tools.spec.ts 107 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453145414551456145714581459146014611462146314641465146614671468146914701471147214731474147514761477147814791480148114821483148414851486148714881489149014911492149314941495149614971498149915001501150215031504150515061507150815091510151115121513151415151516151715181519152015211522152315241525152615271528152915301531153215331534153515361537153815391540154115421543154415451546154715481549155015511552155315541555155615571558155915601561156215631564156515661567156815691570157115721573157415751576157715781579158015811582158315841585158615871588158915901591159215931594159515961597159815991600160116021603160416051606160716081609161016111612161316141615161616171618161916201621162216231624162516261627162816291630163116321633163416351636163716381639164016411642164316441645164616471648164916501651165216531654165516561657165816591660166116621663166416651666166716681669167016711672167316741675167616771678167916801681168216831684168516861687168816891690169116921693169416951696169716981699170017011702170317041705170617071708170917101711171217131714171517161717171817191720172117221723172417251726172717281729173017311732173317341735173617371738173917401741174217431744174517461747174817491750175117521753175417551756175717581759176017611762176317641765176617671768176917701771177217731774177517761777177817791780178117821783178417851786178717881789179017911792179317941795179617971798179918001801180218031804180518061807180818091810181118121813181418151816181718181819182018211822182318241825182618271828182918301831183218331834183518361837183818391840184118421843184418451846184718481849185018511852185318541855185618571858185918601861186218631864186518661867186818691870187118721873187418751876187718781879188018811882188318841885188618871888188918901891189218931894189518961897189818991900190119021903190419051906190719081909191019111912191319141915191619171918191919201921192219231924192519261927192819291930193119321933193419351936193719381939194019411942194319441945194619471948194919501951195219531954195519561957195819591960196119621963196419651966196719681969197019711972197319741975197619771978197919801981198219831984198519861987198819891990199119921993199419951996199719981999200020012002200320042005200620072008200920102011201220132014201520162017201820192020202120222023202420252026202720282029203020312032203320342035203620372038203920402041204220432044204520462047204820492050205120522053205420552056205720582059206020612062206320642065206620672068206920702071207220732074207520762077207820792080208120822083208420852086208720882089209020912092209320942095209620972098209921002101210221032104210521062107210821092110211121122113211421152116211721182119212021212122212321242125212621272128212921302131213221332134213521362137213821392140214121422143214421452146214721482149215021512152215321542155215621572158215921602161216221632164216521662167216821692170217121722173217421752176217721782179218021812182218321842185218621872188218921902191219221932194219521962197219821992200220122022203220422052206220722082209221022112212221322142215221622172218221922202221222222232224222522262227222822292230223122322233223422352236223722382239224022412242224322442245224622472248224922502251225222532254225522562257225822592260226122622263226422652266226722682269227022712272227322742275227622772278227922802281228222832284228522862287228822892290229122922293229422952296229722982299230023012302230323042305230623072308230923102311231223132314231523162317231823192320232123222323232423252326232723282329233023312332233323342335233623372338233923402341234223432344234523462347234823492350235123522353235423552356235723582359236023612362236323642365236623672368236923702371237223732374237523762377237823792380238123822383238423852386238723882389239023912392239323942395239623972398239924002401240224032404240524062407240824092410241124122413241424152416241724182419242024212422242324242425242624272428242924302431243224332434243524362437243824392440244124422443244424452446244724482449245024512452245324542455245624572458245924602461246224632464246524662467246824692470247124722473247424752476247724782479248024812482248324842485248624872488248924902491249224932494249524962497249824992500250125022503250425052506250725082509251025112512251325142515251625172518251925202521252225232524252525262527252825292530253125322533253425352536253725382539254025412542254325442545254625472548254925502551255225532554255525562557255825592560256125622563256425652566256725682569257025712572257325742575257625772578257925802581258225832584258525862587258825892590259125922593259425952596259725982599260026012602260326042605260626072608260926102611261226132614261526162617261826192620262126222623262426252626262726282629263026312632263326342635263626372638263926402641264226432644264526462647264826492650265126522653265426552656265726582659266026612662266326642665266626672668266926702671267226732674267526762677267826792680268126822683268426852686268726882689269026912692269326942695269626972698269927002701270227032704270527062707270827092710271127122713271427152716271727182719272027212722272327242725272627272728272927302731273227332734273527362737273827392740274127422743274427452746274727482749275027512752275327542755275627572758275927602761276227632764276527662767276827692770277127722773277427752776277727782779278027812782278327842785278627872788278927902791279227932794279527962797279827992800280128022803280428052806280728082809281028112812281328142815281628172818281928202821282228232824282528262827
  1. import { describe, expect, expectTypeOf, it } from 'vitest'
  2. import { Context } from '@deepseek-ai/cordis'
  3. import LlmRuntime, { createUserMessage, ToolCallId, HarnessError, type ContentBlock } from '@deepseek-ai/dsh-llm'
  4. import SessionStore, { Session, SessionId } from '@deepseek-ai/dsh-session'
  5. import SessionProjectionRegistry from '@deepseek-ai/dsh-session-projection'
  6. import SystemPrompt from '@deepseek-ai/dsh-system-prompt'
  7. import AgentRegistry, { type Agent } from '@deepseek-ai/dsh-agent'
  8. import AgentLoop from '@deepseek-ai/dsh-agent-loop'
  9. import ApprovalService, { type ApprovalOutcome, type ApprovalRequest } from '@deepseek-ai/dsh-user-approval'
  10. import ToolRuntime, {
  11. defineContentToolFixture, defineTool, JsonSchemaError, parameterSchemaSpecToJsonSchema, validateArgs, ToolArgsError, ToolNotFoundError,
  12. TOOL_ABORTED, TOOL_ABORTED_BEFORE_DISPATCH,
  13. type InferArgs, type ParameterSchemaSpec, type PreToolDecision, type PostToolDecision,
  14. type JsonSchemaNode, type ToolDefinition, type ToolDispatchExecution, type ToolExecutionResult, type ToolExecutionToken,
  15. } from '@deepseek-ai/dsh-tools'
  16. import type { JsonValue } from '@deepseek-ai/dsh-util-values'
  17. const testToolSignal = new AbortController().signal
  18. async function setup() {
  19. const ctx = new Context()
  20. await ctx.plugin(SystemPrompt)
  21. await ctx.plugin(ToolRuntime)
  22. return ctx
  23. }
  24. const echoTool = defineTool({
  25. name: 'echo',
  26. description: 'echo arguments back',
  27. parameters: { text: { type: 'string' } },
  28. output: {
  29. schema: { type: 'string' },
  30. render: (_args, value) => [{ type: 'text', text: value }],
  31. },
  32. async execute(args) {
  33. return args.text ?? ''
  34. },
  35. })
  36. describe('ToolRuntime', () => {
  37. it('registers tools, exposes schemas, and feeds the system-prompt assembly', async () => {
  38. const ctx = await setup()
  39. ctx.tools.register(echoTool)
  40. expect(ctx.tools.schemas()).toEqual([{
  41. name: 'echo',
  42. description: 'echo arguments back',
  43. parameters: { type: 'object', properties: { text: { type: 'string' } } },
  44. }])
  45. // schemas() result must not leak execute — ToolSchema deliberately has no
  46. // 'execute' key, so widen through unknown to probe for the absent property
  47. expect((ctx.tools.schemas()[0] as unknown as Record<string, unknown>).execute).toBeUndefined()
  48. const assembly = await ctx.systemPrompt.assemble()
  49. expect(assembly.tools.map(t => t.name)).toEqual(['echo'])
  50. })
  51. it('schemas() drops host callbacks — they must never reach the model', async () => {
  52. const ctx = await setup()
  53. // Tool definitions contain output, finalization, execution, and presentation
  54. // callbacks. schemas() is an explicit allowlist so none can reach the model.
  55. ctx.tools.register(defineContentToolFixture({
  56. name: 'present',
  57. description: 'has presenters',
  58. parameters: { x: { type: 'string', required: true } },
  59. async execute() { return [] },
  60. finalizeContent: (_exec, result) => result.content,
  61. presentCall: args => ({ card: 'generic', title: args.x }),
  62. presentResult: (args, result) => ({ card: 'generic', title: args.x, content: result.content }),
  63. }))
  64. const schema = ctx.tools.schemas()[0] as unknown as Record<string, unknown>
  65. expect(Object.keys(schema).sort()).toEqual(['description', 'name', 'parameters'])
  66. expect(schema.finalizeContent).toBeUndefined()
  67. expect(schema.presentCall).toBeUndefined()
  68. expect(schema.presentResult).toBeUndefined()
  69. expect(schema.execute).toBeUndefined()
  70. })
  71. it('schemas() excludes timeoutMs — the budget must never reach the model', async () => {
  72. const ctx = await setup()
  73. ctx.tools.register(defineContentToolFixture({
  74. name: 'budgeted', description: 'has a budget', parameters: {}, timeoutMs: 5_000,
  75. async execute() { return [{ type: 'text' as const, text: 'ok' }] },
  76. }))
  77. const schema = ctx.tools.schemas().find(s => s.name === 'budgeted')
  78. expect(schema).toBeDefined()
  79. expect('timeoutMs' in (schema as object)).toBe(false)
  80. })
  81. it('executes a tool and returns its content', async () => {
  82. const ctx = await setup()
  83. ctx.tools.register(echoTool)
  84. let observed: ToolExecutionResult | undefined
  85. ctx.on('tools/result', (_exec, result) => { observed = result })
  86. const result = await ctx.tools.execute({ signal: testToolSignal, callId: ToolCallId('c1'), name: 'echo', arguments: { text: 'hi' } })
  87. expect(result).toEqual({ content: [{ type: 'text', text: 'hi' }], isError: false, value: 'hi' })
  88. expect(observed).toEqual(result)
  89. })
  90. it('projects presentation metadata from the canonical value', async () => {
  91. const ctx = await setup()
  92. ctx.tools.register({
  93. ...echoTool,
  94. name: 'meta-tool',
  95. output: {
  96. ...echoTool.output,
  97. presentationMeta: () => ({ diffs: [{ path: 'a', oldText: null, newText: 'x' }] }),
  98. },
  99. async execute() {
  100. return 'ok'
  101. },
  102. })
  103. const result = await ctx.tools.execute({ signal: testToolSignal, callId: ToolCallId('c1'), name: 'meta-tool', arguments: {} })
  104. expect(result).toEqual({
  105. content: [{ type: 'text', text: 'ok' }],
  106. isError: false,
  107. meta: { diffs: [{ path: 'a', oldText: null, newText: 'x' }] },
  108. value: 'ok',
  109. })
  110. })
  111. it('omits meta when no presentation projector is declared', async () => {
  112. const ctx = await setup()
  113. ctx.tools.register({
  114. ...echoTool,
  115. name: 'no-meta-tool',
  116. async execute() {
  117. return 'ok'
  118. },
  119. })
  120. const result = await ctx.tools.execute({ signal: testToolSignal, callId: ToolCallId('c1'), name: 'no-meta-tool', arguments: {} })
  121. expect(result).toEqual({ content: [{ type: 'text', text: 'ok' }], isError: false, value: 'ok' })
  122. expect('meta' in result).toBe(false)
  123. })
  124. it('normalizes a contract-violating non-cloneable result before final notification', async () => {
  125. const ctx = await setup()
  126. let observedError: boolean | undefined
  127. ctx.on('tools/result', (_exec, result) => { observedError = result.isError })
  128. ctx.tools.register({
  129. ...echoTool,
  130. name: 'bad-meta',
  131. output: {
  132. ...echoTool.output,
  133. presentationMeta: () => (() => undefined) as unknown as JsonValue,
  134. },
  135. async execute() {
  136. return 'ok'
  137. },
  138. })
  139. const result = await ctx.tools.execute({
  140. signal: testToolSignal,
  141. callId: ToolCallId('bad-meta'), name: 'bad-meta', arguments: {},
  142. })
  143. expect(result.isError).toBe(true)
  144. expect(result.content[0]?.type === 'text' && result.content[0].text).toContain('Error:')
  145. expect(result.error).toMatchObject({ info: { name: 'ToolOutputError', code: 'INVALID_TOOL_OUTPUT' } })
  146. expect(observedError).toBe(true)
  147. })
  148. it('finalizes errors discovered while snapshotting non-content result fields', async () => {
  149. const ctx = await setup()
  150. let finalizeCalls = 0
  151. ctx.tools.register({
  152. ...echoTool,
  153. name: 'throwing-meta',
  154. output: {
  155. ...echoTool.output,
  156. presentationMeta() {
  157. const meta = {}
  158. Object.defineProperty(meta, 'value', {
  159. enumerable: true,
  160. get() { throw new Error('snapshot failed: '.repeat(100)) },
  161. })
  162. return meta
  163. },
  164. },
  165. finalizeContent(_exec, result) {
  166. finalizeCalls += 1
  167. const block = result.content[0]
  168. if (block?.type !== 'text') return undefined
  169. return [{ type: 'text', text: block.text.slice(0, 32) }]
  170. },
  171. async execute() {
  172. return 'body'
  173. },
  174. })
  175. const result = await ctx.tools.execute({
  176. signal: testToolSignal,
  177. callId: ToolCallId('throwing-meta'), name: 'throwing-meta', arguments: {},
  178. })
  179. expect(result.isError).toBe(true)
  180. const block = result.content[0]
  181. expect(block?.type).toBe('text')
  182. expect(block?.type === 'text' ? block.text : '').toMatch(/^Error: tool "throwing-meta"/)
  183. expect(block?.type === 'text' ? block.text : '').toHaveLength(32)
  184. expect(finalizeCalls).toBe(1)
  185. })
  186. it('normalizes a throwing final content callback without invoking it again', async () => {
  187. const ctx = await setup()
  188. let finalizeCalls = 0
  189. ctx.tools.register({
  190. ...echoTool,
  191. name: 'throwing-finalizer',
  192. finalizeContent() {
  193. finalizeCalls += 1
  194. throw new Error('finalizer violated its total contract')
  195. },
  196. })
  197. const result = await ctx.tools.execute({
  198. signal: testToolSignal,
  199. callId: ToolCallId('throwing-finalizer'), name: 'throwing-finalizer', arguments: {},
  200. })
  201. expect(result).toEqual({
  202. content: [{ type: 'text', text: 'Error: finalizer violated its total contract' }],
  203. isError: true,
  204. error: { message: 'finalizer violated its total contract' },
  205. })
  206. expect(finalizeCalls).toBe(1)
  207. })
  208. it('requires every raw registration to declare its canonical output', async () => {
  209. const ctx = await setup()
  210. const missingOutput = {
  211. name: 'legacy-content-tool',
  212. description: 'missing output',
  213. parameters: {},
  214. execute: async () => [{ type: 'text', text: 'legacy' }],
  215. } as unknown as ToolDefinition
  216. expect(() => ctx.tools.register(missingOutput))
  217. .toThrow('must declare output { schema, render, presentationMeta? }')
  218. })
  219. it('rejects lossy and schema-mismatched body values before post-execute', async () => {
  220. const ctx = await setup()
  221. ctx.tools.register(defineTool({
  222. name: 'lossy-output',
  223. description: 'lossy',
  224. parameters: {},
  225. output: { schema: { type: 'json' }, render: () => [] },
  226. execute: async () => (() => undefined) as unknown as JsonValue,
  227. }))
  228. ctx.tools.register(defineTool({
  229. name: 'wrong-output',
  230. description: 'wrong schema',
  231. parameters: {},
