hyf

Context-aware query service for Radroots
git clone https://radroots.dev/git/hyf.git
Log | Files | Refs | README | LICENSE

test_jev.mojo (59811B)


      1 from std.collections import List
      2 from std.ffi import ErrNo
      3 from std.testing import TestSuite, assert_equal, assert_raises, assert_true
      4 
      5 from hyf_assist.questions import (
      6     Question,
      7     QuestionBundle,
      8     choice_question,
      9     noul_question,
     10     question_bundle,
     11     score_question,
     12 )
     13 from hyf_provider.jev_request import build_jev_request_body
     14 
     15 
     16 def _bundle() raises -> QuestionBundle:
     17     var choices = List[String]()
     18     choices.append("offered")
     19     choices.append("forecast")
     20     choices.append("unclear")
     21     var questions = List[Question]()
     22     questions.append(choice_question("supply_status", "status?", choices))
     23     questions.append(noul_question("seconds_ok", "seconds?"))
     24     var rubric = List[String]()
     25     rubric.append("unsuitable")
     26     rubric.append("limited")
     27     rubric.append("suitable")
     28     questions.append(score_question("culinary_fit", "fit?", rubric))
     29     return question_bundle("qb1", "1", "jev-1.13.0", questions)
     30 
     31 
     32 def test_jev_request_serialization_shape() raises:
     33     var body = build_jev_request_body(_bundle(), "Roma tomatoes available now")
     34     assert_equal(body["model"].string_value(), "jev-1.13.0")
     35     assert_equal(body["state"].string_value(), "Roma tomatoes available now")
     36     assert_equal(
     37         body["questions"]["supply_status"]["type"].string_value(), "choice"
     38     )
     39     assert_true(
     40         body["questions"]["supply_status"]["criteria"]["offered"].is_null()
     41     )
     42     assert_equal(body["questions"]["seconds_ok"]["type"].string_value(), "noul")
     43     assert_equal(
     44         body["questions"]["culinary_fit"]["type"].string_value(), "score"
     45     )
     46     assert_equal(
     47         len(body["questions"]["culinary_fit"]["criteria"].array_items()), 3
     48     )
     49     with assert_raises():
     50         _ = build_jev_request_body(_bundle(), "")
     51 
     52 
     53 def main() raises:
     54     TestSuite.discover_tests[__functions_in_module()]().run()
     55 
     56 
     57 from hyf_provider.jev_answers import parse_choice_answer, parse_noul_answer
     58 from json import loads
     59 
     60 
     61 def test_parse_choice_and_noul_answers() raises:
     62     var noul = parse_noul_answer(
     63         "seconds_ok", loads('{"type":"noul","noul":0.9}')
     64     )
     65     assert_equal(noul.kind, "noul")
     66     assert_equal(noul.noul, 0.9)
     67     var choices = List[String]()
     68     choices.append("offered")
     69     choices.append("forecast")
     70     choices.append("unclear")
     71     var choice = parse_choice_answer(
     72         "supply_status",
     73         loads(
     74             '{"type":"choice","choice":"offered","probabilities":{"offered":1.0,"forecast":0.0,"unclear":0.0},"confidence":1.0}'
     75         ),
     76         choices,
     77     )
     78     assert_equal(choice.choice, "offered")
     79 
     80     with assert_raises():
     81         _ = parse_noul_answer("q", loads('{"type":"noul","noul":1.5}'))
     82     with assert_raises():
     83         _ = parse_choice_answer(
     84             "q",
     85             loads('{"type":"choice","choice":"bogus","confidence":1.0}'),
     86             choices,
     87         )
     88     with assert_raises():
     89         _ = parse_choice_answer(
     90             "q",
     91             loads(
     92                 '{"type":"choice","choice":"offered","probabilities":{"offered":0.5,"forecast":0.5,"unclear":0.5},"confidence":1.0}'
     93             ),
     94             choices,
     95         )
     96     with assert_raises():
     97         _ = parse_choice_answer(
     98             "q", loads('{"type":"noul","noul":0.5}'), choices
     99         )
    100 
    101 
    102 from hyf_provider.jev_answers import parse_score_answer
    103 
    104 
    105 def test_parse_score_answer_validates_rubric_and_levels() raises:
    106     var rubric = List[String]()
    107     rubric.append("unsuitable")
    108     rubric.append("limited")
    109     rubric.append("suitable")
    110     var answer = parse_score_answer(
    111         "culinary_fit",
    112         loads(
    113             '{"type":"score","score":2,"legend":{"0":"unsuitable","1":"limited","2":"suitable"},"probabilities":{"0":0.0,"1":0.0,"2":1.0},"confidence":1.0}'
    114         ),
    115         rubric,
    116     )
    117     assert_equal(answer.score, 2)
    118     with assert_raises():
    119         _ = parse_score_answer(
    120             "q",
    121             loads(
    122                 '{"type":"score","score":5,"legend":{"0":"a","1":"b","2":"c"},"confidence":1.0}'
    123             ),
    124             rubric,
    125         )
    126     with assert_raises():
    127         _ = parse_score_answer(
    128             "q",
    129             loads(
    130                 '{"type":"score","score":1,"legend":{"0":"a"},"confidence":1.0}'
    131             ),
    132             rubric,
    133         )
    134 
    135 
    136 from hyf_provider.jev_answers import parse_jev_response
    137 
    138 
    139 def test_parse_jev_response_validates_answer_set() raises:
    140     var body = loads(
    141         '{"model":"jev-1.13.0","answers":{'
    142         '"supply_status":{"type":"choice","choice":"offered","probabilities":{"offered":1.0,"forecast":0.0,"unclear":0.0},"confidence":1.0},'
    143         '"seconds_ok":{"type":"noul","noul":0.9},'
    144         '"culinary_fit":{"type":"score","score":2,"legend":{"0":"u","1":"l","2":"s"},"probabilities":{"0":0.0,"1":0.0,"2":1.0},"confidence":1.0}},'
    145         '"usage":{"input_tokens":10,"output_tokens":5}}'
    146     )
    147     var answers = parse_jev_response(body, _bundle())
    148     assert_equal(len(answers), 3)
    149 
    150     var extra = loads(
    151         '{"model":"jev-1.13.0","answers":{'
    152         '"supply_status":{"type":"choice","choice":"offered","probabilities":{"offered":1.0,"forecast":0.0,"unclear":0.0},"confidence":1.0},'
    153         '"seconds_ok":{"type":"noul","noul":0.9},'
    154         '"culinary_fit":{"type":"score","score":2,"legend":{"0":"u","1":"l","2":"s"},"probabilities":{"0":0.0,"1":0.0,"2":1.0},"confidence":1.0},'
    155         '"extra":{"type":"noul","noul":0.5}},'
    156         '"usage":{"input_tokens":10,"output_tokens":5}}'
    157     )
    158     with assert_raises():
    159         _ = parse_jev_response(extra, _bundle())
    160 
    161     var mismatch = loads(
    162         '{"model":"jev-other","answers":{"supply_status":{"type":"choice","choice":"offered","confidence":1.0},"seconds_ok":{"type":"noul","noul":0.9},"culinary_fit":{"type":"score","score":2,"confidence":1.0}}}'
    163     )
    164     with assert_raises():
    165         _ = parse_jev_response(mismatch, _bundle())
    166 
    167     var missing = loads(
    168         '{"model":"jev-1.13.0","answers":{"supply_status":{"type":"choice","choice":"offered","confidence":1.0}}}'
    169     )
    170     with assert_raises():
    171         _ = parse_jev_response(missing, _bundle())
    172 
    173 
    174 def test_jev_envelope_boundary_characterizes_duplicate_and_null_fields() raises:
    175     # H009: pin current JEV envelope boundary behavior. A duplicated model or
    176     # answer key is accepted first-wins; a null answer object is rejected.
    177     var duplicate_model = loads(
    178         '{"model":"jev-1.13.0","model":"jev-other","answers":{'
    179         '"supply_status":{"type":"choice","choice":"offered","probabilities":'
    180         '{"offered":1.0,"forecast":0.0,"unclear":0.0},"confidence":1.0},'
    181         '"seconds_ok":{"type":"noul","noul":0.9},'
    182         '"culinary_fit":{"type":"score","score":2,"legend":{"0":"u","1":"l",'
    183         '"2":"s"},"probabilities":{"0":0.0,"1":0.0,"2":1.0},"confidence":1.0}},'
    184         '"usage":{"input_tokens":10,"output_tokens":5}}'
    185     )
    186     var answers = parse_jev_response(duplicate_model, _bundle())
    187     assert_equal(len(answers), 3)
    188     # A duplicated answer key is rejected at this boundary (unlike the raw JSON
    189     # layer, which accepts duplicates): the answer set is not the declared one.
