Files
wehub-resource-sync 23f7624596
ADR-166 MCP Bridge Security Lock / Static-source security lock (push) Failing after 0s
ADR-166 MCP Bridge Security Lock / Compose default binds loopback + Mongo has auth (push) Failing after 2s
CodeQL Advanced / Analyze (rust) (push) Failing after 0s
ADR-166 MCP Bridge Security Lock / plugin-agent-federation bindHost default (push) Failing after 1s
ADR-166 MCP Bridge Security Lock / Runtime behavior — 401 + terminal gate + fail-closed (push) Failing after 4s
business-pods-smoke / smoke (push) Failing after 1s
all-plugins-smoke / smoke-all (push) Failing after 2s
CI/CD Pipeline / Security & Code Quality (push) Failing after 1s
CI/CD Pipeline / Test Suite (ubuntu-latest) (push) Failing after 1s
CI/CD Pipeline / Build & Package (macos-latest) (push) Has been skipped
CI/CD Pipeline / Build & Package (ubuntu-latest) (push) Has been skipped
CI/CD Pipeline / Build & Package (windows-latest) (push) Has been skipped
CI/CD Pipeline / Documentation & Examples (push) Failing after 1s
Clone Tracker (14-day rolling) / Snapshot clones for ruflo ecosystem (push) Failing after 1s
CodeQL Advanced / Analyze (actions) (push) Failing after 1s
CodeQL Advanced / Analyze (javascript-typescript) (push) Failing after 1s
federation-peer-rust / stable-noop (push) Failing after 1s
metaharness-ci / score (push) Failing after 1s
metaharness-ci / router-compat (push) Failing after 0s
metaharness-ci / similarity-tests (push) Failing after 0s
no-agentbbs-smoke / smoke-without-agentbbs (push) Failing after 1s
V3 CI/CD Pipeline / Build V3 (windows-latest) (push) Has been skipped
codex-integration-audit / Codex integration audit (push) Failing after 1s
helpers-manifest-guard / guard (push) Failing after 1s
🔗 Cross-Agent Integration Tests / 🤝 Agent Coordination Tests (push) Has been skipped
🔗 Cross-Agent Integration Tests / 🧠 Memory Sharing Integration (push) Has been skipped
🔗 Cross-Agent Integration Tests / 🛡️ Fault Tolerance Tests (push) Has been skipped
🔗 Cross-Agent Integration Tests / ⚡ Performance Integration Tests (push) Has been skipped
metaharness-ci / mcp-scan (push) Failing after 1s
metaharness-ci / eject-dryrun (push) Failing after 1s
metaharness-ci / metaharness-real-data (push) Failing after 0s
no-cli-optdep-bloat-2561 / guard (push) Failing after 1s
no-metaharness-smoke / smoke-without-metaharness (push) Failing after 1s
no-phantom-agentic-flow-subpath / guard (push) Failing after 1s
🔄 Automated Rollback Manager / 🚨 Failure Detection (push) Failing after 1s
V3 CI/CD Pipeline / Plugin hooks smoke / ubuntu-latest / Node 22 (push) Failing after 1s
V3 CI/CD Pipeline / ruflo-graph-intelligence build + test smoke (#2044, ADR-123) (push) Failing after 1s
CVE Audit Gate / Audit root (critical-blocking) (push) Failing after 2s
cost-tracker-smoke / smoke (push) Failing after 3s
oia-audit-weekly / audit (push) Failing after 2s
ruflo-agent-smoke / ruflo-agent structural smoke (push) Failing after 1s
📊 Status Badges Update / 📊 Update Status Badges (push) Failing after 1s
V3 CI/CD Pipeline / Static regression guards (#2267 YAML + (push) Failing after 1s
V3 CI/CD Pipeline / Test V3 Packages (push) Failing after 0s
V3 CI/CD Pipeline / agent_execute provider routing smoke (#2042) (push) Failing after 0s
