项目文件夹

文件
wehub-resource-sync 426e9eeabd
Voice Workbench / headless workbench (mocked backends) (push) Has been cancelled
Voice Workbench / real acoustic lane (nightly, provisioned only) (push) Has been cancelled
ci / test (push) Has been cancelled
ci / lint-and-format (push) Has been cancelled
ci / build (push) Has been cancelled
ci / dev-startup (push) Has been cancelled
gitleaks / gitleaks (push) Has been cancelled
Markdown Links / Relative Markdown Links (push) Has been cancelled
Quality (Extended) / Homepage Build (PR smoke) (push) Has been cancelled
Quality (Extended) / Comment-only diff guard (push) Has been cancelled
Quality (Extended) / Format + Type Safety Ratchet (push) Has been cancelled
Quality (Extended) / Develop Gate (secret scan + UI determinism) (push) Has been cancelled
Quality (Extended) / Develop Gate (lint) (push) Has been cancelled
Chat shell gestures / Chat shell gesture + parity e2e (push) Has been cancelled
Cloud Gateway Discord / Test (push) Has been cancelled
Benchmark Bridge Tests / benchmark (bunx @biomejs/biome check packages/lifeops-bench/src, benchmark-lint) (push) Has been cancelled
Benchmark Bridge Tests / benchmark (bunx vitest run --config packages/lifeops-bench/vitest.config.ts --root packages/lifeops-bench --passWithNoTests, benchmark-tests) (push) Has been cancelled
Build Agent Image / build-and-push (push) Has been cancelled
Dev Smoke / bun run dev onboarding chat (push) Has been cancelled
Dev Smoke / Vite HMR dependency-level smoke (push) Has been cancelled
Electrobun Submodule Guard / electrobun gitlink is fetchable (push) Has been cancelled
Publish @elizaos/example-code / check_npm (push) Has been cancelled
Publish @elizaos/example-code / publish_npm (push) Has been cancelled
Publish @elizaos/plugin-elizacloud / verify_version (push) Has been cancelled
Publish @elizaos/plugin-elizacloud / publish_npm (push) Has been cancelled
Sandbox Live Smoke / Sandbox live smoke (push) Has been cancelled
Snap Build & Test / Build Snap (amd64) (push) Has been cancelled
Snap Build & Test / Build Snap (arm64) (push) Has been cancelled
Test Packaging / elizaos CLI global-install smoke (node + bun) (push) Has been cancelled
Cloud Gateway Webhook / Test (push) Has been cancelled
Cloud Tests / lint-and-types (push) Has been cancelled
Cloud Tests / unit-tests (push) Has been cancelled
Cloud Tests / integration-tests (push) Has been cancelled
Cloud Tests / e2e-tests (push) Has been cancelled
CodeQL Advanced / Analyze (javascript-typescript) (push) Has been cancelled
Deploy Apps Worker (Product 2) / Determine environment (push) Has been cancelled
Deploy Apps Worker (Product 2) / Deploy apps worker to apps-control host (${{ needs.determine-env.outputs.environment }}) (push) Has been cancelled
Deploy Eliza Provisioning Worker / Determine environment (push) Has been cancelled
Deploy Eliza Provisioning Worker / Deploy worker to Hetzner host (${{ needs.determine-env.outputs.environment }} @ ${{ needs.determine-env.outputs.deployment_sha }}) (push) Has been cancelled
Dev Smoke / Classify changed paths (push) Has been cancelled
supply-chain / sbom (push) Has been cancelled
supply-chain / vulnerability-scan (push) Has been cancelled
Build, Push & Deploy to Phala Cloud / build-and-push (push) Has been cancelled
Test Packaging / Validate Packaging Configs (push) Has been cancelled
Test Packaging / Build & Test PyPI Package (push) Has been cancelled
Test Packaging / PyPI on Python ${{ matrix.python }} (push) Has been cancelled
Test Packaging / Pack & Test JS Tarballs (push) Has been cancelled
UI Fixture E2E / ui-fixture-e2e (push) Has been cancelled
UI Fixture E2E / fixture-e2e (push) Has been cancelled
UI Story Gate / story-gate (push) Has been cancelled
vault-ci / test (macos-latest) (push) Has been cancelled
vault-ci / test (ubuntu-latest) (push) Has been cancelled
vault-ci / test (windows-latest) (push) Has been cancelled
vault-ci / app-core wiring tests (push) Has been cancelled
verify-patches / verify patches/CHECKSUMS.sha256 (push) Has been cancelled
Voice Benchmark Smoke / voice-emotion fixture smoke (push) Has been cancelled
Voice Benchmark Smoke / voiceagentbench fixture smoke (push) Has been cancelled
Voice Benchmark Smoke / voicebench-quality unit smoke (push) Has been cancelled
Voice Benchmark Smoke / voicebench TypeScript unit (no audio) (push) Has been cancelled