    190     var duplicate_answer = loads(
    191         '{"model":"jev-1.13.0","answers":{'
    192         '"supply_status":{"type":"choice","choice":"offered","probabilities":'
    193         '{"offered":1.0,"forecast":0.0,"unclear":0.0},"confidence":1.0},'
    194         '"seconds_ok":{"type":"noul","noul":0.9},'
    195         '"culinary_fit":{"type":"score","score":2,"legend":{"0":"u","1":"l",'
    196         '"2":"s"},"confidence":1.0},'
    197         '"supply_status":{"type":"noul","noul":0.1}}}'
    198     )
    199     var duplicate_message = ""
    200     try:
    201         _ = parse_jev_response(duplicate_answer, _bundle())
    202     except e:
    203         duplicate_message = String(e)
    204     assert_true(duplicate_message.find("provider_answer_extra") >= 0)
    205     var null_answer = loads(
    206         '{"model":"jev-1.13.0","answers":{"supply_status":null,'
    207         '"seconds_ok":{"type":"noul","noul":0.9},'
    208         '"culinary_fit":{"type":"score","score":2,"legend":{"0":"u","1":"l",'
    209         '"2":"s"},"confidence":1.0}}}'
    210     )
    211     with assert_raises():
    212         _ = parse_jev_response(null_answer, _bundle())
    213 
    214 
    215 from hyf_provider.jev_failures import map_jev_failure
    216 
    217 
    218 def test_jev_failure_mapping_permanent_vs_transient() raises:
    219     assert_equal(map_jev_failure("authentication").family, "provider_auth")
    220     assert_true(not map_jev_failure("authentication").retryable)
    221     assert_equal(map_jev_failure("validation").family, "provider_validation")
    222     assert_true(not map_jev_failure("validation").retryable)
    223     assert_equal(map_jev_failure("rate_limit").family, "provider_capacity")
    224     assert_true(map_jev_failure("rate_limit").retryable)
    225     assert_true(map_jev_failure("overloaded").retryable)
    226     assert_true(map_jev_failure("internal_server").retryable)
    227     assert_equal(
    228         map_jev_failure("response_validation").family,
    229         "provider_response_contract",
    230     )
    231     assert_true(not map_jev_failure("response_validation").retryable)
    232     with assert_raises():
    233         _ = map_jev_failure("mystery")
    234 
    235 
    236 from hyf_provider.jev_projection import (
    237     answer_by_id,
    238     project_choice,
    239     provider_cannot_supply_trusted_identity,
    240 )
    241 
    242 
    243 def test_provider_response_projection() raises:
    244     var body = loads(
    245         '{"model":"jev-1.13.0","answers":{'
    246         '"supply_status":{"type":"choice","choice":"offered","probabilities":{"offered":1.0,"forecast":0.0,"unclear":0.0},"confidence":1.0},'
    247         '"seconds_ok":{"type":"noul","noul":0.9},'
    248         '"culinary_fit":{"type":"score","score":2,"legend":{"0":"u","1":"l","2":"s"},"probabilities":{"0":0.0,"1":0.0,"2":1.0},"confidence":1.0}}}'
    249     )
    250     var answers = parse_jev_response(body, _bundle())
    251     assert_equal(project_choice(answers, "supply_status"), "offered")
    252     assert_equal(answer_by_id(answers, "seconds_ok").noul, 0.9)
    253     assert_true(provider_cannot_supply_trusted_identity())
    254     with assert_raises():
    255         _ = answer_by_id(answers, "nonexistent")
    256 
    257 
    258 from hyf_provider.jev_state import minimal_state, state_includes_full_repository
    259 
    260 
    261 def test_data_minimized_state_projection() raises:
    262     var state = minimal_state(
    263         "Roma tomatoes available now",
    264         "Roma tomatoes",
    265         "Tomatoes for sauce; seconds permitted",
    266     )
    267     assert_true(state.find("farm_update:") >= 0)
    268     assert_true(state.find("focus_product:") >= 0)
    269     assert_true(state.find("buyer_request:") >= 0)
    270     var only_source = minimal_state("Basil sold out", "", "")
    271     assert_equal(only_source, "farm_update: Basil sold out")
    272     assert_true(not state_includes_full_repository())
    273     var huge = String()
    274     for _ in range(2000):
    275         huge += "xxxxxxxxxx"
    276     with assert_raises():
    277         _ = minimal_state(huge, "", "")
    278 
    279 
    280 from hyf_provider.jev_retry import retry_delay_ms, retry_policy, should_retry
    281 
    282 
    283 def test_retry_classification_and_bounded_scheduling() raises:
    284     var policy = retry_policy(3, 100, 500, 1000)
    285     assert_equal(retry_delay_ms(policy, 0), 100)
    286     assert_equal(retry_delay_ms(policy, 1), 200)
    287     assert_equal(retry_delay_ms(policy, 2), 400)
    288     assert_equal(retry_delay_ms(policy, 5), 500)
    289     assert_true(should_retry(policy, 0, 0, True))
    290     assert_true(not should_retry(policy, 0, 0, False))
    291     assert_true(not should_retry(policy, 3, 0, True))
    292     assert_true(not should_retry(policy, 0, 950, True))
    293     with assert_raises():
    294         _ = retry_policy(1, 0, 10, 100)
    295 
    296 
    297 from hyf_provider.jev_circuit import (
    298     circuit_allows,
    299     circuit_record_failure,
    300     circuit_record_success,
    301     circuit_state,
    302     process_liveness_is_provider_readiness,
    303 )
    304 
    305 
    306 def test_circuit_opens_and_recovers() raises:
    307     var state = circuit_state(2)
    308     assert_true(circuit_allows(state))
    309     state = circuit_record_failure(state)
    310     assert_true(circuit_allows(state))
    311     state = circuit_record_failure(state)
    312     assert_true(not circuit_allows(state))
    313     state = circuit_record_success(state)
    314     assert_true(circuit_allows(state))
    315     assert_true(not process_liveness_is_provider_readiness())
    316 
    317 
    318 from flare.http import HttpClient
    319 from parent_lifecycle import CleanupGuard
    320 from jev_provider_helper import (
    321     reserve_jev_port,
    322     spawn_jev_stub_auto,
    323 )
    324 
    325 
    326 def test_local_provider_server_serves_scripted_jev() raises:
    327     var guard_1 = CleanupGuard()
    328     with spawn_jev_stub_auto("ok", 1, guard_1) as started:
    329         var port = started.port
    330         var url = "http://127.0.0.1:" + String(port) + "/v1/systemone"
    331         with HttpClient(timeout_ms=5000, max_redirects=0) as client:
    332             var response = client.post(
    333                 url, '{"model":"jev-1.13.0","state":"s","questions":{}}'
    334             )
    335             assert_true(response.ok())
    336             var body = response.json()
    337             assert_equal(body["model"].string_value(), "jev-1.13.0")
    338         started.stub.wait()
    339 
    340     guard_1.assert_clean()
    341 
    342 
    343 def test_local_provider_server_scripts_transport_failures() raises:
    344     var guard_2 = CleanupGuard()
    345     with spawn_jev_stub_auto("rate_limit", 1, guard_2) as rate_port_started:
    346         var rate_port = rate_port_started.port
    347         with HttpClient(timeout_ms=5000, max_redirects=0) as client:
    348             var response = client.post(
    349                 "http://127.0.0.1:" + String(rate_port) + "/v1/systemone", "{}"
    350             )
    351             assert_equal(response.status, 429)
    352         rate_port_started.stub.wait()
    353 
    354         var guard_3 = CleanupGuard()
    355         with spawn_jev_stub_auto(
    356             "malformed_json", 1, guard_3
    357         ) as malformed_port_started:
    358             var malformed_port = malformed_port_started.port
    359             with HttpClient(timeout_ms=5000, max_redirects=0) as client:
    360                 var response = client.post(
    361                     "http://127.0.0.1:"
    362                     + String(malformed_port)
    363                     + "/v1/systemone",
    364                     "{}",
    365                 )
    366                 assert_equal(response.text(), "not json")
    367             malformed_port_started.stub.wait()
    368 
    369             var guard_4 = CleanupGuard()
    370             with spawn_jev_stub_auto(
    371                 "server_error", 1, guard_4
    372             ) as err_port_started:
    373                 var err_port = err_port_started.port
    374                 with HttpClient(timeout_ms=5000, max_redirects=0) as client:
    375                     var response = client.post(
    376                         "http://127.0.0.1:"
    377                         + String(err_port)
    378                         + "/v1/systemone",
    379                         "{}",
    380                     )
    381                     assert_equal(response.status, 500)
    382                 err_port_started.stub.wait()
    383 
    384             guard_4.assert_clean()
    385         guard_3.assert_clean()
    386     guard_2.assert_clean()
    387 
    388 
    389 from hyf_provider.jev_client import post_jev_systemone, validate_jev_base_url
    390 from json import loads as _loads
    391 
    392 
    393 def test_jev_endpoint_policy_and_loopback_client() raises:
    394     assert_equal(
    395         validate_jev_base_url("https://api.typesafe.ai/"),
    396         "https://api.typesafe.ai",
    397     )
    398     assert_equal(
    399         validate_jev_base_url("http://127.0.0.1:8000"),
