mirror of
https://github.com/Jeuners/ECC.git
synced 2026-09-12 08:22:29 +02:00
feat(ito): expose guarded live node qualification
Expose the canonical Itō CLI's pinned sixtytwo node-qualification path through ECC with double opt-in, explicit node/config gates, credential isolation, and no new MCP or execution authority. Validated across the full Linux, macOS, and Windows Node/package-manager matrix, hosted coverage, CodeQL, security, lint, and focused bridge tests.
This commit is contained in:
parent
34fbe007f0
commit
33c7dbb7d6
11 changed files with 384 additions and 42 deletions
|
|
@ -13,7 +13,15 @@ const { spawnSync } = require("child_process");
|
|||
|
||||
const REPO_ROOT = path.join(__dirname, "..", "..");
|
||||
const ECC_SCRIPT = path.join(REPO_ROOT, "scripts", "ecc.js");
|
||||
const ITO_SCRIPT = path.join(REPO_ROOT, "scripts", "ito.js");
|
||||
const CANONICAL_PACKAGE = "Ito-Markets/ito-cloud-runtime/cli/ito-compute-cli";
|
||||
const {
|
||||
NODE_QUALIFICATION_TIMEOUT_MS,
|
||||
} = require("../../scripts/ito");
|
||||
const {
|
||||
createSafeItoInvocationEnvironment,
|
||||
getInvocationCommand,
|
||||
} = require("../../scripts/lib/ito-environment");
|
||||
|
||||
function runCli(args, environment = {}) {
|
||||
return spawnSync(process.execPath, [ECC_SCRIPT, ...args], {
|
||||
|
|
@ -80,7 +88,7 @@ function main() {
|
|||
console.log("\n=== Testing ECC × Itô real CLI bridge ===\n");
|
||||
|
||||
const tests = [
|
||||
["forwards only auth, find, and status to an explicit local executable", () => {
|
||||
["forwards only the reviewed RFQ CLI surface to an explicit local executable", () => {
|
||||
for (const command of ["auth", "find", "status"]) {
|
||||
const probe = makeItoProbe();
|
||||
try {
|
||||
|
|
@ -152,15 +160,192 @@ function main() {
|
|||
fs.rmSync(probe.directory, { recursive: true, force: true });
|
||||
}
|
||||
}],
|
||||
["rejects unsupported, browser, simulated, and node operations before spawning", () => {
|
||||
for (const command of ["rent", "lock", "run", "inference", "evals", "mcp"]) {
|
||||
["isolates live node qualification from Itô and unrelated credentials", () => {
|
||||
const probe = makeItoProbe();
|
||||
try {
|
||||
const configDirectory = path.join(probe.directory, "qualification");
|
||||
fs.mkdirSync(configDirectory);
|
||||
fs.writeFileSync(path.join(configDirectory, "sixtytwo.yaml"), "suite: full\n");
|
||||
const result = runCli([
|
||||
"ito",
|
||||
"evals",
|
||||
"--cluster", "clu_prod_example",
|
||||
"--live-sixtytwo",
|
||||
"--nodes", "gpu-01,gpu-02",
|
||||
"--config-dir", configDirectory,
|
||||
], {
|
||||
ECC_ITO_CLI_EXECUTABLE: probe.executable,
|
||||
ITO_API_KEY: "must-not-cross-into-node-qualification",
|
||||
ITO_API_URL: "https://compute.example.test",
|
||||
ITO_INVENTORY_URL: "https://edge.example.test",
|
||||
ITO_ENABLE_SIXTYTWO_LIVE: "1",
|
||||
SIXTYTWO_API_TOKEN: "sixtytwo-test-token",
|
||||
SIXTYTWO_TOKEN: "sixtytwo-legacy-test-token",
|
||||
SSH_AUTH_SOCK: "/tmp/ecc-test-agent.sock",
|
||||
ITO_CLI_DEMO: "1",
|
||||
ITO_CLI_STATE_DIR: "/tmp/forbidden-paper-state",
|
||||
AWS_SECRET_ACCESS_KEY: "must-not-cross",
|
||||
OPENAI_API_KEY: "must-not-cross",
|
||||
});
|
||||
assert.strictEqual(result.status, 0, result.stderr);
|
||||
const invocation = readInvocation(probe);
|
||||
assert.deepStrictEqual(invocation.argv, [
|
||||
"evals",
|
||||
"--cluster", "clu_prod_example",
|
||||
"--live-sixtytwo",
|
||||
"--nodes", "gpu-01,gpu-02",
|
||||
"--config-dir", configDirectory,
|
||||
]);
|
||||
assert.strictEqual(invocation.env.ITO_ENABLE_SIXTYTWO_LIVE, "1");
