testkit

package
v0.1.0-rc.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 1, 2026 License: Apache-2.0 Imports: 63 Imported by: 0

Documentation

Overview

Package testkit reserves shared testing helpers, stubs, and fixtures.

Index

Constants

View Source
const (
	// LIPTestPostgresDSN is the preferred runtime DSN for integration tests.
	// Dual-plane pooled gates treat this as the transaction-pooled runtime endpoint.
	LIPTestPostgresDSN = "LIP_TEST_POSTGRES_DSN"
	// LIPTestPostgresAdminDSN is the direct admin/bootstrap/cleanup/migration endpoint.
	// When unset, tests may reuse the runtime DSN if that endpoint has admin rights.
	LIPTestPostgresAdminDSN = "LIP_TEST_POSTGRES_ADMIN_DSN"
	// LIPManagedPostgresDSN is a legacy alias still accepted by [PostgresTestDSN] /
	// [PostgresRuntimeDSN] only. It is not an admin endpoint.
	LIPManagedPostgresDSN = "LIP_MANAGED_POSTGRES_DSN"
	// LIPRequirePostgres turns an otherwise skippable integration test into a
	// hard failure. CI and the explicit make target use it as the proof gate.
	LIPRequirePostgres = "LIP_REQUIRE_POSTGRES"
	// LIPRequirePostgresPooler turns pooled dual-endpoint integration tests into
	// hard failures when either admin or runtime DSN is missing.
	LIPRequirePostgresPooler = "LIP_REQUIRE_POSTGRES_POOLER"
	// LIPTestPostgresRuntimeIsPooler attests that LIP_TEST_POSTGRES_DSN reaches a
	// transaction pooler. Required by the pooled release gate; never inferred.
	LIPTestPostgresRuntimeIsPooler = "LIP_TEST_POSTGRES_RUNTIME_IS_POOLER"
)

Environment variable names for optional PostgreSQL integration tests.

View Source
const (
	// SyntheticOpenAIAPIKey is an OpenAI-shaped placeholder for catalog/matcher tests.
	SyntheticOpenAIAPIKey = "sk-test-openai-secretguard-fixture-001" // #nosec G101 -- synthetic fixture only.

	// SyntheticOpenRouterAPIKey is an OpenRouter-shaped placeholder.
	SyntheticOpenRouterAPIKey = "sk-or-test-secretguard-fixture-002" // #nosec G101 -- synthetic fixture only.

	// SyntheticAnthropicSecretGuardKey is an Anthropic-shaped placeholder distinct from SyntheticAnthropicAPIKey.
	SyntheticAnthropicSecretGuardKey = "sk-ant-test-secretguard-fixture-003" // #nosec G101 -- synthetic fixture only.

	// SyntheticGeminiAPIKey is a Gemini/Google-shaped placeholder.
	SyntheticGeminiAPIKey = "AIzaSyTestSecretGuardFixture0004xxxx" // #nosec G101 -- synthetic fixture only.

	// SyntheticBearerCredential is a multi-user auth credential placeholder (request-scoped matcher only).
	SyntheticBearerCredential = "lip-mu-test-secretguard-bearer-005" // #nosec G101 -- synthetic fixture only.

	// SyntheticShortSecret is intentionally below the default min_secret_bytes (8) for exclusion tests.
	SyntheticShortSecret = "short" // #nosec G101 -- synthetic fixture only.

	// SyntheticOverlapLonger is the longer of two overlapping synthetic values (longest-match wins).
	SyntheticOverlapLonger = "secretguard-overlap-longer-value-aa" // #nosec G101 -- synthetic fixture only.

	// SyntheticOverlapShorter is a proper prefix of SyntheticOverlapLonger.
	SyntheticOverlapShorter = "secretguard-overlap" // #nosec G101 -- synthetic fixture only.

	// SyntheticUnicodeSecret embeds non-ASCII bytes for UTF-8 length preservation tests.
	SyntheticUnicodeSecret = "sg-ünîcode-секрет-006" // #nosec G101 -- synthetic fixture only.

	// SyntheticDuplicateValueAliasA and SyntheticDuplicateValueAliasB share the same value under different names.
	SyntheticDuplicateValueAliasA = "sg-dup-shared-value-fixture-007" // #nosec G101 -- synthetic fixture only.
	SyntheticDuplicateValueAliasB = SyntheticDuplicateValueAliasA
)
View Source
const DefaultFuzzRouteSelector = "stub:model"

DefaultFuzzRouteSelector is used when a fuzz-packed selector decodes to empty.

