* test(#178): update DispatchEvent factory tests to propagate parentTraceId P1.3 test 'parentTraceId is always undefined' replaced with four P1.4 contracts: absent → undefined, string → propagated, null → undefined, non-string → undefined (defensive normalization policy). Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * feat(#178): propagate parentTraceId through DispatchEvent factory Stop ignoring the parentTraceId parameter added as a forward-compat hook in P1.3. Defensive normalization: only non-null strings are propagated; null, non-string values, and absent callers all yield undefined, keeping P1.3 behavior intact for all existing dispatch call sites. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * test(#178): add Hub-level parentTraceId propagation tests Four new assertions: req.parentTraceId propagates to event, absent → undefined (P1.3 regression), shared parentTraceId across multiple dispatches, and unique traceId invariant despite shared parentTraceId. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * feat(#178): plumb parentTraceId through Hub dispatch and _notifyLogger dispatch() now reads req.parentTraceId and passes it to _notifyLogger, which forwards it to makeDispatchEvent. Backward-compatible: callers that omit parentTraceId emit events with parentTraceId: undefined, identical to P1.3 behavior. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * test(#178): add trace correlation end-to-end test Dispatches a root command then 3 children with parentTraceId=rootTraceId. Reads the real .gsd-trace.jsonl audit file and verifies: 4 events total, root has no parentTraceId, all children carry rootTraceId, all traceIds unique, JS filter returns exactly the 3 children given the root's traceId. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * docs(#178): document traceId/parentTraceId in audit file Update Observability section to note that audit events now carry both traceId and parentTraceId, and explain the correlation filter pattern. Note that leaf dispatches emit parentTraceId: undefined until the Phase 2 composer wires it automatically. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * chore(#178): add changeset for trace correlation seam Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * test(#178): cover invalid parentTraceId values in DispatchEvent factory Adds 9 new test cases for UUID v4 validation of parentTraceId: empty string, whitespace, non-UUID, oversized, UUID v1, missing-hyphen, extra-char (all dropped to undefined), plus UPPERCASE and lowercase v4 (both propagated). Tests are intentionally red until the implementation commit that follows. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * feat(#178): validate parentTraceId against UUID v4 before propagation Adds UUID_V4_REGEX constant and isValidParentTraceId() helper to event.cjs. makeDispatchEvent now silently coerces any parentTraceId that fails the UUID v4 check (wrong version nibble, wrong variant, missing hyphens, oversized, empty, etc.) to undefined. No stderr warn is emitted — the factory remains pure and side-effect-free. Closes the correlation- poisoning vector identified in the Codex adversarial review of PR #225. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * test(#178): assert Hub silently drops invalid parentTraceId at the seam Adds two tests to hub-logger-integration.test.cjs: 1. dispatch with 'junk' parentTraceId emits event with parentTraceId===undefined. 2. The logger-failure warn path is NOT triggered — the factory coerces the bad value before onEvent is called, confirmed by zero stderr output even when a logger that would throw on non-undefined parentTraceId is installed. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * test(#178): assert invalid parentTraceId does not poison correlation siblings Adds one test to trace-correlation.test.cjs: dispatches a root, a valid child (parentTraceId = rootTraceId), and an invalid child (parentTraceId = 'junk'). Asserts: valid child carries correct parentTraceId, invalid child has parentTraceId dropped to undefined, filtering by rootTraceId yields exactly 1 event (the valid child only), and all 3 events have unique traceIds. Uses an isolated Hub + tmpdir to avoid shared fixture interference. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * docs(#178): document UUID v4 contract for parentTraceId Appends one sentence to the Observability audit-trail paragraph in CONFIGURATION.md: parentTraceId must be canonical UUID v4 (RFC 4122); values that don't match are silently dropped from audit output. No section restructuring — single sentence addition only. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> --------- Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
83 lines
3.3 KiB
JavaScript
83 lines
3.3 KiB
JavaScript
'use strict';
|
|
|
|
/**
|
|
* DispatchEvent shape factory — issue #177 (ADR-0174 P1.3), extended in #178 (P1.4).
