fix: complete workspace diagnostic adapters
This commit is contained in:
@@ -326,6 +326,24 @@ test("uses strict known-host SSH arguments and always closes the temporary tunne
|
||||
}
|
||||
});
|
||||
|
||||
test("provides a default bounded SSH factory through injected spawn and loopback allocation", async () => {
|
||||
const directory = await mkdtemp(join(tmpdir(), "thothii-diagnostic-"));
|
||||
const privateKeyFile = join(directory, "ssh-key");
|
||||
await writeFile(privateKeyFile, "test-key\n", { mode: 0o600 });
|
||||
const kill = vi.fn(() => true);
|
||||
const sshSpawn = vi.fn(() => ({ kill }));
|
||||
try {
|
||||
const adapter = createConcreteDiagnosticAdapters({ sshSpawn, reserveLoopbackPort: async () => 45432 } as any);
|
||||
await adapter.withSshTunnel({ sshHost: "bastion.example.test", sshPort: 22, sshUser: "tunnel", privateKeyFile, knownHostsFile: "/run/secrets/known-hosts", targetHost: "dwh.internal", targetPort: 5432, localHost: "127.0.0.1", localPort: 0, timeoutMs: 5000, signal: new AbortController().signal }, async () => undefined);
|
||||
expect(sshSpawn).toHaveBeenCalledWith(expect.arrayContaining([
|
||||
"StrictHostKeyChecking=yes", "UserKnownHostsFile=/run/secrets/known-hosts", "-L", "127.0.0.1:45432:dwh.internal:5432",
|
||||
]));
|
||||
expect(kill).toHaveBeenCalledWith("SIGTERM");
|
||||
} finally {
|
||||
await rm(directory, { recursive: true, force: true });
|
||||
}
|
||||
});
|
||||
|
||||
test("requires a matching embedding model vector and removes its unique write probe", async () => {
|
||||
const adapters = successfulAdapters();
|
||||
|
||||
@@ -454,6 +472,25 @@ test("requires an authenticated TLS database query before direct diagnostics suc
|
||||
}
|
||||
});
|
||||
|
||||
test("selects the vector index containing the declared vector column for direct metadata", async () => {
|
||||
const directory = await mkdtemp(join(tmpdir(), "thothii-diagnostic-"));
|
||||
const passwordFile = join(directory, "password");
|
||||
const caFile = join(directory, "ca.pem");
|
||||
await Promise.all([writeFile(passwordFile, "password\n"), writeFile(caFile, "test-ca\n")]);
|
||||
const query = vi.fn(async () => ({ rows: [{ dimensions: 768, distance: "cosine" }] }));
|
||||
const connect = vi.fn(async () => ({ query, end: vi.fn(async () => undefined) }));
|
||||
try {
|
||||
const result = await createConcreteDiagnosticAdapters({ databaseClient: { connect } } as any).inspectVector({
|
||||
transport: "pgvector_direct", host: "127.0.0.1", port: 5432, user: "reader", credentialFile: passwordFile, tlsCaFile: caFile,
|
||||
resource: { database: "postgres", schema: "vectors" }, collection: "clinical_documents", timeoutMs: 5000, signal: new AbortController().signal,
|
||||
});
|
||||
expect(query).toHaveBeenCalledWith(expect.stringContaining("a.attnum = ANY(i.indkey)"), ["vectors", "clinical_documents"]);
|
||||
expect(result).toMatchObject({ dimensions: 768, distance: "cosine" });
|
||||
} finally {
|
||||
await rm(directory, { recursive: true, force: true });
|
||||
}
|
||||
});
|
||||
|
||||
test("honors a declared unauthenticated REST diagnostic without reading a credential", async () => {
|
||||
const fetchSpy = vi.fn(async () => new Response(JSON.stringify({ database: "warehouse", schema: "datawarehouse" }), {
|
||||
status: 200, headers: { "content-type": "application/json" },
|
||||
@@ -472,6 +509,31 @@ test("honors a declared unauthenticated REST diagnostic without reading a creden
|
||||
}
|
||||
});
|
||||
|
||||
test("applies declared auth modes and rejects private CA files across vector REST paths", async () => {
|
||||
const directory = await mkdtemp(join(tmpdir(), "thothii-diagnostic-"));
|
||||
const keyFile = join(directory, "api-key");
|
||||
const caFile = join(directory, "ca.pem");
|
||||
await Promise.all([writeFile(keyFile, "writer-key\n", { mode: 0o600 }), writeFile(caFile, "private-ca\n")]);
|
||||
const fetchSpy = vi.fn(async () => new Response(JSON.stringify({ collection: "clinical_documents", dimensions: 768, distance: "cosine", model: "embed" }), { status: 200, headers: { "content-type": "application/json" } }));
|
||||
vi.stubGlobal("fetch", fetchSpy);
|
||||
const adapter = createConcreteDiagnosticAdapters();
|
||||
const signal = new AbortController().signal;
|
||||
try {
|
||||
await adapter.inspectVector({ transport: "rest_api", baseUrl: "https://vector.example.test", collection: "clinical_documents", timeoutMs: 1, signal, diagnostic: { method: "GET", path: "/metadata", auth: "none", response: { collection: "collection", dimensions: "dimensions", distance: "distance" } } });
|
||||
await adapter.probeEmbedding({ baseUrl: "https://embed.example.test", model: "embed", timeoutMs: 1, signal, credentialFile: keyFile, diagnostic: { method: "POST", path: "/embed", auth: "x-api-key", response: { model: "model", dimensions: "dimensions" } } });
|
||||
await adapter.writeDiagnosticRecord({ baseUrl: "https://vector.example.test", credentialFile: keyFile, collection: "clinical_documents", dimensions: 768, id: "diagnostic:test", timeoutMs: 1, signal, diagnostic: { method: "POST", path: "/probe", auth: "none" } });
|
||||
expect(fetchSpy.mock.calls[0]?.[1]).toMatchObject({ headers: {} });
|
||||
expect(fetchSpy.mock.calls[1]?.[1]).toMatchObject({ headers: { "x-api-key": "writer-key" } });
|
||||
expect(fetchSpy.mock.calls[2]?.[1]).toMatchObject({ headers: expect.not.objectContaining({ authorization: expect.anything() }) });
|
||||
await expect(adapter.inspectVector({ transport: "rest_api", baseUrl: "https://vector.example.test", credentialFile: keyFile, tlsCaFile: caFile, collection: "clinical_documents", timeoutMs: 1, signal, diagnostic: { method: "GET", path: "/metadata", auth: "bearer", response: { collection: "collection", dimensions: "dimensions", distance: "distance" } } })).rejects.toThrow("vector metadata adapter is unavailable");
|
||||
await expect(adapter.probeEmbedding({ baseUrl: "https://embed.example.test", credentialFile: keyFile, tlsCaFile: caFile, model: "embed", timeoutMs: 1, signal, diagnostic: { method: "POST", path: "/embed", auth: "bearer", response: { model: "model", dimensions: "dimensions" } } })).rejects.toThrow("embedding probe failed");
|
||||
await expect(adapter.removeDiagnosticRecord({ baseUrl: "https://vector.example.test", credentialFile: keyFile, tlsCaFile: caFile, collection: "clinical_documents", id: "diagnostic:test", dimensions: 768, timeoutMs: 1, signal, diagnostic: { method: "POST", path: "/probe", auth: "bearer" } })).rejects.toThrow("vector write adapter is unavailable");
|
||||
} finally {
|
||||
vi.unstubAllGlobals();
|
||||
await rm(directory, { recursive: true, force: true });
|
||||
}
|
||||
});
|
||||
|
||||
test("constructs the production diagnoser with the configured timeout and injected adapters", async () => {
|
||||
const adapters = successfulAdapters();
|
||||
|
||||
|
||||
Reference in New Issue
Block a user