|
||||
assert.strictEqual(invocation.env.SIXTYTWO_API_TOKEN, "sixtytwo-test-token");
|
||||
assert.strictEqual(invocation.env.SIXTYTWO_TOKEN, "sixtytwo-legacy-test-token");
|
||||
assert.strictEqual(invocation.env.SSH_AUTH_SOCK, "/tmp/ecc-test-agent.sock");
|
||||
assert.strictEqual(invocation.env.ITO_API_KEY, undefined);
|
||||
assert.strictEqual(invocation.env.ITO_API_URL, undefined);
|
||||
assert.strictEqual(invocation.env.ITO_INVENTORY_URL, undefined);
|
||||
assert.strictEqual(invocation.env.ITO_CLI_DEMO, undefined);
|
||||
assert.strictEqual(invocation.env.ITO_CLI_STATE_DIR, undefined);
|
||||
assert.strictEqual(invocation.env.AWS_SECRET_ACCESS_KEY, undefined);
|
||||
assert.strictEqual(invocation.env.OPENAI_API_KEY, undefined);
|
||||
} finally {
|
||||
fs.rmSync(probe.directory, { recursive: true, force: true });
|
||||
}
|
||||
}],
|
||||
["rejects every incomplete live qualification before spawning", () => {
|
||||
const validArgs = [
|
||||
"ito",
|
||||
"evals",
|
||||
"--cluster", "clu_prod_example",
|
||||
"--live-sixtytwo",
|
||||
"--nodes", "gpu-01,gpu-02",
|
||||
];
|
||||
const cases = [
|
||||
{
|
||||
label: "missing environment opt-in",
|
||||
args: [...validArgs, "--config-dir", "__CONFIG__"],
|
||||
env: {},
|
||||
error: /ITO_ENABLE_SIXTYTWO_LIVE=1/,
|
||||
},
|
||||
{
|
||||
label: "missing live flag",
|
||||
args: validArgs.filter((value) => value !== "--live-sixtytwo")
|
||||
.concat("--config-dir", "__CONFIG__"),
|
||||
env: { ITO_ENABLE_SIXTYTWO_LIVE: "1" },
|
||||
error: /--live-sixtytwo/,
|
||||
},
|
||||
{
|
||||
label: "missing nodes",
|
||||
args: [
|
||||
"ito", "evals",
|
||||
"--cluster", "clu_prod_example",
|
||||
"--live-sixtytwo",
|
||||
"--config-dir", "__CONFIG__",
|
||||
],
|
||||
env: { ITO_ENABLE_SIXTYTWO_LIVE: "1" },
|
||||
error: /--nodes/,
|
||||
},
|
||||
{
|
||||
label: "empty node list",
|
||||
args: [
|
||||
"ito", "evals",
|
||||
"--cluster", "clu_prod_example",
|
||||
"--live-sixtytwo",
|
||||
"--nodes", ",",
|
||||
"--config-dir", "__CONFIG__",
|
||||
],
|
||||
env: { ITO_ENABLE_SIXTYTWO_LIVE: "1" },
|
||||
error: /--nodes/,
|
||||
},
|
||||
{
|
||||
label: "missing cluster",
|
||||
args: [
|
||||
"ito", "evals",
|
||||
"--live-sixtytwo",
|
||||
"--nodes", "gpu-01",
|
||||
"--config-dir", "__CONFIG__",
|
||||
],
|
||||
env: { ITO_ENABLE_SIXTYTWO_LIVE: "1" },
|
||||
error: /--cluster/,
|
||||
},
|
||||
{
|
||||
label: "relative config directory",
|
||||
args: [...validArgs, "--config-dir", "relative/config"],
|
||||
env: { ITO_ENABLE_SIXTYTWO_LIVE: "1" },
|
||||
error: /absolute/,
|
||||
},
|
||||
{
|
||||
label: "missing config directory",
|
||||
args: [...validArgs, "--config-dir", "__MISSING_CONFIG__"],
|
||||
env: { ITO_ENABLE_SIXTYTWO_LIVE: "1" },
|
||||
error: /sixtytwo\.yaml/,
|
||||
},
|
||||
];
|
||||
|
||||
for (const testCase of cases) {
|
||||
const probe = makeItoProbe();
|
||||
try {
|
||||
const configDirectory = path.join(probe.directory, "qualification");
|
||||
fs.mkdirSync(configDirectory);
|
||||
fs.writeFileSync(path.join(configDirectory, "sixtytwo.yaml"), "suite: full\n");
|
||||
const args = testCase.args.map((value) => (
|
||||
value === "__CONFIG__"
|
||||
? configDirectory
|
||||
: value === "__MISSING_CONFIG__"
|
||||
? path.join(probe.directory, "missing")
|
||||
: value
|
||||
));
|
||||
const result = runCli(args, {
|
||||
ECC_ITO_CLI_EXECUTABLE: probe.executable,
|
||||
...testCase.env,
|
||||
});
|
||||
assert.notStrictEqual(result.status, 0, testCase.label);
|
||||