    400         "http://127.0.0.1:8000",
    401     )
    402     with assert_raises():
    403         _ = validate_jev_base_url("http://api.typesafe.ai")
    404     with assert_raises():
    405         _ = validate_jev_base_url("http://127.0.0.1.evil.example")
    406     with assert_raises():
    407         _ = validate_jev_base_url("https://user:pass@api.typesafe.ai")
    408     with assert_raises():
    409         _ = validate_jev_base_url("ftp://api.typesafe.ai")
    410 
    411     var guard_5 = CleanupGuard()
    412     with spawn_jev_stub_auto("ok", 1, guard_5) as started:
    413         var port = started.port
    414         var outcome = post_jev_systemone(
    415             "http://127.0.0.1:" + String(port),
    416             _loads('{"model":"jev-1.13.0","state":"s","questions":{}}'),
    417             5000,
    418         )
    419         assert_equal(outcome.status, 200)
    420         assert_true(outcome.body_text.find("jev-1.13.0") >= 0)
    421         started.stub.wait()
    422 
    423     guard_5.assert_clean()
    424 
    425 
    426 from flare.tls import TlsVerify
    427 from flare.tls import TlsConfig
    428 from hyf_provider.jev_client import (
    429     assert_tls_verification_required,
    430     production_tls_config,
    431     redirects_forward_credentials,
    432 )
    433 
    434 
    435 def test_tls_and_redirect_policy() raises:
    436     var config = production_tls_config()
    437     assert_equal(config.verify, TlsVerify.REQUIRED)
    438     assert_tls_verification_required(config)
    439     with assert_raises():
    440         assert_tls_verification_required(TlsConfig.insecure())
    441     assert_true(not redirects_forward_credentials())
    442 
    443     var guard_6 = CleanupGuard()
    444     with spawn_jev_stub_auto("redirect", 1, guard_6) as started:
    445         var port = started.port
    446         with assert_raises():
    447             with HttpClient(timeout_ms=5000, max_redirects=0) as client:
    448                 _ = client.post(
    449                     "http://127.0.0.1:" + String(port) + "/v1/systemone", "{}"
    450                 )
    451         started.stub.wait()
    452 
    453     guard_6.assert_clean()
    454 
    455 
    456 from hyf_provider.jev_client import failure_kind_for_status, retry_decision
    457 
    458 
    459 def test_bounded_retry_and_budget_behavior() raises:
    460     assert_equal(failure_kind_for_status(401), "authentication")
    461     assert_equal(failure_kind_for_status(429), "rate_limit")
    462     assert_equal(failure_kind_for_status(500), "internal_server")
    463     assert_equal(failure_kind_for_status(529), "overloaded")
    464     var policy = retry_policy(2, 50, 200, 400)
    465     assert_true(retry_decision(policy, 0, 0, 429))
    466     assert_true(retry_decision(policy, 0, 0, 500))
    467     assert_true(not retry_decision(policy, 0, 0, 401))
    468     assert_true(not retry_decision(policy, 0, 0, 422))
    469     assert_true(not retry_decision(policy, 2, 0, 429))
    470     assert_true(not retry_decision(policy, 0, 390, 429))
    471     with assert_raises():
    472         _ = retry_decision(policy, 0, 0, 200)
    473 
    474 
    475 def test_transport_cleanup_and_local_cancellation() raises:
    476     var guard_7 = CleanupGuard()
    477     with spawn_jev_stub_auto("ok", 1, guard_7) as started:
    478         var port = started.port
    479         var outcome = post_jev_systemone(
    480             "http://127.0.0.1:" + String(port),
    481             _loads('{"model":"jev-1.13.0","state":"s","questions":{}}'),
    482             5000,
    483         )
    484         assert_equal(outcome.status, 200)
    485         started.stub.wait()
    486 
    487         # A refused connection is a bounded local transport failure (no listener).
    488         var dead_port = reserve_jev_port()
    489         with assert_raises():
    490             _ = post_jev_systemone(
    491                 "http://127.0.0.1:" + String(dead_port),
    492                 _loads('{"model":"jev-1.13.0","state":"s","questions":{}}'),
    493                 150,
    494             )
    495 
    496     guard_7.assert_clean()
    497 
    498 
    499 from flare.net import SocketAddr
    500 from flare.tcp import TcpStream
    501 from jev_provider_helper import (
    502     header_names_json,
    503     require_bearer_for,
    504     spawn_jev_scripted_auto,
    505 )
    506 from strict_fixture import (
    507     ExchangeScript,
    508     exchange_script,
    509     is_peer_close_cause,
    510     write_errno_class,
    511 )
    512 from bounded_call_helper import run_bounded_call
    513 from parent_lifecycle import now_ms
    514 
    515 # H007 BC02: a distinct correlation value per bounded-call invocation.
    516 comptime JEV_CORRELATION_BODY_STALL = 201
    517 comptime JEV_CORRELATION_DELAYED_SUCCESS = 202
    518 # H007 RP01: distinct correlations for the repaired Jev raw byte-accounting
    519 # controls, so the Jev raw caller is executed and not just a shared branch.
    520 comptime JEV_CORRELATION_RAW_COALESCED = 203
    521 comptime JEV_CORRELATION_RAW_TRUNCATED = 204
    522 # H007 RP03: distinct correlations for the Jev write-error controls.
    523 comptime JEV_CORRELATION_SYNTHETIC_DESCRIPTOR = 205
    524 comptime JEV_CORRELATION_REAL_ERRNO = 206
    525 # H007 OB01-OB03: period-14 observation-integrity controls on the Jev path.
    526 comptime JEV_CORRELATION_OB_SPLIT_TERMINATOR = 210
    527 comptime JEV_CORRELATION_OB_SPLIT_BODY = 211
    528 comptime JEV_CORRELATION_OB_SURPLUS = 212
    529 comptime JEV_CORRELATION_OB_NO_LENGTH = 213
    530 # H007 D44/IL01: distinct correlations for the inclusive raw-body-cap boundary
    531 # controls on the Jev caller.
    532 comptime JEV_CORRELATION_OB_CAP_DECLARED_MINUS = 214
    533 comptime JEV_CORRELATION_OB_CAP_DECLARED_EXACT = 215
    534 comptime JEV_CORRELATION_OB_CAP_DECLARED_PLUS = 216
    535 comptime JEV_CORRELATION_OB_CAP_NO_LENGTH_MINUS = 217
    536 comptime JEV_CORRELATION_OB_CAP_NO_LENGTH_EXACT = 218
    537 comptime JEV_CORRELATION_OB_CAP_NO_LENGTH_PLUS = 219
    538 comptime JEV_CORRELATION_OB_CAP_NO_LENGTH_STALL = 220
    539 
    540 
    541 def _raw_jev_request_text(path: String) -> String:
    542     return (
    543         "POST "
    544         + path
    545         + " HTTP/1.1\r\nhost: 127.0.0.1\r\ncontent-length: 2\r\n"
    546         "connection: close\r\n\r\n{}"
    547     )
    548 
    549 
    550 def _raw_jev_send_then_close(port: Int, path: String) raises:
    551     """Owned raw client that closes right after its request (real peer close).
    552     """
    553     var client = TcpStream.connect(SocketAddr.localhost(UInt16(port)))
    554     client.write_all(Span[UInt8, _](_raw_jev_request_text(path).as_bytes()))
    555     client.close()
    556 
    557 
    558 def _raw_jev_send_and_read(port: Int, path: String) raises -> String:
    559     """Owned raw client that sends one scripted request and reads the reply."""
    560     var client = TcpStream.connect(SocketAddr.localhost(UInt16(port)))
    561     client.write_all(Span[UInt8, _](_raw_jev_request_text(path).as_bytes()))
    562     var response = String("")
    563     var buffer = InlineArray[Byte, 1024](fill=0)
    564     while True:
    565         var n = client.read(buffer.unsafe_ptr(), 1024)
    566         if n <= 0:
    567             break
    568         response += String(
    569             unsafe_from_utf8=Span(ptr=buffer.unsafe_ptr(), length=Int(n))
    570         )
    571     client.close()
    572     return response^
    573 
    574 
    575 def test_jev_headers_then_stall_is_bounded() raises:
    576     # H007/TC01-TC02: the Jev client call against a headers-then-stall peer runs
    577     # under the exact-owned parent-bounded mechanism. Characterized current gap:
    578     # the declared timeout does not bound a body-read stall, so the call returns
    579     # only after the stall completes (elapsed >= 1200 ms) instead of failing
    580     # inside the declared 300 ms timeout. No provider client policy is changed.
    581     var guard = CleanupGuard()
    582     var scripts = List[ExchangeScript]()
    583     var script = exchange_script(
    584         "jev_headers_then_stall", "POST", "/v1/systemone", 200, '{"ok":true}'
    585     )
    586     script.stall_after_head_ms = 1200
    587     scripts.append(script^)
    588     with spawn_jev_scripted_auto(scripts^, guard) as started:
    589         var report = run_bounded_call(
    590             "jev", started.port, 300, 5000, guard, JEV_CORRELATION_BODY_STALL
    591         )
    592         assert_true(report.ok())
    593         assert_true(not report.stopped)
    594         assert_true(report.cleanup_proved)
    595         assert_equal(report.status, 200)
    596         assert_true(report.latency_ms < 0)
    597         assert_true(report.elapsed_ms >= 1200)
    598         assert_true(report.elapsed_ms < 5000)
    599         started.stub.wait()
    600     guard.assert_clean()
    601 
    602 
    603 def test_jev_strict_delayed_success_under_bounded_harness() raises:
    604     # TC01/TC02: a delayed response is not permission to swallow errors; with a
    605     # client budget above the delay the strict scripted Jev exchange succeeds
    606     # and the risky call is parent-bounded.