Voice Benchmark Smoke / voice bench smoke summary (push) Has been cancelled
Windows CI / windows ([bun run --cwd packages/app-core test bun run --cwd packages/elizaos test bun run --cwd packages/cloud/shared test], app-and-cli) (push) Has been cancelled
Windows CI / windows ([bun run --cwd packages/scenario-runner test bun run --cwd packages/vault test bun run --cwd packages/security test bun run --cwd plugins/plugin-coding-tools test], framework-packages) (push) Has been cancelled
Windows CI / windows ([bun run --cwd plugins/plugin-elizacloud test bun run --cwd plugins/plugin-discord test bun run --cwd plugins/plugin-anthropic test bun run --cwd plugins/plugin-openai test bun run --cwd plugins/plugin-app-control test bun run --cwd plugins/pl… (push) Has been cancelled
Windows CI / windows ([node packages/scripts/run-turbo.mjs run build --filter=@elizaos/core --filter=@elizaos/shared --filter=@elizaos/agent --concurrency=4 node packages/scripts/run-bash-linux-only.mjs scripts/verify-riscv64-buildpaths.sh node packages/scripts/run… (push) Has been cancelled
Windows CI / windows ([node packages/scripts/run-turbo.mjs run typecheck --filter=@elizaos/core --filter=@elizaos/shared --filter=@elizaos/cloud-shared --concurrency=4 bun run --cwd packages/core test bun run --cwd packages/shared test], core-runtime, 75) (push) Has been cancelled
chore: import upstream snapshot with attribution
2026-07-13 12:43:05 +08:00

194 行
7.7 KiB
TypeScript

/**
* Unit tests for the CloudAuth background API-key re-validation state machine
* (`decideRevalidation`). This is the self-heal that fixes an agent going
* 401-blind after its injected key is revoked: it retries transient
* cloud-unreachability (so a boot-time outage doesn't leave the key unvalidated
* forever), confirms a revoked key with a single loud actionable error
* (debounced so a transient 5xx doesn't false-alarm), and steady-re-checks so a
* post-boot revocation is caught and a later re-authorization self-heals.
*/
import * as http from "node:http";
import { afterAll, beforeAll, describe, expect, it } from "vitest";
import {
type ApiKeyProbe,
CloudAuthService,
decideRevalidation,
type RevalidationConfig,
type RevalidationState,
} from "../src/services/cloud-auth";
const CFG: RevalidationConfig = {
retryMs: 1_000,
steadyMs: 60_000,
invalidThreshold: 2,
};
const UNKNOWN: RevalidationState = { keyState: "unknown", consecutiveInvalid: 0 };
describe("decideRevalidation", () => {
it("valid probe → confirms the key, logs once, steady re-check", () => {
const d = decideRevalidation(UNKNOWN, "valid", CFG);
expect(d.state).toEqual({ keyState: "valid", consecutiveInvalid: 0 });
expect(d.delayMs).toBe(CFG.steadyMs);
expect(d.log).toEqual({ level: "info", message: expect.stringContaining("validated") });
});
it("valid again (already valid) → no duplicate log", () => {
const d = decideRevalidation({ keyState: "valid", consecutiveInvalid: 0 }, "valid", CFG);
expect(d.state.keyState).toBe("valid");
expect(d.log).toBeNull();
expect(d.delayMs).toBe(CFG.steadyMs);
});
it("unreachable at boot → keeps state unresolved + retries (the 37911a1e fix)", () => {
const d = decideRevalidation(UNKNOWN, "unreachable", CFG);
expect(d.state).toEqual(UNKNOWN); // still unknown — will keep probing
expect(d.delayMs).toBe(CFG.retryMs);
expect(d.log).toBeNull();
});
it("single invalid probe → NOT confirmed yet (debounce), re-probe soon, no error", () => {
const d = decideRevalidation(UNKNOWN, "invalid", CFG);
expect(d.state).toEqual({ keyState: "unknown", consecutiveInvalid: 1 });
expect(d.delayMs).toBe(CFG.retryMs);
expect(d.log).toBeNull();
});
it("second consecutive invalid → CONFIRMS revoked, logs a single error, steady re-check", () => {
const d = decideRevalidation({ keyState: "unknown", consecutiveInvalid: 1 }, "invalid", CFG);
expect(d.state).toEqual({ keyState: "invalid", consecutiveInvalid: 2 });
expect(d.delayMs).toBe(CFG.steadyMs);
expect(d.log?.level).toBe("error");
expect(d.log?.message).toMatch(/REVOKED\/INVALID/);
});
it("invalid again (already invalid) → no duplicate error log", () => {
const d = decideRevalidation({ keyState: "invalid", consecutiveInvalid: 2 }, "invalid", CFG);
expect(d.state.keyState).toBe("invalid");
expect(d.log).toBeNull();
});
it("a network blip between two rejections does NOT reset the confirmation count", () => {
// invalid(1) → unreachable (blip) → invalid → should confirm on the 2nd real rejection
