authorize, message.send and role.revoke consume a cited decision once,
inside the write transaction (lead decision 64). A second use refuses
with decision-consumed; a class mismatch refuses with decision-mismatch.
Candidate agents/rocko/work/slice1-s2b-r2, build.patch 56d572fe,
manifest a89d64ca. Darkwing approved round 2 on #1525 (comment 26769).
Integration gate in a worktree on bba75b4a: every package green on
Node 26; bus 55/55 on Node 24; every scripts/test-*.sh green. Node 24
failures in conversation, ledger, queue, seat and webui are identical
on the unpatched base (container /tmp is overlayfs, no jsonschema).
Co-Authored-By: Claude Opus 5.5 <[email protected]>
243 lines
8.4 KiB
JavaScript
243 lines
8.4 KiB
JavaScript
import test from 'node:test';
|
|
import assert from 'node:assert/strict';
|
|
import { mkdtempSync, rmSync } from 'node:fs';
|
|
import { tmpdir } from 'node:os';
|
|
import { join } from 'node:path';
|
|
import { Store } from '../src/store.mjs';
|
|
import { Broker } from '../src/broker.mjs';
|
|
const businesses = {
|
|
demo: {
|
|
id: 'demo',
|
|
human: 'jason',
|
|
arbiters: { technical: 'cto', delivery: 'pm' },
|
|
roles: {
|
|
coder: { authority: { withinRole: ['message.send'], crossRole: ['task.scope.change'] } },
|
|
cto: { authority: { withinRole: [], crossRole: [] } },
|
|
pm: { authority: { withinRole: [], crossRole: [] } },
|
|
},
|
|
},
|
|
};
|
|
function fixture(t, gatedMessages = false) {
|
|
const root = mkdtempSync(join(tmpdir(), 'bus-once-'));
|
|
let store, b, cap, human;
|
|
const policy = structuredClone(businesses);
|
|
if (gatedMessages) policy.demo.roles.coder.authority.withinRole = [];
|
|
const call = (c, verb, args = {}) => b.request(c, { verb, args });
|
|
const bind = (run) => b.bindLaunch({ business: 'demo', role: 'coder', run, harness: 'pi', address: run });
|
|
function open() {
|
|
store = new Store(root);
|
|
b = new Broker({ store, businesses: policy });
|
|
cap = bind('run1');
|
|
human = b.bindHuman({ business: 'demo', human: 'jason', via: 'cli', outsideAgent: true });
|
|
}
|
|
open();
|
|
call(cap, 'role.claim');
|
|
t.after(() => {
|
|
store.close();
|
|
rmSync(root, { recursive: true, force: true });
|
|
});
|
|
function approve(action = 'deploy', domain = 'delivery', target = 'release1') {
|
|
const d = call(cap, 'decision.raise', {
|
|
action,
|
|
domain,
|
|
target,
|
|
question: 'Allow?',
|
|
options: [
|
|
{ key: 'yes', text: 'Yes' },
|
|
{ key: 'no', text: 'No' },
|
|
],
|
|
recommendation: 'no',
|
|
blocking: false,
|
|
});
|
|
if (d.route_to === 'human') call(human, 'decision.resolve', { id: d.id, choice: 'yes' });
|
|
else {
|
|
const c = b.bindLaunch({ business: 'demo', role: 'cto', run: 'cto1', harness: 'pi', address: 'cto1' });
|
|
call(c, 'role.claim');
|
|
call(c, 'decision.resolve', { id: d.id, choice: 'yes' });
|
|
}
|
|
return d;
|
|
}
|
|
return {
|
|
get b() {
|
|
return b;
|
|
},
|
|
get store() {
|
|
return store;
|
|
},
|
|
get cap() {
|
|
return cap;
|
|
},
|
|
call,
|
|
bind,
|
|
approve,
|
|
use(d, c = cap) {
|
|
return b.authorize(c, d.action, { decision: d.id, target: d.authorization.target });
|
|
},
|
|
setPolicy(withinRole, crossRole) {