View Source
const SyntheticAnthropicAPIKey = "sk-ant-test" // #nosec G101 -- security: documented synthetic fixture only.

SyntheticAnthropicAPIKey is a placeholder Anthropic-shaped API key for tests that talk to in-repo reference servers or emulators. It is not a production or customer credential.

Variables

View Source
var SyntheticSecretGuardEnvNames = []string{
	"OPENAI_API_KEY",
	"OPENAI_API_KEY_2",
	"OPENAI_API_KEY_7",
	"OPENROUTER_API_KEY",
	"ANTHROPIC_API_KEY",
	"GEMINI_API_KEY",
	"LIP_TEST_SECRETGUARD_INCLUDE",
}

SyntheticSecretGuardEnvNames are safe environment-variable *names* used in catalog tests. Values are never asserted by printing; use the Synthetic* constants above.

Functions

func AllSyntheticSecretGuardNeedles

func AllSyntheticSecretGuardNeedles() []string

AllSyntheticSecretGuardNeedles returns meaningful substrings that should also never appear outside the private matcher. These are shorter than the full fixture values so regression checks catch partial leaks.

func AllSyntheticSecretGuardValues

func AllSyntheticSecretGuardValues() []string

AllSyntheticSecretGuardValues returns every synthetic secret string used by secrets-guard tests. Callers should scan logs/errors for these values and fail on any occurrence outside the private matcher.

func AssertEventCount

func AssertEventCount(t *testing.T, events []lipapi.Event, want int)

AssertEventCount asserts the number of canonical events in a non-streaming collection.

func AssertJSONEqual

func AssertJSONEqual(t *testing.T, want, got []byte)

AssertJSONEqual compares two JSON blobs with stable key ordering via compact encoding.

func AuthLeakFixtureSecrets

func AuthLeakFixtureSecrets() []string

AuthLeakFixtureSecrets returns synthetic strings that must not appear in operator-visible outputs in auth regression tests (sinks, HTTP bodies). Kept in test support code only.

func CapBytes

func CapBytes(b []byte, maxLen int) []byte

CapBytes returns a subslice of at most maxLen bytes (or b unchanged if maxLen <= 0).

func CapString

func CapString(s string, maxLen int) string

CapString returns s truncated to maxLen runes-worth is not what we want — byte cap for wire fuzzing.

func ClassifyForbiddenRuntimeSQL

func ClassifyForbiddenRuntimeSQL(query string) string

ClassifyForbiddenRuntimeSQL returns a short reason when query is illegal on a transaction-pooled runtime connection; empty means allowed DML/query.

func CleanupPostgresStoreByID

func CleanupPostgresStoreByID(t *testing.T, adminDSN, storeID string, components ...PostgresStoreComponent)

CleanupPostgresStoreByID deletes dual-plane rows for storeID via the admin DSN. Order is dependency-safe. Shared schema objects are never dropped. After known admin bootstrap, unexpected errors fail the test (no text matching).

func DiscardLogger

func DiscardLogger() *slog.Logger

DiscardLogger returns a logger that discards all output. Use in tests that must satisfy non-nil logger requirements at the composition root.

func DualPlanePostgresSearchPathGuardDirs

func DualPlanePostgresSearchPathGuardDirs() []string

DualPlanePostgresSearchPathGuardDirs lists strict dual-plane store packages whose runtime and test SQL must not depend on session search_path state.

func ExecCtxViewsFixture

func ExecCtxViewsFixture() execctx.Views

ExecCtxViewsFixture returns deterministic plugin-facing views for ordering and snapshot tests (task 4.3).

func ExecCtxViewsFromSubmit

func ExecCtxViewsFromSubmit(traceID string, aLeg b2bua.ALegRecord, call lipapi.Call, ann map[string]string) execctx.Views

ExecCtxViewsFromSubmit wraps execctx.ViewsFromSubmit with a fixed clock-friendly A-leg row.

func FailRuntimeDDLRED

func FailRuntimeDDLRED(t *testing.T, guard *RuntimeSQLGuard, openErr error)

FailRuntimeDDLRED fails with the deterministic Phase-1 RED reason when the constructor/open path emitted runtime DDL (no open-without-migrate API yet).

func FeatureBundle

func FeatureBundle(
	tb testing.TB,
	contributorID string,
	contribute func(*lipfeature.ContributionSet) error,
	lifecycles []lipplugin.Lifecycle,
) lipfeature.FeatureBundle

FeatureBundle constructs a FeatureBundle by contributing into a new ContributionSet, freezing it, and wrapping it via lipfeature.BundleFromPlanes. contributorID provides the bundle/error-context identifier for test failure reporting and does not override contributor IDs passed to lipfeature.Contribute inside the callback. If contribute is nil, an empty PlaneSet is used. If contribute fails, the test fails via t.Fatalf (or panics if t is nil).

