hyf

Context-aware query service for Radroots
git clone https://radroots.dev/git/hyf.git
Log | Files | Refs | README | LICENSE

test_runtime_paths.mojo (36846B)


      1 from std.collections import List
      2 from std.testing import TestSuite, assert_equal, assert_raises, assert_true
      3 
      4 from hyf_runtime.env import (
      5     hyf_paths_profile_env_name,
      6     hyf_paths_repo_local_root_env_name,
      7 )
      8 from hyf_runtime.paths import (
      9     hyf_runtime_paths_for_unix_profile,
     10     runtime_paths_for_namespace,
     11 )
     12 from hyf_runtime.provider_limits import (
     13     PROVIDER_DECLARED_BODY_OVERFLOW_REASON,
     14     PROVIDER_DECLARED_LENGTH_OVERFLOW_CAUSE,
     15     PROVIDER_DECODED_BODY_OVERFLOW_CAUSE,
     16     PROVIDER_DECODED_BODY_OVERFLOW_REASON,
     17     PROVIDER_HEAD_OVERFLOW_CAUSE,
     18     PROVIDER_HEAD_OVERFLOW_REASON,
     19     PROVIDER_MAX_DECODED_BODY_BYTES,
     20     PROVIDER_MAX_HEADER_BYTES,
     21     PROVIDER_MAX_RAW_BODY_BYTES,
     22     PROVIDER_RAW_BODY_OVERFLOW_CAUSE,
     23     PROVIDER_RAW_BODY_OVERFLOW_REASON,
     24     decoded_body_byte_count_within_bound,
     25     header_byte_count_within_bound,
     26     provider_limit_bound,
     27     provider_limit_failure_reason,
     28     provider_limit_is_inclusive,
     29     provider_limit_min_bytes,
     30     provider_limit_overflow_cause,
     31     raw_body_byte_count_within_bound,
     32 )
     33 from hyf_runtime.roots import runtime_roots_from_base_root
     34 from hyf_runtime.startup import RuntimeStartupInput, resolve_startup_context
     35 
     36 
     37 def test_runtime_paths_repo_local_contract_vector() raises:
     38     var paths = hyf_runtime_paths_for_unix_profile(
     39         "repo_local", "/home/unused", "/tmp/radroots-local/"
     40     )
     41 
     42     assert_equal(paths.namespace, "services/hyf")
     43     assert_equal(paths.config_dir, "/tmp/radroots-local/config/services/hyf")
     44     assert_equal(
     45         paths.config_path,
     46         "/tmp/radroots-local/config/services/hyf/config.toml",
     47     )
     48     assert_equal(paths.data_dir, "/tmp/radroots-local/data/services/hyf")
     49     assert_equal(paths.cache_dir, "/tmp/radroots-local/cache/services/hyf")
     50     assert_equal(paths.logs_dir, "/tmp/radroots-local/logs/services/hyf")
     51     assert_equal(
     52         paths.diagnostics_dir,
     53         "/tmp/radroots-local/logs/services/hyf/diagnostics",
     54     )
     55     assert_equal(paths.run_dir, "/tmp/radroots-local/run/services/hyf")
     56     assert_equal(
     57         paths.identity_path,
     58         "/tmp/radroots-local/secrets/services/hyf/identity.secret.json",
     59     )
     60 
     61 
     62 def test_runtime_paths_interactive_user_contract_vector() raises:
     63     var paths = hyf_runtime_paths_for_unix_profile(
     64         "interactive_user", "/Users/radroots-test", ""
     65     )
     66 
     67     assert_equal(
     68         paths.config_path,
     69         "/Users/radroots-test/.radroots/config/services/hyf/config.toml",
     70     )
     71     assert_equal(
     72         paths.data_dir, "/Users/radroots-test/.radroots/data/services/hyf"
     73     )
     74     assert_equal(
     75         paths.secrets_dir,
     76         "/Users/radroots-test/.radroots/secrets/services/hyf",
     77     )
     78 
     79 
     80 def test_runtime_paths_service_host_contract_vector() raises:
     81     var paths = hyf_runtime_paths_for_unix_profile(
     82         "service_host", "/home/unused", ""
     83     )
     84 
     85     assert_equal(paths.config_path, "/etc/radroots/services/hyf/config.toml")
     86     assert_equal(paths.data_dir, "/var/lib/radroots/services/hyf")
     87     assert_equal(paths.cache_dir, "/var/cache/radroots/services/hyf")
     88     assert_equal(paths.logs_dir, "/var/log/radroots/services/hyf")
     89     assert_equal(paths.run_dir, "/run/radroots/services/hyf")
     90     assert_equal(paths.secrets_dir, "/etc/radroots/secrets/services/hyf")
     91 
     92 
     93 def test_runtime_paths_reject_invalid_profile_namespace_and_base_root() raises:
     94     with assert_raises():
     95         _ = hyf_runtime_paths_for_unix_profile(
     96             "developer_laptop", "/Users/radroots-test", ""
     97         )
     98 
     99     with assert_raises():
    100         _ = hyf_runtime_paths_for_unix_profile(
    101             "repo_local", "/Users/radroots-test", ""
    102         )
    103 
    104     with assert_raises():
    105         _ = runtime_paths_for_namespace(
    106             runtime_roots_from_base_root("/tmp/radroots-local"), "hyf"
    107         )
    108 
    109 
    110 def _startup_argv() -> List[String]:
    111     return List[String]()
    112 
    113 
    114 def _startup_argv2(first: String, second: String) -> List[String]:
    115     var args = List[String]()
    116     args.append(first)
    117     args.append(second)
    118     return args^
    119 
    120 
    121 def test_runtime_env_contract_names_are_frozen() raises:
    122     assert_equal(hyf_paths_profile_env_name(), "HYF_PATHS_PROFILE")
    123     assert_equal(
    124         hyf_paths_repo_local_root_env_name(), "HYF_PATHS_REPO_LOCAL_ROOT"
    125     )
    126 
    127 
    128 def test_startup_context_defaults_from_env_and_home() raises:
    129     var context = resolve_startup_context(
    130         RuntimeStartupInput(
    131             env_paths_profile="interactive_user",
    132             env_repo_local_base_root="",
    133             user_home="/home/hyf-test",
    134             argv=_startup_argv(),
    135         )
    136     )
    137 
    138     assert_equal(context.paths_profile, "interactive_user")
    139     assert_equal(
    140         context.paths.config_path,
