Machine-produced by `pnpm run rescope-vendor --apply` plus the regeneration it prints: `pnpm install` for the lockfile, `pnpm run gen-third-party-notices`, `verify-translation-pairing --write` for the touched bilingual pairs, `gen-doc-graphs`, and one typert snapshot whose ids embed character offsets. `pnpm run rescope-vendor --check` verifies the result. Renames nine vendored packages (cordis, cosmokit, schemastery and the six @cordisjs plugins) and every reference that resolves them: manifest names and dependency keys, module specifiers including declare-module merges, cordis.yml plugin names, tsconfig paths, every Markdown fence, and `docs/` prose. Directory names, upstream versions, and dependency ranges are unchanged, so vendor/README.md still reads as an upstream snapshot; its manifest table gains an upstream-name column so THIRD_PARTY_NOTICES keeps MIT attribution pointed at each fork's origin. The tutorial tier follows the rename end to end: its yaml fences named plugins the Loader can no longer resolve, its `ts ignore-check` fences disagreed with the compiled fences beside them, and its prose quoted both. The contracts that told readers to keep upstream names — the root convention and the vendoring cookbook's tree comment and manifest invariant — now say to rescope instead. Two rules read `@deepseek-ai/` as "another workspace plugin": the client bundle purity gate now names the vendored libraries a browser bundle inlines, and the files where a bare `cordis` is an agent-preset id keep that product data.
54 lines
2.1 KiB
TypeScript
54 lines
2.1 KiB
TypeScript
import { describe, expect, it } from 'vitest'
|
|
import { Context } from '@deepseek-ai/cordis'
|
|
import SessionStore, { type Session, type SessionEvent } from '@deepseek-ai/dsh-session'
|
|
import InvariantService, { InvariantError } from '@deepseek-ai/dsh-invariants'
|
|
import * as SandboxPolicyInvariant from '@deepseek-ai/dsh-sandbox-policy/invariant'
|
|
|
|
async function setup(): Promise<Context> {
|
|
const ctx = new Context()
|
|
await ctx.plugin(SessionStore)
|
|
await ctx.plugin(InvariantService, { enabled: true })
|
|
await ctx.plugin(SandboxPolicyInvariant)
|
|
return ctx
|
|
}
|
|
|
|
function modeEvent(mode: string): SessionEvent {
|
|
return { type: 'sandbox/mode', seq: 0, time: 0, data: { mode } } as SessionEvent
|
|
}
|
|
|
|
describe('sandbox-policy invariants', () => {
|
|
it.each(['read-only', 'workspace-write', 'danger-full-access'])(
|
|
'accepts the durable %s mode',
|
|
async (mode) => {
|
|
const ctx = await setup()
|
|
expect(() => { ctx.emit('session/event', {} as Session, modeEvent(mode)) }).not.toThrow()
|
|
},
|
|
)
|
|
|
|
it('ignores unrelated event streams', async () => {
|
|
const ctx = await setup()
|
|
expect(() => { ctx.emit('session/event', {} as Session, {
|
|
type: 'turn/start', seq: 0, time: 0, data: {},
|
|
} as SessionEvent) }).not.toThrow()
|
|
expect(() => { ctx.emit('tools/change') }).not.toThrow()
|
|
})
|
|
|
|
it('rejects and attributes an unknown durable sandbox mode', async () => {
|
|
const ctx = await setup()
|
|
expect(() => { ctx.emit('session/event', {} as Session, modeEvent('host-root')) })
|
|
.toThrow(new InvariantError('@deepseek-ai/dsh-sandbox-policy', 'sandbox/mode carries unknown mode "host-root"'))
|
|
})
|
|
|
|
it('rejects an unknown mode already present on late registration', async () => {
|
|
const ctx = new Context()
|
|
await ctx.plugin(SessionStore)
|
|
ctx.sessions.create().append('sandbox/mode', { mode: 'host-root' as never })
|
|
await ctx.plugin(InvariantService, { enabled: true })
|
|
|
|
await expect(ctx.plugin(SandboxPolicyInvariant).then(() => undefined)).rejects.toMatchObject({
|
|
code: 'INVARIANT',
|
|
packageName: '@deepseek-ai/dsh-sandbox-policy',
|
|
})
|
|
})
|
|
})
|