  232. output: { schema: { type: 'string' }, render: () => [] },
  233. execute: async () => 42 as unknown as string,
  234. }))
  235. const lossy = await ctx.tools.execute({ signal: testToolSignal, callId: ToolCallId('lossy'), name: 'lossy-output', arguments: {} })
  236. const mismatch = await ctx.tools.execute({ signal: testToolSignal, callId: ToolCallId('mismatch'), name: 'wrong-output', arguments: {} })
  237. expect(lossy.error).toMatchObject({ info: { name: 'ToolOutputError', code: 'INVALID_TOOL_OUTPUT' } })
  238. expect(lossy.content[0]?.type === 'text' ? lossy.content[0].text : '').toContain('not lossless JSON')
  239. expect(mismatch.error).toMatchObject({ info: { name: 'ToolOutputError', code: 'INVALID_TOOL_OUTPUT' } })
  240. expect(mismatch.content[0]?.type === 'text' ? mismatch.content[0].text : '').toContain('"value" must be a string')
  241. })
  242. it('classifies a throwing body snapshot as invalid tool output', async () => {
  243. const ctx = await setup()
  244. const hostile = Object.defineProperty({}, 'value', {
  245. enumerable: true,
  246. get: () => { throw new Error('body snapshot getter exploded') },
  247. })
  248. ctx.tools.register(defineTool({
  249. name: 'hostile-body',
  250. description: 'hostile body',
  251. parameters: {},
  252. output: { schema: { type: 'json' }, render: () => [] },
  253. execute: async () => hostile as JsonValue,
  254. }))
  255. const result = await ctx.tools.execute({
  256. signal: testToolSignal,
  257. callId: ToolCallId('hostile-body'), name: 'hostile-body', arguments: {},
  258. })
  259. expect(result.error?.message).toContain('value snapshot failed: body snapshot getter exploded')
  260. expect(result.error?.info).toEqual({ name: 'ToolOutputError', code: 'INVALID_TOOL_OUTPUT' })
  261. })
  262. it.each(['render', 'presentationMeta'] as const)('contains a throwing output.%s projector as one failed call', async (projector) => {
  263. const ctx = await setup()
  264. ctx.tools.register(defineTool({
  265. name: `throwing-${projector}`,
  266. description: projector,
  267. parameters: {},
  268. output: {
  269. schema: { type: 'string' },
  270. render: () => {
  271. if (projector === 'render') throw new Error('renderer exploded')
  272. return [{ type: 'text', text: 'ok' }]
  273. },
  274. presentationMeta: () => {
  275. if (projector === 'presentationMeta') throw new Error('metadata exploded')
  276. return null
  277. },
  278. },
  279. execute: async () => 'ok',
  280. }))
  281. const result = await ctx.tools.execute({ signal: testToolSignal, callId: ToolCallId(projector), name: `throwing-${projector}`, arguments: {} })
  282. expect(result.isError).toBe(true)
  283. expect(result.error?.message)
  284. .toContain(projector === 'render' ? 'renderer exploded' : 'metadata exploded')
  285. expect(result.error?.info).toEqual({ name: 'ToolOutputError', code: 'INVALID_TOOL_OUTPUT' })
  286. expect('value' in result).toBe(false)
  287. })
  288. it.each(['render', 'presentationMeta'] as const)('contains a throwing output.%s snapshot as one failed call', async (projector) => {
  289. const ctx = await setup()
  290. const hostile = Object.defineProperty({}, 'value', {
  291. enumerable: true,
  292. get: () => { throw new Error('snapshot getter exploded') },
  293. })
  294. ctx.tools.register(defineTool({
  295. name: `hostile-${projector}`,
  296. description: projector,
  297. parameters: {},
  298. output: {
  299. schema: { type: 'string' },
  300. render: () => projector === 'render'
  301. ? hostile as unknown as ContentBlock[]
  302. : [{ type: 'text', text: 'ok' }],
  303. presentationMeta: () => projector === 'presentationMeta'
  304. ? hostile as unknown as JsonValue
  305. : null,
  306. },
  307. execute: async () => 'ok',
  308. }))
  309. const result = await ctx.tools.execute({
  310. signal: testToolSignal,
  311. callId: ToolCallId(`hostile-${projector}`), name: `hostile-${projector}`, arguments: {},
  312. })
  313. expect(result.error?.message).toContain('snapshot getter exploded')
  314. expect(result.error?.info).toEqual({ name: 'ToolOutputError', code: 'INVALID_TOOL_OUTPUT' })
  315. })
  316. it('keeps value/meta through content replacement and recomputes both projections after value replacement', async () => {
  317. const ctx = await setup()
  318. ctx.tools.register(defineTool({
  319. name: 'projected',
  320. description: 'projected',
  321. parameters: {},
  322. output: {
  323. schema: {
  324. type: 'object',
  325. additionalProperties: false,
  326. properties: { text: { type: 'string', required: true } },
  327. },
  328. render: (_args, value) => [{ type: 'text', text: `render:${value.text}` }],
  329. presentationMeta: (_args, value) => ({ projected: value.text }),
  330. },
  331. execute: async () => ({ text: 'body' }),
  332. }))
  333. let replacement: 'content' | 'value' = 'content'
  334. ctx.on('tools/post-execute', async () => {
  335. if (replacement === 'content') {
  336. return { kind: 'accept', content: [{ type: 'text', text: 'policy content' }] }
  337. }
  338. return {
  339. kind: 'accept',
  340. value: { text: 'policy value' },
  341. additionalContexts: [createUserMessage({
  342. content: [{ type: 'text', text: 'value context' }], source: { kind: 'plugin', plugin: 'test' },
  343. })],
  344. }
  345. })
  346. const content = await ctx.tools.execute({ signal: testToolSignal, callId: ToolCallId('content'), name: 'projected', arguments: {} })
  347. replacement = 'value'
  348. const value = await ctx.tools.execute({ signal: testToolSignal, callId: ToolCallId('value'), name: 'projected', arguments: {} })
  349. expect(content).toEqual({
  350. isError: false,
  351. value: { text: 'body' },
  352. content: [{ type: 'text', text: 'policy content' }],
  353. meta: { projected: 'body' },
  354. })
  355. expect(value).toEqual({
  356. isError: false,
  357. value: { text: 'policy value' },
  358. content: [{ type: 'text', text: 'render:policy value' }],
  359. meta: { projected: 'policy value' },
  360. additionalContexts: [{
  361. id: expect.any(String) as unknown,
  362. role: 'user',
  363. content: [{ type: 'text', text: 'value context' }],
  364. source: { kind: 'plugin', plugin: 'test' },
  365. }],
  366. })
  367. })
  368. it('fails a post-execute decision that replaces both projections or supplies an invalid value', async () => {
  369. const both = await setup()
  370. both.tools.register(echoTool)
  371. both.on('tools/post-execute', async () => ({
  372. kind: 'accept',
  373. value: 'replacement',
  374. content: [{ type: 'text', text: 'also replacement' }],
  375. } as unknown as PostToolDecision))
  376. const bothResult = await both.tools.execute({ signal: testToolSignal, callId: ToolCallId('both'), name: 'echo', arguments: {} })
  377. expect(bothResult).toMatchObject({
  378. isError: true,
  379. error: { message: 'tools/post-execute accept decision cannot replace both value and content' },
  380. })
  381. const invalid = await setup()
  382. invalid.tools.register(echoTool)
  383. invalid.on('tools/post-execute', async () => ({ kind: 'accept', value: 1 }))
  384. const invalidResult = await invalid.tools.execute({ signal: testToolSignal, callId: ToolCallId('invalid'), name: 'echo', arguments: {} })
  385. expect(invalidResult.error).toMatchObject({ info: { code: 'INVALID_TOOL_OUTPUT' } })
  386. expect('value' in invalidResult).toBe(false)
  387. })
  388. it('turns a post-execute block into a valueless failure', async () => {
  389. const ctx = await setup()
  390. ctx.tools.register(echoTool)
  391. ctx.on('tools/post-execute', async () => ({
  392. kind: 'block',
  393. feedback: [{ type: 'text', text: 'blocked by policy' }],
  394. }))
  395. const result = await ctx.tools.execute({ signal: testToolSignal, callId: ToolCallId('block'), name: 'echo', arguments: { text: 'secret' } })
  396. expect(result).toEqual({
  397. isError: true,
  398. error: { message: 'blocked by policy' },
  399. content: [{ type: 'text', text: 'blocked by policy' }],
  400. })
  401. expect('value' in result).toBe(false)
  402. })
  403. it('replaces a canonical value without manufacturing additional context', async () => {
  404. const ctx = await setup()
  405. ctx.tools.register(echoTool)
  406. ctx.on('tools/post-execute', async () => ({ kind: 'accept', value: 'replacement' }))
  407. const result = await ctx.tools.execute({ signal: testToolSignal, callId: ToolCallId('replace-value'), name: 'echo', arguments: {} })
  408. expect(result).toEqual({
  409. isError: false,
  410. value: 'replacement',
  411. content: [{ type: 'text', text: 'replacement' }],
  412. })
  413. })
  414. it.each([
  415. [[], 'tool result blocked by post-execute policy'],
  416. [[{ type: 'reasoning', text: 'private rationale' }], '[reasoning content]'],
  417. ] as const)('derives a stable failure message from non-text or empty block feedback', async (feedback, message) => {
  418. const ctx = await setup()
  419. ctx.tools.register(echoTool)
  420. ctx.on('tools/post-execute', async () => ({ kind: 'block', feedback: [...feedback] }))
  421. const result = await ctx.tools.execute({ signal: testToolSignal, callId: ToolCallId('block-message'), name: 'echo', arguments: {} })
  422. expect(result.error?.message).toBe(message)
  423. })
  424. it('contains a non-JSON post-execute failure projection as a safe final error', async () => {
  425. const ctx = await setup()
  426. ctx.tools.register(echoTool)
  427. ctx.on('tools/post-execute', async () => ({
  428. kind: 'block',
  429. feedback: [{ type: 'text', text: 'blocked', invalid: () => undefined } as never],
  430. }))
  431. const result = await ctx.tools.execute({ signal: testToolSignal, callId: ToolCallId('invalid-block'), name: 'echo', arguments: {} })
  432. expect(result).toMatchObject({
  433. isError: true,
  434. error: { message: 'tool result must be losslessly JSON-serializable' },
  435. })
  436. })
  437. it('rejects value replacement on a failed dispatch', async () => {
  438. const ctx = await setup()
  439. ctx.tools.register({
  440. ...echoTool,
  441. name: 'throw-before-replace',
  442. async execute() { throw new Error('body failed') },
  443. })
  444. ctx.on('tools/post-execute', async () => ({ kind: 'accept', value: 'replacement' }))
  445. const result = await ctx.tools.execute({
  446. signal: testToolSignal,
  447. callId: ToolCallId('failed-replace'), name: 'throw-before-replace', arguments: {},
  448. })
  449. expect(result.error?.message).toBe('tools/post-execute cannot replace the value of a failed result')
  450. })
  451. it('fails value replacement when the owning tool disappears before post-policy resolves', async () => {
  452. const ctx = await setup()
  453. const dispose = ctx.tools.register(echoTool)
  454. ctx.on('tools/post-execute', async () => {
  455. dispose()
  456. return { kind: 'accept', value: 'replacement' }
  457. })
  458. const result = await ctx.tools.execute({ signal: testToolSignal, callId: ToolCallId('post-disposed'), name: 'echo', arguments: {} })
  459. expect(result.error).toEqual({
  460. message: 'unknown tool "echo"',
  461. info: { name: 'ToolNotFoundError', code: 'UNKNOWN_TOOL' },
  462. })
  463. })
  464. it('normalizes wrapper-authored failure metadata and contexts', async () => {
  465. const ctx = await setup()
  466. ctx.tools.register(echoTool)
  467. ctx.on('tools/execute', async () => ({
  468. isError: true,
  469. error: { message: 'wrapped failure' },
  470. content: [{ type: 'text', text: 'wrapper content' }],
  471. meta: { wrapped: true },
  472. additionalContexts: [createUserMessage({
  473. content: [{ type: 'text', text: 'wrapper context' }], source: { kind: 'plugin', plugin: 'test' },
  474. })],
  475. }))
  476. const result = await ctx.tools.execute({ signal: testToolSignal, callId: ToolCallId('wrapper-failure'), name: 'echo', arguments: {} })
  477. expect(result).toEqual({
  478. isError: true,
  479. error: { message: 'wrapped failure' },
  480. content: [{ type: 'text', text: 'wrapper content' }],
  481. meta: { wrapped: true },
  482. additionalContexts: [{
  483. id: expect.any(String) as unknown,
  484. role: 'user',
  485. content: [{ type: 'text', text: 'wrapper context' }],
  486. source: { kind: 'plugin', plugin: 'test' },
  487. }],
  488. })
  489. })
  490. it('fails wrapper-authored success normalization when the owning tool disappears', async () => {
  491. const ctx = await setup()
  492. const dispose = ctx.tools.register(echoTool)
  493. ctx.on('tools/execute', async () => {
  494. dispose()
  495. return { isError: false, value: 'replacement', content: [] }
  496. })
  497. const result = await ctx.tools.execute({ signal: testToolSignal, callId: ToolCallId('wrapper-disposed'), name: 'echo', arguments: {} })
  498. expect(result.error).toEqual({
  499. message: 'unknown tool "echo"',
  500. info: { name: 'ToolNotFoundError', code: 'UNKNOWN_TOOL' },
  501. })
  502. })
  503. it('suppresses presentation metadata only for nested composite dispatches', async () => {
  504. const ctx = await setup()
  505. ctx.tools.register({
  506. ...echoTool,
  507. name: 'meta-suppression',
  508. output: { ...echoTool.output, presentationMeta: () => ({ card: true }) },
  509. })
  510. const direct = await ctx.tools.execute({ signal: testToolSignal, callId: ToolCallId('direct'), name: 'meta-suppression', arguments: {} })
  511. const nested = await ctx.tools.execute({
  512. signal: testToolSignal,
  513. callId: ToolCallId('nested'),
  514. name: 'meta-suppression',
  515. arguments: {},
  516. parent: Symbol('outer') as ToolExecutionToken,
  517. })
  518. expect(direct.meta).toEqual({ card: true })
  519. expect(nested.meta).toBeUndefined()
  520. expect(nested.isError ? undefined : nested.value).toBe('')
  521. })
  522. it('carries a nested conclusion on the nested result for its composite to forward', async () => {
  523. const ctx = await setup()
  524. ctx.tools.register({
  525. ...echoTool,
  526. name: 'terminal-nested',
  527. async execute(_args, exec) {
  528. exec.concludeTurn()
  529. return 'terminal'
  530. },
  531. })
  532. // A composite that forwards the marker from the nested result — the Code
  533. // Mode dispatch shape. A recovering composite (nested failure swallowed)
  534. // has no marker to forward: ToolExecutionFailure types concludesTurn as
  535. // never, so only an authoritative nested success can conclude the run.
  536. let call = 0
  537. ctx.tools.register({
  538. ...echoTool,
  539. name: 'composite',
  540. async execute(_args, exec) {
  541. call += 1
  542. const nested = await ctx.tools.execute({
  543. signal: exec.signal, callId: ToolCallId(`nested-${call}`), name: 'terminal-nested', arguments: {}, parent: exec.token,
  544. })
  545. if (nested.concludesTurn) exec.concludeTurn()
  546. return nested.isError ? 'nested failed, composite recovered' : 'nested succeeded'
  547. },
  548. })
  549. // A policy converts the nested success into an error: the failed result
  550. // carries no marker, so the recovering composite does not conclude.
  551. const veto = ctx.on('tools/post-execute', async (exec, _result, next): Promise<PostToolDecision> => {
  552. if (exec.name !== 'terminal-nested') return next()
  553. return { kind: 'block', feedback: [{ type: 'text', text: 'nested success rejected' }] }
  554. })
  555. const recovered = await ctx.tools.execute({
  556. signal: testToolSignal, callId: ToolCallId('composite-vetoed'), name: 'composite', arguments: {},
  557. })
  558. expect(recovered.isError).toBe(false)
  559. expect(recovered.concludesTurn).toBeUndefined()
  560. veto()
  561. // The same nested call succeeding carries the marker; the composite
  562. // forwards it onto its own successful result.