    141         "/home/hyf-test/.radroots/config/services/hyf/config.toml",
    142     )
    143     assert_equal(context.startup_config_path, context.paths.config_path)
    144     assert_equal(context.startup_config_path_source, "canonical_runtime_path")
    145 
    146 
    147 def test_startup_context_cli_flags_override_env() raises:
    148     var context = resolve_startup_context(
    149         RuntimeStartupInput(
    150             env_paths_profile="service_host",
    151             env_repo_local_base_root="",
    152             user_home="/home/ignored",
    153             argv=_startup_argv2(
    154                 "--paths-profile=repo_local",
    155                 "--repo-local-root=/tmp/hyf-runtime",
    156             ),
    157         )
    158     )
    159 
    160     assert_equal(context.paths_profile, "repo_local")
    161     assert_equal(context.repo_local_base_root, "/tmp/hyf-runtime")
    162     assert_equal(
    163         context.paths.config_path,
    164         "/tmp/hyf-runtime/config/services/hyf/config.toml",
    165     )
    166 
    167 
    168 def test_startup_context_clears_inactive_repo_local_root() raises:
    169     var context = resolve_startup_context(
    170         RuntimeStartupInput(
    171             env_paths_profile="interactive_user",
    172             env_repo_local_base_root="/tmp/hyf-runtime",
    173             user_home="/home/hyf-test",
    174             argv=_startup_argv2("--repo-local-root", "/tmp/hyf-override"),
    175         )
    176     )
    177 
    178     assert_equal(context.paths_profile, "interactive_user")
    179     assert_equal(context.repo_local_base_root, "")
    180     assert_equal(
    181         context.paths.config_path,
    182         "/home/hyf-test/.radroots/config/services/hyf/config.toml",
    183     )
    184 
    185 
    186 def test_startup_context_config_flag_overrides_config_artifact_only() raises:
    187     var context = resolve_startup_context(
    188         RuntimeStartupInput(
    189             env_paths_profile="repo_local",
    190             env_repo_local_base_root="/tmp/hyf-runtime",
    191             user_home="/home/ignored",
    192             argv=_startup_argv2("--config", "/tmp/hyf-config/config.toml"),
    193         )
    194     )
    195 
    196     assert_equal(
    197         context.paths.config_path,
    198         "/tmp/hyf-runtime/config/services/hyf/config.toml",
    199     )
    200     assert_equal(context.startup_config_path, "/tmp/hyf-config/config.toml")
    201     assert_equal(context.startup_config_path_source, "startup_flag")
    202 
    203 
    204 def test_startup_context_rejects_missing_root_unknown_flag_and_flag_as_value() raises:
    205     with assert_raises():
    206         _ = resolve_startup_context(
    207             RuntimeStartupInput(
    208                 env_paths_profile="repo_local",
    209                 env_repo_local_base_root="",
    210                 user_home="/home/ignored",
    211                 argv=_startup_argv(),
    212             )
    213         )
    214 
    215     with assert_raises():
    216         _ = resolve_startup_context(
    217             RuntimeStartupInput(
    218                 env_paths_profile="interactive_user",
    219                 env_repo_local_base_root="",
    220                 user_home="/home/ignored",
    221                 argv=_startup_argv2("--profile", "repo_local"),
    222             )
    223         )
    224 
    225     with assert_raises():
    226         _ = resolve_startup_context(
    227             RuntimeStartupInput(
    228                 env_paths_profile="interactive_user",
    229                 env_repo_local_base_root="",
    230                 user_home="/home/ignored",
    231                 argv=_startup_argv2("--paths-profile", "--repo-local-root"),
    232             )
    233         )
    234 
    235 
    236 # ── H010 runtime TOML compatibility characterization ────────────────────────
    237 
    238 
    239 from std.pathlib import Path
    240 from safe_tempdir import SafeTempDir
    241 from hyf_runtime.config import load_runtime_config
    242 
    243 
    244 def _load_toml(
    245     temp_dir: String, name: String, text: String
    246 ) raises -> HyfLoadedRuntimeConfig:
    247     var path = temp_dir + "/" + name + ".toml"
    248     Path(path).write_text(text)
    249     return load_runtime_config(path)
    250 
    251 
    252 def _assert_compiled_defaults(config: HyfLoadedRuntimeConfig) raises:
    253     assert_true(not config.effective.runtime.allow_assisted)
    254     assert_equal(config.effective.assisted.provider, "")
    255     assert_true(not config.effective.assisted.max_local.enabled)
    256     assert_equal(config.effective.assisted.max_local.base_url, "")
    257     assert_equal(config.effective.assisted.max_local.request_timeout_ms, 0)
    258 
    259 
    260 def _assert_route_rejected(
    261     config: HyfLoadedRuntimeConfig, message: String
    262 ) raises:
    263     assert_equal(config.load_state, "invalid")
    264     assert_equal(config.load_error, message)
    265 
    266 
    267 def _assert_form_ignored(config: HyfLoadedRuntimeConfig) raises:
    268     assert_equal(config.load_state, "loaded")
    269     assert_true(not config.effective.assisted.max_local.enabled)
    270     assert_equal(config.effective.assisted.max_local.base_url, "")
    271     assert_equal(config.effective.assisted.max_local.request_timeout_ms, 0)
    272 
    273 
    274 comptime ASSISTED_HEADER = (
    275     '[runtime]\nallow_assisted = true\n[assisted]\nprovider = "max_local"\n'
    276 )
    277 
    278 
    279 def test_toml_compatibility_supported_table_forms_are_equivalent() raises:
    280     # H010: the two-level tables the loader applies are `[runtime]` and
    281     # `[assisted]`; blank lines and trailing comments are equivalent.