|
|
*
|
|
* Creates a structured event record for every Hub dispatch, used by
|
|
* DispatchLogger to emit stderr errors and opt-in file audit trails.
|
|
*
|
|
* Shape:
|
|
* traceId: string — UUID v4, generated per dispatch
|
|
* parentTraceId: string|undefined — propagated from the caller when it is a canonical UUID v4
|
|
* (RFC 4122); invalid values are silently coerced to undefined.
|
|
* Enables a future init-composer (Phase 2) to correlate child
|
|
* dispatches to their parent via the audit file.
|
|
* command: string — the dispatched verb
|
|
* args?: unknown — only present when includeArgs === true
|
|
* result: { kind: 'ok' | 'UnknownCommand' | 'InvalidArgs' | 'HandlerRefusal' | 'HandlerFailure', ...payload }
|
|
* timestamp: string — ISO 8601
|
|
*/
|
|
|
|
const { randomUUID } = require('crypto');
|
|
|
|
/**
|
|
* Canonical UUID v4 regex (RFC 4122).
|
|
* - 36 characters total (32 hex + 4 hyphens)
|
|
* - Version nibble: 4
|
|
* - Variant bits: [89ab]
|
|
* - Case-insensitive: accepts both upper- and lowercase hex
|
|
*
|
|
* Used to validate parentTraceId before propagation. traceId is always
|
|
* generated internally by crypto.randomUUID() and is guaranteed valid.
|
|
*/
|
|
const UUID_V4_REGEX = /^[0-9a-f]{8}-[0-9a-f]{4}-4[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$/i;
|
|
|
|
/**
|
|
* Returns true only when value is a canonical UUID v4 string.
|
|
* Any other value (non-string, wrong format, wrong version/variant) → false.
|
|
*
|
|
* @param {unknown} value
|
|
* @returns {boolean}
|
|
*/
|
|
function isValidParentTraceId(value) {
|
|
return typeof value === 'string' && UUID_V4_REGEX.test(value);
|
|
}
|
|
|
|
/**
|
|
* Create a DispatchEvent.
|
|
*
|
|
* @param {object} opts
|
|
* @param {string} opts.command - The dispatched command verb.
|
|
* @param {unknown} [opts.args] - Raw args passed to the hub.
|
|
* @param {object} opts.result - The HubResult returned by the hub.
|
|
* @param {boolean} [opts.includeArgs=false] - When true, include args in the event.
|
|
* @param {string} [opts.parentTraceId] - Must be a canonical UUID v4 (RFC 4122).
|
|
* Invalid values (non-string, wrong format, wrong version/variant) are silently coerced
|
|
* to undefined — no stderr warn is emitted. This prevents correlation poisoning from
|
|
* unvalidated caller input while keeping the factory pure and side-effect-free.
|
|
* @returns {object} Immutable DispatchEvent record.
|
|
*/
|
|
function makeDispatchEvent({ command, args, result, includeArgs = false, parentTraceId }) {
|
|
// Validate parentTraceId against UUID v4 format before propagation.
|
|
// Invalid inputs (empty string, non-UUID, UUID v1, oversized, etc.) are silently
|
|
// coerced to undefined. Silent coercion keeps the factory pure — no side effects,
|
|
// no log spam on bad input, consistent with how non-string values already collapse.
|
|
const resolvedParentTraceId = isValidParentTraceId(parentTraceId) ? parentTraceId : undefined;
|
|
|
|
const event = {
|
|
traceId: randomUUID(),
|
|
parentTraceId: resolvedParentTraceId,
|
|
command: String(command),
|
|
result,
|
|
timestamp: new Date().toISOString(),
|
|
};
|
|
|
|
if (includeArgs && args !== undefined) {
|
|
event.args = args;
|
|
}
|
|
|
|
return Object.freeze(event);
|
|
}
|
|
|
|
module.exports = { makeDispatchEvent };
|