    607     var guard = CleanupGuard()
    608     var scripts = List[ExchangeScript]()
    609     var script = exchange_script(
    610         "jev_delayed_success", "POST", "/v1/systemone", 200, '{"ok":true}'
    611     )
    612     script.delay_ms = 300
    613     scripts.append(script^)
    614     with spawn_jev_scripted_auto(scripts^, guard) as started:
    615         var report = run_bounded_call(
    616             "jev",
    617             started.port,
    618             5000,
    619             5000,
    620             guard,
    621             JEV_CORRELATION_DELAYED_SUCCESS,
    622         )
    623         assert_true(report.ok())
    624         assert_true(not report.stopped)
    625         assert_equal(report.status, 200)
    626         started.stub.wait()
    627         assert_true(started.stub.ok())
    628     guard.assert_clean()
    629 
    630 
    631 def test_jev_raw_head_body_accounts_coalesced_body() raises:
    632     # RP01: the repaired raw observer is executed through the Jev raw caller.
    633     # A body coalesced with the header terminator must be counted exactly.
    634     var guard = CleanupGuard()
    635     var scripts = List[ExchangeScript]()
    636     scripts.append(
    637         exchange_script(
    638             "jev_coalesced_body", "POST", "/v1/systemone", 200, "JEVBODY"
    639         )
    640     )
    641     with spawn_jev_scripted_auto(scripts^, guard) as started:
    642         var report = run_bounded_call(
    643             "raw_jev_head_body",
    644             started.port,
    645             5000,
    646             5000,
    647             guard,
    648             JEV_CORRELATION_RAW_COALESCED,
    649             "/v1/systemone",
    650             "JEVBODY",
    651         )
    652         assert_true(report.ok())
    653         assert_equal(report.status, 200)
    654         assert_equal(report.body_bytes, 7)
    655         assert_equal(report.body_match, "yes")
    656         assert_equal(report.declared_bytes, 7)
    657         assert_equal(report.length_match, "yes")
    658         started.stub.wait()
    659         assert_true(started.stub.ok())
    660     guard.assert_clean()
    661 
    662 
    663 def test_jev_raw_head_body_reports_truncated_length_mismatch() raises:
    664     # RP01: the Jev raw caller reports an explicit truncation truthfully: five
    665     # observed bytes against a declared twenty, with a length mismatch.
    666     var guard = CleanupGuard()
    667     var scripts = List[ExchangeScript]()
    668     var script = exchange_script(
    669         "jev_truncated_body", "POST", "/v1/systemone", 200, ""
    670     )
    671     script.raw_response = (
    672         "HTTP/1.1 200 OK\r\ncontent-type: application/json\r\n"
    673         "content-length: 20\r\nconnection: close\r\n\r\nSHORT"
    674     )
    675     scripts.append(script^)
    676     with spawn_jev_scripted_auto(scripts^, guard) as started:
    677         var report = run_bounded_call(
    678             "raw_jev_head_body",
    679             started.port,
    680             5000,
    681             5000,
    682             guard,
    683             JEV_CORRELATION_RAW_TRUNCATED,
    684             "/v1/systemone",
    685             "SHORT",
    686         )
    687         assert_true(report.completed)
    688         assert_true(report.domain_failure())
    689         assert_equal(report.cause, "raw_body_incomplete")
    690         assert_equal(report.status, 0)
    691         assert_equal(report.body_bytes, 5)
    692         assert_equal(report.body_match, "yes")
    693         assert_equal(report.declared_bytes, 20)
    694         assert_equal(report.length_match, "no")
    695         assert_equal(report.surplus_bytes, 0)
    696         started.stub.wait()
    697         assert_true(started.stub.ok())
    698     guard.assert_clean()
    699 
    700 
    701 def test_jev_scripted_permitted_peer_close_is_declared() raises:
    702     # TC01: the Jev serve path verifies an explicitly declared expected peer
    703     # close (exact bounded cause and phase) and records the observed outcome.
    704     var guard = CleanupGuard()
    705     var scripts = List[ExchangeScript]()
    706     var script = exchange_script(
    707         "jev_permitted_close", "POST", "/v1/systemone", 200, '{"ok":true}'
    708     )
    709     script.stall_after_head_ms = 300
    710     script.expect_peer_close = True
    711     script.expected_close_cause = "broken_pipe"
    712     script.expected_close_phase = "body_stall"
    713     scripts.append(script^)
    714     with spawn_jev_scripted_auto(scripts^, guard) as started:
    715         _raw_jev_send_then_close(started.port, "/v1/systemone")
    716         started.stub.wait()
    717         assert_true(started.stub.ok())
    718         assert_true(started.stub.failure_case().find("_peer_close_") >= 0)
    719         assert_true(started.stub.failure_case().find("_body_stall") >= 0)
    720     guard.assert_clean()
    721 
    722 
    723 def _jev_realerrno_from_reason(reason: String) raises -> Int:
    724     """Raw errno recorded in a bounded Jev write-failure reason, or -1."""
    725     var marker = "realerrno"
    726     var at = reason.find(marker)
    727     if at < 0:
    728         return -1
    729     var digits = String(reason[byte = at + marker.byte_length() :])
    730     var end = digits.find("_")
    731     if end >= 0:
    732         digits = String(digits[byte=0:end])
    733     if digits.byte_length() == 0:
    734         return -1
    735     return Int(digits)
    736 
    737 
    738 def test_jev_scripted_synthetic_invalid_descriptor_is_not_peer_close() raises:
    739     # RP03: the Jev serve path exercises the same narrowly scoped syscall-result
    740     # seam, mapped to the flare write API's EBADF rendering. The invalid
    741     # descriptor is classified, labelled synthetic and rejected even though a
    742     # peer close was declared.
    743     var guard = CleanupGuard()
    744     var scripts = List[ExchangeScript]()
    745     var script = exchange_script(
    746         "jev_synthetic_descriptor", "POST", "/v1/systemone", 200, '{"ok":true}'
    747     )
    748     script.stall_after_head_ms = 200
    749     script.expect_peer_close = True
    750     script.expected_close_cause = "broken_pipe"
    751     script.expected_close_phase = "body_stall"
    752     script.inject_write_errno = Int(ErrNo.EBADF.value)
    753     scripts.append(script^)
    754     with spawn_jev_scripted_auto(scripts^, guard) as started:
    755         _ = _raw_jev_send_and_read(started.port, "/v1/systemone")
    756         started.stub.reap()
    757         assert_true(not started.stub.ok())
    758         assert_true(
    759             started.stub.reason().find(
    760                 "unexpected_write_invalid_descriptor_body_stall_synthdecl"
    761             )
    762             >= 0
    763         )
    764     guard.assert_clean()
    765 
    766 
    767 def test_jev_scripted_real_peer_close_records_raw_errno() raises:
    768     # RP03: a real Jev peer close makes the fixture's real send(2) fail; the
    769     # recorded raw errno's class must equal the observed classification.
    770     var guard = CleanupGuard()
    771     var scripts = List[ExchangeScript]()
    772     var script = exchange_script(
    773         "jev_real_errno", "POST", "/v1/systemone", 200, '{"ok":true}'
    774     )
    775     script.stall_after_head_ms = 300
    776     script.expect_peer_close = True
    777     script.expected_close_cause = "broken_pipe"
    778     script.expected_close_phase = "body_stall"
    779     scripts.append(script^)
    780     with spawn_jev_scripted_auto(scripts^, guard) as started:
    781         _raw_jev_send_then_close(started.port, "/v1/systemone")
    782         started.stub.wait()
    783         assert_true(started.stub.ok())
    784         var token = started.stub.failure_case()
    785         assert_true(token.find("realerrno") >= 0)
    786         var errno = _jev_realerrno_from_reason(token)
    787         assert_true(errno > 0)
    788         var observed = write_errno_class(errno)
    789         assert_true(observed == "broken_pipe" or observed == "peer_reset")
    790         assert_true(token.find("_peer_close_" + observed + "_") >= 0)
    791     guard.assert_clean()
    792 
    793 
    794 def test_jev_scripted_unexpected_peer_close_fails() raises:
    795     # TC01: an undeclared peer close through the Jev serve path fails with a
    796     # bounded, cause-specific reason instead of being swallowed.