func FreezeBundle

func FreezeBundle(bundles ...lipfeature.FeatureBundle) lipfeature.FrozenPlaneSet

FreezeBundle merges one or more FeatureBundles through generated plane adapters and returns the resulting FrozenPlaneSet. Panics if merging fails, making it ideal for concise test setup.

func FreezeTestBundle

func FreezeTestBundle(b TestFeatureBundle) lipfeature.FrozenPlaneSet

FreezeTestBundle converts a TestFeatureBundle into a FrozenPlaneSet, panicking if any contribution fails.

func FreezeTestBundleChecked

func FreezeTestBundleChecked(b TestFeatureBundle) (lipfeature.FrozenPlaneSet, error)

FreezeTestBundleChecked converts a TestFeatureBundle into a FrozenPlaneSet, returning an attributed error if any contribution fails.

func GoldenPathFromRepo

func GoldenPathFromRepo(t *testing.T, repoRoot string, parts ...string) string

GoldenPathFromRepo joins repo root with path segments under testdata/.

func IntegrationHTTPClient

func IntegrationHTTPClient(c *http.Client) *http.Client

IntegrationHTTPClient returns c when non-nil; otherwise it returns httpclient.Standard so integration tests match production outbound pooling and timeouts (not http.DefaultClient).

func LocalTestServerHTTPClient

func LocalTestServerHTTPClient() *http.Client

LocalTestServerHTTPClient returns a short, time-bounded http.Client for tests that call httptest.Server or loopback URLs. Prefer this over the http package default client, which has no timeout. For outbound calls that should match production, use IntegrationHTTPClient (or pass an explicit http.Client from the test harness).

func LookupDualPlanePostgresDSNs

func LookupDualPlanePostgresDSNs() (adminDSN, runtimeDSN string, err error)

LookupDualPlanePostgresDSNs returns admin and runtime DSNs without logging them. Missing endpoints yield an actionable error that names env vars only.

func ModelsDevCatalogSnapshot

func ModelsDevCatalogSnapshot(t *testing.T, rawJSON string, fetchedAt time.Time) modelcatalog.Snapshot

ModelsDevCatalogSnapshot parses models.dev-shaped catalog JSON into a core modelcatalog.Snapshot for tests that need a realistic index without importing the adapter from core packages.

func MustLIPCall

func MustLIPCall(t *testing.T, v any) lipapi.Call

MustLIPCall returns v as lipapi.Call or fails the test.

func MustMapStringAny

func MustMapStringAny(t *testing.T, v any) map[string]any

MustMapStringAny returns v as map[string]any or fails the test.

func MustReadFileUnderRoot

func MustReadFileUnderRoot(tb testing.TB, root, path string) []byte

MustReadFileUnderRoot reads path after verifying its absolute location is under root (root may be relative; both are cleaned). Use for golden and fixture loaders so test path segments cannot escape the repository tree.

func MustSliceAny

func MustSliceAny(t *testing.T, v any) []any

MustSliceAny returns v as []any or fails the test.

func NewStubExecutor

func NewStubExecutor(t *testing.T, caps lipapi.BackendCaps, text string, capture *sync.Map) *runtime.Executor

func NewStubExecutorWithDeltas

func NewStubExecutorWithDeltas(t *testing.T, caps lipapi.BackendCaps, deltas []string, capture *sync.Map) *runtime.Executor

func NewStubExecutorWithSecureSession

func NewStubExecutorWithSecureSession(t *testing.T, opts SecureSessionStubExecutorOptions, caps lipapi.BackendCaps, capture *sync.Map) *runtime.Executor

NewStubExecutorWithSecureSession builds an executor with secure-session enabled, lipapi denial mapping, B2BUA memory store, and an optional stub backend (task 11 E2E harness).

func NewTestExecutor

func NewTestExecutor(tb testing.TB, opts ...ExecutorOption) *runtime.Executor

NewTestExecutor constructs an executor from grouped options. Additional promoted fields can be set on the returned value when an option does not exist yet.

func NewTestRequestRuntimeSnapshot

func NewTestRequestRuntimeSnapshot(bus *hooks.Bus, opts TestSnapshotOptions) *extensions.RequestRuntimeSnapshot

NewTestRequestRuntimeSnapshot builds a snapshot for extension and stage tests using the same composition rules as production extensions.NewRequestRuntimeSnapshot.