assert.match(result.stderr, testCase.error, testCase.label);
|
||||
assert.ok(
|
||||
!fs.existsSync(probe.log),
|
||||
`${testCase.label} must not spawn the canonical Itô CLI`,
|
||||
);
|
||||
} finally {
|
||||
fs.rmSync(probe.directory, { recursive: true, force: true });
|
||||
}
|
||||
}
|
||||
}],
|
||||
["classifies Itō child environments once and fails closed on unknown prefixes", () => {
|
||||
const safe = createSafeItoInvocationEnvironment(
|
||||
{
|
||||
PATH: process.env.PATH,
|
||||
ECC_ITO_CLI_EXECUTABLE: "/operator/canonical/ito.js",
|
||||
ITO_API_KEY: "must-not-cross",
|
||||
SIXTYTWO_TOKEN: "must-not-cross",
|
||||
},
|
||||
["--future-ecc-flag", "evals"],
|
||||
{ includeControls: true },
|
||||
);
|
||||
assert.strictEqual(safe.ECC_ITO_CLI_EXECUTABLE, "/operator/canonical/ito.js");
|
||||
assert.strictEqual(safe.ITO_API_KEY, undefined);
|
||||
assert.strictEqual(safe.SIXTYTWO_TOKEN, undefined);
|
||||
}],
|
||||
["detects the Itō command consistently with or without the global JSON flag", () => {
|
||||
assert.strictEqual(getInvocationCommand(["auth"]), "auth");
|
||||
assert.strictEqual(getInvocationCommand(["--json", "evals"]), "evals");
|
||||
assert.strictEqual(getInvocationCommand([]), undefined);
|
||||
}],
|
||||
["bounds the outer node-qualification process beyond the canonical timeout", () => {
|
||||
assert.strictEqual(NODE_QUALIFICATION_TIMEOUT_MS, 31 * 60 * 1000);
|
||||
const source = fs.readFileSync(ITO_SCRIPT, "utf8");
|
||||
assert.match(
|
||||
source,
|
||||
/timeout: isNodeQualification \? NODE_QUALIFICATION_TIMEOUT_MS : undefined/,
|
||||
);
|
||||
}],
|
||||
["rejects unsupported browser, paper, and execution operations before spawning", () => {
|
||||
for (const command of ["rent", "lock", "run", "inference", "mcp"]) {
|
||||
const probe = makeItoProbe();
|
||||
try {
|
||||
const result = runCli(["ito", command], {
|
||||
ECC_ITO_CLI_EXECUTABLE: probe.executable,
|
||||
});
|
||||
assert.notStrictEqual(result.status, 0, command);
|
||||
assert.match(result.stderr, /only auth, find, and status/i);
|
||||
assert.match(result.stderr, /only auth, find, status, and evals/i);
|
||||
assert.ok(!fs.existsSync(probe.log), `${command} must not spawn the Itô CLI`);
|
||||
} finally {
|
||||
fs.rmSync(probe.directory, { recursive: true, force: true });
|
||||
|
|
@ -335,6 +520,8 @@ function main() {
|
|||
assert.match(result.stdout, /ecc ito auth/);
|
||||
assert.match(result.stdout, /ecc ito find/);
|
||||
assert.match(result.stdout, /ecc ito status/);
|
||||
assert.match(result.stdout, /ecc ito evals/);
|
||||
assert.match(result.stdout, /sixtytwo/i);
|
||||
assert.match(result.stdout, /ito_auth/);
|
||||
assert.match(result.stdout, /ito_find/);
|
||||
assert.match(result.stdout, /ito_status/);
|
||||
|
|
|
|||
|
|
@ -142,8 +142,10 @@ function main() {
|
|||
assert.match(record, /-> any open-source model/);
|
||||
assert.doesNotMatch(record, /public Kimi|Moonshot|video and sponsorship/i);
|
||||
assert.match(record, /Status: \*\*Implemented local CLI bridge/i);
|
||||
assert.match(record, /auth`, `find`, and `status/);
|
||||
assert.match(record, /auth`, `find`, `status`, and `evals/);
|
||||
assert.match(record, /ito_auth`, `ito_find`, and `ito_status/);
|
||||
assert.match(record, /sixtytwo-cli==0\.3\.33/);
|
||||
assert.match(record, /explicit node/i);
|
||||
assert.match(record, /unpublished/i);
|
||||
assert.match(record, /managed inference remains unavailable/i);
|
||||
assert.match(record, /version bump[\s\S]*intentionally deferred/i);
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue