refactor(fs): split filesystem seam into provider ctx.fs + policy ctx.fileContext

Implements the split-the-filesystem-seam RFC. ctx.fs shrinks to a text-storage
provider seam (resolve/stat/readText/streamText/writeText/editText with branded
FsTargetKey/FsVersion and an explicit FsWriteExpectation); the new
dsh-file-context package owns the model-facing policy (read windowing,
observed-state, write/edit freshness) as the concrete ctx.fileContext service.

Authorization is now freshness-based rather than full/partial view: a windowed
read records the file version and authorizes a later edit when the file is
unchanged, removing the dead-end where reading lines 100-150 of a large file
could not edit line 120. editText stays a provider primitive so version guard +
literal match + atomic rewrite remain one critical section, and the stale check
runs before matching so a stale edit reports FS_STALE_VERSION. tool-fs injects
fileContext, never reaching around to ctx.fs (the no-bypass contract).
This commit is contained in:
Dudu-0223
2026-06-26 17:23:18 +08:00
parent c7a197fb5f
commit ef37ce3b9d
42 changed files with 1899 additions and 1466 deletions
+159 -187
View File
@@ -1,7 +1,9 @@
/**
* Tests for the local backend through the `ctx.fs` service: the full
* read→write→edit lifecycle with the read-before-write policy, stale-version
* guards, concurrency races, symlink identity, and HMR/disposal.
* Tests for the local backend through the `ctx.fs` provider seam: stat, whole-
* file/streamed text reads, atomic guarded writes (createIfAbsent /
* replaceIfVersion), version-guarded literal edits, concurrency races, symlink
* identity, and HMR/disposal. Read WINDOWING is policy and lives in
* `dsh-file-context`, so it is not exercised here.
*/
import { afterEach, beforeEach, describe, expect, it } from 'vitest'
@@ -9,8 +11,9 @@ import { mkdtemp, readFile, rm, stat, symlink, writeFile, unlink } from 'node:fs
import { tmpdir } from 'node:os'
import { join } from 'node:path'
import { Context } from 'cordis'
import { LocalFileSystem, probe } from '@deepseek-ai/dsh-fs-local'
import type { FsExecContext } from '@deepseek-ai/dsh-fs'
import { LocalFileSystem } from '@deepseek-ai/dsh-fs-local'
import { FsVersion } from '@deepseek-ai/dsh-fs'
import type { FsTarget } from '@deepseek-ai/dsh-fs'
let dir: string
let ctx: Context
@@ -28,12 +31,17 @@ afterEach(async () => {
await rm(dir, { recursive: true, force: true })
})
const READ_ALL = { offset: 1, limit: 2000 }
const exec = (): FsExecContext => ({ agent: { session: {} } })
function lockCount(localFs: LocalFileSystem): number {
return (localFs as unknown as { locks: Map<string, Promise<unknown>> }).locks.size
}
/** The version the backend currently reports for a resolved target. */
async function versionOf(target: FsTarget): Promise<FsVersion> {
const info = await fs.stat(target)
if (!info) throw new Error('expected target to exist')
return info.version
}
describe('registration', () => {
it('registers LocalFileSystem as ctx.fs with a default cwd', async () => {
const bare = new Context()
@@ -43,255 +51,219 @@ describe('registration', () => {
})
})
describe('read → write → edit lifecycle', () => {
it('creates a new file without a prior read', async () => {
describe('stat', () => {
it('returns file metadata, directory type, and undefined for absent', async () => {
await writeFile(join(dir, 'a.txt'), 'hello')
const fileInfo = await fs.stat(await fs.resolve('a.txt'))
expect(fileInfo?.type).toBe('file')
expect(fileInfo?.size).toBe(5)
expect(typeof fileInfo?.version).toBe('string')
expect((await fs.stat(await fs.resolve('.')))?.type).toBe('directory')
expect(await fs.stat(await fs.resolve('missing.txt'))).toBeUndefined()
})
it('honors a pre-aborted signal', async () => {