  563. const concluded = await ctx.tools.execute({
  564. signal: testToolSignal, callId: ToolCallId('composite-ok'), name: 'composite', arguments: {},
  565. })
  566. expect(concluded.isError).toBe(false)
  567. expect(concluded.concludesTurn).toBe(true)
  568. })
  569. it('returns isError results for unknown tools and throwing tools', async () => {
  570. const ctx = await setup()
  571. ctx.tools.register({
  572. ...echoTool,
  573. name: 'boom',
  574. async execute() {
  575. throw new Error('exploded')
  576. },
  577. })
  578. const unknown = await ctx.tools.execute({ signal: testToolSignal, callId: ToolCallId('c1'), name: 'nope', arguments: {} })
  579. expect(unknown.isError).toBe(true)
  580. expect(unknown.content[0]).toMatchObject({ text: 'Error: unknown tool "nope"' })
  581. // An unknown tool is a routable failure class, same as a tool-thrown one.
  582. expect(unknown.error).toEqual({
  583. message: 'unknown tool "nope"',
  584. info: { name: 'ToolNotFoundError', code: 'UNKNOWN_TOOL' },
  585. })
  586. const thrown = await ctx.tools.execute({ signal: testToolSignal, callId: ToolCallId('c2'), name: 'boom', arguments: {} })
  587. expect(thrown.isError).toBe(true)
  588. expect(thrown.content[0]).toMatchObject({ text: 'Error: exploded' })
  589. })
  590. it('normalizes a hostile thrown value whose inspection and coercion both throw', async () => {
  591. const ctx = await setup()
  592. ctx.tools.register({
  593. ...echoTool,
  594. name: 'hostile-throw',
  595. async execute() {
  596. throw new Proxy({}, {
  597. getPrototypeOf: () => { throw new Error('prototype trap') },
  598. has: () => { throw new Error('has trap') },
  599. get: () => { throw new Error('get trap') },
  600. })
  601. },
  602. })
  603. await expect(ctx.tools.execute({
  604. signal: testToolSignal,
  605. callId: ToolCallId('hostile'), name: 'hostile-throw', arguments: {},
  606. })).resolves.toMatchObject({
  607. isError: true,
  608. content: [{ type: 'text', text: 'Error: <unprintable thrown value>' }],
  609. })
  610. })
  611. it('ToolNotFoundError carries a stable message and code', async () => {
  612. const { HarnessError } = await import('@deepseek-ai/dsh-llm')
  613. const err = new ToolNotFoundError('ghost')
  614. expect(err).toBeInstanceOf(HarnessError)
  615. expect(err.name).toBe('ToolNotFoundError')
  616. expect(err.code).toBe('UNKNOWN_TOOL')
  617. expect(err.message).toBe('unknown tool "ghost"')
  618. })
  619. it('lets a tools/pre-execute listener deny a call (permission pattern)', async () => {
  620. const ctx = await setup()
  621. ctx.tools.register(echoTool)
  622. let postSawFrozen = false
  623. ctx.on('tools/pre-execute', async (exec, next): Promise<PreToolDecision> => {
  624. if (exec.name === 'echo') {
  625. return {
  626. kind: 'deny',
  627. reason: 'denied by policy',
  628. info: { name: 'AutoReviewDeniedError', code: 'AUTO_REVIEW_DENIED', reason: ' raw\nreason ' },
  629. }
  630. }
  631. return next()
  632. })
  633. ctx.on('tools/post-execute', async (_exec, result, next) => {
  634. postSawFrozen = Object.isFrozen(result)
  635. expect(Reflect.set(result, 'content', [])).toBe(false)
  636. return next()
  637. })
  638. const result = await ctx.tools.execute({ signal: testToolSignal, callId: ToolCallId('c1'), name: 'echo', arguments: { text: 'hi' } })
  639. expect(result.isError).toBe(true)
  640. expect(result.content[0]).toMatchObject({ text: 'Error: denied by policy' })
  641. expect(result.error).toEqual({
  642. message: 'denied by policy',
  643. info: { name: 'AutoReviewDeniedError', code: 'AUTO_REVIEW_DENIED', reason: ' raw\nreason ' },
  644. })
  645. expect(postSawFrozen).toBe(true)
  646. })
  647. it('an ask decision degrades to deny when no approval seam is mounted', async () => {
  648. const ctx = await setup()
  649. ctx.tools.register(echoTool)
  650. ctx.on('tools/pre-execute', async (_exec, _next): Promise<PreToolDecision> =>
  651. ({ kind: 'ask', reason: 'needs approval' }))
  652. const result = await ctx.tools.execute({ signal: testToolSignal, callId: ToolCallId('c1'), name: 'echo', arguments: { text: 'hi' } })
  653. expect(result.isError).toBe(true)
  654. expect(result.content[0]).toMatchObject({ text: 'Error: needs approval' })
  655. })
  656. it('an ask decision with no reason degrades to deny with a default message', async () => {
  657. const ctx = await setup()
  658. ctx.tools.register(echoTool)
  659. ctx.on('tools/pre-execute', async (_exec, _next): Promise<PreToolDecision> => ({ kind: 'ask' }))
  660. const result = await ctx.tools.execute({ signal: testToolSignal, callId: ToolCallId('c1'), name: 'echo', arguments: { text: 'hi' } })
  661. expect(result.isError).toBe(true)
  662. expect(result.content[0]).toMatchObject({ text: 'Error: tool "echo" requires approval (not yet supported)' })
  663. })
  664. describe('ask routing through ctx.approval', () => {
  665. function fakeAgent(): Agent {
  666. const session = Session.create(SessionId('approval-fake-agent'))
  667. session.append('turn/start', { turn: 1 })
  668. return { session } as unknown as Agent
  669. }
  670. async function approvalSetup() {
  671. const ctx = new Context()
  672. await ctx.plugin(LlmRuntime)
  673. await ctx.plugin(SessionStore)
  674. await ctx.plugin(SessionProjectionRegistry)
  675. await ctx.plugin(SystemPrompt)
  676. await ctx.plugin(ToolRuntime)
  677. await ctx.plugin(AgentRegistry)
  678. await ctx.plugin(AgentLoop, { agents: [] })
  679. await ctx.plugin(ApprovalService)
  680. ctx.tools.register(echoTool)
  681. return ctx
  682. }
  683. it('dispatches the tool when the answerer grants allowed-once, forwarding the ask fields', async () => {
  684. const ctx = await approvalSetup()
  685. const agent = fakeAgent()
  686. const controller = new AbortController()
  687. const seen: ApprovalRequest[] = []
  688. ctx.on('approval/request', (req) => {
  689. seen.push(req)
  690. return Promise.resolve<ApprovalOutcome>('allowed-once')
  691. })
  692. ctx.on('tools/pre-execute', async (_exec, _next): Promise<PreToolDecision> =>
  693. ({ kind: 'ask', reason: 'hook wants a human' }))
  694. const result = await ctx.tools.execute({
  695. callId: ToolCallId('c1'), name: 'echo', arguments: { text: 'hi' }, agent, signal: controller.signal,
  696. })
  697. expect(result).toMatchObject({ isError: false, content: [{ type: 'text', text: 'hi' }] })
  698. expect(seen).toHaveLength(1)
  699. expect(seen[0]).toMatchObject({ agent, toolName: 'echo', callId: 'c1', reason: 'hook wants a human' })
  700. expect(seen[0]?.signal).toBe(controller.signal)
  701. })
  702. it('denies with the user-rejection reason on rejected', async () => {
  703. const ctx = await approvalSetup()
  704. ctx.on('approval/request', () => Promise.resolve<ApprovalOutcome>('rejected'))
  705. ctx.on('tools/pre-execute', async (_exec, _next): Promise<PreToolDecision> => ({ kind: 'ask' }))
  706. const result = await ctx.tools.execute({ signal: testToolSignal, callId: ToolCallId('c1'), name: 'echo', arguments: {}, agent: fakeAgent() })
  707. expect(result.isError).toBe(true)
  708. expect(result.content[0]).toMatchObject({ text: 'Error: the user rejected tool "echo"' })
  709. })
  710. it('denies with the cancellation reason on cancelled', async () => {
  711. const ctx = await approvalSetup()
  712. ctx.on('approval/request', () => Promise.resolve<ApprovalOutcome>('cancelled'))
  713. ctx.on('tools/pre-execute', async (_exec, _next): Promise<PreToolDecision> => ({ kind: 'ask' }))
  714. const result = await ctx.tools.execute({ signal: testToolSignal, callId: ToolCallId('c1'), name: 'echo', arguments: {}, agent: fakeAgent() })
  715. expect(result.isError).toBe(true)
  716. expect(result.content[0]).toMatchObject({ text: 'Error: approval for tool "echo" was cancelled' })
  717. })
  718. it('returns ABORTED_BEFORE_DISPATCH when caller cancellation overtakes approval', async () => {
  719. const ctx = await approvalSetup()
  720. const entered = Promise.withResolvers<undefined>()
  721. const release = Promise.withResolvers<ApprovalOutcome>()
  722. let dispatched = 0
  723. ctx.tools.register({
  724. ...echoTool,
  725. name: 'approval-probe',
  726. async execute() { dispatched += 1; return [] },
  727. })
  728. ctx.on('approval/request', () => {
  729. entered.resolve(undefined)
  730. return release.promise
  731. })
  732. ctx.on('tools/pre-execute', async (_exec, _next): Promise<PreToolDecision> => ({ kind: 'ask' }))
  733. const controller = new AbortController()
  734. const pending = ctx.tools.execute({
  735. callId: ToolCallId('approval-cancelled'),
  736. name: 'approval-probe',
  737. arguments: {},
  738. agent: fakeAgent(),
  739. signal: controller.signal,
  740. })
  741. await entered.promise
  742. controller.abort('caller cancelled approval')
  743. release.resolve('allowed-once')
  744. await expect(pending).resolves.toMatchObject({
  745. isError: true,
  746. error: { info: { name: 'AbortError', code: TOOL_ABORTED_BEFORE_DISPATCH } },
  747. })
  748. expect(dispatched).toBe(0)
  749. })
  750. it('denies with the no-channel reason when the seam is mounted but nobody answers', async () => {
  751. const ctx = await approvalSetup()
  752. ctx.on('tools/pre-execute', async (_exec, _next): Promise<PreToolDecision> => ({ kind: 'ask' }))
  753. const result = await ctx.tools.execute({ signal: testToolSignal, callId: ToolCallId('c1'), name: 'echo', arguments: {}, agent: fakeAgent() })
  754. expect(result.isError).toBe(true)
  755. expect(result.content[0]).toMatchObject({ text: 'Error: tool "echo" requires approval, but no approval channel is available' })
  756. })
  757. it('denies an agent-less execution without asking — nothing to route or audit through', async () => {
  758. const ctx = await approvalSetup()
  759. let asked = false
  760. ctx.on('approval/request', () => {
  761. asked = true
  762. return Promise.resolve<ApprovalOutcome>('allowed-once')
  763. })
  764. ctx.on('tools/pre-execute', async (_exec, _next): Promise<PreToolDecision> => ({ kind: 'ask' }))
  765. const result = await ctx.tools.execute({ signal: testToolSignal, callId: ToolCallId('c1'), name: 'echo', arguments: {} })
  766. expect(asked).toBe(false)
  767. expect(result.isError).toBe(true)
  768. expect(result.content[0]).toMatchObject({ text: 'Error: tool "echo" requires approval, but the call has no agent to route it through' })
  769. })
  770. it('turns a rogue outcome from a NON-conforming approval stand-in into an isError result', async () => {
  771. // ApprovalService normalizes rogue answers itself; this pins the
  772. // registry's own exhaustiveness backstop by shadowing the service with a
  773. // stand-in that violates the outcome contract.