    282     with SafeTempDir() as temp_dir:
    283         var plain = _load_toml(temp_dir, "plain", ASSISTED_HEADER)
    284         var commented = _load_toml(
    285             temp_dir,
    286             "commented",
    287             (
    288                 "# leading comment\n\n[runtime]\n"
    289                 "allow_assisted = true # trailing\n\n"
    290                 '[assisted]\nprovider = "max_local"\n'
    291             ),
    292         )
    293         assert_equal(plain.load_state, "loaded")
    294         assert_equal(commented.load_state, "loaded")
    295         assert_true(plain.effective.runtime.allow_assisted)
    296         assert_equal(plain.effective.assisted.provider, "max_local")
    297         assert_true(commented.effective.runtime.allow_assisted)
    298         assert_equal(commented.effective.assisted.provider, "max_local")
    299 
    300 
    301 def test_toml_compatibility_ignored_forms_are_characterized() raises:
    302     # H010: current loader limitation, characterized not repaired. Dotted keys,
    303     # three-level tables and array-of-tables headers load without error but do
    304     # not apply their values, so `assisted.max_local.*` cannot be configured
    305     # from a TOML artifact today.
    306     with SafeTempDir() as temp_dir:
    307         var dotted = _load_toml(
    308             temp_dir,
    309             "dotted",
    310             (
    311                 'assisted.provider = "max_local"\n'
    312                 "assisted.max_local.enabled = true\n"
    313                 'assisted.max_local.base_url = "http://127.0.0.1:8080"\n'
    314                 "runtime.allow_assisted = true\n"
    315             ),
    316         )
    317         var deep = _load_toml(
    318             temp_dir,
    319             "deep",
    320             ASSISTED_HEADER
    321             + "[assisted.max_local]\nenabled = true\n"
    322             'base_url = "http://127.0.0.1:8080"\n'
    323             'health_url = "http://127.0.0.1:8080/health"\n'
    324             'model = "m"\nrequest_timeout_ms = 15000\n',
    325         )
    326         var array_header = _load_toml(
    327             temp_dir, "array", '[[assisted]]\nprovider = "max_local"\n'
    328         )
    329         var typesafe = _load_toml(
    330             temp_dir,
    331             "typesafe",
    332             ASSISTED_HEADER
    333             + "[assisted.typesafe]\nenabled = true\n"
    334             'base_url = "https://api.typesafe.ai"\n'
    335             'model = "jev-1.13.0"\nrequest_timeout_ms = 15000\n',
    336         )
    337         _assert_form_ignored(dotted)
    338         _assert_form_ignored(deep)
    339         _assert_form_ignored(array_header)
    340         _assert_form_ignored(typesafe)
    341         assert_true(not typesafe.effective.assisted.typesafe.enabled)
    342         # The array-of-tables form drops the two-level provider key as well.
    343         assert_true(not array_header.effective.runtime.allow_assisted)
    344         assert_equal(array_header.effective.assisted.provider, "")
    345         # The dotted form does not apply the two-level runtime/assisted keys.
    346         assert_true(not dotted.effective.runtime.allow_assisted)
    347         assert_equal(dotted.effective.assisted.provider, "")
    348         # The two-level keys around a three-level table still apply.
    349         assert_true(deep.effective.runtime.allow_assisted)
    350         assert_equal(deep.effective.assisted.provider, "max_local")
    351 
    352 
    353 def test_toml_compatibility_inline_tables_are_characterized() raises:
    354     # H010: inline table forms are characterized. An inline table of tables is
    355     # accepted and ignored; an inline table carrying a string field fails the
    356     # TOML bridge with the current bounded error.
    357     with SafeTempDir() as temp_dir:
    358         var inline_scalar = _load_toml(
    359             temp_dir, "inline_scalar", "runtime = { allow_assisted = true }\n"
    360         )
    361         assert_equal(inline_scalar.load_state, "loaded")
    362         assert_true(not inline_scalar.effective.runtime.allow_assisted)
    363         var inline_tables = _load_toml(
    364             temp_dir,
    365             "inline_tables",
    366             'assisted = { max_local = { enabled = true, route = "/x" } }\n',
    367         )
    368         assert_equal(inline_tables.load_state, "loaded")
    369         assert_true(not inline_tables.effective.assisted.max_local.enabled)
    370         var inline_string = _load_toml(
    371             temp_dir,
    372             "inline_string",
    373             'assisted = { provider = "max_local" }\n',
    374         )
    375         assert_equal(inline_string.load_state, "invalid")
    376         assert_equal(inline_string.load_error, "Empty JSON value")
    377 
    378 
    379 def test_toml_compatibility_rejects_removed_route_syntaxes() raises:
    380     # H010: every syntax of the removed `assisted.max_local.route` the guard
    381     # recognizes is rejected with the contractual message. The deep inline form
    382     # is not recognized today and loads with the key ignored: recorded as a
    383     # characterized gap for the config owner, not repaired here (product source
    384     # is outside this slice).