await expect(fs.stat(await fs.resolve('a.txt'), AbortSignal.abort())).rejects.toMatchObject({ code: 'FS_ABORTED' })
})
})
describe('readText / streamText', () => {
it('reads whole-file text', async () => {
await writeFile(join(dir, 'a.txt'), 'one\ntwo\nthree')
expect(await fs.readText(await fs.resolve('a.txt'))).toBe('one\ntwo\nthree')
})
it('streams the same text', async () => {
await writeFile(join(dir, 'a.txt'), 'one\ntwo\nthree')
const target = await fs.resolve('a.txt')
let streamed = ''
for await (const chunk of await fs.streamText(target)) streamed += chunk
expect(streamed).toBe('one\ntwo\nthree')
})
it('rejects a missing file, a directory, binary, and invalid UTF-8', async () => {
await expect(fs.readText(await fs.resolve('nope'))).rejects.toMatchObject({ code: 'FS_NOT_FOUND' })
await expect(fs.readText(await fs.resolve('.'))).rejects.toMatchObject({ code: 'FS_NOT_REGULAR_FILE' })
await writeFile(join(dir, 'bin'), Buffer.from([0x68, 0x00, 0x69]))
await expect(fs.readText(await fs.resolve('bin'))).rejects.toMatchObject({ code: 'FS_NOT_TEXT' })
await writeFile(join(dir, 'bad'), Buffer.from([0x68, 0xff, 0x69]))
await expect(fs.readText(await fs.resolve('bad'))).rejects.toMatchObject({ code: 'FS_NOT_TEXT' })
})
})
describe('writeText', () => {
it('createIfAbsent creates a new file', async () => {
const target = await fs.resolve('new.txt')
const outcome = await fs.write(target, 'fresh', exec())
const outcome = await fs.writeText(target, 'fresh', { kind: 'createIfAbsent' })
expect(outcome.operation).toBe('create')
expect(await readFile(join(dir, 'new.txt'), 'utf8')).toBe('fresh')
})
it('updates an existing file after reading it', async () => {
it('createIfAbsent rejects an existing file as FS_NOT_OBSERVED', async () => {
await writeFile(join(dir, 'a.txt'), 'old')
const owner = exec()
const target = await fs.resolve('a.txt')
await fs.read(target, READ_ALL, owner)
const outcome = await fs.write(target, 'new', owner)
await expect(fs.writeText(target, 'new', { kind: 'createIfAbsent' }))
.rejects.toMatchObject({ code: 'FS_NOT_OBSERVED' })
expect(await readFile(join(dir, 'a.txt'), 'utf8')).toBe('old')
})
it('replaceIfVersion replaces when the version matches', async () => {
await writeFile(join(dir, 'a.txt'), 'old')
const target = await fs.resolve('a.txt')
const outcome = await fs.writeText(target, 'new', { kind: 'replaceIfVersion', version: await versionOf(target) })
expect(outcome.operation).toBe('update')
expect(await readFile(join(dir, 'a.txt'), 'utf8')).toBe('new')
})
it('edits an existing file after reading it', async () => {
await writeFile(join(dir, 'a.txt'), 'hello world')
const owner = exec()
it('replaceIfVersion rejects a stale version', async () => {
await writeFile(join(dir, 'a.txt'), 'v1')
const target = await fs.resolve('a.txt')
await fs.read(target, READ_ALL, owner)
const outcome = await fs.edit(target, { oldString: 'world', newString: 'there', replaceAll: false }, owner)
expect(outcome.replacements).toBe(1)
expect(await readFile(join(dir, 'a.txt'), 'utf8')).toBe('hello there')
const stale = await versionOf(target)
await writeFile(join(dir, 'a.txt'), 'changed-externally')
await expect(fs.writeText(target, 'v2', { kind: 'replaceIfVersion', version: stale }))
.rejects.toMatchObject({ code: 'FS_STALE_VERSION' })
})
it('rejects an empty edit oldString through ctx.fs without hanging or changing the file', async () => {
await writeFile(join(dir, 'a.txt'), 'hello world')
const owner = exec()
it('replaceIfVersion rejects a deleted target as stale, without recreating it', async () => {
const path = join(dir, 'a.txt')
await writeFile(path, 'v1')
const target = await fs.resolve('a.txt')
await fs.read(target, READ_ALL, owner)
await expect(fs.edit(target, { oldString: '', newString: 'boom', replaceAll: false }, owner))