CVE Audit Gate / Audit v3 (critical-blocking) (push) Failing after 1s
federation-peer-rust / stable-native (push) Failing after 2s
🔗 Cross-Agent Integration Tests / 🚀 Integration Test Setup (push) Failing after 2s
neural-trader-smoke / runtime-smoke (push) Failing after 1s
V3 CI/CD Pipeline / Build V3 (macos-latest) (push) Has been skipped
V3 CI/CD Pipeline / Build V3 (ubuntu-latest) (push) Has been skipped
V3 CI/CD Pipeline / Type Check V3 (push) Failing after 1s
V3 CI/CD Pipeline / Smoke (no better-sqlite3) / ubuntu-latest / Node 24 (push) Failing after 1s
V3 CI/CD Pipeline / Smoke (no better-sqlite3) / ubuntu-latest / Node 22 (push) Failing after 2s
V3 CI/CD Pipeline / browser rvf create flag smoke (#2015) (push) Failing after 0s
V3 CI/CD Pipeline / Dependency review (#2046) (push) Has been skipped
V3 CI/CD Pipeline / Supply-chain audit (#2046) (push) Failing after 0s
V3 CI/CD Pipeline / witness marker drift smoke (#2021) (push) Failing after 1s
V3 CI/CD Pipeline / neural-trader portfolio CG smoke (#2068, ADR-126 Phase 3) (push) Failing after 1s
V3 CI/CD Pipeline / neural-trader backtest signing smoke (#2068, ADR-126 Phase 4) (push) Failing after 1s
V3 CI/CD Pipeline / kg-extract type-import classification smoke (#2049) (push) Failing after 0s
V3 CI/CD Pipeline / witness verify precondition smoke (#1880) (push) Failing after 2s
V3 CI/CD Pipeline / neural-trader pipeline risk-gate smoke (#2068, ADR-126 Phase 5) (push) Failing after 0s
V3 CI/CD Pipeline / neural-trader feature attribution smoke (#2068, ADR-126 Phase 6) (push) Failing after 0s
V3 CI/CD Pipeline / plugin-registry signature verification smoke (#1922, CWE-347) (push) Failing after 4s
V3 CI/CD Pipeline / memory stats legacy-DB smoke (#2120) (push) Failing after 4s
V3 CI/CD Pipeline / github deprecated actions smoke (#2089, ADR-127 Phase 3) (push) Failing after 1s
V3 CI/CD Pipeline / graph query + pathfinder smoke (ADR-130 P2+P5) (push) Has been skipped
V3 CI/CD Pipeline / graph trajectory hooks smoke (ADR-130 P3) (push) Has been skipped
V3 CI/CD Pipeline / graph plugin adapter smoke (ADR-130 P4) (push) Has been skipped
V3 CI/CD Pipeline / graph benchmark (ADR-130 P6) (push) Has been skipped
V3 CI/CD Pipeline / statusline generator delegation smoke (#2195) (push) Failing after 1s
V3 CI/CD Pipeline / wizard init regression guard (#2206 (push) Failing after 1s
V3 CI/CD Pipeline / memory no-stray-db smoke (ADR-125 P7) (push) Failing after 1s
V3 CI/CD Pipeline / github-safe injection smoke (#2089, ADR-127 Phase 1) (push) Failing after 1s
V3 CI/CD Pipeline / github actions pin smoke (#2089, ADR-127 Phase 1) (push) Failing after 1s
V3 CI/CD Pipeline / github attribution opt-in smoke (#2089, ADR-127 Phase 4) (push) Failing after 1s
V3 CI/CD Pipeline / pre-bash hook safety smoke (#2017) (push) Failing after 1s
V3 CI/CD Pipeline / Memory import smoke / ubuntu-latest (push) Failing after 0s
V3 CI/CD Pipeline / MCP protocol smoke / ubuntu-latest (push) Failing after 2s
V3 CI/CD Pipeline / ruvllm WASM auto-init smoke (#2086) (push) Failing after 4s
V3 CI/CD Pipeline / MCP paired-tool round-trip smoke (#1889) (push) Failing after 1s
V3 CI/CD Pipeline / Plugin package install-safety (#1902/#1903/#1904) (push) Failing after 1s
V3 CI/CD Pipeline / Tool description discoverability (ADR-112) (push) Failing after 3s