    797     var guard = CleanupGuard()
    798     var scripts = List[ExchangeScript]()
    799     var script = exchange_script(
    800         "jev_unexpected_close", "POST", "/v1/systemone", 200, '{"ok":true}'
    801     )
    802     script.stall_after_head_ms = 300
    803     scripts.append(script^)
    804     with spawn_jev_scripted_auto(scripts^, guard) as started:
    805         _raw_jev_send_then_close(started.port, "/v1/systemone")
    806         started.stub.reap()
    807         assert_true(not started.stub.ok())
    808         assert_equal(started.stub.phase(), "peer_close")
    809         assert_true(started.stub.reason().find("unexpected_write_") >= 0)
    810         assert_true(started.stub.reason().find("_body_stall") >= 0)
    811     guard.assert_clean()
    812 
    813 
    814 def test_jev_scripted_missing_expected_close_fails() raises:
    815     # EC01: the Jev serve path must reject a declared expected close that never
    816     # happened, even though the response write succeeded.
    817     var guard = CleanupGuard()
    818     var scripts = List[ExchangeScript]()
    819     var script = exchange_script(
    820         "jev_missing_expected_close",
    821         "POST",
    822         "/v1/systemone",
    823         200,
    824         '{"ok":true}',
    825     )
    826     script.expect_peer_close = True
    827     script.expected_close_cause = "broken_pipe"
    828     script.expected_close_phase = "delayed_write"
    829     scripts.append(script^)
    830     with spawn_jev_scripted_auto(scripts^, guard) as started:
    831         _ = _raw_jev_send_and_read(started.port, "/v1/systemone")
    832         started.stub.reap()
    833         assert_true(not started.stub.ok())
    834         assert_equal(started.stub.phase(), "peer_close")
    835         assert_true(
    836             started.stub.reason().find("missing_expected_close_delayed_write")
    837             >= 0
    838         )
    839     guard.assert_clean()
    840 
    841 
    842 def test_jev_permitted_close_continues_script_sequence() raises:
    843     # EC01: on the Jev serve path a permitted peer close consumes that exchange
    844     # only; the remaining scripted exchange is still served and counted.
    845     var guard = CleanupGuard()
    846     var scripts = List[ExchangeScript]()
    847     var closing = exchange_script(
    848         "jev_permitted_then_next", "POST", "/v1/systemone", 200, '{"ok":true}'
    849     )
    850     closing.stall_after_head_ms = 300
    851     closing.expect_peer_close = True
    852     closing.expected_close_cause = "broken_pipe"
    853     closing.expected_close_phase = "body_stall"
    854     scripts.append(closing^)
    855     scripts.append(
    856         exchange_script(
    857             "jev_after_permitted_close",
    858             "POST",
    859             "/v1/systemone",
    860             200,
    861             '{"ok":true}',
    862         )
    863     )
    864     with spawn_jev_scripted_auto(scripts^, guard) as started:
    865         _raw_jev_send_then_close(started.port, "/v1/systemone")
    866         var second = _raw_jev_send_and_read(started.port, "/v1/systemone")
    867         started.stub.wait()
    868         assert_true(started.stub.ok())
    869         assert_equal(started.stub.request_count(), 2)
    870         assert_equal(started.stub.connection_count(), 2)
    871         assert_true(started.stub.failure_case().find("_peer_close_") >= 0)
    872         assert_true(second.find("ok") >= 0)
    873     guard.assert_clean()
    874 
    875 
    876 def test_jev_scripted_injected_write_error_fails() raises:
    877     # TC01: an unrelated injected handler error (here an invalid descriptor)
    878     # must fail the Jev serve path even when a peer close was declared.
    879     var guard = CleanupGuard()
    880     var scripts = List[ExchangeScript]()
    881     var script = exchange_script(
    882         "jev_injected_error", "POST", "/v1/systemone", 200, '{"ok":true}'
    883     )
    884     script.stall_after_head_ms = 200
    885     script.expect_peer_close = True
    886     script.expected_close_cause = "broken_pipe"
    887     script.expected_close_phase = "body_stall"
    888     script.inject_write_error = "Bad file descriptor"
    889     scripts.append(script^)
    890     with spawn_jev_scripted_auto(scripts^, guard) as started:
    891         _ = _raw_jev_exchange(
    892             started.port, _raw_jev_request_text("/v1/systemone")
    893         )
    894         started.stub.reap()
    895         assert_true(not started.stub.ok())
    896         assert_equal(started.stub.phase(), "peer_close")
    897         assert_true(
    898             started.stub.reason().find(
    899                 "unexpected_write_unrelated_error_body_stall"
    900             )
    901             >= 0
    902         )
    903     guard.assert_clean()
    904 
    905 
    906 def _raw_jev_exchange(port: Int, raw: String) raises -> String:
    907     var client = TcpStream.connect(SocketAddr.localhost(UInt16(port)))
    908     client.write_all(Span[UInt8, _](raw.as_bytes()))
    909     var response = String("")
    910     var buffer = InlineArray[Byte, 4096](fill=0)
    911     while True:
    912         var n = client.read(buffer.unsafe_ptr(), 4096)
    913         if n <= 0:
    914             break
    915         response += String(
    916             unsafe_from_utf8=Span(ptr=buffer.unsafe_ptr(), length=Int(n))
    917         )
    918     client.close()
    919     return response^
    920 
    921 
    922 def test_jev_fixture_captures_headers_without_leaking_a_secret() raises:
    923     # H006: the loopback Jev fixture captures request headers and reports only
    924     # the captured *names*, so characterization never needs a real credential.
    925     assert_equal(
    926         header_names_json(
    927             "host: h\r\nx-sentinel: v\r\nauthorization: Bearer t"
    928         ),
    929         '["host","x-sentinel","authorization"]',
    930     )
    931     var guard = CleanupGuard()
    932     with spawn_jev_stub_auto("echo_headers", 1, guard) as started:
    933         var response = _raw_jev_exchange(
    934             started.port,
    935             (
    936                 "POST /v1/systemone HTTP/1.1\r\nhost: 127.0.0.1\r\n"
    937                 "x-sentinel: value\r\nauthorization: Bearer"
    938                 " hyf-sentinel-token\r\ncontent-length: 2\r\n"
    939                 "connection: close\r\n\r\n{}"
    940             ),
    941         )
    942         assert_true(response.find('"x-sentinel"') >= 0)
    943         assert_true(response.find('"authorization"') >= 0)
    944         # Redaction baseline: names only, never the credential value.
    945         assert_true(response.find("hyf-sentinel-token") < 0)
    946         started.stub.wait()
    947     guard.assert_clean()
    948 
    949 
    950 def test_jev_provider_wiring_sends_no_authorization_today() raises:
    951     # H006: characterize the current absence. The Jev client reaches the
    952     # intended origin today without an Authorization header; this test is green
    953     # by design and documents exactly what the later implementation step flips.
    954     var guard = CleanupGuard()
    955     with spawn_jev_stub_auto("echo_headers", 1, guard) as started:
    956         var outcome = post_jev_systemone(
    957             "http://127.0.0.1:" + String(started.port),
    958             _loads('{"model":"jev-1.13.0","state":"s","questions":{}}'),
    959             5000,
    960         )
    961         assert_equal(outcome.status, 200)
    962         assert_true(outcome.body_text.find('"captured_headers"') >= 0)
    963         # Current gap: no credential header is sent or captured.
    964         assert_true(outcome.body_text.find('"authorization"') < 0)
    965         assert_true(outcome.body_text.find('"x-sentinel"') < 0)
    966         started.stub.wait()
    967     guard.assert_clean()
    968 
    969 
    970 def test_jev_target_requires_bearer_header_characterization() raises:
    971     # H006: the target behavior for the intended origin is that a Bearer header
    972     # is required. Turning this on for the real wiring is the later step's
    973     # change; the sentinel value is the only credential used here.
    974     var guard = CleanupGuard()
    975     var scripts = List[ExchangeScript]()
    976     var script = exchange_script(
    977         "target_auth", "POST", "/v1/systemone", 200, '{"ok":true}'
    978     )
    979     script.require_bearer = True
    980     scripts.append(script^)
    981     with spawn_jev_scripted_auto(scripts^, guard) as started:
    982         # The intended origin refuses the exchange before answering: the
    983         # fixture records the exact rejection reason instead of returning 200.
    984         _ = _raw_jev_exchange(
    985             started.port,
    986             (
    987                 "POST /v1/systemone HTTP/1.1\r\nhost: 127.0.0.1\r\n"
    988                 "content-length: 2\r\nconnection: close\r\n\r\n{}"
    989             ),
    990         )
    991         started.stub.reap()
    992         assert_equal(started.stub.phase(), "exchange")
    993         assert_equal(started.stub.reason(), "auth_missing")
    994     guard.assert_clean()
    995 
    996     var accepted_guard = CleanupGuard()
    997     var accepted_scripts = List[ExchangeScript]()
    998     var accepted_script = exchange_script(
    999         "target_auth_ok", "POST", "/v1/systemone", 200, '{"ok":true}'
   1000     )
   1001     accepted_script.require_bearer = True
   1002     accepted_scripts.append(accepted_script^)
   1003     with spawn_jev_scripted_auto(
   1004         accepted_scripts^, accepted_guard
   1005     ) as ok_started:
   1006         var accepted = _raw_jev_exchange(
   1007             ok_started.port,
   1008             (
   1009                 "POST /v1/systemone HTTP/1.1\r\nhost: 127.0.0.1\r\n"
   1010                 "authorization: Bearer hyf-sentinel-token\r\n"
   1011                 "content-length: 2\r\nconnection: close\r\n\r\n{}"
   1012             ),
   1013         )
   1014         assert_true(accepted.find("200") >= 0)
   1015         ok_started.stub.wait()
   1016     accepted_guard.assert_clean()
   1017 
   1018 
   1019 def test_jev_require_bearer_target_is_characterized_off() raises:
   1020     # H006: the fixture's convenience modes still report no Bearer requirement,
   1021     # which is the characterization surface the later step flips.