    385     var message = (
    386         "assisted.max_local.route has been removed; provider route is derived"
    387         " by HYF"
    388     )
    389     with SafeTempDir() as temp_dir:
    390         var table = _load_toml(
    391             temp_dir, "route_table", '[assisted.max_local]\nroute = "/v1"\n'
    392         )
    393         var dotted = _load_toml(
    394             temp_dir, "route_dotted", 'assisted.max_local.route = "/v1"\n'
    395         )
    396         var quoted = _load_toml(
    397             temp_dir, "route_quoted", '[assisted."max_local"]\nroute = "/v1"\n'
    398         )
    399         var inline = _load_toml(
    400             temp_dir, "route_inline", 'assisted.max_local = { route = "/v1" }\n'
    401         )
    402         _assert_route_rejected(table, message)
    403         _assert_route_rejected(dotted, message)
    404         _assert_route_rejected(quoted, message)
    405         _assert_route_rejected(inline, message)
    406         var deep_inline = _load_toml(
    407             temp_dir,
    408             "route_deep",
    409             'assisted = { max_local = { route = "/v1" } }\n',
    410         )
    411         assert_equal(deep_inline.load_state, "loaded")
    412         assert_equal(deep_inline.load_error, "")
    413 
    414 
    415 def test_toml_compatibility_unknown_keys_and_defaults_are_characterized() raises:
    416     # H010: unknown keys anywhere are accepted without error, a missing artifact
    417     # leaves the compiled defaults active, and an invalid artifact falls back to
    418     # those same compiled defaults.
    419     with SafeTempDir() as temp_dir:
    420         var unknown_top = _load_toml(
    421             temp_dir, "unknown_top", "unknown = true\n"
    422         )
    423         assert_equal(unknown_top.load_state, "loaded")
    424         assert_equal(unknown_top.load_error, "")
    425         var unknown_table = _load_toml(
    426             temp_dir,
    427             "unknown_table",
    428             '[assisted]\nunknown = "value"\n[runtime]\nunknown_number = 3\n',
    429         )
    430         assert_equal(unknown_table.load_state, "loaded")
    431         assert_equal(unknown_table.load_error, "")
    432         var missing = load_runtime_config(temp_dir + "/absent.toml")
    433         assert_equal(missing.load_state, "not_found")
    434         assert_true(not missing.artifact_present)
    435         assert_true(missing.compiled_defaults_active)
    436         _assert_compiled_defaults(unknown_top)
    437         _assert_compiled_defaults(unknown_table)
    438         _assert_compiled_defaults(missing)
    439         var invalid = _load_toml(
    440             temp_dir, "invalid_defaults", '[service]\ntransport = "udp"\n'
    441         )
    442         assert_equal(invalid.load_state, "invalid")
    443         assert_true(invalid.compiled_defaults_active)
    444         _assert_compiled_defaults(invalid)
    445         assert_equal(invalid.effective.service.transport, "stdio")
    446 
    447 
    448 def test_toml_compatibility_rejects_invalid_scalar_and_cross_field_forms() raises:
    449     # H010: invalid scalar values, cross-field combinations and a malformed
    450     # header preserve their current bounded error categories/messages.
    451     with SafeTempDir() as temp_dir:
    452         var transport = _load_toml(
    453             temp_dir, "transport", '[service]\ntransport = "udp"\n'
    454         )
    455         assert_equal(transport.load_state, "invalid")
    456         assert_equal(transport.load_error, "service.transport must be 'stdio'")
    457         var mode = _load_toml(
    458             temp_dir, "mode", '[runtime]\ndefault_execution_mode = "assisted"\n'
    459         )
    460         assert_equal(mode.load_state, "invalid")
    461         assert_equal(
    462             mode.load_error,
    463             (
    464                 "runtime.default_execution_mode must be 'deterministic' in the"
    465                 " foundation wave"
    466             ),
    467         )
    468         var provider = _load_toml(
    469             temp_dir,
    470             "provider",
    471             (
    472                 "[runtime]\nallow_assisted = true\n[assisted]\n"
    473                 'provider = "other"\n'
    474             ),
    475         )
    476         assert_equal(provider.load_state, "invalid")
    477         assert_equal(
    478             provider.load_error,
    479             (
    480                 "assisted.provider must be 'max_local' or 'typesafe' when"
    481                 " runtime.allow_assisted is true"
    482             ),
    483         )
    484         var whitespace = _load_toml(
    485             temp_dir,
    486             "whitespace",
    487             (
    488                 "[runtime]\nallow_assisted = true\n[assisted]\n"
    489                 'provider = " max_local"\n'
    490             ),
    491         )
    492         assert_equal(whitespace.load_state, "invalid")
    493         assert_equal(
    494             whitespace.load_error,
    495             "assisted.provider must not include leading or trailing whitespace",
    496         )
    497         var header = _load_toml(
    498             temp_dir, "header", '[assisted\nprovider = "max_local"\n'
    499         )
    500         assert_equal(header.load_state, "invalid")
    501         assert_true(header.load_error.startswith("Invalid TOML table header"))
    502 
    503 
    504 def main() raises:
    505     TestSuite.discover_tests[__functions_in_module()]().run()
    506 
    507 
    508 from hyf_runtime.config import (
    509     HyfAssistedRuntimeConfig,
    510     HyfExecutionRuntimeConfig,
    511     HyfLoadedRuntimeConfig,
    512     HyfMaxLocalProviderRuntimeConfig,
    513     HyfRuntimeConfig,
    514     HyfServiceRuntimeConfig,
    515     HyfTypesafeProviderRuntimeConfig,
    516     assisted_runtime_configured,
    517     typesafe_provider_configured,
    518 )
    519 
    520 
    521 def _typesafe_config(enabled: Bool, base_url: String) -> HyfLoadedRuntimeConfig:
    522     var runtime = HyfExecutionRuntimeConfig()