.rejects.toMatchObject({ code: 'FS_EDIT_NOT_FOUND' })
expect(await readFile(join(dir, 'a.txt'), 'utf8')).toBe('hello world')
const version = await versionOf(target)
await unlink(path)
await expect(fs.writeText(target, 'v2', { kind: 'replaceIfVersion', version }))
.rejects.toMatchObject({ code: 'FS_STALE_VERSION' })
await expect(stat(path)).rejects.toMatchObject({ code: 'ENOENT' })
})
it('propagates truncatedByBytes from a byte-capped read', async () => {
await writeFile(join(dir, 'big.txt'), Array.from({ length: 2000 }, () => 'y'.repeat(100)).join('\n'))
const outcome = await fs.read(await fs.resolve('big.txt'), READ_ALL, exec())
expect(outcome.truncatedByBytes).toBe(true)
expect(outcome.view).toBe('partial')
})
it('records an over-long-line read as partial, so write/edit stay blocked', async () => {
await writeFile(join(dir, 'long.txt'), 'x'.repeat(3000))
const owner = exec()
const target = await fs.resolve('long.txt')
const outcome = await fs.read(target, READ_ALL, owner)
expect(outcome.view).toBe('partial')
await expect(fs.write(target, 'new', owner)).rejects.toMatchObject({ code: 'FS_PARTIAL_OBSERVATION' })
await expect(
fs.edit(target, { oldString: 'x', newString: 'y', replaceAll: false }, owner),
).rejects.toMatchObject({ code: 'FS_PARTIAL_OBSERVATION' })
})
it('allows a follow-up edit without re-reading (write/edit refresh state)', async () => {
await writeFile(join(dir, 'a.txt'), 'a b')
const owner = exec()
const target = await fs.resolve('a.txt')
await fs.read(target, READ_ALL, owner)
await fs.edit(target, { oldString: 'a', newString: 'X', replaceAll: false }, owner)
await fs.edit(target, { oldString: 'b', newString: 'Y', replaceAll: false }, owner)
expect(await readFile(join(dir, 'a.txt'), 'utf8')).toBe('X Y')
it('rejects writing onto a directory', async () => {
const target = await fs.resolve('.')
await expect(fs.writeText(target, 'x', { kind: 'createIfAbsent' }))
.rejects.toMatchObject({ code: 'FS_NOT_REGULAR_FILE' })
})
it('releases per-target mutation locks after success and failure', async () => {
const target = await fs.resolve('a.txt')
await fs.write(target, 'created', exec())
await fs.writeText(target, 'created', { kind: 'createIfAbsent' })
expect(lockCount(fs)).toBe(0)
await expect(fs.write(target, 'blind overwrite', exec())).rejects.toMatchObject({ code: 'FS_NOT_OBSERVED' })
await expect(fs.writeText(target, 'again', { kind: 'createIfAbsent' }))
.rejects.toMatchObject({ code: 'FS_NOT_OBSERVED' })
expect(lockCount(fs)).toBe(0)
})
})
describe('read-before-write policy', () => {
it('rejects a blind overwrite of an existing file (no prior read)', async () => {
await writeFile(join(dir, 'a.txt'), 'old')
describe('editText', () => {
it('applies a literal edit at the matching version', async () => {
await writeFile(join(dir, 'a.txt'), 'hello world')
const target = await fs.resolve('a.txt')
await expect(fs.write(target, 'new', exec())).rejects.toMatchObject({ code: 'FS_NOT_OBSERVED' })
const outcome = await fs.editText(target, { oldString: 'world', newString: 'there', replaceAll: false }, { version: await versionOf(target) })
expect(outcome.replacements).toBe(1)
expect(await readFile(join(dir, 'a.txt'), 'utf8')).toBe('hello there')
})
it('rejects a write after only a partial read', async () => {
await writeFile(join(dir, 'a.txt'), 'one\ntwo')
const owner = exec()
it('checks the stale version BEFORE literal matching', async () => {
await writeFile(join(dir, 'a.txt'), 'hello world')
const target = await fs.resolve('a.txt')
await fs.read(target, { offset: 1, limit: 1 }, owner)
await expect(fs.write(target, 'new', owner)).rejects.toMatchObject({ code: 'FS_PARTIAL_OBSERVATION' })
const stale = await versionOf(target)
// Change the file so 'world' is gone — a stale edit must report STALE, not NOT_FOUND.
