Merge remote-tracking branch 'origin/master' into codex/project-instruction-files
# Conflicts: # AGENTS.md # docs/config-catalog.md # docs/cordis-catalog/events.md # docs/cordis-catalog/services.md # docs/core-data-structures/core.md # docs/event-producer-consumer.md # docs/persistence-catalog.md # docs/rfc/implemented/architecture/2026-07-05-reconstructable-requests.md # docs/rfc/implemented/feature/2026-06-15-code-mode.md # docs/rfc/implemented/feature/2026-06-30-hook-bridges.md # docs/rfc/implemented/feature/2026-06-30-interception-seams.md # docs/rfc/implemented/feature/2026-07-08-repeat-tool-guard.md # docs/rfc/proposed/simplification/2026-07-04-prune-dead-core-spine-surface.md # examples/AGENTS.md # examples/acp-agent/cordis.yml # examples/acp-agent/tests/acp.snapshot.ts # examples/echo-agent/cordis.yml # examples/sandbox-acp-agent/cordis.yml # packages/cordis/tool-cordis/src/api-catalog.ts # packages/core/agent-core/README.md # packages/core/agent-core/src/index.ts # packages/core/agent-loop/README.md # packages/core/agent-loop/src/loop.ts # packages/core/agent-loop/tests/interception.spec.ts # packages/core/agent/src/types.ts # packages/core/tools/README.md # packages/core/tools/src/code-mode.ts # packages/core/tools/src/index.ts # packages/fs/fs-local/src/index.ts # packages/fs/fs/README.md # packages/fs/fs/src/index.ts # packages/guard/repeat-tool-guard/README.md # packages/guard/repeat-tool-guard/src/index.ts # packages/hooks/hooks-claude/src/index.ts # packages/hooks/hooks-codex/src/index.ts # packages/ui/acp-agent/src/index.ts
This commit is contained in:
@@ -30,4 +30,4 @@ Ask for `cordis_inspect` with `what: "api"` or `what: "events"` to see the gener
|
||||
|
||||
## End-to-end tests
|
||||
|
||||
`tests/keyless-smoke.e2e.ts` boots the real `cordis.yml` through the Loader with a dummy key and asserts the banner + clean EOF exit (the export-shape / real-load-path guard, now across the package-name resolution). `tests/cordis-tools.e2e.ts` is the with-key smoke: a real model mounts a status listener (asserting the tagged console line actually fires — the world, not the agent's claim), builds itself a `reverse_text` tool and uses it, and composes two mounts via provide/inject. The tool logic itself is unit-tested in [`packages/cordis/tool-cordis`](../../packages/cordis/tool-cordis) under the per-file 100% coverage gate.
|
||||
`tests/keyless-smoke.e2e.ts` boots the real `cordis.yml` through the Loader with a dummy key and asserts the banner, package-name resolution, and clean EOF exit. `tests/cordis-tools.e2e.ts` is the with-key smoke: a real model mounts a status listener and the test verifies its tagged console line, creates and uses a `reverse_text` tool, and composes two mounts through provide/inject. [`packages/cordis/tool-cordis`](../../packages/cordis/tool-cordis) carries the unit coverage under the per-file 100% gate.