   1022     assert_true(not require_bearer_for("ok"))
   1023     assert_true(not require_bearer_for("echo_headers"))
   1024 
   1025 
   1026 # ── H008 exact wire attempt counts ──────────────────────────────────────────
   1027 
   1028 
   1029 def test_retry_policy_units_are_bounded() raises:
   1030     # H008: pin the existing HYF retry-policy unit behavior before any client
   1031     # change can introduce a hidden Flare retry.
   1032     var policy = retry_policy(2, 100, 500, 1000)
   1033     assert_equal(retry_delay_ms(policy, 0), 100)
   1034     assert_equal(retry_delay_ms(policy, 1), 200)
   1035     assert_equal(retry_delay_ms(policy, 2), 400)
   1036     assert_equal(retry_delay_ms(policy, 3), 500)
   1037     assert_equal(retry_delay_ms(policy, 9), 500)
   1038     assert_true(should_retry(policy, 0, 0, True))
   1039     assert_true(not should_retry(policy, 0, 0, False))
   1040     assert_true(not should_retry(policy, 2, 0, True))
   1041     assert_true(not should_retry(policy, 0, 900, True))
   1042     assert_true(should_retry(policy, 0, 899, True))
   1043     with assert_raises():
   1044         _ = retry_policy(-1, 100, 200, 1000)
   1045     with assert_raises():
   1046         _ = retry_policy(1, 0, 200, 1000)
   1047     with assert_raises():
   1048         _ = retry_policy(1, 300, 200, 1000)
   1049     with assert_raises():
   1050         _ = retry_policy(1, 100, 200, 0)
   1051 
   1052 
   1053 def test_jev_wire_attempt_counts_for_retryable_then_success() raises:
   1054     # H008: a retryable status does not trigger a hidden retry. Each explicit
   1055     # call makes exactly one counted wire attempt, and applying the retry
   1056     # decision produces the next counted attempt.
   1057     var guard = CleanupGuard()
   1058     var scripts = List[ExchangeScript]()
   1059     scripts.append(
   1060         exchange_script(
   1061             "retryable_500", "POST", "/v1/systemone", 500, '{"error":"busy"}'
   1062         )
   1063     )
   1064     scripts.append(
   1065         exchange_script(
   1066             "retry_success", "POST", "/v1/systemone", 200, '{"ok":true}'
   1067         )
   1068     )
   1069     with spawn_jev_scripted_auto(scripts^, guard) as started:
   1070         var payload = _loads(
   1071             '{"model":"jev-1.13.0","state":"s","questions":{}}'
   1072         )
   1073         var url = "http://127.0.0.1:" + String(started.port)
   1074         var first = post_jev_systemone(url, payload, 3000)
   1075         assert_equal(first.status, 500)
   1076         var policy = retry_policy(1, 50, 200, 5000)
   1077         assert_true(retry_decision(policy, 0, 0, 500))
   1078         var second = post_jev_systemone(url, payload, 3000)
   1079         assert_equal(second.status, 200)
   1080         started.stub.wait()
   1081         assert_true(started.stub.ok())
   1082         assert_equal(started.stub.request_count(), 2)
   1083         assert_equal(started.stub.connection_count(), 2)
   1084     guard.assert_clean()
   1085 
   1086 
   1087 def test_jev_wire_attempt_counts_for_non_retryable_failure() raises:
   1088     # H008: a non-retryable status is one wire attempt and the decision is
   1089     # false, so no later migration may silently retry it.
   1090     var guard = CleanupGuard()
   1091     var scripts = List[ExchangeScript]()
   1092     scripts.append(
   1093         exchange_script(
   1094             "auth_401", "POST", "/v1/systemone", 401, '{"error":"denied"}'
   1095         )
   1096     )
   1097     with spawn_jev_scripted_auto(scripts^, guard) as started:
   1098         var payload = _loads(
   1099             '{"model":"jev-1.13.0","state":"s","questions":{}}'
   1100         )
   1101         var outcome = post_jev_systemone(
   1102             "http://127.0.0.1:" + String(started.port), payload, 3000
   1103         )
   1104         assert_equal(outcome.status, 401)
   1105         var policy = retry_policy(2, 50, 200, 5000)
   1106         assert_true(not retry_decision(policy, 0, 0, 401))
   1107         started.stub.wait()
   1108         assert_true(started.stub.ok())
   1109         assert_equal(started.stub.request_count(), 1)
   1110         assert_equal(started.stub.connection_count(), 1)
   1111     guard.assert_clean()
   1112 
   1113 
   1114 # OB02: the Jev raw path must execute the same exact framing/cap/surplus and
   1115 # actual incremental fragmentation controls, not only a dormant shared branch.
   1116 
   1117 
   1118 def test_jev_raw_head_body_split_header_terminator_is_preserved() raises:
   1119     var scripts = List[ExchangeScript]()
   1120     scripts.append(
   1121         exchange_script(
   1122             "jev_split_terminator", "POST", "/v1/systemone", 200, "JEVBODY"
   1123         )
   1124     )
   1125     var plan = List[Int]()
   1126     plan.append(1)
   1127     var guard = CleanupGuard()
   1128     with spawn_jev_scripted_auto(scripts^, guard) as started:
   1129         var report = run_bounded_call(
   1130             "raw_jev_head_body",
   1131             started.port,
   1132             5000,
   1133             5000,
   1134             guard,
   1135             JEV_CORRELATION_OB_SPLIT_TERMINATOR,
   1136             "/v1/systemone",
   1137             "JEVBODY",
   1138             raw_chunk_plan=plan,
   1139         )
   1140         assert_true(report.ok())
   1141         assert_equal(report.status, 200)
   1142         assert_equal(report.body_bytes, 7)
   1143         assert_equal(report.body_match, "yes")
   1144         assert_equal(report.declared_bytes, 7)
   1145         assert_equal(report.length_match, "yes")
   1146         assert_equal(report.surplus_bytes, 0)
   1147         started.stub.wait()
   1148         assert_true(started.stub.ok())
   1149     guard.assert_clean()
   1150 
   1151 
   1152 def test_jev_raw_head_body_split_multibyte_body_is_preserved() raises:
   1153     var scripts = List[ExchangeScript]()
   1154     scripts.append(
   1155         exchange_script(
   1156             "jev_split_multibyte",
   1157             "POST",
   1158             "/v1/systemone",
   1159             200,
   1160             '{"mark":"x☃y"}',
   1161         )
   1162     )
   1163     var plan = List[Int]()
   1164     plan.append(1)
   1165     var guard = CleanupGuard()
   1166     with spawn_jev_scripted_auto(scripts^, guard) as started:
   1167         var report = run_bounded_call(
   1168             "raw_jev_head_body",
   1169             started.port,
   1170             5000,
   1171             5000,
   1172             guard,
   1173             JEV_CORRELATION_OB_SPLIT_BODY,
   1174             "/v1/systemone",
   1175             "x☃y",
   1176             raw_chunk_plan=plan,
   1177         )
   1178         assert_true(report.ok())
   1179         assert_equal(report.status, 200)
   1180         assert_equal(report.body_bytes, '{"mark":"x☃y"}'.byte_length())
   1181         assert_equal(report.body_match, "yes")
   1182         assert_equal(report.length_match, "yes")
   1183         started.stub.wait()
   1184         assert_true(started.stub.ok())
   1185     guard.assert_clean()
   1186 
   1187 
   1188 def test_jev_raw_head_body_accounts_buffered_surplus() raises:
   1189     var scripts = List[ExchangeScript]()
   1190     var script = exchange_script(
   1191         "jev_buffered_surplus", "POST", "/v1/systemone", 200, ""
   1192     )
   1193     script.raw_response = (
   1194         "HTTP/1.1 200 OK\r\ncontent-length: 3\r\nconnection: close\r\n\r\nabcde"
   1195     )
   1196     scripts.append(script^)
   1197     var guard = CleanupGuard()
   1198     with spawn_jev_scripted_auto(scripts^, guard) as started:
   1199         var report = run_bounded_call(
   1200             "raw_jev_head_body",
   1201             started.port,
   1202             5000,
   1203             5000,
   1204             guard,
   1205             JEV_CORRELATION_OB_SURPLUS,
   1206             "/v1/systemone",
   1207             "abc",
   1208         )
   1209         assert_true(report.ok())
   1210         assert_equal(report.status, 200)
   1211         assert_equal(report.body_bytes, 5)
   1212         assert_equal(report.declared_bytes, 3)
   1213         assert_equal(report.length_match, "no")
   1214         assert_equal(report.surplus_bytes, 2)
   1215         started.stub.wait()
   1216         assert_true(started.stub.ok())
   1217     guard.assert_clean()
   1218 
   1219 
   1220 def test_jev_raw_head_body_no_length_completes_at_eof() raises:
   1221     var scripts = List[ExchangeScript]()
   1222     var script = exchange_script(
   1223         "jev_no_length", "POST", "/v1/systemone", 200, ""
   1224     )
   1225     script.raw_response = (
   1226         "HTTP/1.1 200 OK\r\nconnection: close\r\n\r\nNOLENGTHBODY"
   1227     )
   1228     scripts.append(script^)
   1229     var guard = CleanupGuard()
   1230     with spawn_jev_scripted_auto(scripts^, guard) as started:
   1231         var report = run_bounded_call(
   1232             "raw_jev_head_body",
   1233             started.port,
   1234             5000,
   1235             5000,
   1236             guard,
   1237             JEV_CORRELATION_OB_NO_LENGTH,
   1238             "/v1/systemone",
   1239             "NOLENGTHBODY",
   1240         )
   1241         assert_true(report.ok())
   1242         assert_equal(report.status, 200)
   1243         assert_equal(report.body_bytes, "NOLENGTHBODY".byte_length())
   1244         assert_equal(report.body_match, "yes")
   1245         assert_equal(report.declared_bytes, -1)
   1246         assert_equal(report.length_match, "unknown")
   1247         started.stub.wait()
   1248         assert_true(started.stub.ok())
   1249     guard.assert_clean()
   1250 
   1251 
   1252 # D44/IL01: the inclusive 1,048,576-byte raw-body cap on the Jev caller, for
   1253 # both a declared Content-Length and an EOF-delimited (no-length) response.
   1254 
   1255 comptime JEV_RAW_BODY_CAP_TEST = 1048576
   1256 
   1257 
   1258 def _jev_cap_body(count: Int) -> String:
   1259     var out = List[UInt8]()
   1260     var mark_bytes = "a".as_bytes()
   1261     for _ in range(count):
   1262         for index in range(len(mark_bytes)):
   1263             out.append(UInt8(Int(mark_bytes[index])))
   1264     return String(unsafe_from_utf8=Span(ptr=out.unsafe_ptr(), length=len(out)))
   1265 
   1266 
   1267 def test_jev_raw_head_body_declared_cap_minus_one_succeeds() raises:
   1268     var body = _jev_cap_body(JEV_RAW_BODY_CAP_TEST - 1)
   1269     var scripts = List[ExchangeScript]()
   1270     var script = exchange_script(
   1271         "jev_declared_cap_m1", "POST", "/v1/systemone", 200, ""
   1272     )
   1273     script.raw_response = (
   1274         "HTTP/1.1 200 OK\r\ncontent-length: "
   1275         + String(JEV_RAW_BODY_CAP_TEST - 1)
   1276         + "\r\nconnection: close\r\n\r\n"
   1277         + body
   1278     )
   1279     scripts.append(script^)
   1280     var guard = CleanupGuard()
   1281     with spawn_jev_scripted_auto(scripts^, guard) as started:
   1282         var report = run_bounded_call(
   1283             "raw_jev_head_body",
   1284             started.port,
   1285             10000,
   1286             10000,
   1287             guard,
   1288             JEV_CORRELATION_OB_CAP_DECLARED_MINUS,
   1289             "/v1/systemone",
   1290             "aaa",
   1291         )
   1292         assert_true(report.ok())
   1293         assert_equal(report.status, 200)
   1294         assert_equal(report.body_bytes, JEV_RAW_BODY_CAP_TEST - 1)
   1295         assert_equal(report.declared_bytes, JEV_RAW_BODY_CAP_TEST - 1)
   1296         assert_equal(report.length_match, "yes")
   1297         assert_equal(report.surplus_bytes, 0)
   1298         started.stub.wait()
   1299         assert_true(started.stub.ok())
   1300     guard.assert_clean()
   1301 
   1302 
   1303 def test_jev_raw_head_body_declared_cap_exact_succeeds() raises:
   1304     var body = _jev_cap_body(JEV_RAW_BODY_CAP_TEST)
   1305     var scripts = List[ExchangeScript]()
   1306     var script = exchange_script(
   1307         "jev_declared_cap_exact", "POST", "/v1/systemone", 200, ""
   1308     )
   1309     script.raw_response = (
   1310         "HTTP/1.1 200 OK\r\ncontent-length: "
   1311         + String(JEV_RAW_BODY_CAP_TEST)
   1312         + "\r\nconnection: close\r\n\r\n"
   1313         + body
   1314     )
   1315     scripts.append(script^)
   1316     var guard = CleanupGuard()
   1317     with spawn_jev_scripted_auto(scripts^, guard) as started:
   1318         var report = run_bounded_call(
   1319             "raw_jev_head_body",
   1320             started.port,
   1321             10000,
   1322             10000,
   1323             guard,
   1324             JEV_CORRELATION_OB_CAP_DECLARED_EXACT,
   1325             "/v1/systemone",
   1326             "aaa",
   1327         )
   1328         assert_true(report.ok())
   1329         assert_equal(report.status, 200)
   1330         assert_equal(report.body_bytes, JEV_RAW_BODY_CAP_TEST)
   1331         assert_equal(report.declared_bytes, JEV_RAW_BODY_CAP_TEST)
   1332         assert_equal(report.length_match, "yes")
   1333         assert_equal(report.surplus_bytes, 0)
   1334         started.stub.wait()
   1335         assert_true(started.stub.ok())
   1336     guard.assert_clean()
   1337 
   1338 
   1339 def test_jev_raw_head_body_declared_cap_plus_one_is_over_cap() raises:
   1340     var scripts = List[ExchangeScript]()
   1341     var script = exchange_script(
   1342         "jev_declared_cap_p1", "POST", "/v1/systemone", 200, ""
   1343     )
   1344     script.raw_response = (
   1345         "HTTP/1.1 200 OK\r\ncontent-length: "
   1346         + String(JEV_RAW_BODY_CAP_TEST + 1)
   1347         + "\r\nconnection: close\r\n\r\nabc"
   1348     )
   1349     scripts.append(script^)
   1350     var guard = CleanupGuard()
   1351     with spawn_jev_scripted_auto(scripts^, guard) as started:
   1352         var report = run_bounded_call(
   1353             "raw_jev_head_body",
   1354             started.port,
   1355             10000,
   1356             10000,
   1357             guard,
   1358             JEV_CORRELATION_OB_CAP_DECLARED_PLUS,
   1359             "/v1/systemone",
   1360             "abc",
   1361         )
   1362         assert_true(report.completed)
   1363         assert_true(report.domain_failure())
   1364         assert_equal(report.cause, "raw_body_overflow")
   1365         assert_equal(report.reason, "raw_body_overflow")
   1366         started.stub.wait()
   1367         assert_true(started.stub.ok())
   1368     guard.assert_clean()
   1369 
   1370 
   1371 def test_jev_raw_head_body_no_length_cap_minus_one_succeeds() raises:
   1372     var body = _jev_cap_body(JEV_RAW_BODY_CAP_TEST - 1)
   1373     var scripts = List[ExchangeScript]()
   1374     var script = exchange_script(
   1375         "jev_nolen_cap_m1", "POST", "/v1/systemone", 200, ""
   1376     )
   1377     script.raw_response = "HTTP/1.1 200 OK\r\nconnection: close\r\n\r\n" + body
   1378     scripts.append(script^)
   1379     var guard = CleanupGuard()
   1380     with spawn_jev_scripted_auto(scripts^, guard) as started:
   1381         var report = run_bounded_call(
   1382             "raw_jev_head_body",
   1383             started.port,
   1384             10000,
   1385             10000,
   1386             guard,
   1387             JEV_CORRELATION_OB_CAP_NO_LENGTH_MINUS,
   1388             "/v1/systemone",
   1389             "aaa",
   1390         )
   1391         assert_true(report.ok())
   1392         assert_equal(report.status, 200)
   1393         assert_equal(report.body_bytes, JEV_RAW_BODY_CAP_TEST - 1)
   1394         assert_equal(report.declared_bytes, -1)
   1395         assert_equal(report.length_match, "unknown")
   1396         assert_equal(report.surplus_bytes, 0)
   1397         started.stub.wait()
   1398         assert_true(started.stub.ok())
   1399     guard.assert_clean()
   1400 
   1401 
   1402 def test_jev_raw_head_body_no_length_exact_cap_succeeds_at_eof() raises:
   1403     var body = _jev_cap_body(JEV_RAW_BODY_CAP_TEST)
   1404     var scripts = List[ExchangeScript]()
   1405     var script = exchange_script(
   1406         "jev_nolen_cap_exact", "POST", "/v1/systemone", 200, ""
   1407     )
   1408     script.raw_response = "HTTP/1.1 200 OK\r\nconnection: close\r\n\r\n" + body
   1409     scripts.append(script^)
   1410     var guard = CleanupGuard()
   1411     with spawn_jev_scripted_auto(scripts^, guard) as started:
   1412         var report = run_bounded_call(
   1413             "raw_jev_head_body",
   1414             started.port,
   1415             10000,
   1416             10000,
   1417             guard,
   1418             JEV_CORRELATION_OB_CAP_NO_LENGTH_EXACT,
   1419             "/v1/systemone",
   1420             "aaa",
   1421         )
   1422         assert_true(report.ok())
   1423         assert_equal(report.status, 200)
   1424         assert_equal(report.body_bytes, JEV_RAW_BODY_CAP_TEST)
   1425         assert_equal(report.declared_bytes, -1)
   1426         assert_equal(report.length_match, "unknown")
   1427         assert_equal(report.surplus_bytes, 0)
   1428         started.stub.wait()
   1429         assert_true(started.stub.ok())
   1430     guard.assert_clean()
   1431 
   1432 
   1433 def test_jev_raw_head_body_no_length_cap_plus_one_overflows() raises:
   1434     var body = _jev_cap_body(JEV_RAW_BODY_CAP_TEST + 1)
   1435     var scripts = List[ExchangeScript]()
   1436     var script = exchange_script(
   1437         "jev_nolen_cap_p1", "POST", "/v1/systemone", 200, ""
   1438     )
   1439     script.raw_response = "HTTP/1.1 200 OK\r\nconnection: close\r\n\r\n" + body
   1440     scripts.append(script^)
   1441     var guard = CleanupGuard()
   1442     with spawn_jev_scripted_auto(scripts^, guard) as started:
   1443         var report = run_bounded_call(
   1444             "raw_jev_head_body",
   1445             started.port,
   1446             10000,
   1447             10000,
   1448             guard,
   1449             JEV_CORRELATION_OB_CAP_NO_LENGTH_PLUS,
   1450             "/v1/systemone",
   1451             "aaa",
   1452         )
   1453         assert_true(report.completed)
   1454         assert_true(report.domain_failure())
   1455         assert_equal(report.cause, "raw_body_overflow")
   1456         assert_equal(report.reason, "body_overflow")
   1457         assert_equal(report.body_bytes, JEV_RAW_BODY_CAP_TEST)
   1458         assert_equal(report.surplus_bytes, 0)
   1459         started.stub.wait()
   1460         assert_true(started.stub.ok())
   1461     guard.assert_clean()
   1462 
   1463 
   1464 def test_jev_raw_head_body_no_length_exact_cap_stall_is_timeout() raises:
   1465     # D44/IL01: the Jev caller must also report a stopped (timeout) call, not an
   1466     # invented overflow, when an EOF-delimited peer delivers exactly the cap and
   1467     # then stalls under the existing parent deadline.