|
|
policy.demo.roles.coder.authority = { withinRole, crossRole };
|
|
},
|
|
narrowToCross(action) {
|
|
policy.demo.roles.coder.authority.crossRole.push(action);
|
|
},
|
|
reopen() {
|
|
store.close();
|
|
open();
|
|
},
|
|
count(d) {
|
|
return store.get(
|
|
"SELECT count(*) AS n FROM events WHERE kind='action.allowed' AND json_extract(body,'$.decision')=? AND json_extract(body,'$.operation') IS NOT 'decision.raise'",
|
|
d.id,
|
|
).n;
|
|
},
|
|
};
|
|
}
|
|
test('gated approval authorizes once, survives store reopen, and fresh approval works', (t) => {
|
|
const f = fixture(t),
|
|
d = f.approve();
|
|
assert.equal(f.use(d).class, 'gated');
|
|
assert.equal(f.count(d), 1);
|
|
assert.throws(() => f.use(d), /decision-consumed/);
|
|
assert.equal(f.count(d), 1);
|
|
f.reopen();
|
|
assert.throws(() => f.use(d), /decision-consumed/);
|
|
const fresh = f.approve();
|
|
f.use(fresh);
|
|
assert.equal(f.count(fresh), 1);
|
|
});
|
|
test('another run cannot consume an approval; a failed check leaves it usable', (t) => {
|
|
const f = fixture(t),
|
|
d = f.approve(),
|
|
other = f.bind('run2');
|
|
f.call(f.cap, 'role.release');
|
|
f.call(other, 'role.claim');
|
|
assert.throws(() => f.use(d, other), /decision-mismatch/);
|
|
assert.equal(f.count(d), 0);
|
|
f.call(other, 'role.release');
|
|
f.call(f.cap, 'role.claim');
|
|
assert.throws(
|
|
() => f.b.authorize(f.cap, 'deploy', { decision: d.id, target: 'other' }),
|
|
/decision-mismatch/,
|
|
);
|
|
f.use(d);
|
|
assert.equal(f.count(d), 1);
|
|
});
|
|
test('two scheduled callers have exactly one grant and one consumed refusal', async (t) => {
|
|
const f = fixture(t),
|
|
d = f.approve();
|
|
const results = await Promise.allSettled([
|
|
Promise.resolve().then(() => f.use(d)),
|
|
Promise.resolve().then(() => f.use(d)),
|
|
]);
|
|
assert.equal(results.filter((r) => r.status === 'fulfilled').length, 1);
|
|
assert.equal(results.find((r) => r.status === 'rejected').reason.code, 'decision-consumed');
|
|
assert.equal(f.count(d), 1);
|
|
});
|
|
test('failed commit rolls consumption back; cross-role consumes and within-role stays reusable', (t) => {
|
|
const f = fixture(t),
|
|
d = f.approve(),
|
|
transaction = f.store.transaction.bind(f.store);
|
|
f.store.transaction = (fn) =>
|
|
transaction(() => {
|
|
fn();
|
|
throw Error('fixture rollback');
|
|
});
|
|
assert.throws(() => f.use(d), /fixture rollback/);
|
|
f.store.transaction = transaction;
|
|
assert.equal(f.count(d), 0);
|
|
f.use(d);
|
|
const cross = f.approve('task.scope.change', 'technical');
|
|
f.use(cross);
|
|
assert.throws(() => f.use(cross), /decision-consumed/);
|
|
f.reopen();
|
|
assert.throws(() => f.use(cross), /decision-consumed/);
|
|
assert.equal(f.count(cross), 1);
|
|
for (let n = 0; n < 2; n++) assert.equal(f.b.authorize(f.cap, 'message.send').class, 'within-role');
|
|
const within = f.call(f.cap, 'decision.raise', {
|
|
action: 'message.send',
|
|
question: 'Send?',
|
|
options: [
|
|
{ key: 'yes', text: 'Yes' },
|
|
{ key: 'no', text: 'No' },
|
|
],
|
|
recommendation: 'yes',
|
|
choice: 'yes',
|
|
blocking: false,
|
|
});
|
|
assert.equal(within.route_to, 'coder');
|
|
f.use(within);