    523     runtime.default_execution_mode = "deterministic"
    524     runtime.allow_assisted = True
    525     return HyfLoadedRuntimeConfig(
    526         artifact_present=True,
    527         loaded=True,
    528         compiled_defaults_active=False,
    529         load_state="loaded",
    530         load_error="",
    531         effective=HyfRuntimeConfig(
    532             service=HyfServiceRuntimeConfig(transport="stdio"),
    533             runtime=runtime.copy(),
    534             assisted=HyfAssistedRuntimeConfig(
    535                 provider="typesafe",
    536                 max_local=HyfMaxLocalProviderRuntimeConfig(),
    537                 typesafe=HyfTypesafeProviderRuntimeConfig(
    538                     enabled=enabled,
    539                     base_url=base_url,
    540                     model="jev-1.13.0",
    541                     request_timeout_ms=15000,
    542                 ),
    543             ),
    544         ),
    545     )
    546 
    547 
    548 def test_typesafe_profile_is_configured_and_pins_https_model() raises:
    549     var config = _typesafe_config(True, "https://api.typesafe.ai")
    550     assert_true(assisted_runtime_configured(config))
    551     assert_true(typesafe_provider_configured(config))
    552     assert_equal(config.effective.assisted.typesafe.model, "jev-1.13.0")
    553     var disabled = _typesafe_config(False, "https://api.typesafe.ai")
    554     assert_true(not assisted_runtime_configured(disabled))
    555 
    556 
    557 from hyf_runtime.config import (
    558     default_loaded_runtime_config,
    559     operation_enabled,
    560     provider_disabled,
    561 )
    562 
    563 
    564 def test_operation_enablement_and_kill_switch() raises:
    565     var config = default_loaded_runtime_config()
    566     assert_true(not operation_enabled(config, "farm_update.interpret"))
    567     assert_true(not operation_enabled(config, "buyer_request.interpret"))
    568     assert_true(not operation_enabled(config, "buyer_request.match"))
    569     assert_true(not provider_disabled(config))
    570     config.effective.runtime.enable_buyer_request_match = True
    571     assert_true(operation_enabled(config, "buyer_request.match"))
    572     config.effective.runtime.disable_provider = True
    573     assert_true(provider_disabled(config))
    574     assert_true(not operation_enabled(config, "buyer_request.match"))
    575 
    576 
    577 from hyf_runtime.budget import (
    578     budget_from_clock,
    579     budget_remaining_ms,
    580     budget_exhausted,
    581 )
    582 
    583 
    584 def test_shared_budget_does_not_reset_per_stage() raises:
    585     var value = budget_from_clock(500, 2000, 0)
    586     assert_equal(value.cap_ms, 500)
    587     assert_equal(budget_remaining_ms(value, 200_000_000), 300)
    588     assert_equal(budget_remaining_ms(value, 600_000_000), 0)
    589     assert_true(budget_exhausted(value, 600_000_000))
    590     var capped = budget_from_clock(5000, 2000, 0)
    591     assert_equal(capped.cap_ms, 2000)
    592 
    593 
    594 def test_budget_boundaries_are_deterministic() raises:
    595     # H007: deterministic budget-unit controls that stay green before any
    596     # transport migration. The unit is one monotonic budget with no per-stage
    597     # reset, exact boundary behavior and non-negative remaining time.
    598     var no_deadline = budget_from_clock(0, 400, 0)
    599     assert_equal(no_deadline.cap_ms, 400)
    600     assert_equal(budget_remaining_ms(no_deadline, 0), 400)
    601 
    602     var negative_deadline = budget_from_clock(-5, 400, 0)
    603     assert_equal(negative_deadline.cap_ms, 400)
    604 
    605     var exact = budget_from_clock(250, 400, 0)
    606     assert_equal(budget_remaining_ms(exact, 0), 250)
    607     assert_equal(budget_remaining_ms(exact, 249_000_000), 1)
    608     assert_equal(budget_remaining_ms(exact, 250_000_000), 0)
    609     assert_true(not budget_exhausted(exact, 249_999_999))
    610     assert_true(budget_exhausted(exact, 250_000_000))
    611 
    612     # The same budget object across staged clock advancement must not reset: a
    613     # freshly constructed object would report the full cap again, which cannot
    614     # prove the original budget was preserved (ADR-0020 TC03).
    615     var staged = budget_from_clock(250, 400, 0)
    616     assert_equal(staged.cap_ms, 250)
    617     assert_equal(budget_remaining_ms(staged, 0), 250)
    618     assert_equal(budget_remaining_ms(staged, 200_000_000), 50)
    619     assert_equal(budget_remaining_ms(staged, 249_000_000), 1)
    620     assert_equal(budget_remaining_ms(staged, 250_000_000), 0)
    621     assert_equal(budget_remaining_ms(staged, 400_000_000), 0)
    622     assert_true(not budget_exhausted(staged, 249_999_999))
    623     assert_true(budget_exhausted(staged, 250_000_000))
    624 
    625 
    626 from hyf_application.resource_envelope import (
    627     RESOURCE_ENVELOPE_MAX_CANDIDATES,
    628     RESOURCE_ENVELOPE_MAX_PLANS,
    629     RESOURCE_ENVELOPE_MAX_PROVIDER_CALLS,
    630     RESOURCE_ENVELOPE_MAX_QUESTIONS,
    631     RESOURCE_ENVELOPE_MAX_STATE_BYTES,
    632     default_resource_envelope,
    633     within_envelope,
    634 )
    635 from hyf_runtime.budget import (
    636     CIRCUIT_COOLDOWN_MS,
    637     CIRCUIT_HALF_OPEN_PROBES,
    638     CIRCUIT_OPEN_THRESHOLD,
    639     CONNECT_READ_CAP_MS,
    640     MAX_RETRIES_PER_CALL,
    641     MAX_WIRE_ATTEMPTS,
    642     OUTPUT_BLOCK_CAP_MS,
    643     RETRY_BACKOFF_MS,
    644 )
    645 from hyf_stdio.server import MAX_FRAME_BYTES, frame_too_large
    646 from hyf_runtime.config import DEFAULT_PROVIDER_REQUEST_TIMEOUT_MS
    647 
    648 
    649 def _frame_of(count: Int) -> String:
    650     var out = List[UInt8]()
    651     for _ in range(count):
    652         out.append(UInt8(97))
    653     return String(unsafe_from_utf8=Span(ptr=out.unsafe_ptr(), length=len(out)))
    654 
    655 
    656 def test_policy_constants_match_frozen_d21_values() raises:
    657     # C003 / ADR-0010 D21: the already-selected constants are frozen exactly in
    658     # their named capsule owners; this slice may not enlarge or weaken them.