await writeFile(join(dir, 'a.txt'), 'goodbye')
await expect(fs.editText(target, { oldString: 'world', newString: 'there', replaceAll: false }, { version: stale }))
.rejects.toMatchObject({ code: 'FS_STALE_VERSION' })
})
it('rejects a write after a partial read when the file was deleted, without recreating it', async () => {
const path = join(dir, 'a.txt')
await writeFile(path, 'one\ntwo')
const owner = exec()
it('rejects a deleted target as stale (before matching)', async () => {
await writeFile(join(dir, 'a.txt'), 'hello')
const target = await fs.resolve('a.txt')
await fs.read(target, { offset: 1, limit: 1 }, owner)
await unlink(path)
await expect(fs.write(target, 'new', owner)).rejects.toMatchObject({ code: 'FS_STALE_VERSION' })
await expect(stat(path)).rejects.toMatchObject({ code: 'ENOENT' })
const version = await versionOf(target)
await unlink(join(dir, 'a.txt'))
await expect(fs.editText(target, { oldString: 'hello', newString: 'bye', replaceAll: false }, { version }))
.rejects.toMatchObject({ code: 'FS_STALE_VERSION' })
})
it('rejects an edit with no prior read (FS_NOT_OBSERVED)', async () => {
await writeFile(join(dir, 'a.txt'), 'old')
const target = await fs.resolve('a.txt')
await expect(fs.edit(target, { oldString: 'old', newString: 'new', replaceAll: false }, exec()))
.rejects.toMatchObject({ code: 'FS_NOT_OBSERVED' })
it('rejects a non-regular target', async () => {
const target = await fs.resolve('.')
await expect(fs.editText(target, { oldString: 'a', newString: 'b', replaceAll: false }, { version: FsVersion('v') }))
.rejects.toMatchObject({ code: 'FS_NOT_REGULAR_FILE' })
})
it('rejects invalid UTF-8 reads and edits without rewriting the file', async () => {
const path = join(dir, 'invalid-utf8.txt')
it('rejects zero matches and ambiguous matches at the right version', async () => {
await writeFile(join(dir, 'a.txt'), 'a a a')
const target = await fs.resolve('a.txt')
const version = await versionOf(target)
await expect(fs.editText(target, { oldString: 'z', newString: 'X', replaceAll: false }, { version }))
.rejects.toMatchObject({ code: 'FS_EDIT_NOT_FOUND' })
await expect(fs.editText(target, { oldString: 'a', newString: 'X', replaceAll: false }, { version }))
.rejects.toMatchObject({ code: 'FS_AMBIGUOUS_EDIT' })
})
it('replaces all matches with replaceAll', async () => {
await writeFile(join(dir, 'a.txt'), 'a a a')
const target = await fs.resolve('a.txt')
const outcome = await fs.editText(target, { oldString: 'a', newString: 'b', replaceAll: true }, { version: await versionOf(target) })
expect(outcome.replacements).toBe(3)
expect(await readFile(join(dir, 'a.txt'), 'utf8')).toBe('b b b')
})
it('rejects invalid UTF-8 without rewriting the file', async () => {
const path = join(dir, 'bad.txt')
const bytes = Buffer.from([0x68, 0xff, 0x69])
await writeFile(path, bytes)
const owner = exec()
const target = await fs.resolve('invalid-utf8.txt')
await expect(fs.read(target, READ_ALL, owner)).rejects.toMatchObject({ code: 'FS_NOT_TEXT' })
const existing = await probe(target.targetKey)
if (!existing) throw new Error('expected invalid UTF-8 fixture to exist')
await expect(
fs.applyEdit(target, { oldString: 'h', newString: 'H', replaceAll: false }, { version: existing.version }),
).rejects.toMatchObject({ code: 'FS_NOT_TEXT' })
const target = await fs.resolve('bad.txt')
const version = await versionOf(target)
await expect(fs.editText(target, { oldString: 'h', newString: 'H', replaceAll: false }, { version }))
.rejects.toMatchObject({ code: 'FS_NOT_TEXT' })
expect(await readFile(path)).toEqual(bytes)
})
})
describe('stale-version guard + concurrency (defensive class B)', () => {
it('rejects a write when the file changed since it was read', async () => {
await writeFile(join(dir, 'a.txt'), 'v1')
const owner = exec()
const target = await fs.resolve('a.txt')
await fs.read(target, READ_ALL, owner)
// An out-of-band change after the read.
