hyf

Context-aware query service for Radroots
git clone https://radroots.dev/git/hyf.git
Log | Files | Refs | README | LICENSE

commit 572775a3c7783aac2c8c1017c8195ef4590c0852
parent e38628d9f89c1d136bf7e5d6393ea1af7efcad5a
Author: triesap <tyson@radroots.org>
Date:   Thu, 24 Sep 2026 02:42:48 +0000

H007: make the raw-body cap inclusive with an EOF sentinel read (D44)

ADR-0024 IL01-IL02. The shared raw observer treated a no-length
(EOF-delimited) response of exactly the 1,048,576-byte cap as
raw_body_overflow, because it tested the cap before attempting any read.

- at the exact cap, distinguish a real EOF from one extra byte with at most a
  single one-byte sentinel read under the existing parent deadline; the sentinel
  is never appended to the capped body, so the reported body_bytes stays at the
  inclusive maximum
- EOF at cap succeeds; a real extra byte fails raw_body_overflow; a stalled
  exact-cap peer is reported as a stopped (timeout) call by the existing parent
  deadline/cleanup, never an invented overflow
- add executed declared/no-length cap-1/cap/cap+1 and exact-cap stall controls to
  both the MaxLocal and Jev callers, distinguishing declared-length rejection
  (reason raw_body_overflow) from EOF acquisition (reason body_overflow)
- test-only: no product src/schema/pixi/dependency/lock/environment change

Diffstat:
Mtests/bounded_call_helper.mojo | 14+++++++++++++-
Mtests/test_jev.mojo | 258+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Mtests/test_provider_adapter.mojo | 267+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
3 files changed, 538 insertions(+), 1 deletion(-)

diff --git a/tests/bounded_call_helper.mojo b/tests/bounded_call_helper.mojo @@ -738,7 +738,19 @@ def _child_raw_head_body( if declared >= 0 and body_bytes >= declared: break if declared < 0 and body_bytes >= RAW_MAX_BODY_BYTES: - overflow = True + # D44/IL01: the 1,048,576-byte body cap is inclusive and a no-length + # (EOF-delimited) response is complete at the exact cap only when + # the peer has actually closed. Distinguish a real EOF from a real + # extra byte with at most one one-byte sentinel read under the same + # parent deadline; the sentinel is never appended to the capped + # body, so the reported body_bytes stays at the inclusive maximum. + # A peer that instead stalls leaves this read blocking, and the + # existing parent deadline/cleanup reports a stopped (timeout) + # call rather than an invented overflow. + var sentinel = InlineArray[Byte, 1](fill=0) + var extra = client.read(sentinel.unsafe_ptr(), 1) + if extra > 0: + overflow = True break var want2 = _plan_read_size( chunk_plan, plan_index, RAW_READ_CHUNK_BYTES diff --git a/tests/test_jev.mojo b/tests/test_jev.mojo @@ -527,6 +527,15 @@ comptime JEV_CORRELATION_OB_SPLIT_TERMINATOR = 210 comptime JEV_CORRELATION_OB_SPLIT_BODY = 211 comptime JEV_CORRELATION_OB_SURPLUS = 212 comptime JEV_CORRELATION_OB_NO_LENGTH = 213 +# H007 D44/IL01: distinct correlations for the inclusive raw-body-cap boundary +# controls on the Jev caller. +comptime JEV_CORRELATION_OB_CAP_DECLARED_MINUS = 214 +comptime JEV_CORRELATION_OB_CAP_DECLARED_EXACT = 215 +comptime JEV_CORRELATION_OB_CAP_DECLARED_PLUS = 216 +comptime JEV_CORRELATION_OB_CAP_NO_LENGTH_MINUS = 217 +comptime JEV_CORRELATION_OB_CAP_NO_LENGTH_EXACT = 218 +comptime JEV_CORRELATION_OB_CAP_NO_LENGTH_PLUS = 219 +comptime JEV_CORRELATION_OB_CAP_NO_LENGTH_STALL = 220 def _raw_jev_request_text(path: String) -> String: @@ -1240,6 +1249,255 @@ def test_jev_raw_head_body_no_length_completes_at_eof() raises: guard.assert_clean() +# D44/IL01: the inclusive 1,048,576-byte raw-body cap on the Jev caller, for +# both a declared Content-Length and an EOF-delimited (no-length) response. + +comptime JEV_RAW_BODY_CAP_TEST = 1048576 + + +def _jev_cap_body(count: Int) -> String: + var out = List[UInt8]() + var mark_bytes = "a".as_bytes() + for _ in range(count): + for index in range(len(mark_bytes)): + out.append(UInt8(Int(mark_bytes[index]))) + return String(unsafe_from_utf8=Span(ptr=out.unsafe_ptr(), length=len(out))) + + +def test_jev_raw_head_body_declared_cap_minus_one_succeeds() raises: + var body = _jev_cap_body(JEV_RAW_BODY_CAP_TEST - 1) + var scripts = List[ExchangeScript]() + var script = exchange_script( + "jev_declared_cap_m1", "POST", "/v1/systemone", 200, "" + ) + script.raw_response = ( + "HTTP/1.1 200 OK\r\ncontent-length: " + + String(JEV_RAW_BODY_CAP_TEST - 1) + + "\r\nconnection: close\r\n\r\n" + + body + ) + scripts.append(script^) + var guard = CleanupGuard() + with spawn_jev_scripted_auto(scripts^, guard) as started: + var report = run_bounded_call( + "raw_jev_head_body", + started.port, + 10000, + 10000, + guard, + JEV_CORRELATION_OB_CAP_DECLARED_MINUS, + "/v1/systemone", + "aaa", + ) + assert_true(report.ok()) + assert_equal(report.status, 200) + assert_equal(report.body_bytes, JEV_RAW_BODY_CAP_TEST - 1) + assert_equal(report.declared_bytes, JEV_RAW_BODY_CAP_TEST - 1) + assert_equal(report.length_match, "yes") + assert_equal(report.surplus_bytes, 0) + started.stub.wait() + assert_true(started.stub.ok()) + guard.assert_clean() + + +def test_jev_raw_head_body_declared_cap_exact_succeeds() raises: + var body = _jev_cap_body(JEV_RAW_BODY_CAP_TEST) + var scripts = List[ExchangeScript]() + var script = exchange_script( + "jev_declared_cap_exact", "POST", "/v1/systemone", 200, "" + ) + script.raw_response = ( + "HTTP/1.1 200 OK\r\ncontent-length: " + + String(JEV_RAW_BODY_CAP_TEST) + + "\r\nconnection: close\r\n\r\n" + + body + ) + scripts.append(script^) + var guard = CleanupGuard() + with spawn_jev_scripted_auto(scripts^, guard) as started: + var report = run_bounded_call( + "raw_jev_head_body", + started.port, + 10000, + 10000, + guard, + JEV_CORRELATION_OB_CAP_DECLARED_EXACT, + "/v1/systemone", + "aaa", + ) + assert_true(report.ok()) + assert_equal(report.status, 200) + assert_equal(report.body_bytes, JEV_RAW_BODY_CAP_TEST) + assert_equal(report.declared_bytes, JEV_RAW_BODY_CAP_TEST) + assert_equal(report.length_match, "yes") + assert_equal(report.surplus_bytes, 0) + started.stub.wait() + assert_true(started.stub.ok()) + guard.assert_clean() + + +def test_jev_raw_head_body_declared_cap_plus_one_is_over_cap() raises: + var scripts = List[ExchangeScript]() + var script = exchange_script( + "jev_declared_cap_p1", "POST", "/v1/systemone", 200, "" + ) + script.raw_response = ( + "HTTP/1.1 200 OK\r\ncontent-length: " + + String(JEV_RAW_BODY_CAP_TEST + 1) + + "\r\nconnection: close\r\n\r\nabc" + ) + scripts.append(script^) + var guard = CleanupGuard() + with spawn_jev_scripted_auto(scripts^, guard) as started: + var report = run_bounded_call( + "raw_jev_head_body", + started.port, + 10000, + 10000, + guard, + JEV_CORRELATION_OB_CAP_DECLARED_PLUS, + "/v1/systemone", + "abc", + ) + assert_true(report.completed) + assert_true(report.domain_failure()) + assert_equal(report.cause, "raw_body_overflow") + assert_equal(report.reason, "raw_body_overflow") + started.stub.wait() + assert_true(started.stub.ok()) + guard.assert_clean() + + +def