  774. const ctx = await setup()
  775. ctx.tools.register(echoTool)
  776. ctx.provide('approval', { request: () => Promise.resolve('yolo') } as unknown as ApprovalService)
  777. ctx.on('tools/pre-execute', async (_exec, _next): Promise<PreToolDecision> => ({ kind: 'ask' }))
  778. const result = await ctx.tools.execute({ signal: testToolSignal, callId: ToolCallId('c1'), name: 'echo', arguments: {}, agent: fakeAgent() })
  779. expect(result.isError).toBe(true)
  780. const text = result.content[0]?.type === 'text' ? result.content[0].text : ''
  781. expect(text).toContain('unreachable')
  782. })
  783. })
  784. it('a tools/post-execute listener can replace the result content (accept) ', async () => {
  785. const ctx = await setup()
  786. ctx.tools.register(echoTool)
  787. ctx.on('tools/post-execute', async (_exec, _result, _next): Promise<PostToolDecision> =>
  788. ({ kind: 'accept', content: [{ type: 'text', text: 'rewritten' }] }))
  789. const result = await ctx.tools.execute({ signal: testToolSignal, callId: ToolCallId('c1'), name: 'echo', arguments: { text: 'hi' } })
  790. expect(result.isError).toBe(false)
  791. expect(result.content[0]).toMatchObject({ text: 'rewritten' })
  792. })
  793. it('a tools/post-execute block turns the call into an isError with corrective feedback', async () => {
  794. const ctx = await setup()
  795. ctx.tools.register(echoTool)
  796. ctx.on('tools/post-execute', async (_exec, _result, _next): Promise<PostToolDecision> =>
  797. ({ kind: 'block', feedback: [{ type: 'text', text: 'output rejected: try again' }] }))
  798. const result = await ctx.tools.execute({ signal: testToolSignal, callId: ToolCallId('c1'), name: 'echo', arguments: { text: 'hi' } })
  799. expect(result.isError).toBe(true)
  800. expect(result.content[0]).toMatchObject({ text: 'output rejected: try again' })
  801. })
  802. it('runs the snapshotted final content transform after outer pipeline normalization', async () => {
  803. const ctx = await setup()
  804. const dispose = ctx.tools.register(defineContentToolFixture({
  805. name: 'bounded',
  806. description: 'bounded result',
  807. parameters: {},
  808. async execute() { return [{ type: 'text', text: 'body' }] },
  809. finalizeContent(exec, result) {
  810. expect(exec.name).toBe('bounded')
  811. expect(result.isError).toBe(true)
  812. return [{ type: 'text', text: 'bounded failure' }]
  813. },
  814. }))
  815. ctx.on('tools/pre-execute', async () => {
  816. dispose()
  817. throw new HarnessError('policy failed', 'POLICY_FAILED')
  818. })
  819. const result = await ctx.tools.execute({ signal: testToolSignal, callId: ToolCallId('bounded'), name: 'bounded', arguments: {} })
  820. expect(result).toEqual({
  821. content: [{ type: 'text', text: 'bounded failure' }],
  822. isError: true,
  823. error: {
  824. message: 'policy failed',
  825. info: { name: 'HarnessError', code: 'POLICY_FAILED' },
  826. },
  827. })
  828. })
  829. it('keeps the normalized content when the final content transform returns undefined', async () => {
  830. const ctx = await setup()
  831. let finalized = 0
  832. ctx.tools.register({
  833. ...echoTool,
  834. name: 'identity-finalizer',
  835. finalizeContent() {
  836. finalized += 1
  837. return undefined
  838. },
  839. })
  840. const result = await ctx.tools.execute({ signal: testToolSignal, callId: ToolCallId('identity-finalizer'), name: 'identity-finalizer', arguments: {} })
  841. expect(result.isError).toBe(false)
  842. expect(result.content).toEqual([{ type: 'text', text: '' }])
  843. expect(finalized).toBe(1)
  844. })
  845. it('a block decision can ALSO attach additionalContexts', async () => {
  846. const ctx = await setup()
  847. ctx.tools.register(echoTool)
  848. ctx.on('tools/post-execute', async (_exec, _result, _next): Promise<PostToolDecision> =>
  849. ({
  850. kind: 'block',
  851. feedback: [{ type: 'text', text: 'rejected' }],
  852. additionalContexts: [createUserMessage({
  853. content: [{ type: 'text', text: 'why it was rejected' }], source: { kind: 'plugin', plugin: 'test' },
  854. })],
  855. }))
  856. const result = await ctx.tools.execute({ signal: testToolSignal, callId: ToolCallId('c1'), name: 'echo', arguments: { text: 'hi' } })
  857. expect(result.isError).toBe(true)
  858. expect(result.content[0]).toMatchObject({ text: 'rejected' })
  859. expect(result.additionalContexts).toMatchObject([{ content: [{ text: 'why it was rejected' }], source: { kind: 'plugin', plugin: 'test' } }])
  860. })
  861. it('post-execute additionalContexts ride on the result for the loop to buffer', async () => {
  862. const ctx = await setup()
  863. ctx.tools.register(echoTool)
  864. ctx.on('tools/post-execute', async (_exec, _result, _next): Promise<PostToolDecision> =>
  865. ({ kind: 'accept', additionalContexts: [createUserMessage({
  866. content: [{ type: 'text', text: 'fyi' }], source: { kind: 'plugin', plugin: 'test' },
  867. })] }))
  868. const result = await ctx.tools.execute({ signal: testToolSignal, callId: ToolCallId('c1'), name: 'echo', arguments: { text: 'hi' } })
  869. expect(result.additionalContexts).toMatchObject([{ content: [{ text: 'fyi' }], source: { kind: 'plugin', plugin: 'test' } }])
  870. })
  871. it('preserves tool-deferred, execute-wrapper, and post-execute contexts in order', async () => {
  872. const ctx = await setup()
  873. ctx.tools.register(defineContentToolFixture({
  874. name: 'composite',
  875. description: 'composite',
  876. parameters: {},
  877. async execute(_args, exec) {
  878. exec.deferContext(createUserMessage({
  879. content: [{ type: 'text', text: 'nested-1' }], source: { kind: 'plugin', plugin: 'nested-1' },
  880. }))
  881. exec.deferContext(createUserMessage({
  882. content: [{ type: 'text', text: 'nested-2' }], source: { kind: 'plugin', plugin: 'nested-2' },
  883. }))
  884. return [{ type: 'text', text: 'done' }]
  885. },
  886. }))
  887. ctx.on('tools/execute', async (_exec, next) => {
  888. const result = await next()
  889. return {
  890. ...result,
  891. additionalContexts: [
  892. ...result.additionalContexts ?? [],
  893. createUserMessage({
  894. content: [{ type: 'text', text: 'wrapper' }], source: { kind: 'plugin', plugin: 'wrapper' },
  895. }),
  896. ],
  897. }
  898. })
  899. ctx.on('tools/post-execute', async (_exec, _result, next): Promise<PostToolDecision> => {
  900. const downstream = await next()
  901. return {
  902. ...downstream,
  903. additionalContexts: [
  904. createUserMessage({
  905. content: [{ type: 'text', text: 'post' }], source: { kind: 'plugin', plugin: 'post' },
  906. }),
  907. ...downstream.additionalContexts ?? [],
  908. ],
  909. }
  910. })
  911. const result = await ctx.tools.execute({ signal: testToolSignal, callId: ToolCallId('composite'), name: 'composite', arguments: {} })
  912. expect(result.additionalContexts?.map(context => context.source)).toEqual([
  913. { kind: 'plugin', plugin: 'nested-1' },
  914. { kind: 'plugin', plugin: 'nested-2' },
  915. { kind: 'plugin', plugin: 'wrapper' },
  916. { kind: 'plugin', plugin: 'post' },
  917. ])
  918. })
  919. it('keeps deferred contexts when a composite tool throws, but drops them when the outer call is blocked', async () => {
  920. const ctx = await setup()
  921. ctx.tools.register(defineContentToolFixture({
  922. name: 'failing-composite',
  923. description: 'failing composite',
  924. parameters: {},
  925. async execute(_args, exec) {
  926. exec.deferContext(createUserMessage({
  927. content: [{ type: 'text', text: 'nested' }], source: { kind: 'plugin', plugin: 'nested' },
  928. }))
  929. throw new Error('outer failure')
  930. },
  931. }))
  932. const failed = await ctx.tools.execute({ signal: testToolSignal, callId: ToolCallId('failed'), name: 'failing-composite', arguments: {} })
  933. expect(failed.isError).toBe(true)
  934. expect(failed.additionalContexts?.map(context => context.source)).toEqual([{ kind: 'plugin', plugin: 'nested' }])
  935. ctx.on('tools/post-execute', async (): Promise<PostToolDecision> => ({
  936. kind: 'block',
  937. feedback: [{ type: 'text', text: 'blocked' }],
  938. additionalContexts: [createUserMessage({
  939. content: [{ type: 'text', text: 'block-only' }], source: { kind: 'plugin', plugin: 'blocker' },
  940. })],
  941. }))
  942. const blocked = await ctx.tools.execute({ signal: testToolSignal, callId: ToolCallId('blocked'), name: 'failing-composite', arguments: {} })
  943. expect(blocked.isError).toBe(true)
  944. expect(blocked.additionalContexts?.map(context => context.source)).toEqual([{ kind: 'plugin', plugin: 'blocker' }])
  945. })
  946. it('composes pre + post waterfalls around dispatch (sandbox-wrap pattern)', async () => {
  947. const ctx = await setup()
  948. ctx.tools.register(echoTool)
  949. const order: string[] = []
  950. ctx.on('tools/pre-execute', async (_exec, next) => {
  951. order.push('pre:before')
  952. const decision = await next()
  953. order.push('pre:after')
  954. return decision
  955. })
  956. ctx.on('tools/post-execute', async (_exec, _result, next) => {
  957. order.push('post:before')
  958. const decision = await next()
  959. order.push('post:after')
  960. return decision
  961. })
  962. const result = await ctx.tools.execute({ signal: testToolSignal, callId: ToolCallId('c1'), name: 'echo', arguments: { text: 'x' } })
  963. expect(result.isError).toBe(false)
  964. // pre runs fully (gate) before dispatch, then post runs over the result.
  965. expect(order).toEqual(['pre:before', 'pre:after', 'post:before', 'post:after'])
  966. })
  967. it('runs tools/execute after an allowed pre-execute, around dispatch, and before post-execute', async () => {
  968. const ctx = await setup()
  969. const order: string[] = []
  970. ctx.tools.register(defineContentToolFixture({
  971. name: 'traced',
  972. description: 'echo',
  973. parameters: { text: { type: 'string' } },
  974. async execute(args) {
  975. order.push('dispatch')
  976. return [{ type: 'text' as const, text: args.text ?? '' }]
  977. },
  978. }))
  979. ctx.on('tools/pre-execute', async (_exec, next) => { order.push('pre'); return next() })
  980. ctx.on('tools/execute', async (_exec: ToolDispatchExecution, next: () => Promise<ToolExecutionResult>): Promise<ToolExecutionResult> => {
  981. order.push('execute:before')
  982. const result = await next()
  983. order.push('execute:after')
  984. return result
  985. })
  986. ctx.on('tools/post-execute', async (_exec, _result, next) => { order.push('post'); return next() })
  987. const result = await ctx.tools.execute({ signal: testToolSignal, callId: ToolCallId('c1'), name: 'traced', arguments: { text: 'hi' } })
  988. expect(result).toEqual({ content: [{ type: 'text', text: 'hi' }], isError: false, value: [{ type: 'text', text: 'hi' }] })
  989. // The around-dispatch extension point wraps dispatch; pre gates before it, post runs over its result.
  990. expect(order).toEqual(['pre', 'execute:before', 'dispatch', 'execute:after', 'post'])
  991. })
  992. it('skips dispatch when caller cancellation arrives while pre-execute awaits', async () => {
  993. const ctx = await setup()
  994. let dispatched = 0
  995. ctx.tools.register({
  996. ...echoTool,
  997. name: 'must-not-run',
  998. async execute() { dispatched += 1; return [] },
  999. })
  1000. const entered = Promise.withResolvers<undefined>()
  1001. const release = Promise.withResolvers<undefined>()
  1002. ctx.on('tools/pre-execute', async (_exec, next) => {
  1003. entered.resolve(undefined)
  1004. await release.promise
  1005. return await next()
  1006. })
  1007. const controller = new AbortController()
  1008. const pending = ctx.tools.execute({
  1009. callId: ToolCallId('cancelled-in-pre'), name: 'must-not-run', arguments: {}, signal: controller.signal,
  1010. })
  1011. await entered.promise
  1012. controller.abort('cancelled in policy')
  1013. release.resolve(undefined)
  1014. await expect(pending).resolves.toMatchObject({
  1015. content: [{ type: 'text', text: 'Error: tool call aborted before dispatch' }],
  1016. isError: true,
  1017. error: { info: { name: 'AbortError', code: TOOL_ABORTED_BEFORE_DISPATCH } },
  1018. })
  1019. expect(dispatched).toBe(0)
  1020. })
  1021. it('maps an explicit pre-execute cancellation to the canonical before-dispatch result', async () => {
  1022. const ctx = await setup()
  1023. let dispatched = 0
  1024. ctx.tools.register({
  1025. ...echoTool,
  1026. name: 'cancelled-by-policy',
  1027. async execute() { dispatched += 1; return [] },
  1028. })
  1029. ctx.on('tools/pre-execute', async () => ({ kind: 'cancel' }))
  1030. await expect(ctx.tools.execute({
  1031. callId: ToolCallId('cancelled-by-policy'),
  1032. name: 'cancelled-by-policy',
  1033. arguments: {},
  1034. signal: new AbortController().signal,
  1035. })).resolves.toEqual({
  1036. content: [{ type: 'text', text: 'Error: tool call aborted before dispatch' }],
  1037. isError: true,
  1038. error: {
  1039. message: 'tool call aborted before dispatch',
  1040. info: { name: 'AbortError', code: TOOL_ABORTED_BEFORE_DISPATCH },
  1041. },
  1042. })
  1043. expect(dispatched).toBe(0)
  1044. })
  1045. it('preserves a pre-execute denial that settles after cancellation', async () => {
  1046. const ctx = await setup()
  1047. let dispatched = 0
  1048. ctx.tools.register({
  1049. ...echoTool,
  1050. name: 'denied-after-cancel',
  1051. async execute() { dispatched += 1; return [] },
  1052. })
  1053. const entered = Promise.withResolvers<undefined>()
  1054. const release = Promise.withResolvers<undefined>()
  1055. ctx.on('tools/pre-execute', async () => {
  1056. entered.resolve(undefined)
  1057. await release.promise
  1058. return { kind: 'deny', reason: 'policy denied the call' }
  1059. })
  1060. const controller = new AbortController()
  1061. const pending = ctx.tools.execute({
  1062. callId: ToolCallId('denied-after-cancel'), name: 'denied-after-cancel', arguments: {}, signal: controller.signal,
  1063. })
  1064. await entered.promise
  1065. controller.abort('cancelled while policy decided')
  1066. release.resolve(undefined)
  1067. await expect(pending).resolves.toEqual({
  1068. content: [{ type: 'text', text: 'Error: policy denied the call' }],
  1069. isError: true,
  1070. error: { message: 'policy denied the call' },
  1071. })
  1072. expect(dispatched).toBe(0)
  1073. })
  1074. it('preserves an async pre-execute failure that settles after cancellation', async () => {
  1075. const ctx = await setup()
  1076. let dispatched = 0
  1077. ctx.tools.register({
  1078. ...echoTool,
  1079. name: 'must-not-run',
  1080. async execute() { dispatched += 1; return [] },
  1081. })
  1082. const entered = Promise.withResolvers<undefined>()
  1083. const release = Promise.withResolvers<undefined>()
  1084. ctx.on('tools/pre-execute', async () => {
  1085. entered.resolve(undefined)
  1086. await release.promise
  1087. throw new Error('gate interrupted')
  1088. })
  1089. const controller = new AbortController()
  1090. const pending = ctx.tools.execute({
  1091. callId: ToolCallId('cancelled-pre-error'), name: 'must-not-run', arguments: {}, signal: controller.signal,
  1092. })
  1093. await entered.promise
  1094. controller.abort('cancelled in policy')
  1095. release.resolve(undefined)
  1096. await expect(pending).resolves.toEqual({
  1097. content: [{ type: 'text', text: 'Error: gate interrupted' }],
  1098. isError: true,
  1099. error: { message: 'gate interrupted' },
  1100. })
  1101. expect(dispatched).toBe(0)
  1102. })
  1103. it('rechecks caller cancellation after an async around-dispatch wrapper delegates', async () => {
  1104. const ctx = await setup()
  1105. let dispatched = 0
  1106. ctx.tools.register({
  1107. ...echoTool,
  1108. name: 'must-not-run',
  1109. async execute() { dispatched += 1; return [] },
  1110. })
  1111. const entered = Promise.withResolvers<undefined>()
  1112. const release = Promise.withResolvers<undefined>()
  1113. const replacement = new AbortController()
  1114. ctx.on('tools/execute', async (exec, next) => {
  1115. const upstream = exec.signal
  1116. exec.signal = replacement.signal
  1117. try {
  1118. entered.resolve(undefined)
  1119. await release.promise
  1120. return await next()
  1121. } finally {
  1122. exec.signal = upstream
  1123. }
  1124. })
  1125. const controller = new AbortController()
  1126. const pending = ctx.tools.execute({
  1127. callId: ToolCallId('cancelled-in-around'), name: 'must-not-run', arguments: {}, signal: controller.signal,
  1128. })
  1129. await entered.promise
  1130. controller.abort('cancelled in wrapper')
  1131. release.resolve(undefined)
  1132. await expect(pending).resolves.toMatchObject({
  1133. isError: true,
  1134. error: { info: { name: 'AbortError', code: TOOL_ABORTED_BEFORE_DISPATCH } },
  1135. })
  1136. expect(dispatched).toBe(0)
  1137. })
  1138. it('skips dispatch when an around wrapper supplies an already-aborted signal', async () => {
  1139. const ctx = await setup()
  1140. let dispatched = 0