|
|
assert.throws(() => f.use(within), /decision-consumed/);
|
|
assert.equal(f.count(within), 1);
|
|
});
|
|
|
|
for (const [from, to] of [
|
|
['gated', 'cross-role'],
|
|
['cross-role', 'gated'],
|
|
['gated', 'within-role'],
|
|
['cross-role', 'within-role'],
|
|
['within-role', 'gated'],
|
|
['within-role', 'cross-role'],
|
|
]) {
|
|
test(`class drift ${from} to ${to} refuses before consumption`, (t) => {
|
|
const f = fixture(t),
|
|
action = 'task.priority.change';
|
|
f.setPolicy(from === 'within-role' ? [action] : [], from === 'cross-role' ? [action] : []);
|
|
f.reopen();
|
|
let d;
|
|
if (from === 'within-role')
|
|
d = f.call(f.cap, 'decision.raise', {
|
|
action,
|
|
target: 'release1',
|
|
question: 'Allow?',
|
|
options: [
|
|
{ key: 'yes', text: 'Yes' },
|
|
{ key: 'no', text: 'No' },
|
|
],
|
|
recommendation: 'yes',
|
|
choice: 'yes',
|
|
blocking: false,
|
|
});
|
|
else d = f.approve(action, 'technical');
|
|
f.setPolicy(to === 'within-role' ? [action] : [], to === 'cross-role' ? [action] : []);
|
|
f.reopen();
|
|
assert.throws(() => f.use(d), /decision-mismatch/);
|
|
assert.equal(f.count(d), 0);
|
|
});
|
|
}
|
|
test('message.send consumes approval and prevents a later send or authorize', (t) => {
|
|
const f = fixture(t, true),
|
|
d = f.approve('message.send', 'delivery', 'pm');
|
|
// Invalid effect must roll the consumption insert back with the message.
|
|
assert.throws(() => f.call(f.cap, 'message.send', { to: 'pm', body: '', decision: d.id }), /invalid/);
|
|
assert.equal(f.count(d), 0);
|
|
f.call(f.cap, 'message.send', { to: 'pm', body: 'once', decision: d.id });
|
|
assert.equal(f.count(d), 1);
|
|
assert.throws(
|
|
() => f.call(f.cap, 'message.send', { to: 'pm', body: 'twice', decision: d.id }),
|
|
/decision-consumed/,
|
|
);
|
|
assert.throws(() => f.use(d), /decision-consumed/);
|
|
assert.equal(f.store.get('SELECT count(*) AS n FROM messages').n, 1);
|
|
const fresh = f.approve('message.send', 'delivery', 'pm');
|
|
f.use(fresh);
|
|
assert.throws(
|
|
() => f.call(f.cap, 'message.send', { to: 'pm', body: 'after authorize', decision: fresh.id }),
|
|
/decision-consumed/,
|
|
);
|
|
});
|
|
test('role.revoke consumes approval and prevents a later revoke or authorize', (t) => {
|
|
const f = fixture(t),
|
|
pm = f.b.bindLaunch({ business: 'demo', role: 'pm', run: 'pm1', harness: 'pi', address: 'pm1' });
|
|
f.call(pm, 'role.claim');
|
|
const d = f.approve('role.revoke', 'delivery', 'pm');
|
|
f.call(f.cap, 'role.revoke', { role: 'pm', decision: d.id });
|
|
assert.equal(f.count(d), 1);
|
|
assert.throws(() => f.call(f.cap, 'role.revoke', { role: 'pm', decision: d.id }), /decision-consumed/);
|
|
assert.throws(() => f.use(d), /decision-consumed/);
|
|
assert.equal(f.store.get("SELECT count(*) AS n FROM role_claims WHERE op='revoke'").n, 1);
|
|
const next = f.b.bindLaunch({ business: 'demo', role: 'pm', run: 'pm2', harness: 'pi', address: 'pm2' });
|
|
f.call(next, 'role.claim');
|
|
const fresh = f.approve('role.revoke', 'delivery', 'pm');
|
|
f.use(fresh);
|
|
assert.throws(() => f.call(f.cap, 'role.revoke', { role: 'pm', decision: fresh.id }), /decision-consumed/);
|
|
});
|