test_jev_raw_head_body_no_length_cap_minus_one_succeeds() raises: + var body = _jev_cap_body(JEV_RAW_BODY_CAP_TEST - 1) + var scripts = List[ExchangeScript]() + var script = exchange_script( + "jev_nolen_cap_m1", "POST", "/v1/systemone", 200, "" + ) + script.raw_response = "HTTP/1.1 200 OK\r\nconnection: close\r\n\r\n" + body + scripts.append(script^) + var guard = CleanupGuard() + with spawn_jev_scripted_auto(scripts^, guard) as started: + var report = run_bounded_call( + "raw_jev_head_body", + started.port, + 10000, + 10000, + guard, + JEV_CORRELATION_OB_CAP_NO_LENGTH_MINUS, + "/v1/systemone", + "aaa", + ) + assert_true(report.ok()) + assert_equal(report.status, 200) + assert_equal(report.body_bytes, JEV_RAW_BODY_CAP_TEST - 1) + assert_equal(report.declared_bytes, -1) + assert_equal(report.length_match, "unknown") + assert_equal(report.surplus_bytes, 0) + started.stub.wait() + assert_true(started.stub.ok()) + guard.assert_clean() + + +def test_jev_raw_head_body_no_length_exact_cap_succeeds_at_eof() raises: + var body = _jev_cap_body(JEV_RAW_BODY_CAP_TEST) + var scripts = List[ExchangeScript]() + var script = exchange_script( + "jev_nolen_cap_exact", "POST", "/v1/systemone", 200, "" + ) + script.raw_response = "HTTP/1.1 200 OK\r\nconnection: close\r\n\r\n" + body + scripts.append(script^) + var guard = CleanupGuard() + with spawn_jev_scripted_auto(scripts^, guard) as started: + var report = run_bounded_call( + "raw_jev_head_body", + started.port, + 10000, + 10000, + guard, + JEV_CORRELATION_OB_CAP_NO_LENGTH_EXACT, + "/v1/systemone", + "aaa", + ) + assert_true(report.ok()) + assert_equal(report.status, 200) + assert_equal(report.body_bytes, JEV_RAW_BODY_CAP_TEST) + assert_equal(report.declared_bytes, -1) + assert_equal(report.length_match, "unknown") + assert_equal(report.surplus_bytes, 0) + started.stub.wait() + assert_true(started.stub.ok()) + guard.assert_clean() + + +def test_jev_raw_head_body_no_length_cap_plus_one_overflows() raises: + var body = _jev_cap_body(JEV_RAW_BODY_CAP_TEST + 1) + var scripts = List[ExchangeScript]() + var script = exchange_script( + "jev_nolen_cap_p1", "POST", "/v1/systemone", 200, "" + ) + script.raw_response = "HTTP/1.1 200 OK\r\nconnection: close\r\n\r\n" + body + scripts.append(script^) + var guard = CleanupGuard() + with spawn_jev_scripted_auto(scripts^, guard) as started: + var report = run_bounded_call( + "raw_jev_head_body", + started.port, + 10000, + 10000, + guard, + JEV_CORRELATION_OB_CAP_NO_LENGTH_PLUS, + "/v1/systemone", + "aaa", + ) + assert_true(report.completed) + assert_true(report.domain_failure()) + assert_equal(report.cause, "raw_body_overflow") + assert_equal(report.reason, "body_overflow") + assert_equal(report.body_bytes, JEV_RAW_BODY_CAP_TEST) + assert_equal(report.surplus_bytes, 0) + started.stub.wait() + assert_true(started.stub.ok()) + guard.assert_clean() + + +def test_jev_raw_head_body_no_length_exact_cap_stall_is_timeout() raises: + # D44/IL01: the Jev caller must also report a stopped (timeout) call, not an + # invented overflow, when an EOF-delimited peer delivers exactly the cap and + # then stalls under the existing parent deadline. + var body = _jev_cap_body(JEV_RAW_BODY_CAP_TEST) + var scripts = List[ExchangeScript]() + var script = exchange_script( + "jev_nolen_cap_stall", "POST", "/v1/systemone", 