  1141. ctx.tools.register({
  1142. ...echoTool,
  1143. name: 'must-not-run',
  1144. async execute() { dispatched += 1; return [] },
  1145. })
  1146. const replacement = AbortSignal.abort('wrapper cancelled')
  1147. ctx.on('tools/execute', async (exec, next) => {
  1148. const upstream = exec.signal
  1149. exec.signal = replacement
  1150. try {
  1151. return await next()
  1152. } finally {
  1153. exec.signal = upstream
  1154. }
  1155. })
  1156. const controller = new AbortController()
  1157. const result = await ctx.tools.execute({
  1158. callId: ToolCallId('cancelled-wrapper'), name: 'must-not-run', arguments: {}, signal: controller.signal,
  1159. })
  1160. expect(result.error).toEqual({
  1161. message: 'tool call aborted before dispatch',
  1162. info: { name: 'AbortError', code: TOOL_ABORTED_BEFORE_DISPATCH },
  1163. })
  1164. expect(dispatched).toBe(0)
  1165. })
  1166. it('uses ABORTED_BEFORE_DISPATCH when cancellation overtakes a wrapper short-circuit', async () => {
  1167. const ctx = await setup()
  1168. let dispatched = 0
  1169. ctx.tools.register({
  1170. ...echoTool,
  1171. name: 'short-circuited',
  1172. async execute() { dispatched += 1; return [] },
  1173. })
  1174. const entered = Promise.withResolvers<undefined>()
  1175. const release = Promise.withResolvers<undefined>()
  1176. ctx.on('tools/execute', async () => {
  1177. entered.resolve(undefined)
  1178. await release.promise
  1179. return {
  1180. value: 'wrapper success',
  1181. content: [{ type: 'text', text: 'wrapper success' }],
  1182. isError: false,
  1183. additionalContexts: [createUserMessage({
  1184. content: [{ type: 'text', text: 'wrapper context' }],
  1185. source: { kind: 'plugin', plugin: 'wrapper' },
  1186. })],
  1187. }
  1188. })
  1189. const controller = new AbortController()
  1190. const pending = ctx.tools.execute({
  1191. callId: ToolCallId('cancelled-short-circuit'),
  1192. name: 'short-circuited',
  1193. arguments: {},
  1194. signal: controller.signal,
  1195. })
  1196. await entered.promise
  1197. controller.abort('cancelled while wrapper waited')
  1198. release.resolve(undefined)
  1199. await expect(pending).resolves.toMatchObject({
  1200. content: [{ type: 'text', text: 'Error: tool call aborted before dispatch' }],
  1201. isError: true,
  1202. error: { info: { name: 'AbortError', code: TOOL_ABORTED_BEFORE_DISPATCH } },
  1203. additionalContexts: [{ source: { kind: 'plugin', plugin: 'wrapper' } }],
  1204. })
  1205. expect(dispatched).toBe(0)
  1206. })
  1207. it('replaces a late wrapper success with ABORTED and preserves deferred contexts', async () => {
  1208. const ctx = await setup()
  1209. ctx.tools.register({
  1210. ...echoTool,
  1211. name: 'completed-before-wrapper',
  1212. async execute(_args, exec) {
  1213. exec.deferContext(createUserMessage({
  1214. content: [{ type: 'text', text: 'completed child work' }],
  1215. source: { kind: 'plugin', plugin: 'child' },
  1216. }))
  1217. return 'body complete'
  1218. },
  1219. })
  1220. const entered = Promise.withResolvers<undefined>()
  1221. const release = Promise.withResolvers<undefined>()
  1222. ctx.on('tools/execute', async (_exec, next) => {
  1223. const result = await next()
  1224. entered.resolve(undefined)
  1225. await release.promise
  1226. return result
  1227. })
  1228. const controller = new AbortController()
  1229. const pending = ctx.tools.execute({
  1230. callId: ToolCallId('cancelled-after-body'), name: 'completed-before-wrapper', arguments: {}, signal: controller.signal,
  1231. })
  1232. await entered.promise
  1233. controller.abort('cancelled while wrapper settled')
  1234. release.resolve(undefined)
  1235. await expect(pending).resolves.toMatchObject({
  1236. content: [{ type: 'text', text: 'Error: tool call aborted' }],
  1237. isError: true,
  1238. error: { info: { name: 'AbortError', code: TOOL_ABORTED } },
  1239. additionalContexts: [{ source: { kind: 'plugin', plugin: 'child' } }],
  1240. })
  1241. })
  1242. it('replaces a late post-execute success with ABORTED and preserves contexts', async () => {
  1243. const ctx = await setup()
  1244. ctx.tools.register({
  1245. ...echoTool,
  1246. name: 'completed-before-post',
  1247. async execute(_args, exec) {
  1248. exec.deferContext(createUserMessage({
  1249. content: [{ type: 'text', text: 'completed child work' }],
  1250. source: { kind: 'plugin', plugin: 'child' },
  1251. }))
  1252. return 'body complete'
  1253. },
  1254. })
  1255. const entered = Promise.withResolvers<undefined>()
  1256. const release = Promise.withResolvers<undefined>()
  1257. ctx.on('tools/post-execute', async (_exec, _result, next) => {
  1258. const decision = await next()
  1259. entered.resolve(undefined)
  1260. await release.promise
  1261. return {
  1262. ...decision,
  1263. additionalContexts: [createUserMessage({
  1264. content: [{ type: 'text', text: 'post context' }],
  1265. source: { kind: 'plugin', plugin: 'post' },
  1266. })],
  1267. }
  1268. })
  1269. const controller = new AbortController()
  1270. const pending = ctx.tools.execute({
  1271. callId: ToolCallId('cancelled-in-post'), name: 'completed-before-post', arguments: {}, signal: controller.signal,
  1272. })
  1273. await entered.promise
  1274. controller.abort('cancelled while post policy waits')
  1275. release.resolve(undefined)
  1276. await expect(pending).resolves.toMatchObject({
  1277. content: [{ type: 'text', text: 'Error: tool call aborted' }],
  1278. isError: true,
  1279. error: { info: { name: 'AbortError', code: TOOL_ABORTED } },
  1280. additionalContexts: [
  1281. { source: { kind: 'plugin', plugin: 'child' } },
  1282. { source: { kind: 'plugin', plugin: 'post' } },
  1283. ],
  1284. })
  1285. })
  1286. it('preserves an around-dispatch failure that settles after cancellation', async () => {
  1287. const ctx = await setup()
  1288. let dispatched = 0
  1289. ctx.tools.register({
  1290. ...echoTool,
  1291. name: 'wrapper-failure',
  1292. async execute() { dispatched += 1; return [] },
  1293. })
  1294. const entered = Promise.withResolvers<undefined>()
  1295. const release = Promise.withResolvers<undefined>()
  1296. ctx.on('tools/execute', async () => {
  1297. entered.resolve(undefined)
  1298. await release.promise
  1299. throw new HarnessError('wrapper failed', 'WRAPPER_FAILURE')
  1300. })
  1301. const controller = new AbortController()
  1302. const pending = ctx.tools.execute({
  1303. callId: ToolCallId('wrapper-failure'), name: 'wrapper-failure', arguments: {}, signal: controller.signal,
  1304. })
  1305. await entered.promise
  1306. controller.abort('cancelled while wrapper failed')
  1307. release.resolve(undefined)
  1308. await expect(pending).resolves.toMatchObject({
  1309. content: [{ type: 'text', text: 'Error: wrapper failed' }],
  1310. isError: true,
  1311. error: { info: { name: 'HarnessError', code: 'WRAPPER_FAILURE' } },
  1312. })
  1313. expect(dispatched).toBe(0)
  1314. })
  1315. it('preserves a tool-owned failure after the body observes cancellation', async () => {
  1316. const ctx = await setup()
  1317. const entered = Promise.withResolvers<undefined>()
  1318. ctx.tools.register({
  1319. ...echoTool,
  1320. name: 'tool-failure',
  1321. execute(_args, exec) {
  1322. entered.resolve(undefined)
  1323. return new Promise<never>((_resolve, reject) => {
  1324. exec.signal.addEventListener('abort', () => {
  1325. reject(new HarnessError('tool failed', 'TOOL_FAILURE'))
  1326. }, { once: true })
  1327. })
  1328. },
  1329. })
  1330. const controller = new AbortController()
  1331. const pending = ctx.tools.execute({
  1332. callId: ToolCallId('tool-failure'), name: 'tool-failure', arguments: {}, signal: controller.signal,
  1333. })
  1334. await entered.promise
  1335. controller.abort('cancelled running body')
  1336. await expect(pending).resolves.toMatchObject({
  1337. content: [{ type: 'text', text: 'Error: tool failed' }],
  1338. isError: true,
  1339. error: { info: { name: 'HarnessError', code: 'TOOL_FAILURE' } },
  1340. })
  1341. })
  1342. it('preserves a post-policy failure that settles after cancellation', async () => {
  1343. const ctx = await setup()
  1344. ctx.tools.register(echoTool)
  1345. const entered = Promise.withResolvers<undefined>()
  1346. const release = Promise.withResolvers<undefined>()
  1347. ctx.on('tools/post-execute', async () => {
  1348. entered.resolve(undefined)
  1349. await release.promise
  1350. throw new HarnessError('post-policy failed', 'POST_FAILURE')
  1351. })
  1352. const controller = new AbortController()
  1353. const pending = ctx.tools.execute({
  1354. callId: ToolCallId('post-failure'), name: 'echo', arguments: {}, signal: controller.signal,
  1355. })
  1356. await entered.promise
  1357. controller.abort('cancelled while post-policy failed')
  1358. release.resolve(undefined)
  1359. await expect(pending).resolves.toMatchObject({
  1360. content: [{ type: 'text', text: 'Error: post-policy failed' }],
  1361. isError: true,
  1362. error: { info: { name: 'HarnessError', code: 'POST_FAILURE' } },
  1363. })
  1364. })
  1365. it('fuses caller cancellation back into a wrapper replacement for the running body', async () => {
  1366. const ctx = await setup()
  1367. const entered = Promise.withResolvers<undefined>()
  1368. const replacement = new AbortController()
  1369. let bodySignal: AbortSignal | undefined
  1370. ctx.tools.register({
  1371. ...echoTool,
  1372. name: 'cooperative',
  1373. execute(_args, exec) {
  1374. bodySignal = exec.signal
  1375. entered.resolve(undefined)
  1376. if (exec.signal.aborted) return Promise.resolve('stopped')
  1377. return new Promise<string>((resolve) => {
  1378. exec.signal.addEventListener('abort', () => { resolve('stopped') }, { once: true })
  1379. })
  1380. },
  1381. })
  1382. ctx.on('tools/execute', async (exec, next) => {
  1383. const upstream = exec.signal
  1384. exec.signal = replacement.signal
  1385. try {
  1386. return await next()
  1387. } finally {
  1388. exec.signal = upstream
  1389. }
  1390. })
  1391. const controller = new AbortController()
  1392. const pending = ctx.tools.execute({
  1393. callId: ToolCallId('cancelled-body'), name: 'cooperative', arguments: {}, signal: controller.signal,
  1394. })
  1395. await entered.promise
  1396. expect(bodySignal).not.toBe(controller.signal)
  1397. expect(bodySignal).not.toBe(replacement.signal)
  1398. controller.abort('cancel running body')
  1399. await expect(pending).resolves.toMatchObject({
  1400. isError: true,
  1401. error: { info: { name: 'AbortError', code: TOOL_ABORTED } },
  1402. })
  1403. expect(bodySignal?.aborted).toBe(true)
  1404. expect(replacement.signal.aborted).toBe(false)
  1405. })
  1406. it('restores the required caller signal after around dispatch', async () => {
  1407. const ctx = await setup()
  1408. let postSignal: AbortSignal | undefined
  1409. ctx.on('tools/execute', async (exec, next) => {
  1410. const upstream = exec.signal
  1411. exec.signal = new AbortController().signal
  1412. try {
  1413. return await next()
  1414. } finally {
  1415. exec.signal = upstream
  1416. }
  1417. })
  1418. ctx.on('tools/post-execute', async (exec, _result, next) => {
  1419. postSignal = exec.signal
  1420. return next()
  1421. })
  1422. const controller = new AbortController()
  1423. await ctx.tools.execute({
  1424. callId: ToolCallId('restored-signal'), name: 'echo', arguments: {}, signal: controller.signal,
  1425. })
  1426. expect(postSignal).toBe(controller.signal)
  1427. })
  1428. it('waits for an uncooperative started body before returning ABORTED', async () => {
  1429. const ctx = await setup()
  1430. const entered = Promise.withResolvers<undefined>()
  1431. const release = Promise.withResolvers<string>()
  1432. ctx.tools.register({
  1433. ...echoTool,
  1434. name: 'uncooperative',
  1435. execute(_args, exec) {
  1436. exec.deferContext(createUserMessage({
  1437. content: [{ type: 'text', text: 'nested outcome' }],
  1438. source: { kind: 'plugin', plugin: 'nested' },
  1439. }))
  1440. entered.resolve(undefined)
  1441. return release.promise
  1442. },
  1443. })
  1444. const controller = new AbortController()
  1445. const pending = ctx.tools.execute({
  1446. callId: ToolCallId('drain-body'), name: 'uncooperative', arguments: {}, signal: controller.signal,
  1447. })
  1448. await entered.promise
  1449. controller.abort('must still drain')
  1450. const state = await Promise.race([
  1451. pending.then(() => 'settled' as const),
  1452. Promise.resolve('pending' as const),
  1453. ])
  1454. expect(state).toBe('pending')
  1455. release.resolve('settled')
  1456. await expect(pending).resolves.toMatchObject({
  1457. isError: true,
  1458. error: { info: { name: 'AbortError', code: TOOL_ABORTED } },
  1459. additionalContexts: [{ source: { kind: 'plugin', plugin: 'nested' } }],
  1460. })
  1461. })
  1462. it('materializes a pre-aborted call and publishes one result without entering pipeline phases', async () => {
  1463. const ctx = await setup()
  1464. const phases = { pre: 0, around: 0, body: 0, post: 0, result: 0 }
  1465. const callerArguments = { nested: { value: 1 } }
  1466. const callerSignal = AbortSignal.abort('already cancelled')
  1467. let argumentReads = 0
  1468. let observedArguments: unknown
  1469. let observedExecution: object | undefined
  1470. let observedToken: symbol | undefined
  1471. let observedSignal: AbortSignal | undefined
  1472. let observedResult: ToolExecutionResult | undefined
  1473. ctx.tools.register({
  1474. ...echoTool,
  1475. name: 'domain-abort',
  1476. async execute() { phases.body += 1; return [] },
  1477. })
  1478. ctx.on('tools/pre-execute', async (_exec, next) => { phases.pre += 1; return next() })
  1479. ctx.on('tools/execute', async (_exec, next) => { phases.around += 1; return next() })
  1480. ctx.on('tools/post-execute', async (_exec, _result, next) => { phases.post += 1; return next() })
  1481. ctx.on('tools/result', (exec, result) => {
  1482. phases.result += 1
  1483. observedExecution = exec
  1484. observedArguments = exec.arguments
  1485. observedToken = exec.token
  1486. observedSignal = exec.signal
  1487. observedResult = result
  1488. })
  1489. const result = await ctx.tools.execute({
  1490. callId: ToolCallId('pre-aborted'),
  1491. name: 'domain-abort',
  1492. get arguments() { argumentReads += 1; return callerArguments },
  1493. signal: callerSignal,
  1494. })
  1495. expect(argumentReads).toBe(1)
  1496. expect(phases).toEqual({ pre: 0, around: 0, body: 0, post: 0, result: 1 })
  1497. expect(result).toEqual({
  1498. content: [{ type: 'text', text: 'Error: tool call aborted before dispatch' }],
  1499. isError: true,
  1500. error: {
  1501. message: 'tool call aborted before dispatch',
  1502. info: { name: 'AbortError', code: TOOL_ABORTED_BEFORE_DISPATCH },
  1503. },
  1504. })
  1505. expect(observedResult).toBe(result)
  1506. expect(Object.isFrozen(observedExecution)).toBe(true)
  1507. expect(typeof observedToken).toBe('symbol')
  1508. expect(observedSignal).toBe(callerSignal)
  1509. expect(Object.isFrozen(result)).toBe(true)
  1510. expect(observedArguments).not.toBe(callerArguments)
  1511. expect(Object.isFrozen(observedArguments)).toBe(true)
  1512. expect(Object.isFrozen((observedArguments as { nested: object }).nested)).toBe(true)
  1513. })
  1514. it('lets argument materialization failure win over a pre-aborted signal', async () => {
  1515. const ctx = await setup()
  1516. let observed = 0
  1517. ctx.on('tools/result', () => { observed += 1 })
  1518. const result = await ctx.tools.execute({
  1519. callId: ToolCallId('invalid-pre-aborted'),
  1520. name: 'missing',
  1521. arguments: { invalid: () => undefined },
  1522. signal: AbortSignal.abort('already cancelled'),
  1523. })
  1524. expect(result).toEqual({
  1525. content: [{ type: 'text', text: 'Error: tool execution arguments must be losslessly JSON-serializable' }],
  1526. isError: true,
  1527. error: { message: 'tool execution arguments must be losslessly JSON-serializable' },
  1528. })
  1529. expect(observed).toBe(1)
  1530. })
  1531. it('a pre-execute deny short-circuits before tools/execute (the seam never runs)', async () => {
  1532. const ctx = await setup()
  1533. ctx.tools.register(echoTool)
  1534. let entered = false
  1535. ctx.on('tools/pre-execute', async (_exec, _next): Promise<PreToolDecision> => ({ kind: 'deny', reason: 'nope' }))
  1536. ctx.on('tools/execute', async (_exec: ToolDispatchExecution, next: () => Promise<ToolExecutionResult>): Promise<ToolExecutionResult> => {
  1537. entered = true
  1538. return next()
  1539. })
  1540. const result = await ctx.tools.execute({ signal: testToolSignal, callId: ToolCallId('c1'), name: 'echo', arguments: { text: 'hi' } })
  1541. expect(result.isError).toBe(true)
  1542. expect(result.content[0]).toMatchObject({ text: 'Error: nope' })
  1543. expect(entered).toBe(false) // A denied call never enters the around-dispatch extension point.