   1468     var body = _jev_cap_body(JEV_RAW_BODY_CAP_TEST)
   1469     var scripts = List[ExchangeScript]()
   1470     var script = exchange_script(
   1471         "jev_nolen_cap_stall", "POST", "/v1/systemone", 200, ""
   1472     )
   1473     script.raw_response = "HTTP/1.1 200 OK\r\nconnection: close\r\n\r\n" + body
   1474     script.close_connection = False
   1475     scripts.append(script^)
   1476     scripts.append(
   1477         exchange_script(
   1478             "jev_nolen_cap_stall_unused", "POST", "/v1/systemone", 200, ""
   1479         )
   1480     )
   1481     var guard = CleanupGuard()
   1482     with spawn_jev_scripted_auto(scripts^, guard) as started:
   1483         var report = run_bounded_call(
   1484             "raw_jev_head_body",
   1485             started.port,
   1486             10000,
   1487             1500,
   1488             guard,
   1489             JEV_CORRELATION_OB_CAP_NO_LENGTH_STALL,
   1490             "/v1/systemone",
   1491             "aaa",
   1492         )
   1493         assert_true(report.stopped)
   1494         assert_true(not report.completed)
   1495         assert_true(report.cleanup_proved)
   1496         assert_equal(report.problem, "")
   1497         assert_equal(report.cause, "")
   1498     guard.assert_clean()
   1499 
   1500 
   1501 # OB03: the Jev serve path must also reject every synthetic write-error seam,
   1502 # with and without an expected-close declaration.
   1503 
   1504 
   1505 def _assert_jev_synthetic_errno_rejected(errno: Int, declared: Bool) raises:
   1506     var scripts = List[ExchangeScript]()
   1507     var script = exchange_script(
   1508         "jev_synthetic_errno", "POST", "/v1/systemone", 200, '{"ok":true}'
   1509     )
   1510     script.stall_after_head_ms = 200
   1511     if declared:
   1512         script.expect_peer_close = True
   1513         script.expected_close_cause = "broken_pipe"
   1514         script.expected_close_phase = "body_stall"
   1515     script.inject_write_errno = errno
   1516     scripts.append(script^)
   1517     var guard = CleanupGuard()
   1518     with spawn_jev_scripted_auto(scripts^, guard) as started:
   1519         _ = _raw_jev_send_and_read(started.port, "/v1/systemone")
   1520         started.stub.reap()
   1521         assert_true(not started.stub.ok())
   1522         assert_equal(started.stub.phase(), "peer_close")
   1523         assert_true(started.stub.reason().find("unexpected_write_") >= 0)
   1524         assert_true(started.stub.reason().find("synthdecl") >= 0)
   1525     guard.assert_clean()
   1526 
   1527 
   1528 def test_jev_scripted_epipe_with_declaration_is_not_peer_close() raises:
   1529     _assert_jev_synthetic_errno_rejected(Int(ErrNo.EPIPE.value), True)
   1530 
   1531 
   1532 def test_jev_scripted_epipe_without_declaration_is_not_peer_close() raises:
   1533     _assert_jev_synthetic_errno_rejected(Int(ErrNo.EPIPE.value), False)
   1534 
   1535 
   1536 def test_jev_scripted_econnreset_with_declaration_is_not_peer_close() raises:
   1537     _assert_jev_synthetic_errno_rejected(Int(ErrNo.ECONNRESET.value), True)
   1538 
   1539 
   1540 def test_jev_scripted_econnreset_without_declaration_is_not_peer_close() raises:
   1541     _assert_jev_synthetic_errno_rejected(Int(ErrNo.ECONNRESET.value), False)
   1542 
   1543 
   1544 def test_jev_scripted_eagain_with_declaration_is_not_peer_close() raises:
   1545     _assert_jev_synthetic_errno_rejected(Int(ErrNo.EAGAIN.value), True)
   1546 
   1547 
   1548 def test_jev_scripted_eagain_without_declaration_is_not_peer_close() raises:
   1549     _assert_jev_synthetic_errno_rejected(Int(ErrNo.EAGAIN.value), False)
   1550 
   1551 
   1552 def test_jev_scripted_ebadf_with_declaration_is_not_peer_close() raises:
   1553     _assert_jev_synthetic_errno_rejected(Int(ErrNo.EBADF.value), True)
   1554 
   1555 
   1556 def test_jev_scripted_ebadf_without_declaration_is_not_peer_close() raises:
   1557     _assert_jev_synthetic_errno_rejected(Int(ErrNo.EBADF.value), False)
   1558 
   1559 
   1560 def _assert_jev_synthetic_errno_delayed_write_rejected(errno: Int) raises:
   1561     var scripts = List[ExchangeScript]()
   1562     var script = exchange_script(
   1563         "jev_synthetic_delayed", "POST", "/v1/systemone", 200, '{"ok":true}'
   1564     )
   1565     script.expect_peer_close = True
   1566     script.expected_close_cause = "broken_pipe"
   1567     script.expected_close_phase = "delayed_write"
   1568     script.inject_write_errno = errno
   1569     scripts.append(script^)
   1570     var guard = CleanupGuard()
   1571     with spawn_jev_scripted_auto(scripts^, guard) as started:
   1572         _ = _raw_jev_send_and_read(started.port, "/v1/systemone")
   1573         started.stub.reap()
   1574         assert_true(not started.stub.ok())
   1575         assert_equal(started.stub.phase(), "peer_close")
   1576         assert_true(started.stub.reason().find("unexpected_write_") >= 0)
   1577         assert_true(started.stub.reason().find("_delayed_write_") >= 0)
   1578         assert_true(started.stub.reason().find("synthdecl") >= 0)
   1579     guard.assert_clean()
   1580 
   1581 
   1582 def test_jev_scripted_epipe_delayed_write_is_not_peer_close() raises:
   1583     _assert_jev_synthetic_errno_delayed_write_rejected(Int(ErrNo.EPIPE.value))
   1584 
   1585 
   1586 def test_jev_scripted_econnreset_delayed_write_is_not_peer_close() raises:
   1587     _assert_jev_synthetic_errno_delayed_write_rejected(
   1588         Int(ErrNo.ECONNRESET.value)
   1589     )
   1590 
   1591 
   1592 def test_jev_scripted_eagain_delayed_write_is_not_peer_close() raises:
   1593     _assert_jev_synthetic_errno_delayed_write_rejected(Int(ErrNo.EAGAIN.value))
   1594 
   1595 
   1596 def test_jev_scripted_ebadf_delayed_write_is_not_peer_close() raises:
   1597     _assert_jev_synthetic_errno_delayed_write_rejected(Int(ErrNo.EBADF.value))