200, "" + ) + script.raw_response = "HTTP/1.1 200 OK\r\nconnection: close\r\n\r\n" + body + script.close_connection = False + scripts.append(script^) + scripts.append( + exchange_script( + "jev_nolen_cap_stall_unused", "POST", "/v1/systemone", 200, "" + ) + ) + var guard = CleanupGuard() + with spawn_jev_scripted_auto(scripts^, guard) as started: + var report = run_bounded_call( + "raw_jev_head_body", + started.port, + 10000, + 1500, + guard, + JEV_CORRELATION_OB_CAP_NO_LENGTH_STALL, + "/v1/systemone", + "aaa", + ) + assert_true(report.stopped) + assert_true(not report.completed) + assert_true(report.cleanup_proved) + assert_equal(report.problem, "") + assert_equal(report.cause, "") + guard.assert_clean() + + # OB03: the Jev serve path must also reject every synthetic write-error seam, # with and without an expected-close declaration. diff --git a/tests/test_provider_adapter.mojo b/tests/test_provider_adapter.mojo @@ -98,6 +98,15 @@ comptime BOUNDED_CORRELATION_OB_SPLIT_BODY = 147 comptime BOUNDED_CORRELATION_OB_NEAR_CAP = 148 comptime BOUNDED_CORRELATION_OB_MALFORMED_HEAD = 149 comptime BOUNDED_CORRELATION_OB_SYNTHETIC = 150 +# H007 D44/IL01: distinct correlations for the inclusive raw-body-cap boundary +# controls (declared and EOF-delimited) through the actual acquisition path. +comptime BOUNDED_CORRELATION_OB_CAP_DECLARED_MINUS = 151 +comptime BOUNDED_CORRELATION_OB_CAP_DECLARED_EXACT = 152 +comptime BOUNDED_CORRELATION_OB_CAP_DECLARED_PLUS = 153 +comptime BOUNDED_CORRELATION_OB_CAP_NO_LENGTH_MINUS = 154 +comptime BOUNDED_CORRELATION_OB_CAP_NO_LENGTH_EXACT = 155 +comptime BOUNDED_CORRELATION_OB_CAP_NO_LENGTH_PLUS = 156 +comptime BOUNDED_CORRELATION_OB_CAP_NO_LENGTH_STALL = 157 from flare.net import SocketAddr from flare.tcp import TcpStream @@ -2300,6 +2309,264 @@ def test_provider_raw_head_body_reports_malformed_length_grammar() raises: guard.assert_clean() +# D44/IL01: the inclusive 1,048,576-byte raw-body cap, proven through the +# actual incremental acquisition path for both a declared Content-Length and an +# EOF-delimited (no-length) response. Exact cap is inclusive; a real extra byte +# fails overflow; a stalled peer fails the existing parent deadline (timeout), +# never an invented overflow. + +comptime RAW_BODY_CAP_TEST = 1048576 + + +def _cap_body(count: Int) -> String: + return _repeat_text("a", count) + + +def test_provider_raw_head_body_declared_cap_minus_one_succeeds() raises: + var body = _cap_body(RAW_BODY_CAP_TEST - 1) + var scripts = List[ExchangeScript]() + var script = exchange_script( + "declared_cap_m1", "POST", "/v1/chat/completions", 200, "" + ) + script.raw_response = ( + "HTTP/1.1 200 OK\r\ncontent-length: " + + String(RAW_BODY_CAP_TEST - 1) + + "\r\nconnection: close\r\n\r\n" + + body + ) + scripts.append(script^) + var guard = CleanupGuard() + with spawn_max_local_scripted(0, scripts^, guard) as provider_stub: + var report = run_bounded_call( + "raw_head_body", + provider_stub.port, + 10000, + 10000, + guard, + BOUNDED_CORRELATION_OB_CAP_DECLARED_MINUS, + "/v1/chat/completions", + "aaa", + ) + assert_true(report.ok()) + assert_equal(report.status, 200) + assert_equal(report.body_bytes, RAW_BODY_CAP_TEST - 1) + assert_equal(report.declared_bytes, RAW_BODY_CAP_TEST - 1) + assert_equal(report.length_match, "yes") + assert_equal(report.surplus_bytes, 0) + provider_stub.wait() + assert_true(provider_stub.ok()) + guard.assert_clean() + + +def