  1544. })
  1545. it('a thrown tool is normalized to an isError result BEFORE a tools/execute listener sees next()', async () => {
  1546. const ctx = await setup()
  1547. ctx.tools.register({
  1548. ...echoTool,
  1549. name: 'boom',
  1550. async execute() { throw new HarnessError('kaboom', 'BOOM') },
  1551. })
  1552. let seen: { isError: boolean; error?: unknown } | undefined
  1553. ctx.on('tools/execute', async (_exec: ToolDispatchExecution, next: () => Promise<ToolExecutionResult>): Promise<ToolExecutionResult> => {
  1554. const result = await next()
  1555. // The base next() IS dispatch-with-normalization: the wrapper sees the
  1556. // normalized isError result, never a raw throw from the tool body.
  1557. seen = { isError: result.isError, error: result.error }
  1558. return result
  1559. })
  1560. const result = await ctx.tools.execute({ signal: testToolSignal, callId: ToolCallId('c1'), name: 'boom', arguments: {} })
  1561. expect(seen).toEqual({
  1562. isError: true,
  1563. error: { message: 'kaboom', info: { name: 'HarnessError', code: 'BOOM' } },
  1564. })
  1565. expect(result.isError).toBe(true)
  1566. expect(result.content[0]).toMatchObject({ text: 'Error: kaboom' })
  1567. })
  1568. it('freezes core dispatch outcomes before around and post listeners can observe them', async () => {
  1569. const ctx = await setup()
  1570. ctx.tools.register(echoTool)
  1571. const mutationAttempts: boolean[] = []
  1572. ctx.on('tools/execute', async (_exec, next) => {
  1573. const result = await next()
  1574. mutationAttempts.push(Reflect.set(result, 'value', 'around mutation'))
  1575. return result
  1576. })
  1577. ctx.on('tools/post-execute', async (_exec, result, next) => {
  1578. mutationAttempts.push(Reflect.set(result, 'value', 'post mutation'))
  1579. return next()
  1580. })
  1581. const result = await ctx.tools.execute({
  1582. signal: testToolSignal,
  1583. callId: ToolCallId('frozen-canonical'), name: 'echo', arguments: { text: 'original' },
  1584. })
  1585. expect(mutationAttempts).toEqual([false, false])
  1586. expect(result.isError ? undefined : result.value).toBe('original')
  1587. })
  1588. it('a thrown tool normalized inside tools/execute still reaches post-execute', async () => {
  1589. const ctx = await setup()
  1590. ctx.tools.register({
  1591. ...echoTool,
  1592. name: 'boom',
  1593. async execute() { throw new Error('exploded') },
  1594. })
  1595. let postSaw: boolean | undefined
  1596. ctx.on('tools/execute', async (_exec: ToolDispatchExecution, next: () => Promise<ToolExecutionResult>): Promise<ToolExecutionResult> => next())
  1597. ctx.on('tools/post-execute', async (_exec, result, next) => {
  1598. postSaw = result.isError
  1599. return next()
  1600. })
  1601. const result = await ctx.tools.execute({ signal: testToolSignal, callId: ToolCallId('c1'), name: 'boom', arguments: {} })
  1602. expect(postSaw).toBe(true) // the normalized isError still flows through post-execute
  1603. expect(result.isError).toBe(true)
  1604. expect(result.content[0]).toMatchObject({ text: 'Error: exploded' })
  1605. })
  1606. it('re-fuses the caller signal with an around-dispatch replacement for the body', async () => {
  1607. const ctx = await setup()
  1608. let seenSignal: AbortSignal | undefined
  1609. ctx.tools.register({
  1610. ...echoTool,
  1611. name: 'signal-probe',
  1612. async execute(_args, exec) {
  1613. seenSignal = exec.signal
  1614. return 'ok'
  1615. },
  1616. })
  1617. const upstream = new AbortController().signal
  1618. const replacement = new AbortController().signal
  1619. ctx.on('tools/execute', async (exec: ToolDispatchExecution, next: () => Promise<ToolExecutionResult>): Promise<ToolExecutionResult> => {
  1620. expect(exec.signal).toBe(upstream)
  1621. // Cordis next() ignores passed arguments, so a wrapper mutates exec in
  1622. // place (the documented "mutate the shared object, then delegate" idiom).
  1623. exec.signal = replacement
  1624. return next()
  1625. })
  1626. await ctx.tools.execute({ callId: ToolCallId('c1'), name: 'signal-probe', arguments: {}, signal: upstream })
  1627. expect(seenSignal).toBeDefined()
  1628. expect(seenSignal).not.toBe(upstream)
  1629. expect(seenSignal).not.toBe(replacement)
  1630. })
  1631. it('a tools/execute listener can short-circuit dispatch by returning a result without next()', async () => {
  1632. const ctx = await setup()
  1633. let dispatched = false
  1634. ctx.tools.register({
  1635. ...echoTool,
  1636. name: 'never-runs',
  1637. async execute() { dispatched = true; return 'unreachable' },
  1638. })
  1639. ctx.on('tools/execute', async (_exec: ToolDispatchExecution, _next: () => Promise<ToolExecutionResult>): Promise<ToolExecutionResult> =>
  1640. ({ content: [{ type: 'text', text: 'ignored authored content' }], isError: false, value: 'short-circuited' }))
  1641. const result = await ctx.tools.execute({ signal: testToolSignal, callId: ToolCallId('c1'), name: 'never-runs', arguments: {} })
  1642. expect(dispatched).toBe(false) // returning without next() skips core dispatch
  1643. expect(result.content[0]).toMatchObject({ text: 'short-circuited' })
  1644. })
  1645. it('revalidates a cached canonical result returned from a different dispatch', async () => {
  1646. const ctx = await setup()
  1647. ctx.tools.register({ ...echoTool, name: 'string-output', async execute() { return 'cached' } })
  1648. let objectBodyRan = false
  1649. ctx.tools.register(defineTool({
  1650. name: 'object-output',
  1651. description: 'Return one closed object.',
  1652. parameters: {},
  1653. output: {
  1654. schema: {
  1655. type: 'object',
  1656. properties: { ok: { type: 'boolean', required: true } },
  1657. additionalProperties: false,
  1658. },
  1659. render: (_args, value) => [{ type: 'text', text: String(value.ok) }],
  1660. },
  1661. execute() {
  1662. objectBodyRan = true
  1663. return Promise.resolve({ ok: true })
  1664. },
  1665. }))
  1666. let cached: ToolExecutionResult | undefined
  1667. ctx.on('tools/execute', async (exec, next) => {
  1668. if (exec.name === 'string-output') {
  1669. cached = await next()
  1670. return cached
  1671. }
  1672. if (exec.name === 'object-output') {
  1673. if (cached === undefined) throw new Error('expected the first dispatch result')
  1674. return cached
  1675. }
  1676. return next()
  1677. })
  1678. const first = await ctx.tools.execute({
  1679. signal: testToolSignal, callId: ToolCallId('cached-first'), name: 'string-output', arguments: {},
  1680. })
  1681. const second = await ctx.tools.execute({
  1682. signal: testToolSignal, callId: ToolCallId('cached-second'), name: 'object-output', arguments: {},
  1683. })
  1684. expect(first.isError ? undefined : first.value).toBe('cached')
  1685. expect(objectBodyRan).toBe(false)
  1686. expect(second).toMatchObject({
  1687. isError: true,
  1688. error: { info: { name: 'ToolOutputError', code: 'INVALID_TOOL_OUTPUT' } },
  1689. })
  1690. })
  1691. it('preserves additionalContexts supplied by an around-dispatch result', async () => {
  1692. const ctx = await setup()
  1693. ctx.tools.register(echoTool)
  1694. ctx.on('tools/execute', async () => ({
  1695. content: [{ type: 'text', text: 'short-circuited with context' }],
  1696. isError: false,
  1697. value: 'short-circuited with context',
  1698. additionalContexts: [createUserMessage({
  1699. content: [{ type: 'text', text: 'from around dispatch' }],
  1700. source: { kind: 'plugin', plugin: 'test' },
  1701. })],
  1702. }))
  1703. const result = await ctx.tools.execute({
  1704. signal: testToolSignal,
  1705. callId: ToolCallId('around-context'), name: 'echo', arguments: {},
  1706. })
  1707. expect(result.additionalContexts).toEqual([{
  1708. id: expect.any(String) as unknown,
  1709. role: 'user',
  1710. content: [{ type: 'text', text: 'from around dispatch' }],
  1711. source: { kind: 'plugin', plugin: 'test' },
  1712. }])
  1713. })
  1714. it('returns an isError result when a tools/execute listener throws', async () => {
  1715. const ctx = await setup()
  1716. ctx.tools.register(echoTool)
  1717. ctx.on('tools/execute', async () => { throw new Error('wrapper broke') })
  1718. const result = await ctx.tools.execute({ signal: testToolSignal, callId: ToolCallId('c1'), name: 'echo', arguments: { text: 'hi' } })
  1719. expect(result).toEqual({
  1720. content: [{ type: 'text', text: 'Error: wrapper broke' }],
  1721. error: { message: 'wrapper broke' },
  1722. isError: true,
  1723. })
  1724. })
  1725. it('returns an isError result when a tools/pre-execute listener throws', async () => {
  1726. const ctx = await setup()
  1727. ctx.tools.register(echoTool)
  1728. ctx.on('tools/pre-execute', async () => {
  1729. throw new Error('permission hook broke')
  1730. })
  1731. const result = await ctx.tools.execute({ signal: testToolSignal, callId: ToolCallId('c1'), name: 'echo', arguments: { text: 'hi' } })
  1732. expect(result).toEqual({
  1733. content: [{ type: 'text', text: 'Error: permission hook broke' }],
  1734. error: { message: 'permission hook broke' },
  1735. isError: true,
  1736. })
  1737. })
  1738. it('returns an isError result when a tools/post-execute listener throws', async () => {
  1739. const ctx = await setup()
  1740. ctx.tools.register(echoTool)
  1741. ctx.on('tools/post-execute', async () => {
  1742. throw new Error('post hook broke')
  1743. })
  1744. const result = await ctx.tools.execute({ signal: testToolSignal, callId: ToolCallId('c1'), name: 'echo', arguments: { text: 'hi' } })
  1745. expect(result).toEqual({
  1746. content: [{ type: 'text', text: 'Error: post hook broke' }],
  1747. error: { message: 'post hook broke' },
  1748. isError: true,
  1749. })
  1750. })
  1751. it('preserves structured error info when a tools/pre-execute listener throws HarnessError', async () => {
  1752. const ctx = await setup()
  1753. ctx.tools.register(echoTool)
  1754. ctx.on('tools/pre-execute', async () => {
  1755. throw new HarnessError('denied', 'DENIED')
  1756. })
  1757. const result = await ctx.tools.execute({ signal: testToolSignal, callId: ToolCallId('c1'), name: 'echo', arguments: { text: 'hi' } })
  1758. expect(result).toMatchObject({
  1759. isError: true,
  1760. error: { message: 'denied', info: { name: 'HarnessError', code: 'DENIED' } },
  1761. })
  1762. })
  1763. it('schemas() snapshots tool schemas instead of exposing registry objects', async () => {
  1764. const ctx = await setup()
  1765. ctx.tools.register(echoTool)
  1766. const first = ctx.tools.schemas()
  1767. const firstParameters = first[0]!.parameters as { properties: Record<string, unknown> }
  1768. firstParameters.properties['mutated'] = { type: 'string' }
  1769. first[0]!.description = 'mutated'
  1770. expect(ctx.tools.schemas()).toEqual([{
  1771. name: 'echo',
  1772. description: 'echo arguments back',
  1773. parameters: { type: 'object', properties: { text: { type: 'string' } } },
  1774. }])
  1775. })
  1776. it('schemas() snapshots deeply nested parameters without using structured-clone recursion', async () => {
  1777. const ctx = await setup()
  1778. const depth = 5_000
  1779. let nested: JsonSchemaNode = { type: 'string' }
  1780. for (let index = 0; index < depth; index++) nested = { oneOf: [nested, { type: 'null' }] }
  1781. ctx.tools.register({
  1782. ...echoTool,
  1783. name: 'deep-schema',
  1784. parameters: { type: 'object', properties: { nested } },
  1785. })
  1786. const projected = ctx.tools.schemas()[0]!.parameters as JsonSchemaNode
  1787. let cursor = projected.properties!.nested!
  1788. let layers = 0
  1789. while (cursor.oneOf !== undefined) {
  1790. cursor = cursor.oneOf[0]!
  1791. layers++
  1792. }
  1793. expect(layers).toBe(depth)
  1794. expect(cursor).toEqual({ type: 'string' })
  1795. })
  1796. it('rejects schema projection when a raw registration is not lossless JSON', async () => {
  1797. const ctx = await setup()
  1798. ctx.tools.register({
  1799. ...echoTool,
  1800. name: 'lossy-schema',
  1801. parameters: { type: 'object', default: Number.NaN },
  1802. })
  1803. expect(() => ctx.tools.schemas())
  1804. .toThrow('tool "lossy-schema" parameters must be lossless JSON before schema projection')
  1805. })
  1806. it('rejects a non-positive or non-finite registration timeout', async () => {
  1807. const ctx = await setup()
  1808. expect(() => ctx.tools.register({ ...echoTool, name: 'zero-timeout', timeoutMs: 0 }))
  1809. .toThrow('timeoutMs must be a positive finite number')
  1810. expect(() => ctx.tools.register({ ...echoTool, name: 'infinite-timeout', timeoutMs: Number.POSITIVE_INFINITY }))
  1811. .toThrow('timeoutMs must be a positive finite number')
  1812. })
  1813. it('rejects duplicate names and unregisters on fiber dispose (HMR safety)', async () => {
  1814. const ctx = await setup()
  1815. ctx.tools.register(echoTool)
  1816. expect(() => ctx.tools.register(echoTool)).toThrow('already registered')
  1817. const fiber = await ctx.plugin(Object.assign((inner: Context) => {
  1818. inner.tools.register({ ...echoTool, name: 'scoped' })
  1819. }, { inject: ['tools'] }))
  1820. expect(ctx.tools.schemas().map(t => t.name)).toEqual(['echo', 'scoped'])
  1821. await fiber.dispose()
  1822. expect(ctx.tools.schemas().map(t => t.name)).toEqual(['echo'])
  1823. })
  1824. it('returns a callable disposer from register() that unregisters the tool', async () => {
  1825. const ctx = await setup()
  1826. ctx.tools.register(echoTool)
  1827. const dispose = ctx.tools.register({ ...echoTool, name: 'disposable' })
  1828. expect(ctx.tools.schemas().map(t => t.name)).toEqual(['echo', 'disposable'])
  1829. dispose()
  1830. expect(ctx.tools.schemas().map(t => t.name)).toEqual(['echo'])
  1831. })
  1832. it('rolls back the tool entry when a tools/change listener throws (P1-1)', async () => {
  1833. const ctx = await setup()
  1834. let threw = false
  1835. ctx.on('tools/change', () => {
  1836. if (!threw) { threw = true; throw new Error('boom change listener') }
  1837. })
  1838. // The throwing emit must roll the entry back, not leak it.
  1839. expect(() => ctx.tools.register(echoTool)).toThrow('boom change listener')
  1840. expect(ctx.tools.get('echo')).toBeUndefined() // rolled back, not leaked
  1841. expect(ctx.tools.schemas()).toHaveLength(0)
  1842. // A subsequent listener-free register of the SAME name succeeds and is
  1843. // exposed exactly once (the duplicate-name check is not wedged).
  1844. const dispose = ctx.tools.register(echoTool)
  1845. expect(ctx.tools.schemas().map(t => t.name)).toEqual(['echo'])
  1846. dispose()
  1847. expect(ctx.tools.get('echo')).toBeUndefined()
  1848. })
  1849. it('register() returns the EXACT effect disposer: a composite yield nests the teardown in order', async () => {
  1850. // Registry methods return the exact Cordis effect disposer so a composite yield places
  1851. // unregistration at its LIFO position. A wrapper would create a concurrent sibling; this async
  1852. // probe yields during earlier teardown and would then observe the tool already removed.