    659     assert_equal(MAX_FRAME_BYTES, 1048576)
    660     assert_equal(CONNECT_READ_CAP_MS, 1000)
    661     assert_equal(OUTPUT_BLOCK_CAP_MS, 1000)
    662     assert_equal(MAX_WIRE_ATTEMPTS, 4)
    663     assert_equal(MAX_RETRIES_PER_CALL, 1)
    664     assert_equal(RETRY_BACKOFF_MS, 100)
    665     assert_equal(CIRCUIT_OPEN_THRESHOLD, 3)
    666     assert_equal(CIRCUIT_COOLDOWN_MS, 30000)
    667     assert_equal(CIRCUIT_HALF_OPEN_PROBES, 1)
    668     assert_equal(DEFAULT_PROVIDER_REQUEST_TIMEOUT_MS, 15000)
    669     assert_true(MAX_RETRIES_PER_CALL < MAX_WIRE_ATTEMPTS)
    670 
    671 
    672 def test_resource_envelope_boundaries_are_inclusive() raises:
    673     # C003 / D21 limits: every semantic dimension is cap-1/cap/cap+1 tested and
    674     # the cap itself is inclusive.
    675     var envelope = default_resource_envelope()
    676     assert_equal(envelope.max_candidates, RESOURCE_ENVELOPE_MAX_CANDIDATES)
    677     assert_equal(envelope.max_plans, RESOURCE_ENVELOPE_MAX_PLANS)
    678     assert_equal(envelope.max_state_bytes, RESOURCE_ENVELOPE_MAX_STATE_BYTES)
    679     assert_equal(envelope.max_questions, RESOURCE_ENVELOPE_MAX_QUESTIONS)
    680     assert_equal(
    681         envelope.max_provider_calls, RESOURCE_ENVELOPE_MAX_PROVIDER_CALLS
    682     )
    683     # candidates
    684     assert_true(
    685         within_envelope(
    686             envelope, RESOURCE_ENVELOPE_MAX_CANDIDATES - 1, 0, 0, 0, 0
    687         )
    688     )
    689     assert_true(
    690         within_envelope(envelope, RESOURCE_ENVELOPE_MAX_CANDIDATES, 0, 0, 0, 0)
    691     )
    692     assert_true(
    693         not within_envelope(
    694             envelope, RESOURCE_ENVELOPE_MAX_CANDIDATES + 1, 0, 0, 0, 0
    695         )
    696     )
    697     # plans
    698     assert_true(
    699         within_envelope(envelope, 0, RESOURCE_ENVELOPE_MAX_PLANS - 1, 0, 0, 0)
    700     )
    701     assert_true(
    702         within_envelope(envelope, 0, RESOURCE_ENVELOPE_MAX_PLANS, 0, 0, 0)
    703     )
    704     assert_true(
    705         not within_envelope(
    706             envelope, 0, RESOURCE_ENVELOPE_MAX_PLANS + 1, 0, 0, 0
    707         )
    708     )
    709     # state bytes
    710     assert_true(
    711         within_envelope(
    712             envelope, 0, 0, RESOURCE_ENVELOPE_MAX_STATE_BYTES - 1, 0, 0
    713         )
    714     )
    715     assert_true(
    716         within_envelope(envelope, 0, 0, RESOURCE_ENVELOPE_MAX_STATE_BYTES, 0, 0)
    717     )
    718     assert_true(
    719         not within_envelope(
    720             envelope, 0, 0, RESOURCE_ENVELOPE_MAX_STATE_BYTES + 1, 0, 0
    721         )
    722     )
    723     # questions
    724     assert_true(
    725         within_envelope(
    726             envelope, 0, 0, 0, RESOURCE_ENVELOPE_MAX_QUESTIONS - 1, 0
    727         )
    728     )
    729     assert_true(
    730         within_envelope(envelope, 0, 0, 0, RESOURCE_ENVELOPE_MAX_QUESTIONS, 0)
    731     )
    732     assert_true(
    733         not within_envelope(
    734             envelope, 0, 0, 0, RESOURCE_ENVELOPE_MAX_QUESTIONS + 1, 0
    735         )
    736     )
    737     # logical provider calls
    738     assert_true(
    739         within_envelope(
    740             envelope, 0, 0, 0, 0, RESOURCE_ENVELOPE_MAX_PROVIDER_CALLS - 1
    741         )
    742     )
    743     assert_true(
    744         within_envelope(
    745             envelope, 0, 0, 0, 0, RESOURCE_ENVELOPE_MAX_PROVIDER_CALLS
    746         )
    747     )
    748     assert_true(
    749         not within_envelope(
    750             envelope, 0, 0, 0, 0, RESOURCE_ENVELOPE_MAX_PROVIDER_CALLS + 1
    751         )
    752     )
    753 
    754 
    755 def test_budget_cap_boundaries_are_inclusive() raises:
    756     # C003 / D21 timeout: the absolute request budget is
    757     # min(positive deadline, server cap) and the cap itself is inclusive.