V3 CI/CD Pipeline / CLI npx-install smoke (#1147 / (22) (push) Failing after 1s
V3 CI/CD Pipeline / CLI npx-install smoke (#1147 / (24) (push) Failing after 1s
V3 CI/CD Pipeline / Windows hook shim smoke (#2132) / ubuntu-latest (push) Failing after 2s
V3 CI/CD Pipeline / Windows hook execution smoke (#2132) / ubuntu-latest (push) Failing after 1s
V3 CI/CD Pipeline / Windows init hooks smoke (#2132) / ubuntu-latest (push) Failing after 1s
V3 CI/CD Pipeline / Vector-index dimension audit (#1947) (push) Failing after 0s
V3 CI/CD Pipeline / Hook-command install safety (#1921) (push) Failing after 1s
V3 CI/CD Pipeline / ToolOutputGuardrail smoke (ADR-131, (push) Failing after 1s
V3 CI/CD Pipeline / init-bundle invariants smoke (#2095, ADR-128 Phase 5) (push) Failing after 1s
V3 CI/CD Pipeline / wasm provider bridge smoke (ADR-129 P1) (push) Failing after 2s
V3 CI/CD Pipeline / wasm gallery CRUD smoke (ADR-129 P3) (push) Failing after 1s
V3 CI/CD Pipeline / wasm plugin bridge smoke (ADR-129 P4) (push) Failing after 0s
V3 CI/CD Pipeline / wasm compose smoke (ADR-129 P2) (push) Failing after 4s
V3 CI/CD Pipeline / graph schema smoke (ADR-130 P1) (push) Failing after 0s
Validate Marketplace / validate (push) Failing after 1s
🔍 Verification Pipeline / 🚀 Setup Verification (push) Failing after 1s
🔍 Verification Pipeline / 🛡️ Security Verification (push) Has been skipped
🔍 Verification Pipeline / 📝 Code Quality (push) Has been skipped
🔍 Verification Pipeline / 🧪 Test Verification (${{ matrix.os }}, Node ${{ matrix.node }}) (push) Has been skipped
🔍 Verification Pipeline / 🏗️ Build Verification (push) Has been skipped
🔍 Verification Pipeline / 📚 Documentation Verification (push) Has been skipped
CVE Audit Gate / High-severity report (warn only) (push) Has been cancelled
🔄 Automated Rollback Manager / 🔄 Execute Rollback (push) Has been cancelled
🔄 Automated Rollback Manager / ✅ Post-Rollback Verification (push) Has been cancelled
🔄 Automated Rollback Manager / 📊 Rollback Monitoring (push) Has been cancelled
V3 CI/CD Pipeline / Windows init hooks smoke (#2132) / windows-latest (push) Has been cancelled
V3 CI/CD Pipeline / Windows hook execution smoke (#2132) / macos-latest (push) Has been cancelled
V3 CI/CD Pipeline / Windows hook execution smoke (#2132) / windows-latest (push) Has been cancelled
🔄 Automated Rollback Manager / ⏳ Manual Rollback Approval (push) Has been cancelled
V3 CI/CD Pipeline / MCP protocol smoke / macos-latest (push) Has been cancelled
V3 CI/CD Pipeline / Memory import smoke / macos-latest (push) Has been cancelled
V3 CI/CD Pipeline / Windows hook shim smoke (#2132) / macos-latest (push) Has been cancelled
V3 CI/CD Pipeline / Windows hook shim smoke (#2132) / windows-latest (push) Has been cancelled
V3 CI/CD Pipeline / Windows init hooks smoke (#2132) / macos-latest (push) Has been cancelled
V3 CI/CD Pipeline / Witness verify (signed manifest) / macos-latest (push) Has been cancelled
V3 CI/CD Pipeline / Witness verify (signed manifest) / ubuntu-latest (push) Has been cancelled
V3 CI/CD Pipeline / Witness verify (signed manifest) / windows-latest (push) Has been cancelled
V3 CI/CD Pipeline / Publish to npm (alpha) (push) Has been cancelled
V3 CI/CD Pipeline / Smoke (no better-sqlite3) / macos-latest / Node 22 (push) Has been cancelled