test_provider_raw_head_body_declared_cap_exact_succeeds() raises: + # D44/IL01: a declared body of exactly the cap is inclusive and completes + # without a sentinel read, because the declared length already bounds it. + var body = _cap_body(RAW_BODY_CAP_TEST) + var scripts = List[ExchangeScript]() + var script = exchange_script( + "declared_cap_exact", "POST", "/v1/chat/completions", 200, "" + ) + script.raw_response = ( + "HTTP/1.1 200 OK\r\ncontent-length: " + + String(RAW_BODY_CAP_TEST) + + "\r\nconnection: close\r\n\r\n" + + body + ) + scripts.append(script^) + var guard = CleanupGuard() + with spawn_max_local_scripted(0, scripts^, guard) as provider_stub: + var report = run_bounded_call( + "raw_head_body", + provider_stub.port, + 10000, + 10000, + guard, + BOUNDED_CORRELATION_OB_CAP_DECLARED_EXACT, + "/v1/chat/completions", + "aaa", + ) + assert_true(report.ok()) + assert_equal(report.status, 200) + assert_equal(report.body_bytes, RAW_BODY_CAP_TEST) + assert_equal(report.declared_bytes, RAW_BODY_CAP_TEST) + assert_equal(report.length_match, "yes") + assert_equal(report.surplus_bytes, 0) + provider_stub.wait() + assert_true(provider_stub.ok()) + guard.assert_clean() + + +def test_provider_raw_head_body_declared_cap_plus_one_is_over_cap() raises: + # D44/IL01: a declared length above the cap is rejected at the head grammar + # (declared-length rejection), distinctly from an EOF acquisition overflow. + var scripts = List[ExchangeScript]() + var script = exchange_script( + "declared_cap_p1", "POST", "/v1/chat/completions", 200, "" + ) + script.raw_response = ( + "HTTP/1.1 200 OK\r\ncontent-length: " + + String(RAW_BODY_CAP_TEST + 1) + + "\r\nconnection: close\r\n\r\nabc" + ) + scripts.append(script^) + var guard = CleanupGuard() + with spawn_max_local_scripted(0, scripts^, guard) as provider_stub: + var report = run_bounded_call( + "raw_head_body", + provider_stub.port, + 10000, + 10000, + guard, + BOUNDED_CORRELATION_OB_CAP_DECLARED_PLUS, + "/v1/chat/completions", + "abc", + ) + assert_true(report.completed) + assert_true(report.domain_failure()) + assert_equal(report.cause, "raw_body_overflow") + assert_equal(report.reason, "raw_body_overflow") + provider_stub.wait() + assert_true(provider_stub.ok()) + guard.assert_clean() + + +def test_provider_raw_head_body_no_length_cap_minus_one_succeeds() raises: + var body = _cap_body(RAW_BODY_CAP_TEST - 1) + var scripts = List[ExchangeScript]() + var script = exchange_script( + "nolen_cap_m1", "POST", "/v1/chat/completions", 200, "" + ) + script.raw_response = "HTTP/1.1 200 OK\r\nconnection: close\r\n\r\n" + body + scripts.append(script^) + var guard = CleanupGuard() + with spawn_max_local_scripted(0, scripts^, guard) as provider_stub: + var report = run_bounded_call( + "raw_head_body", + provider_stub.port, + 10000, + 10000, + guard, + BOUNDED_CORRELATION_OB_CAP_NO_LENGTH_MINUS, + "/v1/chat/completions", + "aaa", + ) + assert_true(report.ok()) + assert_equal(report.status, 200) + assert_equal(report.body_bytes, RAW_BODY_CAP_TEST - 1) + assert_equal(report.declared_bytes, -1) + assert_equal(report.length_match, "unknown") + assert_equal(report.surplus_bytes, 0) + provider_stub.wait() + assert_true(provider_stub.ok()) + guard.assert_clean() + + +def test_provider_raw_head_body_no_length_exact_cap_succeeds_at_eof() raises: + # D44/IL01 regression: the exact inclusive cap is a success when the peer + # closed at the cap. The one-byte sentinel observes EOF and is never + # appended, so body_bytes stays at the cap. + var body = _cap_body(RAW_BODY_CAP_TEST) + var scripts = List[ExchangeScript]() + var script = exchange_script( + "nolen_cap_exact", "POST", "/v1/chat/completions", 200, "" + ) + script.raw_response = "HTTP/1.1 200 OK\r\nconnection: close\r\n\r\n" + body + scripts.append(script^) + var guard = CleanupGuard() + with spawn_max_local_scripted(0, scripts^, guard) as provider_stub: + var report = run_bounded_call( + "raw_head_body", + provider_stub.port, + 10000, + 10000, + guard, + BOUNDED_CORRELATION_OB_CAP_NO_LENGTH_EXACT, + "/v1/chat/completions", + "aaa", + ) + assert_true(report.ok()) + assert_equal(report.status, 200) + assert_equal(report.body_bytes, RAW_BODY_CAP_TEST) + assert_equal(report.declared_bytes, -1) + assert_equal(report.length_match, "unknown") + assert_equal(report.surplus_bytes, 0) + provider_stub.wait() + assert_true(provider_stub.ok()) + guard.assert_clean() + + +def test_provider_raw_head_body_no_length_cap_plus_one_overflows() raises: + # D44/IL01: a real extra byte beyond the cap fails overflow through the + # sentinel read; the sentinel is never appended, so body_bytes stays at the + # inclusive maximum rather than exceeding it. + var body = _cap_body(RAW_BODY_CAP_TEST + 1) + var scripts = List[ExchangeScript]() + var script = exchange_script( + "nolen_cap_p1", "POST", "/v1/chat/completions", 200, "" + ) + script.raw_response = "HTTP/1.1 200 OK\r\nconnection: close\r\n\r\n" + body + scripts.append(script^) + var guard = CleanupGuard() + with spawn_max_local_scripted(0, scripts^, guard) as provider_stub: + var report = run_bounded_call( + "raw_head_body", + provider_stub.port, + 10000, + 10000, + guard, + BOUNDED_CORRELATION_OB_CAP_NO_LENGTH_PLUS, + "/v1/chat/completions", + "aaa", + ) + assert_true(report.completed) + assert_true(report.domain_failure()) + assert_equal(report.cause, "raw_body_overflow") + assert_equal(report.reason, "body_overflow") + assert_equal(report.body_bytes, RAW_BODY_CAP_TEST) + assert_equal(report.surplus_bytes, 0) + provider_stub.wait() + assert_true(provider_stub.ok()) + guard.assert_clean() + + +def test_provider_raw_head_body_no_length_exact_cap_stall_is_timeout() raises: + # D44/IL01: a peer that delivers exactly the cap and then stalls must be + # reported by the existing parent deadline as a stopped (timeout) call, + # never as an invented raw_body_overflow. The fixture keeps the connection + # open, so only the parent deadline can end the call. + var body = _cap_body(RAW_BODY_CAP_TEST) + var scripts = List[ExchangeScript]() + var script = exchange_script( + "nolen_cap_stall", "POST", "/v1/chat/completions", 200, "" + ) + script.raw_response = "HTTP/1.1 200 OK\r\nconnection: close\r\n\r\n" + body + script.close_connection = False + scripts.append(script^) + scripts.append( + exchange_script( + "nolen_cap_stall_unused", "POST", "/v1/chat/completions", 200, "" + ) + ) + var guard = CleanupGuard() + with spawn_max_local_scripted(0, scripts^, guard) as provider_stub: + var report = run_bounded_call( + "raw_head_body", + provider_stub.port, + 10000, + 1500, + guard, + BOUNDED_CORRELATION_OB_CAP_NO_LENGTH_STALL, + "/v1/chat/completions", + "aaa", + ) + assert_true(report.stopped) + assert_true(not report.completed) + assert_true(report.cleanup_proved) + assert_equal(report.problem, "") + assert_equal(report.cause, "") + guard.assert_clean() + + # OB03: a synthetic write-error seam is never a real peer close.