await writeFile(join(dir, 'a.txt'), 'changed-externally')
await expect(fs.write(target, 'v2', owner)).rejects.toMatchObject({ code: 'FS_STALE_VERSION' })
})
it('rejects an observed write when the file was deleted after the read', async () => {
await writeFile(join(dir, 'a.txt'), 'v1')
const owner = exec()
const target = await fs.resolve('a.txt')
await fs.read(target, READ_ALL, owner)
await unlink(join(dir, 'a.txt')) // file vanishes; observed write must fail (not silently create)
await expect(fs.write(target, 'v2', owner)).rejects.toMatchObject({ code: 'FS_STALE_VERSION' })
})
it('two concurrent edits: one wins, the other is rejected as stale', async () => {
await writeFile(join(dir, 'a.txt'), 'base')
const owner = exec()
const target = await fs.resolve('a.txt')
await fs.read(target, READ_ALL, owner)
// Both edits captured the same recorded version; only one rename can match it.
const version = await versionOf(target)
const results = await Promise.allSettled([
fs.edit(target, { oldString: 'base', newString: 'one', replaceAll: false }, owner),
fs.edit(target, { oldString: 'base', newString: 'two', replaceAll: false }, owner),
fs.editText(target, { oldString: 'base', newString: 'one', replaceAll: false }, { version }),
fs.editText(target, { oldString: 'base', newString: 'two', replaceAll: false }, { version }),
])
const fulfilled = results.filter(r => r.status === 'fulfilled')
expect(results.filter(r => r.status === 'fulfilled')).toHaveLength(1)
const rejected = results.filter(r => r.status === 'rejected')
expect(fulfilled).toHaveLength(1)
expect(rejected).toHaveLength(1)
expect((rejected[0] as PromiseRejectedResult).reason).toMatchObject({ code: 'FS_STALE_VERSION' })
expect(lockCount(fs)).toBe(0)
})
})
describe('symlink targetKey identity (defensive class F)', () => {
it('a read via the real path authorizes an edit via the symlink path', async () => {
describe('symlink targetKey identity', () => {
it('two paths to the same file via a symlink share one version and write the real target', async () => {
await writeFile(join(dir, 'real.txt'), 'hello')
await symlink(join(dir, 'real.txt'), join(dir, 'link.txt'))
const owner = exec()
await fs.read(await fs.resolve('real.txt'), READ_ALL, owner)
// Edit through the link: same realpath → same targetKey → prior read counts.
const linkTarget = await fs.resolve('link.txt')
const outcome = await fs.edit(linkTarget, { oldString: 'hello', newString: 'bye', replaceAll: false }, owner)
expect(outcome.replacements).toBe(1)
expect(await readFile(join(dir, 'real.txt'), 'utf8')).toBe('bye') // link preserved, target written
})
const viaReal = await fs.resolve('real.txt')
const viaLink = await fs.resolve('link.txt')
expect(viaLink.targetKey).toBe(viaReal.targetKey)
it('write through a symlink preserves the link and writes the real target', async () => {
await writeFile(join(dir, 'real.txt'), 'hello')
await symlink(join(dir, 'real.txt'), join(dir, 'link.txt'))
const owner = exec()
const linkTarget = await fs.resolve('link.txt')
await fs.read(linkTarget, READ_ALL, owner)
await fs.write(linkTarget, 'replaced', owner)
expect(await readFile(join(dir, 'real.txt'), 'utf8')).toBe('replaced')
const version = await versionOf(viaReal)
await fs.editText(viaLink, { oldString: 'hello', newString: 'bye', replaceAll: false }, { version })
expect(await readFile(join(dir, 'real.txt'), 'utf8')).toBe('bye') // link preserved
})
it('a stale change is detected across both paths', async () => {
await writeFile(join(dir, 'real.txt'), 'hello')
await symlink(join(dir, 'real.txt'), join(dir, 'link.txt'))
const owner = exec()
await fs.read(await fs.resolve('real.txt'), READ_ALL, owner)
await writeFile(join(dir, 'real.txt'), 'changed') // out-of-band via real path
const linkTarget = await fs.resolve('link.txt')
await expect(fs.edit(linkTarget, { oldString: 'hello', newString: 'bye', replaceAll: false }, owner))
const viaReal = await fs.resolve('real.txt')
const stale = await versionOf(viaReal)
await writeFile(join(dir, 'real.txt'), 'changed')
const viaLink = await fs.resolve('link.txt')
await expect(fs.editText(viaLink, { oldString: 'hello', newString: 'bye', replaceAll: false }, { version: stale }))
.rejects.toMatchObject({ code: 'FS_STALE_VERSION' })
})
})
describe('non-regular targets', () => {
it('rejects writing onto a directory', async () => {
const target = await fs.resolve('.') // the cwd dir
await expect(fs.write(target, 'x', exec())).rejects.toMatchObject({ code: 'FS_NOT_REGULAR_FILE' })
})
it('applyEdit rejects a target that vanished after the read', async () => {
await writeFile(join(dir, 'a.txt'), 'hello')
const owner = exec()
const target = await fs.resolve('a.txt')
const version = (await fs.read(target, READ_ALL, owner)).version
await unlink(join(dir, 'a.txt'))
await expect(fs.applyEdit(target, { oldString: 'hello', newString: 'bye', replaceAll: false }, { version }))
.rejects.toMatchObject({ code: 'FS_NOT_FOUND' })
})
it('applyEdit rejects a non-regular target', async () => {
const target = await fs.resolve('.')
await expect(fs.applyEdit(target, { oldString: 'a', newString: 'b', replaceAll: false }, { version: 'v' }))
.rejects.toMatchObject({ code: 'FS_NOT_REGULAR_FILE' })
})
})
describe('HMR / disposal (defensive class D)', () => {
describe('HMR / disposal', () => {
it('disposing the fiber withdraws ctx.fs', async () => {
const local = new Context()
const fiber = await local.plugin(LocalFileSystem, { cwd: dir })
const localFiber = await local.plugin(LocalFileSystem, { cwd: dir })
expect(local.fs).toBeDefined()
await fiber.dispose()
await localFiber.dispose()
expect(local.fs).toBeUndefined()
})
it('a fresh provider does not inherit recorded file state', async () => {
await writeFile(join(dir, 'a.txt'), 'hello')
const local = new Context()
const owner = exec()
const fiber = await local.plugin(LocalFileSystem, { cwd: dir })
await (local.fs as LocalFileSystem).read(await local.fs.resolve('a.txt'), READ_ALL, owner)
await fiber.dispose()
await local.plugin(LocalFileSystem, { cwd: dir })
const fs2 = local.fs as LocalFileSystem
const target = await fs2.resolve('a.txt')
// Same owner object, but state was released on disposal.
await expect(fs2.edit(target, { oldString: 'hello', newString: 'bye', replaceAll: false }, owner))
.rejects.toMatchObject({ code: 'FS_NOT_OBSERVED' })
})
})