    758     var server_cap = 1000
    759     var at_cap = budget_from_clock(server_cap, server_cap, 0)
    760     assert_equal(at_cap.cap_ms, server_cap)
    761     var under_cap = budget_from_clock(server_cap - 1, server_cap, 0)
    762     assert_equal(under_cap.cap_ms, server_cap - 1)
    763     var over_cap = budget_from_clock(server_cap + 1, server_cap, 0)
    764     assert_equal(over_cap.cap_ms, server_cap)
    765     # remaining-time boundary: 1 ms left at cap-1, exhausted at cap.
    766     assert_equal(budget_remaining_ms(at_cap, (server_cap - 1) * 1_000_000), 1)
    767     assert_equal(budget_remaining_ms(at_cap, server_cap * 1_000_000), 0)
    768 
    769 
    770 def test_stdio_frame_cap_boundaries_are_inclusive() raises:
    771     # C003 / D21 stdio frame cap: the frame limit is inclusive (cap-1 and cap
    772     # are accepted; only cap+1 is oversized).
    773     assert_true(not frame_too_large(_frame_of(MAX_FRAME_BYTES - 1)))
    774     assert_true(not frame_too_large(_frame_of(MAX_FRAME_BYTES)))
    775     assert_true(frame_too_large(_frame_of(MAX_FRAME_BYTES + 1)))
    776 
    777 
    778 from hyf_runtime.jev_composition import compose_jev
    779 
    780 
    781 def test_jev_runtime_composition_reasons() raises:
    782     var disabled = default_loaded_runtime_config()
    783     assert_equal(compose_jev(disabled).reason, "disabled_by_runtime_config")
    784     var configured = _typesafe_config(True, "https://api.typesafe.ai")
    785     var composition = compose_jev(configured)
    786     assert_true(not composition.usable)
    787     assert_equal(composition.reason, "missing_credentials")
    788     assert_equal(composition.model, "jev-1.13.0")
    789 
    790 
    791 def test_new_operation_configuration_matrix() raises:
    792     var config = default_loaded_runtime_config()
    793     assert_true(not operation_enabled(config, "farm_update.interpret"))
    794     assert_true(not operation_enabled(config, "buyer_request.interpret"))
    795     assert_true(not operation_enabled(config, "buyer_request.match"))
    796     config.effective.runtime.enable_farm_update_interpret = True
    797     assert_true(operation_enabled(config, "farm_update.interpret"))
    798     config.effective.runtime.enable_buyer_request_interpret = True
    799     assert_true(operation_enabled(config, "buyer_request.interpret"))
    800     config.effective.runtime.enable_buyer_request_match = True
    801     assert_true(operation_enabled(config, "buyer_request.match"))
    802     config.effective.runtime.disable_provider = True
    803     assert_true(not operation_enabled(config, "farm_update.interpret"))
    804     assert_true(not operation_enabled(config, "buyer_request.interpret"))
    805     assert_true(not operation_enabled(config, "buyer_request.match"))
    806 
    807 
    808 # H092 / ADR-0010 D21: internal timeout derivation, positivity and total-phase bounds.
    809 from hyf_runtime.budget import (
    810     budget_stage_cap_ms,
    811     derived_connect_read_cap_ms,
    812     derived_output_block_cap_ms,
    813     derived_stage_cap_ms,
    814     request_budget_cap_ms,
    815     request_budget_from_config,
    816 )
    817 
    818 
    819 def test_h092_request_budget_derivation_table() raises:
    820     # min(positive deadline, configured timeout); the configured cap governs
    821     # when the caller supplies no (or a non-positive) deadline.
    822     assert_equal(request_budget_cap_ms(2500, 15000), 2500)
    823     assert_equal(request_budget_cap_ms(20000, 15000), 15000)
    824     assert_equal(request_budget_cap_ms(15000, 15000), 15000)
    825     assert_equal(request_budget_cap_ms(1, 15000), 1)
    826     assert_equal(request_budget_cap_ms(0, 15000), 15000)
    827     assert_equal(request_budget_cap_ms(-5, 15000), 15000)
    828     # A non-positive configured timeout is invalid configuration, not a
    829     # silently zero/unbounded budget.
    830     with assert_raises():
    831         _ = request_budget_cap_ms(2500, 0)
    832     with assert_raises():
    833         _ = request_budget_cap_ms(2500, -1)
    834     assert_true(request_budget_cap_ms(2500, 15000) > 0)
    835 
    836 
    837 def test_h092_stage_cap_derivations_are_bounded_and_inclusive() raises:
    838     # connect/read and output caps are min(1000, remaining), inclusive at cap.
    839     assert_equal(derived_connect_read_cap_ms(999), 999)
    840     assert_equal(derived_connect_read_cap_ms(1000), 1000)
    841     assert_equal(derived_connect_read_cap_ms(1001), 1000)
    842     assert_equal(derived_output_block_cap_ms(999), 999)
    843     assert_equal(derived_output_block_cap_ms(1000), 1000)
    844     assert_equal(derived_output_block_cap_ms(1001), 1000)
    845     # Zero/negative remaining budget collapses to zero, never negative and
    846     # never an extension of the deadline.
