio-agent),
|
||||
# plus @deepseek-ai/dsh-tool-cordis, which gives the model three tools over the
|
||||
# live cordis runtime it is running inside: cordis_inspect (services / plugin
|
||||
# tree / tools / dynamic mounts / api / events), cordis_mount (evaluate
|
||||
# model-written code in a vm sandbox and mount the returned plugin under the
|
||||
# `cordis-dynamic` group), and cordis_unmount (dispose one mount by id).
|
||||
# Requires DEEPSEEK_API_KEY (and optionally DEEPSEEK_BASE_URL) — the
|
||||
# dsh-stdio-agent bin loads the gitignored repo-root .env first.
|
||||
#
|
||||
# Trust stance (docs/rfc/implemented/feature/2026-07-08-self-referential-cordis-toolset.md):
|
||||
# the mounted code gets the REAL ctx — the
|
||||
# vm sandbox only prevents accidental global pollution. Load the toolset as
|
||||
# deliberately as you would grant a bash tool.
|
||||
# Self-referential stdio demo: the coding spine plus tools to inspect the live
|
||||
# service/plugin/tool/mount/API/event state, mount a model-written plugin under
|
||||
# `cordis-dynamic`, and quiescently unmount it. The app bin loads the gitignored
|
||||
# root `.env` before reading the required DeepSeek key and optional base URL.
|
||||
# Trust stance: the vm and context façade limit accidental global/framework
|
||||
# access but are not a security boundary; mounted code can reach live capabilities
|
||||
# such as `ctx.bash`. Grant this toolset like bash access. See
|
||||
# ../../docs/rfc/implemented/feature/2026-07-08-self-referential-cordis-toolset.md.
|
||||
|
||||
# Hot-module reload for the dev/demo loop (needs `node --expose-internals`).
|
||||
- id: hmr
|
||||
@@ -53,8 +47,7 @@
|
||||
- id: web-fetch-local
|
||||
name: '@deepseek-ai/dsh-web-fetch-local'
|
||||
|
||||
# The stdio chat app: the whole spine + front-door cluster, configured for the
|
||||
# self-referential demo driving a pre-created `main` agent.
|
||||
# The app bundle pre-creates the self-referential demo's `main` agent.
|
||||
- id: stdio-agent
|
||||
name: '@deepseek-ai/dsh-stdio-agent'
|
||||
config:
|
||||
|
||||
@@ -78,10 +78,9 @@ describe.skipIf(!process.env.DEEPSEEK_API_KEY)('cordis tools: a real model modif
|
||||
}])
|
||||
await waitForIdle(ctx, agent)
|
||||
|
||||
// World checks: the tool exists in the registry, was invoked as a real
|
||||
// tool call, and its RESULT (the self-made execute actually running) is the
|
||||
// reversed string. The model's prose is not asserted — the tool result is
|
||||
// the world; the summary sentence is just the self-report.
|
||||
// World checks: the tool exists in the registry, was invoked as a real tool call, and its
|
||||
// RESULT (the self-made execute actually running) is the reversed string. Model prose is only
|
||||
// self-report and is deliberately not asserted.
|
||||
expect(ctx.tools.get('reverse_text')).toBeDefined()
|
||||
const events = [...agent.session.events]
|
||||
const calls = events.filter(event => event.type === 'tool/call')
|
||||
|
||||
Reference in New Issue
Block a user