  1853. const ctx = await setup()
  1854. const order: string[] = []
  1855. const fiber = await ctx.plugin(Object.assign((inner: Context) => {
  1856. inner.effect(function* () {
  1857. yield () => { order.push('disposed-last') }
  1858. yield inner.tools.register({ ...echoTool, name: 'nested' })
  1859. order.push('registered')
  1860. yield async () => {
  1861. await new Promise(resolve => setTimeout(resolve, 0))
  1862. order.push(inner.tools.get('nested') ? 'first: still registered' : 'first: already gone')
  1863. }
  1864. })
  1865. }, { inject: ['tools'] }))
  1866. await fiber.dispose()
  1867. expect(order).toEqual(['registered', 'first: still registered', 'disposed-last'])
  1868. expect(ctx.tools.get('nested')).toBeUndefined()
  1869. })
  1870. })
  1871. describe('defineTool / schema DSL', () => {
  1872. it('converts ParameterSchemaSpec to standard JSON Schema with required array', () => {
  1873. const spec = {
  1874. path: { type: 'string', required: true, description: 'Absolute path' },
  1875. offset: { type: 'number' },
  1876. limit: { type: 'number', description: 'Max lines' },
  1877. } satisfies ParameterSchemaSpec
  1878. const jsonSchema = parameterSchemaSpecToJsonSchema(spec)
  1879. expect(jsonSchema).toEqual({
  1880. type: 'object',
  1881. properties: {
  1882. path: { type: 'string', description: 'Absolute path' },
  1883. offset: { type: 'number' },
  1884. limit: { type: 'number', description: 'Max lines' },
  1885. },
  1886. required: ['path'],
  1887. })
  1888. })
  1889. it('handles empty spec (no properties, no required)', () => {
  1890. expect(parameterSchemaSpecToJsonSchema({})).toEqual({
  1891. type: 'object',
  1892. properties: {},
  1893. })
  1894. })
  1895. it('handles nested object spec', () => {
  1896. const spec = {
  1897. config: {
  1898. type: 'object',
  1899. additionalProperties: true,
  1900. required: true,
  1901. properties: {
  1902. host: { type: 'string', required: true },
  1903. port: { type: 'number' },
  1904. },
  1905. },
  1906. } satisfies ParameterSchemaSpec
  1907. const jsonSchema = parameterSchemaSpecToJsonSchema(spec)
  1908. expect(jsonSchema).toEqual({
  1909. type: 'object',
  1910. properties: {
  1911. config: {
  1912. type: 'object',
  1913. additionalProperties: true,
  1914. properties: {
  1915. host: { type: 'string' },
  1916. port: { type: 'number' },
  1917. },
  1918. required: ['host'],
  1919. },
  1920. },
  1921. required: ['config'],
  1922. })
  1923. })
  1924. it('defineTool returns a valid ToolDefinition with typed execute', async () => {
  1925. const ctx = await setup()
  1926. const tool = defineTool({
  1927. name: 'typed-echo',
  1928. description: 'A typed echo tool',
  1929. parameters: {
  1930. text: { type: 'string', required: true },
  1931. uppercase: { type: 'boolean' },
  1932. },
  1933. output: {
  1934. schema: { type: 'string' },
  1935. render: (_args, value) => [{ type: 'text', text: value }],
  1936. },
  1937. async execute(args) {
  1938. // args is typed: { text: string; uppercase?: boolean }
  1939. const result = args.uppercase ? args.text.toUpperCase() : args.text
  1940. return result
  1941. },
  1942. })
  1943. ctx.tools.register(tool)
  1944. expect(ctx.tools.schemas()).toEqual([{
  1945. name: 'typed-echo',
  1946. description: 'A typed echo tool',
  1947. parameters: {
  1948. type: 'object',
  1949. properties: {
  1950. text: { type: 'string' },
  1951. uppercase: { type: 'boolean' },
  1952. },
  1953. required: ['text'],
  1954. },
  1955. }])
  1956. const result = await ctx.tools.execute({
  1957. signal: testToolSignal,
  1958. callId: ToolCallId('c1'),
  1959. name: 'typed-echo',
  1960. arguments: { text: 'hello', uppercase: true },
  1961. })
  1962. expect(result.isError).toBe(false)
  1963. expect(result.isError ? undefined : result.value).toBe('HELLO')
  1964. expect(result.content).toEqual([{ type: 'text', text: 'HELLO' }])
  1965. })
  1966. it('type-level: InferArgs maps required properties to non-optional', () => {
  1967. // Compile-time check: if this compiles, InferArgs is correct.
  1968. // args.a is string (required), args.b is number|undefined (optional).
  1969. const tool = defineTool({
  1970. name: 'type-check',
  1971. description: '',
  1972. parameters: { a: { type: 'string' as const, required: true as const }, b: { type: 'number' as const } },
  1973. output: { schema: { type: 'string' }, render: () => [] },
  1974. async execute(args) {
  1975. expect(typeof args.a).toBe('string')
  1976. void args
  1977. return args.a
  1978. },
  1979. })
  1980. void tool
  1981. })
  1982. it('registry round-trips a defineTool definition (register→schemas→execute)', async () => {
  1983. const ctx = await setup()
  1984. ctx.tools.register(defineTool({
  1985. name: 'roundtrip',
  1986. description: 'Round-trip test',
  1987. parameters: {
  1988. req: { type: 'string', required: true },
  1989. opt: { type: 'number', description: 'Optional number' },
  1990. },
  1991. output: {
  1992. schema: { type: 'string' },
  1993. render: (_args, value) => [{ type: 'text', text: value }],
  1994. },
  1995. async execute(args) {
  1996. return `${args.req}:${args.opt ?? 'none'}`
  1997. },
  1998. }))
  1999. // Schema round-trip: schemas() returns standard JSON Schema
  2000. const schemas = ctx.tools.schemas()
  2001. expect(schemas).toHaveLength(1)
  2002. expect(schemas[0]!.parameters).toEqual({
  2003. type: 'object',
  2004. properties: {
  2005. req: { type: 'string' },
  2006. opt: { type: 'number', description: 'Optional number' },
  2007. },
  2008. required: ['req'],
  2009. })
  2010. // Execution round-trip
  2011. const result = await ctx.tools.execute({
  2012. signal: testToolSignal,
  2013. callId: ToolCallId('c1'),
  2014. name: 'roundtrip',
  2015. arguments: { req: 'hello' },
  2016. })
  2017. expect(result.isError).toBe(false)
  2018. expect(result.content).toEqual([{ type: 'text', text: 'hello:none' }])
  2019. })
  2020. it('still accepts raw JSON-Schema ToolDefinition directly (MCP interop)', async () => {
  2021. const ctx = await setup()
  2022. ctx.tools.register({
  2023. name: 'raw-tool',
  2024. description: 'Raw JSON Schema tool (like an MCP adapter would register)',
  2025. parameters: {
  2026. type: 'object',
  2027. properties: { path: { type: 'string' } },
  2028. required: ['path'],
  2029. },
  2030. output: {
  2031. schema: { type: 'string' },
  2032. render: (_args, value) => [{ type: 'text', text: value as string }],
  2033. },
  2034. async execute(args: unknown) {
  2035. const p = args as { path: string }
  2036. return p.path
  2037. },
  2038. })
  2039. const schemas = ctx.tools.schemas()
  2040. expect(schemas[0]!.parameters).toEqual({
  2041. type: 'object',
  2042. properties: { path: { type: 'string' } },
  2043. required: ['path'],
  2044. })
  2045. const result = await ctx.tools.execute({
  2046. signal: testToolSignal,
  2047. callId: ToolCallId('c1'),
  2048. name: 'raw-tool',
  2049. arguments: { path: '/tmp' },
  2050. })
  2051. expect(result.isError).toBe(false)
  2052. expect(result.content).toEqual([{ type: 'text', text: '/tmp' }])
  2053. })
  2054. })
  2055. describe('schema DSL edge cases', () => {
  2056. it('emits enum values in JSON Schema property', () => {
  2057. const spec = {
  2058. color: { type: 'string', enum: ['red', 'green', 'blue'], description: 'Color choice' },
  2059. } satisfies ParameterSchemaSpec
  2060. const jsonSchema = parameterSchemaSpecToJsonSchema(spec)
  2061. expect(jsonSchema.properties['color']).toMatchObject({
  2062. type: 'string',
  2063. enum: ['red', 'green', 'blue'],
  2064. description: 'Color choice',
  2065. })
  2066. })
  2067. it('emits default value in JSON Schema property', () => {
  2068. const spec = {
  2069. limit: { type: 'number', default: 25 },
  2070. } satisfies ParameterSchemaSpec
  2071. const jsonSchema = parameterSchemaSpecToJsonSchema(spec)
  2072. expect(jsonSchema.properties['limit']).toMatchObject({
  2073. type: 'number',
  2074. default: 25,
  2075. })
  2076. })
  2077. it('handles array items without nested properties (plain type array)', () => {
  2078. const spec = {
  2079. tags: { type: 'array', items: { type: 'string' } },
  2080. } satisfies ParameterSchemaSpec
  2081. const jsonSchema = parameterSchemaSpecToJsonSchema(spec)
  2082. expect(jsonSchema.properties['tags']).toEqual({
  2083. type: 'array',
  2084. items: { type: 'string' },
  2085. })
  2086. })
  2087. it('handles enum and default together in one property', () => {
  2088. const spec = {
  2089. level: { type: 'string', enum: ['low', 'high'], default: 'low' },
  2090. } satisfies ParameterSchemaSpec
  2091. const jsonSchema = parameterSchemaSpecToJsonSchema(spec)
  2092. expect(jsonSchema.properties['level']).toMatchObject({
  2093. type: 'string',
  2094. enum: ['low', 'high'],
  2095. default: 'low',
  2096. })
  2097. })
  2098. it('omits description, enum, default keys when not specified', () => {
  2099. const spec = {
  2100. bare: { type: 'string' },
  2101. } satisfies ParameterSchemaSpec
  2102. const jsonSchema = parameterSchemaSpecToJsonSchema(spec)
  2103. const prop = jsonSchema.properties['bare'] as Record<string, unknown>
  2104. expect(prop).toEqual({ type: 'string' })
  2105. expect('description' in prop).toBe(false)
  2106. expect('enum' in prop).toBe(false)
  2107. expect('default' in prop).toBe(false)
  2108. })
  2109. it('handles array with no items (items omitted)', () => {
  2110. const spec = {
  2111. raw: { type: 'array' },
  2112. } satisfies ParameterSchemaSpec
  2113. const jsonSchema = parameterSchemaSpecToJsonSchema(spec)
  2114. expect(jsonSchema.properties['raw']).toEqual({
  2115. type: 'array',
  2116. })
  2117. })
  2118. it('handles nested object with all-optional properties (no required array)', () => {
  2119. const spec = {
  2120. config: {
  2121. type: 'object',
  2122. additionalProperties: true,
  2123. properties: {
  2124. host: { type: 'string' },
  2125. port: { type: 'number' },
  2126. },
  2127. },
  2128. } satisfies ParameterSchemaSpec
  2129. const jsonSchema = parameterSchemaSpecToJsonSchema(spec)
  2130. expect(jsonSchema.properties['config']).toMatchObject({
  2131. type: 'object',
  2132. properties: {
  2133. host: { type: 'string' },
  2134. port: { type: 'number' },
  2135. },
  2136. })
  2137. const config = jsonSchema.properties['config'] as Record<string, unknown>
  2138. expect('required' in config).toBe(false)
  2139. })
  2140. })
  2141. describe('schema DSL optional and nested contracts', () => {
  2142. it('InferArgs makes non-required keys genuinely optional (omittable)', () => {
  2143. type Args = InferArgs<{
  2144. path: { type: 'string'; required: true }
  2145. limit: { type: 'number' }
  2146. }>
  2147. expectTypeOf<Args>().toEqualTypeOf<{ path: string; limit?: number }>()
  2148. const omitted: Args = { path: '/tmp' }
  2149. expect(omitted.limit).toBeUndefined()
  2150. })
  2151. it('InferArgs recurses into array items, including arrays of objects', () => {
  2152. type Args = InferArgs<{
  2153. names: { type: 'array'; required: true; items: { type: 'string' } }
  2154. servers: {
  2155. type: 'array'
  2156. items: {
  2157. type: 'object'
  2158. additionalProperties: true
  2159. properties: {
  2160. host: { type: 'string'; required: true }
  2161. port: { type: 'number' }
  2162. }
  2163. }
  2164. }
  2165. }>
  2166. expectTypeOf<Args>().toEqualTypeOf<{
  2167. names: string[]
  2168. servers?: ({ host: string; port?: number } & Record<string, JsonValue>)[]
  2169. }>()
  2170. })
  2171. it('runtime JSON Schema matches the array-of-objects inference', () => {
  2172. const spec = {
  2173. servers: {
  2174. type: 'array',
  2175. items: {
  2176. type: 'object',
  2177. additionalProperties: true,
  2178. properties: {
  2179. host: { type: 'string', required: true },
  2180. port: { type: 'number' },
  2181. },
  2182. },
  2183. },
  2184. } satisfies ParameterSchemaSpec
  2185. expect(parameterSchemaSpecToJsonSchema(spec)).toEqual({
  2186. type: 'object',
  2187. properties: {
  2188. servers: {
  2189. type: 'array',
  2190. items: {
  2191. type: 'object',
  2192. additionalProperties: true,
  2193. properties: {
  2194. host: { type: 'string' },
  2195. port: { type: 'number' },
  2196. },
  2197. required: ['host'],
  2198. },
  2199. },
  2200. },
  2201. })
  2202. })
  2203. it('reports messages from non-Error throws (throw { message })', async () => {
  2204. const ctx = await setup()
  2205. ctx.tools.register({
  2206. ...echoTool,
  2207. name: 'object-thrower',
  2208. async execute() {
  2209. // testing non-Error throws on purpose
  2210. throw { message: 'denied by object' }
  2211. },
  2212. })
  2213. const result = await ctx.tools.execute({ signal: testToolSignal, callId: ToolCallId('c1'), name: 'object-thrower', arguments: {} })
  2214. expect(result.isError).toBe(true)
  2215. expect(result.content[0]).toMatchObject({ text: 'Error: denied by object' })
  2216. })
  2217. it('reports messages from throws of non-objects (throw "string")', async () => {
  2218. const ctx = await setup()
  2219. ctx.tools.register({
  2220. ...echoTool,
  2221. name: 'string-thrower',
  2222. async execute() {
  2223. // testing primitive throws on purpose
  2224. throw 'kaboom'
  2225. },
  2226. })
  2227. const result = await ctx.tools.execute({ signal: testToolSignal, callId: ToolCallId('c1'), name: 'string-thrower', arguments: {} })
  2228. expect(result.isError).toBe(true)
  2229. expect(result.content[0]).toMatchObject({ text: 'Error: kaboom' })
  2230. })
  2231. it('reports messages from throws of objects without message property', async () => {
  2232. const ctx = await setup()
  2233. ctx.tools.register({
  2234. ...echoTool,
  2235. name: 'object-no-message',
  2236. async execute() {
  2237. // testing object throw without .message
  2238. throw { code: 500 }
  2239. },
  2240. })
  2241. const result = await ctx.tools.execute({ signal: testToolSignal, callId: ToolCallId('c1'), name: 'object-no-message', arguments: {} })
  2242. expect(result.isError).toBe(true)
  2243. const firstContent = result.content[0]!