    847     assert_equal(derived_connect_read_cap_ms(0), 0)
    848     assert_equal(derived_output_block_cap_ms(0), 0)
    849     assert_equal(derived_connect_read_cap_ms(-10), 0)
    850     assert_equal(derived_output_block_cap_ms(-10), 0)
    851     assert_equal(derived_stage_cap_ms(1000, -1), 0)
    852 
    853 
    854 def test_h092_budget_stage_cap_respects_absolute_deadline() raises:
    855     var value = request_budget_from_config(500, 15000, 0)
    856     assert_equal(value.cap_ms, 500)
    857     assert_equal(budget_remaining_ms(value, 0), 500)
    858     assert_equal(budget_stage_cap_ms(value, 0, 1000), 500)
    859     assert_equal(budget_stage_cap_ms(value, 200_000_000, 1000), 300)
    860     assert_equal(budget_stage_cap_ms(value, 499_000_000, 1000), 1)
    861     assert_equal(budget_stage_cap_ms(value, 500_000_000, 1000), 0)
    862     assert_equal(budget_stage_cap_ms(value, 900_000_000, 1000), 0)
    863     # The configured timeout governs when it is smaller than the deadline, and
    864     # the same object never resets across staged clock advancement.
    865     var configured = request_budget_from_config(20000, 1500, 0)
    866     assert_equal(configured.cap_ms, 1500)
    867     assert_equal(budget_stage_cap_ms(configured, 1_000_000_000, 1000), 500)
    868     assert_equal(budget_stage_cap_ms(configured, 1_500_000_000, 1000), 0)
    869 
    870 
    871 # ADR-0026 D46 H093: codified inclusive provider response byte limits. Pure
    872 # boundary surface; pre-allocation/transport enforcement remains C005/C047.
    873 def test_h093_provider_limit_constants_match_policy_v2() raises:
    874     assert_equal(PROVIDER_MAX_HEADER_BYTES, 65536)
    875     assert_equal(PROVIDER_MAX_RAW_BODY_BYTES, 1048576)
    876     assert_equal(PROVIDER_MAX_DECODED_BODY_BYTES, 4194304)
    877     assert_true(provider_limit_is_inclusive())
    878     assert_equal(provider_limit_bound("header"), 65536)
    879     assert_equal(provider_limit_bound("raw_body"), 1048576)
    880     assert_equal(provider_limit_bound("decoded_body"), 4194304)
    881 
    882 
    883 def test_h093_provider_limit_bounds_are_inclusive() raises:
    884     # header 65536
    885     assert_true(header_byte_count_within_bound(65535))
    886     assert_true(header_byte_count_within_bound(65536))
    887     assert_true(not header_byte_count_within_bound(65537))
    888     # raw body 1048576
    889     assert_true(raw_body_byte_count_within_bound(1048575))
    890     assert_true(raw_body_byte_count_within_bound(1048576))
    891     assert_true(not raw_body_byte_count_within_bound(1048577))
    892     # decoded body 4194304
    893     assert_true(decoded_body_byte_count_within_bound(4194303))
    894     assert_true(decoded_body_byte_count_within_bound(4194304))
    895     assert_true(not decoded_body_byte_count_within_bound(4194305))
    896     # zero-byte bodies are admissible at the raw/decoded bounds; the header
    897     # policy lower bound is min=1, so a zero header count is below range.
    898     assert_true(not header_byte_count_within_bound(0))
    899     assert_true(raw_body_byte_count_within_bound(0))
    900     assert_true(decoded_body_byte_count_within_bound(0))
    901     assert_equal(provider_limit_min_bytes("header"), 1)
    902     assert_equal(provider_limit_min_bytes("raw_body"), 0)
    903     assert_equal(provider_limit_min_bytes("decoded_body"), 0)
    904 
    905 
    906 def test_h093_provider_limit_counts_must_be_nonnegative() raises:
    907     with assert_raises():
    908         _ = header_byte_count_within_bound(-1)
    909     with assert_raises():
    910         _ = raw_body_byte_count_within_bound(-1)
    911     with assert_raises():
    912         _ = decoded_body_byte_count_within_bound(-1)
    913     with assert_raises():
    914         _ = provider_limit_bound("unknown")
    915     with assert_raises():
    916         _ = provider_limit_min_bytes("unknown")
    917     with assert_raises():
    918         _ = provider_limit_failure_reason("unknown")
    919     with assert_raises():
    920         _ = provider_limit_overflow_cause("unknown")
    921 
    922 
    923 def test_h093_provider_limit_failures_are_stable() raises:
    924     assert_equal(
    925         provider_limit_overflow_cause("header"), PROVIDER_HEAD_OVERFLOW_CAUSE
    926     )
    927     assert_equal(
    928         provider_limit_failure_reason("header"), PROVIDER_HEAD_OVERFLOW_REASON
    929     )
    930     assert_equal(
    931         provider_limit_overflow_cause("raw_body"),
    932         PROVIDER_RAW_BODY_OVERFLOW_CAUSE,
    933     )
    934     assert_equal(
    935         provider_limit_failure_reason("raw_body"),
    936         PROVIDER_RAW_BODY_OVERFLOW_REASON,
    937     )
    938     assert_equal(
    939         provider_limit_failure_reason("declared_length"),
    940         PROVIDER_DECLARED_LENGTH_OVERFLOW_CAUSE,
    941     )
    942     assert_equal(
    943         provider_limit_overflow_cause("declared_body"),
    944         PROVIDER_RAW_BODY_OVERFLOW_CAUSE,
    945     )
    946     assert_equal(
    947         provider_limit_failure_reason("declared_body"),
    948         PROVIDER_DECLARED_BODY_OVERFLOW_REASON,
    949     )
    950     assert_equal(
    951         provider_limit_overflow_cause("decoded_body"),
    952         PROVIDER_DECODED_BODY_OVERFLOW_CAUSE,
    953     )
    954     assert_equal(
    955         provider_limit_failure_reason("decoded_body"),
    956         PROVIDER_DECODED_BODY_OVERFLOW_REASON,
    957     )