let s = decideRevalidation(UNKNOWN, "invalid", CFG).state; // count=1
s = decideRevalidation(s, "unreachable", CFG).state; // count preserved
expect(s.consecutiveInvalid).toBe(1);
const d = decideRevalidation(s, "invalid", CFG); // count=2 → confirmed
expect(d.state.keyState).toBe("invalid");
expect(d.log?.level).toBe("error");
});
it("self-heals: confirmed-invalid → valid re-authorization clears the state + logs recovery", () => {
const d = decideRevalidation({ keyState: "invalid", consecutiveInvalid: 2 }, "valid", CFG);
expect(d.state).toEqual({ keyState: "valid", consecutiveInvalid: 0 });
expect(d.log).toEqual({ level: "info", message: expect.stringContaining("validated") });
expect(d.delayMs).toBe(CFG.steadyMs);
});
it("uses the default config when none is passed", () => {
const d = decideRevalidation(UNKNOWN, "valid");
expect(d.state.keyState).toBe("valid");
expect(d.delayMs).toBe(30 * 60_000);
});
});
/**
* I/O-layer classification tests for the private `probeApiKey`. These exercise
* the REAL `CloudApiClient` against a local HTTP server so the genuine
* `CloudApiError` (non-2xx) / raw-fetch-error (timeout, connection refused)
* paths are hit — the layer the unit tests above intentionally don't cover.
*
* The defect being guarded: a catch-all `return "invalid"` turned every non-auth
* failure (5xx / 429 / timeout / outage) into a false "key REVOKED" alarm. Only
* a reachable-but-rejected auth response (401/403) is `invalid`; everything else
* is `unreachable`.
*/
describe("CloudAuthService.probeApiKey classification (I/O)", () => {
let server: http.Server;
let baseUrl: string;
/** Per-test response control. `hang: true` never responds → forces a timeout. */
let next: { status: number; hang: boolean };
function probe(): Promise<ApiKeyProbe> {
const service = new CloudAuthService();
service.getClient().setBaseUrl(baseUrl);
// probeApiKey is private; reach it through a typed cast — we're testing the
// real method, not re-implementing it.
return (service as unknown as { probeApiKey(key: string): Promise<ApiKeyProbe> }).probeApiKey(
"test-key"
);
}
beforeAll(async () => {
server = http.createServer((_req, res) => {
if (next.hang) {
return; // never respond → client AbortSignal.timeout fires
}
res.writeHead(next.status, { "Content-Type": "application/json" });
res.end(JSON.stringify({ success: false, error: `HTTP ${next.status}` }));
});
await new Promise<void>((resolve) => {
server.listen(0, "127.0.0.1", () => {
const addr = server.address();
if (addr === null || typeof addr === "string") {
throw new Error("expected an AddressInfo from server.address()");
}
baseUrl = `http://127.0.0.1:${addr.port}`;
resolve();
});
});
});
afterAll(async () => {
await new Promise<void>((resolve, reject) => {
server.close((err) => (err ? reject(err) : resolve()));
});
});
it("200 OK → valid", async () => {
next = { status: 200, hang: false };
expect(await probe()).toBe("valid");
});
it("401 (cloud reachable, key rejected) → invalid", async () => {
next = { status: 401, hang: false };
expect(await probe()).toBe("invalid");
});
it("403 (cloud reachable, key forbidden) → invalid", async () => {
next = { status: 403, hang: false };
expect(await probe()).toBe("invalid");
});
it("500 (server error, NOT an auth signal) → unreachable, NOT invalid", async () => {
next = { status: 500, hang: false };
const result = await probe();
expect(result).toBe("unreachable");
expect(result).not.toBe("invalid");
});
it("429 (rate limited) → unreachable, NOT invalid", async () => {
next = { status: 429, hang: false };
const result = await probe();
expect(result).toBe("unreachable");
expect(result).not.toBe("invalid");
});
it("timeout / AbortError (server never responds) → unreachable, NOT invalid", async () => {
next = { status: 0, hang: true };
const result = await probe();
expect(result).toBe("unreachable");
expect(result).not.toBe("invalid");
});
it("connection refused (no server) → unreachable, NOT invalid", async () => {
const service = new CloudAuthService();
// Reserved-by-RFC port that nothing listens on → ECONNREFUSED (raw fetch error).
service.getClient().setBaseUrl("http://127.0.0.1:1");
const result = await (
service as unknown as { probeApiKey(key: string): Promise<ApiKeyProbe> }
).probeApiKey("test-key");
expect(result).toBe("unreachable");
expect(result).not.toBe("invalid");
});
});