hyf

Context-aware query service for Radroots
git clone https://radroots.dev/git/hyf.git
Log | Files | Refs | README | LICENSE

commit b00c097333e25e8c7ac5de5f9d01e8a194f1cb9f
parent 985663ff1f52ac5daf36ea128371ffa753702b7d
Author: triesap <tyson@radroots.org>
Date:   Tue, 22 Sep 2026 17:02:28 +0000

tests: close C002B review findings on framing controls

- Add cause-specific premature-EOF, duplicate Content-Length, body-cap and
  header-cap negative controls so FX03 branches are proven, not just coded.
- Re-add an X-Authorization rejection control for the Jev auth echo path.
- Add a bounded /dev/fd descriptor-census control proving repeated teardown
  leaks no owned descriptor.
- Correct the C002B criterion matrix to cite existing tests only.

Diffstat:
Mtests/parent_lifecycle.mojo | 37+++++++++++++++++++++++++++++++++++++
Mtests/test_provider_helpers.mojo | 71++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++-
2 files changed, 107 insertions(+), 1 deletion(-)

diff --git a/tests/parent_lifecycle.mojo b/tests/parent_lifecycle.mojo @@ -312,3 +312,40 @@ def pid_not_waitable(pid: Int) -> Bool: test did not fork and never scans by process name. """ return wait_nohang(pid).state == "gone" + + +def open_fd_count() -> Int: + """Count this process's open descriptors by probing ``/dev/fd/N``. + + A bounded, read-only descriptor census used to evidence that repeated + teardown leaks no descriptors. Returns -1 if the platform probe is + unavailable (never treated as a pass). + """ + var probe = String("/dev/fd") + var dir = Int( + external_call["open", c_int]( + probe.as_c_string_slice().unsafe_ptr(), c_int(0) + ) + ) + if dir < 0: + probe = "/proc/self/fd" + dir = Int( + external_call["open", c_int]( + probe.as_c_string_slice().unsafe_ptr(), c_int(0) + ) + ) + if dir < 0: + return -1 + close_fd(dir) + var count = 0 + for n in range(3, 1024): + var path = probe + "/" + String(n) + var fd = Int( + external_call["open", c_int]( + path.as_c_string_slice().unsafe_ptr(), c_int(0) + ) + ) + if fd >= 0: + count += 1 + close_fd(fd) + return count diff --git a/tests/test_provider_helpers.mojo b/tests/test_provider_helpers.mojo @@ -10,7 +10,7 @@ from std.testing import TestSuite, assert_true, assert_equal from flare.net import SocketAddr from flare.tcp import TcpListener, TcpStream -from parent_lifecycle import pid_not_waitable +from parent_lifecycle import open_fd_count, pid_not_waitable from strict_fixture import ( ExchangeScript, FramedRequest, @@ -426,6 +426,63 @@ def test_strict_framing_conflicting_and_transfer_modes() raises: assert_equal(duplicate.reason(), "duplicate_transfer_encoding") +def test_strict_framing_premature_eof() raises: + var stub = _framing_failure( + "POST /v1/chat/completions HTTP/1.1\r\nhost: 127.0.0.1\r\n" + "content-length: 100\r\nconnection: close\r\n\r\nshort" + ) + assert_equal(stub.phase(), "read") + assert_equal(stub.reason(), "premature_eof") + + +def test_strict_framing_duplicate_content_length() raises: + var stub = _framing_failure( + "POST /v1/chat/completions HTTP/1.1\r\nhost: 127.0.0.1\r\n" + "content-length: 2\r\ncontent-length: 2\r\n" + "connection: close\r\n\r\n{}" + ) + assert_equal(stub.phase(), "read") + assert_equal(stub.reason(), "duplicate_content_length") + + +def test_strict_framing_body_cap_exceeded() raises: + var stub = _framing_failure( + "POST /v1/chat/completions HTTP/1.1\r\nhost: 127.0.0.1\r\n" + "content-length: 1048577\r\nconnection: close\r\n\r\n" + ) + assert_equal(stub.phase(), "read") + assert_equal(stub.reason(), "body_too_large") + + +def test_strict_framing_header_cap_exceeded() raises: + var filler = String("") + for _ in range(70000): + filler += "a" + var stub = _framing_failure( + ( + "POST /v1/chat/completions HTTP/1.1\r\nhost: 127.0.0.1\r\nx-big: " + + filler + + "\r\n\r\n" + ) + ) + assert_equal(stub.phase(), "read") + assert_equal(stub.reason(), "header_too_large") + + +def test_jev_echo_authorization_ignores_x_authorization() raises: + var started = spawn_jev_stub_auto("echo_authorization", 1) + var response = _request( + started.port, + "POST", + "/v1/systemone", + "{}", + "x-authorization: Bearer spoof\r\n", + ) + assert_true(response.find("401") >= 0) + assert_true(response.find("spoof") < 0) + started.stub.wait() + + def test_strict_framing_split_utf8_body() raises: var scripts = List[ExchangeScript]() var script = exchange_script( @@ -707,6 +764,18 @@ def test_repeated_failures_leave_no_owned_child() raises: assert_true(pid_not_waitable(stub.pid)) +def test_repeated_teardown_does_not_leak_descriptors() raises: + var before = open_fd_count() + assert_true(before > 0) + for _ in range(5): + var stub = spawn_max_local_stub(0, "count_requests", 1) + stub.terminate() + assert_true(pid_not_waitable(stub.pid)) + var after = open_fd_count() + assert_true(after > 0) + assert_true(after <= before) + + def test_timeout_terminates_and_reaps_stalled_child() raises: var stub = spawn_max_local_stub(0, "stall", 1) _raw_send_only(