V3 CI/CD Pipeline / Plugin hooks smoke / macos-latest / Node 22 (push) Has been cancelled
CI/CD Pipeline / Deploy & Release (push) Has been cancelled
CI/CD Pipeline / CI Status (push) Has been cancelled
🔗 Cross-Agent Integration Tests / 📊 Integration Test Report (push) Has been cancelled
🔄 Automated Rollback Manager / 🔍 Pre-Rollback Validation (push) Has been cancelled
🔍 Verification Pipeline / ⚡ Performance Verification (push) Has been cancelled
🔍 Verification Pipeline / 📊 Verification Report (push) Has been cancelled
chore: import upstream snapshot with attribution
2026-07-13 12:02:19 +08:00

247 lines
9.7 KiB
TypeScript

/**
* A2A Agent Card adapter tests — generation (FederationManifest → card,
* golden-file), validation (A2A 1.0 §4.4.1 required fields), and
* consumption (card → bespoke federation registry shape).
*/
import { describe, it, expect } from 'vitest';
import { readFileSync } from 'node:fs';
import { join, dirname } from 'node:path';
import { fileURLToPath } from 'node:url';
import {
toAgentCard,
fromAgentCard,
validateAgentCard,
A2A_PROTOCOL_VERSION,
A2A_WELL_KNOWN_PATH,
RUFLO_FEDERATION_BINDING,
RUFLO_FEDERATION_EXTENSION_URI,
type A2AAgentCard,
} from '../../src/a2a/agent-card.js';
import { DiscoveryService } from '../../src/domain/services/discovery-service.js';
import { TrustLevel } from '../../src/domain/entities/trust-level.js';
import type { FederationManifest } from '../../src/domain/services/discovery-service.js';
const FIXTURES = join(dirname(fileURLToPath(import.meta.url)), '..', 'fixtures');
function goldenCard(): A2AAgentCard {
return JSON.parse(readFileSync(join(FIXTURES, 'a2a-agent-card.golden.json'), 'utf-8'));
}
function makeManifest(overrides: Partial<FederationManifest> = {}): FederationManifest {
return {
nodeId: 'node-golden',
publicKey: 'aabbccddeeff',
endpoint: 'ws://127.0.0.1:9100',
capabilities: {
agentTypes: ['coder', 'reviewer'],
maxConcurrentSessions: 5,
supportedProtocols: ['websocket', 'http'],
complianceModes: ['hipaa'],
},
version: '1.0.0-alpha.16',
signature: 'sig-golden',
timestamp: '2026-07-03T00:00:00.000Z',
...overrides,
};
}
describe('A2A constants', () => {
it('targets A2A protocol 1.0 at the spec well-known path', () => {
expect(A2A_PROTOCOL_VERSION).toBe('1.0');
// 0.3.0+ renamed agent.json → agent-card.json; 1.0 keeps agent-card.json
expect(A2A_WELL_KNOWN_PATH).toBe('/.well-known/agent-card.json');
});
});
describe('toAgentCard', () => {
it('matches the golden card byte-for-byte (deep equal)', () => {
expect(toAgentCard(makeManifest())).toEqual(goldenCard());
});
it('produces a card that passes its own spec validation', () => {
const result = validateAgentCard(toAgentCard(makeManifest()));
expect(result.errors).toEqual([]);
expect(result.valid).toBe(true);
});
it('includes every A2A 1.0 REQUIRED field', () => {
const card = toAgentCard(makeManifest());
// spec §4.4.1 required: name, description, supportedInterfaces, version,
// capabilities, defaultInputModes, defaultOutputModes, skills
expect(card.name).toBeTruthy();
expect(card.description).toBeTruthy();
expect(card.supportedInterfaces.length).toBeGreaterThan(0);
expect(card.version).toBeTruthy();
expect(card.capabilities).toBeTypeOf('object');
expect(card.defaultInputModes.length).toBeGreaterThan(0);