func OpenPostgresBun

func OpenPostgresBun(dsn string, maxOpen int) (*bun.DB, error)

OpenPostgresBun opens a small owned Bun PostgreSQL pool for tests. Callers must Close the returned handle (or register cleanup). Errors omit DSN values.

func OpenPostgresBunForTest

func OpenPostgresBunForTest(t *testing.T, dsn string, maxOpen int) *bun.DB

OpenPostgresBunForTest opens a Bun pool or fails the test.

func PatchExecutor

func PatchExecutor(ex *runtime.Executor, patch func(*runtime.Executor)) *runtime.Executor

PatchExecutor applies a mutation to an existing executor in tests (promoted fields).

func PostgresAdminDSN

func PostgresAdminDSN() (dsn string, ok bool)

PostgresAdminDSN returns the direct admin/bootstrap/cleanup DSN. Tests may reuse the runtime DSN when it has admin rights; an explicit admin DSN wins. No hostname inference or DSN rewriting is performed.

func PostgresPoolerRequired

func PostgresPoolerRequired() bool

PostgresPoolerRequired reports whether LIP_REQUIRE_POSTGRES_POOLER requests fail-closed dual-endpoint pooled-gate behavior.

func PostgresRequired

func PostgresRequired() bool

PostgresRequired reports whether LIP_REQUIRE_POSTGRES requests fail-closed behavior.

func PostgresRuntimeDSN

func PostgresRuntimeDSN() (dsn string, ok bool)

PostgresRuntimeDSN is the dual-plane name for the transaction-pooled runtime DSN. It shares precedence with PostgresTestDSN (preferred test name, then legacy alias).

func PostgresTestDSN

func PostgresTestDSN() (dsn string, ok bool)

PostgresTestDSN returns a non-empty managed PostgreSQL DSN when LIPTestPostgresDSN or LIPManagedPostgresDSN is set. If both are set, LIPTestPostgresDSN wins.

func ReadGoldenBytes

func ReadGoldenBytes(t *testing.T, repoRoot string, parts ...string) []byte

ReadGoldenBytes loads a fixture file relative to repo root.

func SecureSessionTestFingerprintKey

func SecureSessionTestFingerprintKey() []byte

SecureSessionTestFingerprintKey returns a deterministic 32-byte key for secure-session tests.

func SkipUnlessPostgres

func SkipUnlessPostgres(t *testing.T) string

SkipUnlessPostgres skips the test when no integration DSN is configured or when PostgreSQL integration tests are not requested via LIP_REQUIRE_POSTGRES=1.

func SkipUnlessPostgresPooled

func SkipUnlessPostgresPooled(t *testing.T) (adminDSN, runtimeDSN string)

SkipUnlessPostgresPooled skips (or fails closed) unless both admin and runtime DSNs are configured and the runtime endpoint is explicitly attested as a transaction pooler. When LIP_REQUIRE_POSTGRES_POOLER is set, missing endpoints or missing attestation fail with an actionable message and never infer/rewrite hostnames.

func SplitFuzzPackedRouteBody

func SplitFuzzPackedRouteBody(b []byte, maxSel, maxBody int) (selector string, body []byte)

SplitFuzzPackedRouteBody splits one fuzz blob into a route selector prefix and HTTP body. Layout: [1 byte: selLen][selector bytes][body bytes]. selLen is capped by maxSel and available bytes.

func UniquePostgresStoreID

func UniquePostgresStoreID(prefix string) string

UniquePostgresStoreID returns a process-unique store_id for pooler-safe isolation.

func WireConformanceExecutorSecureSession

func WireConformanceExecutorSecureSession(tb testing.TB, ex *runtime.Executor)

WireConformanceExecutorSecureSession attaches an in-memory secure-session manager and lipapi denial mapping for conformance harness executors (and other tests that construct *runtime.Executor outside package runtime).

Types

type DualPlanePostgresGate

type DualPlanePostgresGate struct {
	AdminDSN   string
	RuntimeDSN string
	// Err is non-nil when either endpoint is missing (env names only; never DSNs).
	Err error
	// FailClosed is true when LIP_REQUIRE_POSTGRES_POOLER requests hard failure.
	FailClosed bool
}

DualPlanePostgresGate is the non-fatal decision for pooled dual-endpoint tests.

func EvaluateDualPlanePostgresGate

func EvaluateDualPlanePostgresGate() DualPlanePostgresGate

EvaluateDualPlanePostgresGate looks up admin/runtime DSNs without logging them. Explicit LIP_TEST_POSTGRES_RUNTIME_IS_POOLER=1 attestation is always required before pooled helpers may proceed — ambient admin/runtime DSNs alone are not enough (make qa must skip, not hang, against a direct endpoint).

