Repository navigation
test(reborn): add runtime lane dispatch smoke coverage - #3109
serrrfirat merged 2 commits into
Conversation
There was a problem hiding this comment.
Code Review
This pull request introduces comprehensive integration tests for the MCP, Script, and WASM dispatch lanes, while updating test fixtures to use the 'untrusted' trust level. Feedback identifies a trust level inconsistency in a manifest, a potential resource exhaustion vulnerability where expensive WASM compilation occurs before resource reservation, and resource leaks in test helpers due to the use of .keep() on temporary directories.
| name = "GitHub MCP" | ||
| version = "0.1.0" | ||
| description = "GitHub MCP adapter" | ||
| trust = "third_party" |
There was a problem hiding this comment.
| let prepared = self | ||
| .runtime | ||
| .prepare(request.capability_id.as_str(), &wasm_bytes) | ||
| .map_err(|error| DispatchError::Wasm { | ||
| kind: wasm_error_kind(&error), | ||
| })?; |
There was a problem hiding this comment.
Expensive WASM preparation (compilation) is performed before checking or creating a resource reservation. This is inconsistent with the MCP and Script lanes, and could allow a burst of requests to exhaust host CPU/memory during the compilation phase before the governor can apply concurrency limits. Consider moving the reservation logic to the beginning of dispatch_json.
References
- Prioritize addressing contention and resource exhaustion issues, as these are considered high-priority correctness concerns.
| } | ||
|
|
||
| fn mounted_empty_extension_root() -> LocalFilesystem { | ||
| let storage = tempfile::tempdir().unwrap().keep(); |
There was a problem hiding this comment.
Using .keep() on a TempDir prevents the directory from being deleted when the test finishes, leading to resource leaks in the /tmp directory. Consider returning the TempDir from this helper and binding it in the test function to manage its lifetime without leaking.
References
- Encapsulate complex logic within helper functions and expose a simpler interface or data structure tailored to the caller's needs, such as returning resource handles to the caller for lifetime management.
| } | ||
|
|
||
| fn mounted_empty_extension_root() -> LocalFilesystem { | ||
| let storage = tempfile::tempdir().unwrap().keep(); |
There was a problem hiding this comment.
Using .keep() on a TempDir prevents the directory from being deleted when the test finishes, leading to resource leaks in the /tmp directory. Consider returning the TempDir from this helper and binding it in the test function to manage its lifetime without leaking.
References
- Encapsulate complex logic within helper functions and expose a simpler interface or data structure tailored to the caller's needs, such as returning resource handles to the caller for lifetime management.
| } | ||
|
|
||
| fn mounted_empty_extension_root() -> LocalFilesystem { | ||
| let storage = tempfile::tempdir().unwrap().keep(); |
There was a problem hiding this comment.
Using .keep() on a TempDir prevents the directory from being deleted when the test finishes, leading to resource leaks in the /tmp directory. Consider returning the TempDir from this helper and binding it in the test function to manage its lifetime without leaking.
References
- Encapsulate complex logic within helper functions and expose a simpler interface or data structure tailored to the caller's needs, such as returning resource handles to the caller for lifetime management.
* test(reborn): add runtime lane dispatch smoke coverage * test(reborn): harden runtime lane smoke coverage
Summary
Implements issue #3067 Phase 2 runtime-lane smoke coverage now that Script/MCP (#3027) and WIT WASM (#3097) are both on
reborn-integration.Adds caller-level tests that drive each real runtime lane through the public
RuntimeDispatcher/RuntimeAdapterseam instead of only through crate-local runtime contracts:crates/ironclaw_scripts/tests/script_dispatch_integration.rscrates/ironclaw_mcp/tests/mcp_dispatch_integration.rscrates/ironclaw_wasm/tests/wasm_dispatch_integration.rsRootFilesystemvirtual pathsAlso updates stale dispatcher test fixtures from obsolete
trust = "sandbox"totrust = "untrusted", matching the current manifest parser.Verification
Links