expect(card.defaultOutputModes.length).toBeGreaterThan(0);
expect(Array.isArray(card.skills)).toBe(true);
});
it('advertises the federation endpoint as an open-form RUFLO-FEDERATION binding', () => {
const card = toAgentCard(makeManifest());
const iface = card.supportedInterfaces[0]!;
expect(iface.protocolBinding).toBe(RUFLO_FEDERATION_BINDING);
expect(iface.protocolVersion).toBe(A2A_PROTOCOL_VERSION);
expect(iface.url).toBe('ws://127.0.0.1:9100');
});
it('normalizes a bare host:port endpoint into a URL', () => {
const card = toAgentCard(makeManifest({ endpoint: '10.0.0.5:9100' }));
expect(card.supportedInterfaces[0]!.url).toBe('ws://10.0.0.5:9100');
});
it('maps every agent type to a spec-valid AgentSkill', () => {
const card = toAgentCard(makeManifest());
expect(card.skills.map((s) => s.id)).toEqual(['agent-type:coder', 'agent-type:reviewer']);
for (const skill of card.skills) {
expect(skill.name).toBeTruthy();
expect(skill.description).toBeTruthy();
expect(skill.tags.length).toBeGreaterThan(0); // tags REQUIRED per §4.4.5
}
});
it('supports name/description/provider/interface overrides', () => {
const card = toAgentCard(makeManifest(), {
name: 'My Agent',
description: 'Custom description',
provider: { url: 'https://ruv.net', organization: 'ruvnet' },
additionalInterfaces: [
{ url: 'https://api.example.com/a2a/v1', protocolBinding: 'JSONRPC', protocolVersion: '1.0' },
],
});
expect(card.name).toBe('My Agent');
expect(card.description).toBe('Custom description');
expect(card.provider).toEqual({ url: 'https://ruv.net', organization: 'ruvnet' });
// additional interfaces come first (preferred per spec ordering)
expect(card.supportedInterfaces[0]!.protocolBinding).toBe('JSONRPC');
expect(card.supportedInterfaces[1]!.protocolBinding).toBe(RUFLO_FEDERATION_BINDING);
});
});
describe('validateAgentCard', () => {
it('accepts the golden card', () => {
expect(validateAgentCard(goldenCard()).valid).toBe(true);
});
it('rejects non-objects', () => {
expect(validateAgentCard(null).valid).toBe(false);
expect(validateAgentCard('card').valid).toBe(false);
expect(validateAgentCard([]).valid).toBe(false);
});
it.each([
['name'], ['description'], ['version'],
['supportedInterfaces'], ['capabilities'],
['defaultInputModes'], ['defaultOutputModes'], ['skills'],
])('rejects a card missing required field %s', (field) => {
const card = { ...goldenCard() } as Record<string, unknown>;
delete card[field];
const result = validateAgentCard(card);
expect(result.valid).toBe(false);
expect(result.errors.some((e) => e.includes(field))).toBe(true);
});
it('rejects interfaces missing url/protocolBinding/protocolVersion', () => {
const card = { ...goldenCard(), supportedInterfaces: [{ url: 'ws://x' }] };
const result = validateAgentCard(card);
expect(result.valid).toBe(false);
expect(result.errors.join(' ')).toContain('protocolBinding');
expect(result.errors.join(' ')).toContain('protocolVersion');
});
it('rejects skills missing required id/name/description/tags', () => {
const card = { ...goldenCard(), skills: [{ id: 'x' }] };
const result = validateAgentCard(card);
expect(result.valid).toBe(false);
expect(result.errors.join(' ')).toContain('tags');
});
it('tolerates unknown extra fields (forward compatibility)', () => {
const card = { ...goldenCard(), futureField: { anything: true } };
expect(validateAgentCard(card).valid).toBe(true);
});
});
describe('fromAgentCard', () => {
it('round-trips a ruflo-generated card back to the federation identity', () => {
const manifest = makeManifest();
const node = fromAgentCard(toAgentCard(manifest), 'http://127.0.0.1:41241/.well-known/agent-card.json');
expect(node.nodeId).toBe('node-golden');
expect(node.publicKey).toBe('aabbccddeeff');
expect(node.endpoint).toBe('ws://127.0.0.1:9100');
expect(node.capabilities.agentTypes).toEqual(['coder', 'reviewer']);
expect(node.capabilities.maxConcurrentSessions).toBe(5);
expect(node.capabilities.supportedProtocols).toEqual(['websocket', 'http']);
expect(node.capabilities.complianceModes).toEqual(['hipaa']);
expect(node.metadata.discoveryMechanism).toBe('a2a-card');
});
it('always enters at TrustLevel.UNTRUSTED regardless of card claims', () => {
const node = fromAgentCard(toAgentCard(makeManifest()));
expect(node.trustLevel).toBe(TrustLevel.UNTRUSTED);
expect(node.trustScore).toBe(0);
});
it('maps a foreign (non-ruflo) A2A card without the federation extension', () => {
const foreign: A2AAgentCard = {
name: 'GeoSpatial Route Planner Agent',
description: 'Route planning services.',
supportedInterfaces: [
{ url: 'https://georoute.example.com/a2a/v1', protocolBinding: 'JSONRPC', protocolVersion: '1.0' },
],
version: '1.2.0',
capabilities: { streaming: true },
defaultInputModes: ['application/json'],
defaultOutputModes: ['application/json'],
skills: [
{ id: 'route-optimizer', name: 'Route Optimizer', description: 'Optimizes routes.', tags: ['maps'] },
],
};
expect(validateAgentCard(foreign).valid).toBe(true);
const node = fromAgentCard(foreign, 'https://georoute.example.com/.well-known/agent-card.json');
expect(node.nodeId).toBe('a2a-geospatial-route-planner-agent');
expect(node.publicKey).toBe('');
expect(node.endpoint).toBe('https://georoute.example.com/a2a/v1');
expect(node.capabilities.agentTypes).toEqual(['route-optimizer']);
expect(node.capabilities.supportedProtocols).toEqual(['jsonrpc']);
expect(node.trustLevel).toBe(TrustLevel.UNTRUSTED);
expect((node.metadata as { a2a?: { sourceUrl?: string } }).a2a?.sourceUrl)
.toBe('https://georoute.example.com/.well-known/agent-card.json');
});
});
describe('DiscoveryService.registerExternalPeer', () => {
function makeDiscovery() {
return new DiscoveryService({
signManifest: async () => 'sig',
verifyManifest: async () => true,
});
}
it('registers an A2A-card peer so it appears in federation discovery', () => {
const discovery = makeDiscovery();
const node = fromAgentCard(toAgentCard(makeManifest()));
discovery.registerExternalPeer(node);
const peers = discovery.listPeers();
expect(peers).toHaveLength(1);
expect(peers[0]!.nodeId).toBe('node-golden');
expect(peers[0]!.metadata.discoveryMechanism).toBe('a2a-card');
});
it('refreshes (not replaces) an existing peer, preserving trust state', () => {
const discovery = makeDiscovery();
const first = discovery.registerExternalPeer(fromAgentCard(toAgentCard(makeManifest())));
first.updateTrustScore(0.7);
const again = discovery.registerExternalPeer(fromAgentCard(toAgentCard(makeManifest())));
expect(again).toBe(first);
expect(again.trustScore).toBe(0.7);
expect(discovery.listPeers()).toHaveLength(1);
});
});