|
||||
|
||||
@@ -1,17 +1,11 @@
|
||||
# The cordis-agent plugin tree: the SELF-REFERENTIAL harness demo. Same spine
|
||||
# as coding-agent (DeepSeek V4 + local bash on @deepseek-ai/dsh-stdio-agent),
|
||||
# plus @deepseek-ai/dsh-tool-cordis, which gives the model three tools over the
|
||||
# live cordis runtime it is running inside: cordis_inspect (services / plugin
|
||||
# tree / tools / dynamic mounts / api / events), cordis_mount (evaluate
|
||||
# model-written code in a vm sandbox and mount the returned plugin under the
|
||||
# `cordis-dynamic` group), and cordis_unmount (dispose one mount by id).
|
||||
# Requires DEEPSEEK_API_KEY (and optionally DEEPSEEK_BASE_URL) — the
|
||||
# dsh-stdio-agent bin loads the gitignored repo-root .env first.
|
||||
#
|
||||
# Trust stance (docs/rfc/implemented/feature/2026-07-08-self-referential-cordis-toolset.md):
|
||||
# the mounted code gets the REAL ctx — the
|
||||
# vm sandbox only prevents accidental global pollution. Load the toolset as
|
||||
# deliberately as you would grant a bash tool.
|
||||
# Self-referential stdio demo: the coding spine plus tools to inspect the live
|
||||
# service/plugin/tool/mount/API/event state, mount a model-written plugin under
|
||||
# `cordis-dynamic`, and quiescently unmount it. The app bin loads the gitignored
|
||||
# root `.env` before reading the required DeepSeek key and optional base URL.
|
||||
# Trust stance: the vm and context façade limit accidental global/framework
|
||||
# access but are not a security boundary; mounted code can reach live capabilities
|
||||
# such as `ctx.bash`. Grant this toolset like bash access. See
|
||||
# ../../docs/rfc/implemented/feature/2026-07-08-self-referential-cordis-toolset.md.
|
||||
|
||||
# Hot-module reload for the dev/demo loop (needs `node --expose-internals`).
|
||||
- id: hmr
|
||||
@@ -53,8 +47,7 @@
|
||||
- id: web-fetch-local
|
||||
name: '@deepseek-ai/dsh-web-fetch-local'
|
||||
|
||||
# The stdio chat app: the whole spine + front-door cluster, configured for the
|
||||
# self-referential demo driving a pre-created `main` agent.
|
||||
# The app bundle pre-creates the self-referential demo's `main` agent.
|
||||
- id: stdio-agent
|
||||
name: '@deepseek-ai/dsh-stdio-agent'
|
||||
config:
|
||||
|
||||
@@ -78,10 +78,9 @@ describe.skipIf(!process.env.DEEPSEEK_API_KEY)('cordis tools: a real model modif
|
||||
}])
|
||||
await waitForIdle(ctx, agent)
|
||||
|
||||
// World checks: the tool exists in the registry, was invoked as a real
|
||||
// tool call, and its RESULT (the self-made execute actually running) is the
|
||||
// reversed string. The model's prose is not asserted — the tool result is
|
||||
// the world; the summary sentence is just the self-report.
|
||||
// World checks: the tool exists in the registry, was invoked as a real tool call, and its
|
||||
// RESULT (the self-made execute actually running) is the reversed string. Model prose is only
|
||||
// self-report and is deliberately not asserted.
|
||||
expect(ctx.tools.get('reverse_text')).toBeDefined()
|
||||
const events = [...agent.session.events]
|
||||
const calls = events.filter(event => event.type === 'tool/call')
|
||||
|
||||
@@ -6,22 +6,16 @@ import { fileURLToPath } from 'node:url'
|
||||
import { afterEach, describe, expect, it } from 'vitest'
|
||||
|
||||
/**
|
||||
* Keyless Loader-path smoke for examples/cordis-agent: boot the REAL example
|
||||
* through the `@deepseek-ai/dsh-stdio-agent` bin against its `cordis.yml` —
|
||||
* the cordis Loader, `unwrapExports`, the full plugin tree INCLUDING the
|
||||
* `@deepseek-ai/dsh-tool-cordis` package resolved by name (whose `inject`
|
||||
* would crash a collapsed export shape at load, see docs/postmortem/0001) —
|
||||
* then close stdin with no prompt and assert the ready banner + a clean exit.
|
||||
*
|
||||
* No prompt is ever sent, so the model is NEVER called — that is why it runs
|
||||
* without a real key: `llm-deepseek`'s apply() only requires a key to be
|
||||
* PRESENT, and the absence of any prompt guarantees no network call. The
|
||||
* with-key product proof lives in cordis-tools.e2e.ts.
|
||||
* Keyless Loader-path smoke for examples/cordis-agent: boot the real example through the
|
||||
* `@deepseek-ai/dsh-stdio-agent` bin against its `cordis.yml` — the cordis Loader,
|
||||
* `unwrapExports`, the full plugin tree INCLUDING the `@deepseek-ai/dsh-tool-cordis` package
|
||||
* resolved by name (whose `inject` would crash a collapsed export shape at load, see
|
||||
* docs/postmortem/0001) — then close stdin with no prompt and assert the ready banner + a
|
||||
* clean exit. A dummy key satisfies adapter boot, but no prompt means no network
|
||||
* call; `cordis-tools.e2e.ts` owns the with-key product proof.
|
||||
*/
|
||||
|
||||
// The dsh-stdio-agent bin (the demo:cordis entry) and this example's cordis.yml.
|
||||
// The bin resolves its config-path arg from CWD; the test spawns from a temp
|
||||
// cwd, so we pass the example config's ABSOLUTE path.
|
||||
// The temp-cwd child needs absolute bin and config paths.
|
||||
const binScript = fileURLToPath(new URL('../../../packages/ui/stdio-agent/src/bin.ts', import.meta.url))
|
||||
const configPath = fileURLToPath(new URL('../cordis.yml', import.meta.url))
|
||||
const tsxLoader = fileURLToPath(import.meta.resolve('tsx'))
|
||||
@@ -29,10 +23,8 @@ const tsxLoader = fileURLToPath(import.meta.resolve('tsx'))
|
||||
// `paths` map; tsx searches UP from cwd, and we spawn from a temp dir outside
|
||||
// the repo, so point it at the repo tsconfig (root is three levels up).
|
||||
const repoTsconfig = fileURLToPath(new URL('../../../tsconfig.json', import.meta.url))
|
||||
// The real-API workflow runs up to 14 e2e files at once. Cold tsx/Loader
|
||||
// startup can therefore outlive a tight smoke-test deadline before the child
|
||||
// emits any output; 30s still detects a wedged process without confusing
|
||||
// bounded CI contention with a lifecycle failure.
|
||||
// Under parallel e2e load, cold tsx/Loader startup can exceed a tight deadline;
|
||||
// 30s still detects a wedged child.
|
||||
const PROCESS_TIMEOUT_MS = 30_000
|
||||
// Leave enough room for the process-owned timeout to report captured output
|
||||
// before Vitest aborts the test itself.
|
||||
|
||||
Reference in New Issue
Block a user