type ExecutorOption

type ExecutorOption func(*runtime.ExecutorConfig)

ExecutorOption mutates an runtime.ExecutorConfig before construction.

func WithBackends

func WithBackends(backends map[string]execbackend.Backend) ExecutorOption

WithBackends sets backend adapters keyed by routing primary backend id.

func WithBus

func WithBus(bus *hooks.Bus) ExecutorOption

WithBus sets the hook bus.

func WithDefaultBackend

func WithDefaultBackend(backend string) ExecutorOption

WithDefaultBackend sets model-only default backend resolution.

func WithExecutionClasses

func WithExecutionClasses(classes map[string]lipsdk.BackendExecutionClass) ExecutorOption

WithExecutionClasses sets explicit backend execution classes for test backends.

func WithExecutionPolicy

func WithExecutionPolicy(policy config.ExecutionCompositionPolicy) ExecutorOption

WithExecutionPolicy sets routing execution composition policy in tests.

func WithRand

func WithRand(rng routing.Rng) ExecutorOption

WithRand sets the routing RNG.

func WithSelectorAliases

func WithSelectorAliases(ar *routing.AliasResolver) ExecutorOption

WithSelectorAliases sets selector alias rewriting.

func WithStore

func WithStore(store b2bua.Store) ExecutorOption

WithStore sets the B2BUA continuity store.

type FakeAuxClient

type FakeAuxClient struct{}

FakeAuxClient returns empty results without calling a backend (task 4.3).

func (FakeAuxClient) Collect

func (FakeAuxClient) Stream

type FakeB2BUAStore

type FakeB2BUAStore struct {
	Impl b2bua.Store

	ResolveALegErr              error
	CreateALegErr               error
	FetchALegErr                error
	SetWeightedFirstConsumedErr error
	NextBLegErr                 error
	RecordAttemptErr            error
	LoadAttemptsErr             error

	ResolveALegHook              func(ctx context.Context, continuityKey string) (b2bua.ALegRecord, error)
	CreateALegHook               func(ctx context.Context, continuityKey string) (b2bua.ALegRecord, error)
	FetchALegHook                func(ctx context.Context, aLegID string) (b2bua.ALegRecord, error)
	SetWeightedFirstConsumedHook func(ctx context.Context, aLegID string, consumed bool) error
	NextBLegHook                 func(ctx context.Context, aLegID string) (b2bua.BLegRecord, error)
	RecordAttemptHook            func(ctx context.Context, rec lipapi.AttemptRecord) error
	LoadAttemptsHook             func(ctx context.Context, aLegID string) ([]lipapi.AttemptRecord, error)
}

FakeB2BUAStore implements b2bua.Store with injectable errors and optional backing implementation.

func (*FakeB2BUAStore) CreateALeg

func (f *FakeB2BUAStore) CreateALeg(ctx context.Context, continuityKey string) (b2bua.ALegRecord, error)

func (*FakeB2BUAStore) FetchALeg

func (f *FakeB2BUAStore) FetchALeg(ctx context.Context, aLegID string) (b2bua.ALegRecord, error)

func (*FakeB2BUAStore) LoadAttempts

func (f *FakeB2BUAStore) LoadAttempts(ctx context.Context, aLegID string) ([]lipapi.AttemptRecord, error)

func (*FakeB2BUAStore) NextBLeg

func (f *FakeB2BUAStore) NextBLeg(ctx context.Context, aLegID string) (b2bua.BLegRecord, error)

func (*FakeB2BUAStore) RecordAttempt

func (f *FakeB2BUAStore) RecordAttempt(ctx context.Context, rec lipapi.AttemptRecord) error

func (*FakeB2BUAStore) ResolveALeg

func (f *FakeB2BUAStore) ResolveALeg(ctx context.Context, continuityKey string) (b2bua.ALegRecord, error)

func (*FakeB2BUAStore) SetWeightedFirstConsumed

func (f *FakeB2BUAStore) SetWeightedFirstConsumed(ctx context.Context, aLegID string, consumed bool) error

type FakeSecureSessionRecorder

type FakeSecureSessionRecorder struct {
	PostOutputFailure error

	TranscriptAppends int
	AuditAppends      int
	UsageAdds         int
	TouchCalls        int
	GateRecords       int
	StreamRecords     int
	// contains filtered or unexported fields
}

FakeSecureSessionRecorder is a placeholder for future secure-session recorder wiring (tasks 5.x/6.x). Use PostOutputFailure to simulate recorder errors after client-visible output has begun.

func (*FakeSecureSessionRecorder) AddUsage

func (*FakeSecureSessionRecorder) AppendAudit

func (*FakeSecureSessionRecorder) AppendTranscript

func (*FakeSecureSessionRecorder) RecordClientTurnAfterGate

func (f *FakeSecureSessionRecorder) RecordClientTurnAfterGate(_ context.Context, _ app.ClientTurnRecordInput) error

func (*FakeSecureSessionRecorder) RecordPostHookStreamEvent

func (f *FakeSecureSessionRecorder) RecordPostHookStreamEvent(_ context.Context, _ app.StreamEventRecordInput) error

func (*FakeSecureSessionRecorder) TouchActivity

type FakeSecureSessionStore

type FakeSecureSessionStore struct {
	Delegate app.Store

	CreateErr                  error
	LoadByIDErr                error
	LoadByResumeFingerprintErr error
	LoadByALegIDErr            error
	TouchActivityErr           error
	AppendAttemptTraceErr      error
	UpdateAttemptOutcomeErr    error
	AppendTranscriptErr        error
	NextTranscriptSeqErr       error
	AddUsageErr                error
	AppendAuditErr             error
	NextAuditSeqErr            error
	AuditErr                   error
	SummaryErr                 error
	TranscriptErr              error
	ListAttemptEvidenceErr     error
	CheckReadinessErr          error
	QuarantineErr              error

	CreateCalls     int
	QuarantineCalls int
	// contains filtered or unexported fields
}

FakeSecureSessionStore implements app.Store with injectable per-method errors. When a field is nil and Delegate is non-nil, the call forwards to Delegate. When both are unset, reads return domain.ErrSessionNotFound and mutating calls return nil or not-found as appropriate.

func (*FakeSecureSessionStore) AddUsage

func (f *FakeSecureSessionStore) AddUsage(ctx context.Context, delta domain.UsageDelta) error

func (*FakeSecureSessionStore) AppendAttemptTrace

func (f *FakeSecureSessionStore) AppendAttemptTrace(ctx context.Context, trace domain.AttemptTrace) error

func (*FakeSecureSessionStore) AppendAudit

func (f *FakeSecureSessionStore) AppendAudit(ctx context.Context, item domain.AuditItem) error

func (*FakeSecureSessionStore) AppendTranscript

func (f *FakeSecureSessionStore) AppendTranscript(ctx context.Context, item domain.TranscriptItem) error

func (*FakeSecureSessionStore) Audit

func (*FakeSecureSessionStore) CheckReadiness

func (f *FakeSecureSessionStore) CheckReadiness(ctx context.Context, policy domain.PolicyMetadata) error

func (*FakeSecureSessionStore) Create

func (*FakeSecureSessionStore) ListAttemptEvidence

func (*FakeSecureSessionStore) LoadByALegID

func (f *FakeSecureSessionStore) LoadByALegID(ctx context.Context, aLegID string) (domain.Record, error)

func (*FakeSecureSessionStore) LoadByID

func (*FakeSecureSessionStore) LoadByResumeFingerprint

func (f *FakeSecureSessionStore) LoadByResumeFingerprint(ctx context.Context, fp domain.TokenFingerprint) (domain.Record, error)

func (*FakeSecureSessionStore) NextAuditSeq

func (f *FakeSecureSessionStore) NextAuditSeq(ctx context.Context, id domain.SessionID) (int64, error)

func (*FakeSecureSessionStore) NextTranscriptSeq

func (f *FakeSecureSessionStore) NextTranscriptSeq(ctx context.Context, id domain.SessionID) (int64, error)

func (*FakeSecureSessionStore) Quarantine

func (*FakeSecureSessionStore) Summary

func (*FakeSecureSessionStore) TouchActivity

func (f *FakeSecureSessionStore) TouchActivity(ctx context.Context, id domain.SessionID, at time.Time, source domain.ActivitySource) error

func (*FakeSecureSessionStore) Transcript

func (*FakeSecureSessionStore) UpdateAttemptOutcome

func (f *FakeSecureSessionStore) UpdateAttemptOutcome(ctx context.Context, outcome domain.AttemptOutcome) error

func (*FakeSecureSessionStore) UsageTokenTotals

func (f *FakeSecureSessionStore) UsageTokenTotals(ctx context.Context, id domain.SessionID) (int64, int64, error)

type FakeStateStore

type FakeStateStore struct {
	lipstate.Store
}

FakeStateStore is an in-memory lipstate.Store backed by the core mem implementation for deterministic TTL and scope behavior (tasks 4.3, 6, 6.1).