  2244. expect(firstContent.type).toBe('text')
  2245. if (firstContent.type === 'text') {
  2246. expect(firstContent.text).toBe('Error: [object Object]')
  2247. }
  2248. })
  2249. })
  2250. describe('ToolRuntime.get', () => {
  2251. it('get() returns the registered tool definition', async () => {
  2252. const ctx = await setup()
  2253. ctx.tools.register(echoTool)
  2254. const tool = ctx.tools.get('echo')
  2255. expect(tool).toBeDefined()
  2256. expect(tool!.name).toBe('echo')
  2257. })
  2258. it('get() returns undefined for unknown tool names', async () => {
  2259. const ctx = await setup()
  2260. expect(ctx.tools.get('nope')).toBeUndefined()
  2261. })
  2262. })
  2263. describe('validateArgs (the runtime-validation Agent Note, part 1)', () => {
  2264. it('returns [] for valid args and is total over malformed input', () => {
  2265. const spec = {
  2266. path: { type: 'string', required: true },
  2267. limit: { type: 'number' },
  2268. } satisfies ParameterSchemaSpec
  2269. expect(validateArgs(spec, { path: '/tmp' })).toEqual([])
  2270. expect(validateArgs(spec, { path: '/tmp', limit: 5 })).toEqual([])
  2271. // never throws regardless of shape
  2272. expect(validateArgs(spec, null)).toHaveLength(1)
  2273. expect(validateArgs(spec, 'nope')).toHaveLength(1)
  2274. expect(validateArgs(spec, [])).toHaveLength(1)
  2275. })
  2276. it('flags a missing required key and a required key present as undefined', () => {
  2277. const spec = { path: { type: 'string', required: true } } satisfies ParameterSchemaSpec
  2278. expect(validateArgs(spec, {})).toEqual(['missing required property "path"'])
  2279. expect(validateArgs(spec, { path: undefined })).toEqual(['missing required property "path"'])
  2280. })
  2281. it('allows extra keys (no additionalProperties:false) and omitted optionals', () => {
  2282. const spec = { path: { type: 'string', required: true } } satisfies ParameterSchemaSpec
  2283. expect(validateArgs(spec, { path: '/tmp', extra: 1 })).toEqual([])
  2284. })
  2285. it('does not apply defaults (validation only)', () => {
  2286. const spec = { limit: { type: 'number', default: 25 } } satisfies ParameterSchemaSpec
  2287. // absent optional is valid, and validation does not synthesize the default
  2288. expect(validateArgs(spec, {})).toEqual([])
  2289. })
  2290. it('type-checks primitives', () => {
  2291. const spec = {
  2292. s: { type: 'string' },
  2293. n: { type: 'number' },
  2294. b: { type: 'boolean' },
  2295. } satisfies ParameterSchemaSpec
  2296. expect(validateArgs(spec, { s: 1 })).toEqual(['"s" must be a string'])
  2297. expect(validateArgs(spec, { n: 'x' })).toEqual(['"n" must be a number'])
  2298. expect(validateArgs(spec, { b: 'x' })).toEqual(['"b" must be a boolean'])
  2299. })
  2300. it('checks enum membership', () => {
  2301. const spec = { color: { type: 'string', enum: ['red', 'green'] } } satisfies ParameterSchemaSpec
  2302. expect(validateArgs(spec, { color: 'red' })).toEqual([])
  2303. expect(validateArgs(spec, { color: 'blue' })).toEqual(['"color" must be one of ["red","green"]'])
  2304. })
  2305. it('enforces type-correct scalar enum declarations', () => {
  2306. const spec = { n: { type: 'number', enum: [1, 2] } } satisfies ParameterSchemaSpec
  2307. expect(validateArgs(spec, { n: 1 })).toEqual([])
  2308. expect(validateArgs(spec, { n: 3 })).toEqual(['"n" must be one of [1,2]'])
  2309. const invalid = { n: { type: 'number', enum: ['1', '2'] } } as unknown as ParameterSchemaSpec
  2310. expect(() => validateArgs(invalid, { n: 1 })).toThrow(JsonSchemaError)
  2311. })
  2312. it('rejects an unknown schema type at the author boundary', () => {
  2313. const spec = { x: { type: 'weird' } } as unknown as ParameterSchemaSpec
  2314. expect(() => validateArgs(spec, { x: 1 })).toThrow(JsonSchemaError)
  2315. })
  2316. it('recurses into nested objects (and an object without properties only type-checks)', () => {
  2317. const spec = {
  2318. config: {
  2319. type: 'object',
  2320. additionalProperties: true,
  2321. required: true,
  2322. properties: { host: { type: 'string', required: true }, port: { type: 'number' } },
  2323. },
  2324. bag: { type: 'object', additionalProperties: true },
  2325. } satisfies ParameterSchemaSpec
  2326. expect(validateArgs(spec, { config: { host: 'h' }, bag: { anything: true } })).toEqual([])
  2327. expect(validateArgs(spec, { config: { port: 9 }, bag: 5 })).toEqual([
  2328. 'missing required property "config.host"',
  2329. '"bag" must be an object',
  2330. ])
  2331. })
  2332. it('recurses into array items (and an array without items only type-checks)', () => {
  2333. const spec = {
  2334. tags: { type: 'array', items: { type: 'string' } },
  2335. raw: { type: 'array' },
  2336. } satisfies ParameterSchemaSpec
  2337. expect(validateArgs(spec, { tags: ['a', 'b'], raw: [1, {}, 'x'] })).toEqual([])
  2338. expect(validateArgs(spec, { tags: ['a', 2] })).toEqual(['"tags[1]" must be a string'])
  2339. // a non-array value for an array-typed prop
  2340. expect(validateArgs(spec, { tags: 'nope' })).toEqual(['"tags" must be an array'])
  2341. })
  2342. it('validates arrays of objects element-wise', () => {
  2343. const spec = {
  2344. servers: {
  2345. type: 'array',
  2346. items: { type: 'object', additionalProperties: true, properties: { host: { type: 'string', required: true } } },
  2347. },
  2348. } satisfies ParameterSchemaSpec
  2349. expect(validateArgs(spec, { servers: [{ host: 'a' }, {}] })).toEqual([
  2350. 'missing required property "servers[1].host"',
  2351. ])
  2352. })
  2353. })
  2354. describe('defineTool validation (the runtime-validation Agent Note, part 1)', () => {
  2355. it('returns an isError result with the violations when the model sends bad args', async () => {
  2356. const ctx = await setup()
  2357. ctx.tools.register(defineContentToolFixture({
  2358. name: 'reader',
  2359. description: 'reads a path',
  2360. parameters: { path: { type: 'string', required: true } },
  2361. async execute(args) {
  2362. return [{ type: 'text', text: args.path }]
  2363. },
  2364. }))
  2365. const result = await ctx.tools.execute({ signal: testToolSignal, callId: ToolCallId('c1'), name: 'reader', arguments: {} })
  2366. expect(result.isError).toBe(true)
  2367. expect(result.content[0]).toMatchObject({
  2368. text: 'Error: invalid arguments: missing required property "path"',
  2369. })
  2370. })
  2371. it('runs execute normally when args are valid', async () => {
  2372. const ctx = await setup()
  2373. ctx.tools.register(defineContentToolFixture({
  2374. name: 'reader',
  2375. description: 'reads a path',
  2376. parameters: { path: { type: 'string', required: true } },
  2377. async execute(args) {
  2378. return [{ type: 'text', text: `read ${args.path}` }]
  2379. },
  2380. }))
  2381. const result = await ctx.tools.execute({ signal: testToolSignal, callId: ToolCallId('c1'), name: 'reader', arguments: { path: '/x' } })
  2382. expect(result).toEqual({
  2383. content: [{ type: 'text', text: 'read /x' }],
  2384. isError: false,
  2385. value: [{ type: 'text', text: 'read /x' }],
  2386. })
  2387. })
  2388. it('ToolArgsError carries a stable code and the violation list', () => {
  2389. const err = new ToolArgsError(['missing required property "a"', '"b" must be a number'])
  2390. expect(err).toBeInstanceOf(Error)
  2391. expect(err.name).toBe('ToolArgsError')
  2392. expect(err.code).toBe('INVALID_ARGS')
  2393. expect(err.violations).toEqual(['missing required property "a"', '"b" must be a number'])
  2394. expect(err.message).toBe('invalid arguments: missing required property "a"; "b" must be a number')
  2395. })
  2396. it('a schema-invalid call surfaces the structured error on the result', async () => {
  2397. const ctx = await setup()
  2398. ctx.tools.register(defineContentToolFixture({
  2399. name: 'reader',
  2400. description: 'reads a path',
  2401. parameters: { path: { type: 'string', required: true } },
  2402. async execute(args) {
  2403. return [{ type: 'text', text: args.path }]
  2404. },
  2405. }))
  2406. const result = await ctx.tools.execute({ signal: testToolSignal, callId: ToolCallId('c1'), name: 'reader', arguments: {} })
  2407. expect(result.isError).toBe(true)
  2408. expect(result.error).toEqual({
  2409. message: 'invalid arguments: missing required property "path"',
  2410. info: { name: 'ToolArgsError', code: 'INVALID_ARGS' },
  2411. })
  2412. })
  2413. it('a tool throwing a HarnessError surfaces its name and code', async () => {
  2414. const { HarnessError } = await import('@deepseek-ai/dsh-llm')
  2415. const ctx = await setup()
  2416. ctx.tools.register({
  2417. ...echoTool,
  2418. name: 'coded',
  2419. async execute() {
  2420. throw new HarnessError('disk full', 'ENOSPC')
  2421. },
  2422. })
  2423. const result = await ctx.tools.execute({ signal: testToolSignal, callId: ToolCallId('c1'), name: 'coded', arguments: {} })
  2424. expect(result.isError).toBe(true)
  2425. expect(result.error).toEqual({ message: 'disk full', info: { name: 'HarnessError', code: 'ENOSPC' } })
  2426. expect(result.content[0]).toMatchObject({ text: 'Error: disk full' })
  2427. })
  2428. it('a non-HarnessError throw retains only its message', async () => {
  2429. const ctx = await setup()
  2430. ctx.tools.register({
  2431. ...echoTool,
  2432. name: 'plain',
  2433. async execute() {
  2434. throw new Error('just a message')
  2435. },
  2436. })
  2437. const result = await ctx.tools.execute({ signal: testToolSignal, callId: ToolCallId('c1'), name: 'plain', arguments: {} })
  2438. expect(result.isError).toBe(true)
  2439. expect(result.error).toEqual({ message: 'just a message' })
  2440. expect(result.content[0]).toMatchObject({ text: 'Error: just a message' })
  2441. })
  2442. it('raw-registered tools are NOT validated by defineTool (MCP keeps its own)', async () => {
  2443. const ctx = await setup()
  2444. // A raw ToolDefinition: no defineTool wrapping, so no validateArgs guard.
  2445. ctx.tools.register({
  2446. name: 'raw',
  2447. description: 'raw tool',
  2448. parameters: { type: 'object', properties: { path: { type: 'string' } }, required: ['path'] },
  2449. output: {
  2450. schema: { type: 'string' },
  2451. render: (_args, value) => [{ type: 'text', text: value as string }],
  2452. },
  2453. async execute(args: unknown) {
  2454. return typeof args
  2455. },
  2456. })
  2457. // Missing the "required" path — but raw tools validate their own input, so
  2458. // this reaches execute rather than being rejected by the harness.
  2459. const result = await ctx.tools.execute({ signal: testToolSignal, callId: ToolCallId('c1'), name: 'raw', arguments: {} })
  2460. expect(result.isError).toBe(false)
  2461. })
  2462. it('attaches a positive-finite timeoutMs to the definition', () => {
  2463. const tool = defineContentToolFixture({
  2464. name: 'x', description: 'd', parameters: {}, timeoutMs: 30_000,
  2465. async execute() { return [{ type: 'text' as const, text: 'ok' }] },
  2466. })
  2467. expect(tool.timeoutMs).toBe(30_000)
  2468. })
  2469. it('omits timeoutMs when not declared', () => {
  2470. const tool = defineContentToolFixture({
  2471. name: 'x', description: 'd', parameters: {},
  2472. async execute() { return [{ type: 'text' as const, text: 'ok' }] },
  2473. })
  2474. expect(tool.timeoutMs).toBeUndefined()
  2475. })
  2476. it('throws when timeoutMs is zero or negative', () => {
  2477. const make = (ms: number) => defineContentToolFixture({
  2478. name: 'x', description: 'd', parameters: {}, timeoutMs: ms,
  2479. async execute() { return [{ type: 'text' as const, text: 'ok' }] },
  2480. })
  2481. expect(() => make(0)).toThrow('timeoutMs must be a positive finite number')
  2482. expect(() => make(-5)).toThrow('positive finite number')
  2483. })
  2484. it('throws when timeoutMs is non-finite', () => {
  2485. expect(() => defineContentToolFixture({
  2486. name: 'x', description: 'd', parameters: {}, timeoutMs: Infinity,
  2487. async execute() { return [{ type: 'text' as const, text: 'ok' }] },
  2488. })).toThrow('positive finite number')
  2489. })
  2490. })
  2491. describe('defineTool presentation (presentCall / presentResult)', () => {
  2492. it('preserves inline enum and const literals in inferred arguments', () => {
  2493. defineTool({
  2494. name: 'literal-args',
  2495. description: 'literal arguments',
  2496. parameters: {
  2497. mode: { type: 'string', enum: ['read', 'write'], required: true },
  2498. attempt: { type: 'integer', const: 1 },
  2499. },
  2500. output: {
  2501. schema: { type: 'null' },
  2502. render: () => [],
  2503. },
  2504. async execute(args) {
  2505. expectTypeOf(args).toEqualTypeOf<{ mode: 'read' | 'write'; attempt?: 1 }>()
  2506. return null
  2507. },
  2508. })
  2509. })
  2510. it('threads presentCall/presentResult onto the ToolDefinition with typed args', () => {
  2511. const tool = defineContentToolFixture({
  2512. name: 'demo',
  2513. description: 'demo',
  2514. parameters: { path: { type: 'string', required: true }, n: { type: 'number' } },
  2515. async execute() { return [{ type: 'text', text: 'ok' }] },
  2516. presentCall(args) {
  2517. // args is typed { path: string; n?: number } — zero casts.
  2518. expectTypeOf(args).toEqualTypeOf<{ path: string; n?: number }>()
  2519. return { card: 'generic', title: `Open ${args.path}`, kind: 'read', rawInput: args.path }
  2520. },
  2521. presentResult(args, result) {
  2522. return { card: 'generic', title: `Opened ${args.path}`, content: result.content }
  2523. },
  2524. })
  2525. expect(tool.presentCall!({ path: '/a', n: 2 })).toEqual({ card: 'generic', title: 'Open /a', kind: 'read', rawInput: '/a' })
  2526. expect(tool.presentResult!({ path: '/a' }, { content: [{ type: 'text', text: 'x' }], isError: false }))
  2527. .toEqual({ card: 'generic', title: 'Opened /a', content: [{ type: 'text', text: 'x' }] })
  2528. })
  2529. it('a tool without presentCall/presentResult leaves them undefined (UI falls back generically)', () => {
  2530. const tool = defineContentToolFixture({
  2531. name: 'plain',
  2532. description: 'plain',
  2533. parameters: { x: { type: 'string', required: true } },
  2534. async execute() { return [] },
  2535. })
  2536. expect(typeof tool.presentCall).toBe('undefined')
  2537. expect(typeof tool.presentResult).toBe('undefined')
  2538. })
  2539. it('presentCall/presentResult validate softly: malformed args return undefined, never throw (display runs on replay)', () => {
  2540. const tool = defineContentToolFixture({
  2541. name: 'demo',
  2542. description: 'demo',
  2543. parameters: { path: { type: 'string', required: true } },
  2544. async execute() { return [] },
  2545. presentCall: args => ({ card: 'generic', title: args.path }),
  2546. presentResult: (args, result) => ({ card: 'generic', title: args.path, content: result.content }),
  2547. })
  2548. // Unlike execute (which throws ToolArgsError on a mismatch), the display
  2549. // methods soft-validate and fall back to undefined so a UI never crashes
  2550. // replaying an old/foreign log entry. The ToolDefinition methods take
  2551. // `unknown`, so malformed shapes pass without a cast.
  2552. expect(tool.presentCall?.({})).toBeUndefined()
  2553. expect(tool.presentResult?.({ wrong: 1 }, { content: [], isError: false })).toBeUndefined()
  2554. })
  2555. })