func NewFakeStateStore

func NewFakeStateStore() *FakeStateStore

NewFakeStateStore returns a fake store using wall clock time.

func NewFakeStateStoreAt

func NewFakeStateStoreAt(now func() time.Time) *FakeStateStore

NewFakeStateStoreAt returns a fake store with an injectable clock (deterministic TTL tests).

type FakeWorkspaceResolver

type FakeWorkspaceResolver struct {
	View workspace.WorkspaceView
	Err  error
}

FakeWorkspaceResolver returns a fixed [workspace.WorkspaceView] (task 4.3).

func (FakeWorkspaceResolver) Resolve

type PostgresStoreComponent

type PostgresStoreComponent string

PostgresStoreComponent identifies dual-plane tables cleaned by store_id.

const (
	PostgresComponentAuthority    PostgresStoreComponent = "authority"
	PostgresComponentLease        PostgresStoreComponent = "lease"
	PostgresComponentJournal      PostgresStoreComponent = "journal"
	PostgresComponentTerminalWork PostgresStoreComponent = "terminal-work"
)

type ProviderStub

type ProviderStub struct {
	ID string
}

ProviderStub is a minimal no-op backend stand-in for conformance and wiring tests.

func (ProviderStub) Invoke

Invoke returns an empty stream placeholder until the canonical stream engine exists.

type RecordingRawCaptureSink

type RecordingRawCaptureSink struct {
	Seen []traffic.CaptureMeta
	Data [][]byte
	// contains filtered or unexported fields
}

RecordingRawCaptureSink records privileged raw writes (task 10.1).

func (*RecordingRawCaptureSink) WriteRaw

func (r *RecordingRawCaptureSink) WriteRaw(_ context.Context, leg traffic.Leg, meta traffic.CaptureMeta, payload []byte) error

type RecordingTrafficObserver

type RecordingTrafficObserver struct {
	Seen []traffic.Observation
	// contains filtered or unexported fields
}

RecordingTrafficObserver appends observations for assertions (task 4.3).

func (*RecordingTrafficObserver) OnObservation

type RuntimeSQLGuard

type RuntimeSQLGuard struct {
	// contains filtered or unexported fields
}

RuntimeSQLGuard records forbidden runtime SQL observed through a bun query hook.

func NewRuntimeSQLGuard

func NewRuntimeSQLGuard() *RuntimeSQLGuard

NewRuntimeSQLGuard returns an empty guard suitable for bun.DB.AddQueryHook.

func (*RuntimeSQLGuard) AfterQuery

func (*RuntimeSQLGuard) AfterQuery(context.Context, *bun.QueryEvent)

AfterQuery implements bun.QueryHook.

func (*RuntimeSQLGuard) AssertNoViolations

func (g *RuntimeSQLGuard) AssertNoViolations(t *testing.T)

AssertNoViolations fails the test when forbidden runtime SQL was observed.

func (*RuntimeSQLGuard) BeforeQuery

func (g *RuntimeSQLGuard) BeforeQuery(ctx context.Context, event *bun.QueryEvent) context.Context

BeforeQuery implements bun.QueryHook.

func (*RuntimeSQLGuard) HasRuntimeDDL

func (g *RuntimeSQLGuard) HasRuntimeDDL() bool

HasRuntimeDDL reports whether any recorded violation is runtime DDL or temp DDL.

func (*RuntimeSQLGuard) Reset

func (g *RuntimeSQLGuard) Reset()

Reset clears recorded violations between tests sharing a query hook.

func (*RuntimeSQLGuard) Violations

func (g *RuntimeSQLGuard) Violations() []string

Violations returns a snapshot of recorded forbidden SQL reasons.

type SSEFrame

type SSEFrame struct {
	Event string
	Data  string
}

func ParseRecorderSSE

func ParseRecorderSSE(rec *httptest.ResponseRecorder) []SSEFrame

func ParseSSEBody

func ParseSSEBody(body string) []SSEFrame

type SecureSessionStubExecutorOptions

type SecureSessionStubExecutorOptions struct {
	Now      func() time.Time
	Rand     routing.Rng
	RandSeed int64 // used when Rand is nil (default 42)

	// Workspace is merged into the runtime snapshot; nil uses empty workspace (void resolver).
	Workspace lipworkspace.Resolver

	// SecureStore when non-nil is used as the secure-session durable store; otherwise a memory
	// store with SimulateDurable=true is constructed.
	SecureStore app.Store

	// SecureSessionRequireWorkspaceID mirrors runtime.Executor.SecureSessionRequireWorkspaceID.
	SecureSessionRequireWorkspaceID bool
	// SecureSessionWorkspaceResolveFailClosed mirrors runtime.Executor.SecureSessionWorkspaceResolveFailClosed.
	SecureSessionWorkspaceResolveFailClosed bool

	// FingerprintKey for resume fingerprinting; nil uses [SecureSessionTestFingerprintKey].
	FingerprintKey []byte

	// ManagerConfig is merged after FingerprintKey/ResumeWindow/StoreDurable defaults are applied.
	ManagerConfig app.ManagerConfig

	// Backends when non-nil replaces the default single-stub map entirely.
	Backends map[string]execbackend.Backend

	// StubText is emitted as one text delta when Backends is nil (same as [NewStubExecutor]).
	StubText string

	SecureSessionRecorder           app.GateRecording
	SecureSessionRecordingMandatory bool
}

SecureSessionStubExecutorOptions configures NewStubExecutorWithSecureSession (task 11.x harness).

type StubRemoteDecider

type StubRemoteDecider struct {
	Decision sdkauth.Decision
	Err      error
}

StubRemoteDecider is a fixed [coreauth.RemoteDecider] for composition and runtimebundle tests.

func (*StubRemoteDecider) Decide

Decide implements [coreauth.RemoteDecider].

type TestFeatureBundle

type TestFeatureBundle struct {
	ContributorID                    string
	CompletionGates                  []completion.Gate
	RequestTransforms                []request.Transform
	PreRequestHandlers               []prerequest.Handler
	RouteHintProviders               []routehint.Provider
	AttemptTransforms                []request.AttemptTransform
	SessionOpeners                   []session.Opener
	WorkspaceResolvers               []lipworkspace.Resolver
	ToolCatalogFilters               []toolcatalog.Filter
	ToolCallPolicies                 []toolpolicy.Policy
	ToolCallFinalizers               []toolcall.Finalizer
	ToolCallFinalizationMaxArgsBytes int
	CompactionObservers              []compaction.Observer
	CompactionPreservers             []compaction.Preserver
	TrafficObservers                 []traffic.Observer
	UsageObservers                   []usage.Observer
	RawCaptureSinks                  []traffic.RawCaptureSink
	TrafficRedactors                 []traffic.Redactor
	StreamObserverFactories          []response.StreamObserverFactory
	LocalTurnHandlers                []localturn.Handler
	TerminalDecisionProvider         terminaldecision.Provider
	SecretGuards                     []secretguard.Guard
}

TestFeatureBundle is a test fixture struct for constructing FrozenPlaneSets.

type TestSnapshotOptions

type TestSnapshotOptions struct {
	Generation      int64
	State           state.Store
	Aux             auxiliary.Client
	TrafficObserver traffic.Observer
	RawCapture      traffic.RawCaptureSink
	Workspace       workspace.Resolver
}

TestSnapshotOptions configures NewTestRequestRuntimeSnapshot for deterministic tests (task 4.3).

Directories

Path Synopsis
Package backendplugin provides a deterministic in-process fake backend plugin and a future executable command skeleton name for host launch tests.
Package backendplugin provides a deterministic in-process fake backend plugin and a future executable command skeleton name for host launch tests.
Package billsem is a self-contained, test-only reference implementation of component-schema quantity semantics.
Package billsem is a self-contained, test-only reference implementation of component-schema quantity semantics.
Package compatibleparity holds deterministic canonical parity and instance-isolation fixtures for the three built-in compatible backend modes.
Package compatibleparity holds deterministic canonical parity and instance-isolation fixtures for the three built-in compatible backend modes.
Package conformance hosts the bundled frontend × backend conformance matrix (spec tasks 12.x).
Package conformance hosts the bundled frontend × backend conformance matrix (spec tasks 12.x).
metering
Package metering contains a bounded family-level contract test for provider normalizers and the shared V2 reducer.
Package metering contains a bounded family-level contract test for provider normalizers and the shared V2 reducer.
cmd command
Package nativecontext contains deterministic, content-safe evidence helpers for the experimental Codex native-context integration and quality suites.
Package nativecontext contains deterministic, content-safe evidence helpers for the experimental Codex native-context integration and quality suites.
cmd/evaluate command
Package reasoninge2e provides a deterministic client-transcript model and backend-request oracle for reasoning-preservation full HTTP E2E phases.
Package reasoninge2e provides a deterministic client-transcript model and backend-request oracle for reasoning-preservation full HTTP E2E phases.
Package terminaldecision contains deterministic coordination fixtures for terminal-decision platform tests.
Package terminaldecision contains deterministic coordination fixtures for terminal-decision platform tests.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL