3683e70043
* feat(relay): live-card ops — native draft streaming + task cards over the relay (gateway half)
NS-658. Three additive ops within contract v1, emitted only when the
connector's negotiated descriptor advertises them:
{op: draft, chat_id, draft_id, content, final, metadata}
{op: task_card, chat_id, card_id, chunks, metadata}
{op: task_card_stop, chat_id, card_id, metadata}
The gateway side is deliberately dumb: no platform API knowledge, no new
config keys. Slack mechanics (chat.startStream/appendStream/stopStream,
per-workspace feature-gate cache, send+edit fallback) live connector-side
where the platform adapter lives in the relay model.
Semantic bridge: base send_draft is Telegram-shaped (draft clears; final
is a separate send). Slack native streaming makes the stream THE message.
The adapter tracks the open draft per chat and converts the turn-final
send() into draft(final=true) so the connector seals the stream instead
of posting a duplicate; the stream ts returns as the message identity.
A failed frame disarms interception so the edit-based fallback's real
send goes through untouched.
BEHAVIOR CHANGE (deliberate): relay supports_draft_streaming() now
requires the descriptor flag AND the draft op. Flag-only was a latent
lie — send_draft inherited NotImplementedError, so a connector setting
the flag without the op would have crashed the stream consumer's draft
path. supported_ops stays fail-open for legacy (pre-contract) ops;
draft/task_card did not exist pre-contract and must not fail open.
Task cards ride #85476's adapter-agnostic TurnRunner seam (hasattr on
send_native_task_card_progress); supports_native_task_cards() is the
descriptor probe. Connector half + E2E harness pair follow in the gg
repo.
* fix(relay): expose native_task_cards_enabled() on the relay adapter
Live-canary finding (Alice, staging): the TurnRunner's task-card lane
probes adapter.native_task_cards_enabled() (the native Slack adapter's
opt-in contract). The relay adapter only offered
supports_native_task_cards(), so the hasattr gate failed silently and
tool progress stayed on the text path — draft streaming worked, cards
never rendered. Alias it to the descriptor probe.
* fix(relay): match task-card methods to the TurnRunner's native keyword contract
Live-canary finding #2 (Alice, staging): gateway/run.py's card lane calls
send/stop_native_task_card_progress with the NATIVE Slack adapter's
signature (tasks/title/reply_to/metadata/fallback_text, keyword-only) —
PR 85796's relay methods took a positional card_id, so every call raised
TypeError('unexpected keyword argument reply_to') in the progress task,
repeatedly killing the card publisher (and the retry loop resent the
final delivery 4-5x). Card id now derives per turn thread
(turn:<reply_to>), thread_ts anchored like draft; title/fallback_text
accepted for parity, not forwarded (plan-mode stream renders chunks).
* fix(relay): one draft stream per turn for stream-is-the-message adapters
Live-canary finding #4 (Alice, staging): the stream consumer bumps
draft_id at every tool boundary so Telegram-shaped drafts animate each
text segment as a fresh preview. On relay Slack NATIVE streaming a new
draft_id opens a brand-new chat.startStream — the user saw one frozen
message per segment (stuck streaming cursor ▉, never sealed: only the
LAST stream gets the final=true seal) plus the real final; 5-6 cumulative
snapshots per turn. Adapters that mark draft_stream_is_message keep ONE
stream per turn: tool progress lives in the native task card, and the
connector's suffix-delta falls back to whole-text append on prefix
mismatch, so segments append cleanly. Telegram-shaped drafts keep the
per-segment bump.
* fix(relay): don't seal the native stream at tool boundaries — only the turn-final does
Live-canary finding #5 (Alice; supersedes the incomplete #4 which was
necessary but not sufficient). Root cause CONFIRMED by integration trace
(test_live_cards_flow_trace.py, real consumer semantics + real adapter +
stub transport): at every tool boundary the consumer calls
_send_or_edit(finalize=True), which skips the draft path and issues a
real send(); the relay adapter's seal-interception converts THAT into
draft(final=true) — sealing the stream once per segment. Timeline showed
3 seals for a 3-segment turn: exactly the frozen cumulative ▉ snapshots
seen live (the replaced stream never gets stopStream, keeping its cursor).
Fix: for draft_stream_is_message adapters, a segment-break finalize
(finalize=True, is_turn_final=False) stays ON the draft path as another
cumulative frame; only got_done (is_turn_final=True) falls through to
send() and seals. Telegram-shaped platforms unchanged. Trace test now
pins the invariant: ONE user-visible message per turn.
* fix(relay): strip the text cursor from native draft frames
Live-canary finding #6 (Alice) — the ACTUAL duplicate-content mechanism,
confirmed by full-flow scan of both sides' code + logs. The consumer
appends its text cursor (▉) to every non-final display_text tick. The
connector's stream sender diffs CUMULATIVE frames via prefix check:
'abc▉'.startsWith → 'abc def▉' is NEVER a prefix match (the cursor sits
mid-string), so deltaFor falls back to whole-text append on EVERY tick —
chat.appendStream stacks each full cumulative snapshot (cursor included)
into the ONE stream message. Exactly the observed thread: repeated
blocks, each ending in a frozen ▉, growing per tick.
Fixes #4/#5 were real (one stream per turn now) but this was the last
mechanism standing. Native streams render their own typing indicator, so
the text cursor is pure noise on this path: strip it from draft frames.
Prefix check now holds; every tick appends only its true suffix delta.
* fix(relay): seal-interception covers EVERY egress door, not just send()
Live-canary finding #7 (Alice): one duplication remained after #6 — the
stream froze mid-word with the live indicator (never sealed) and the
final posted as a separate message. Log receipt: 'Queued follow-up:
final text delivery confirmed; delivering explicit media before
continuing' — the turn's final went out via the DELIVERY RESOLVER lane
(gateway/delivery.py), which calls send_for_platform() DIRECTLY,
bypassing send() and its seal-interception. The open stream never
absorbed the final; it arrived as a plain 'send' op → chat.postMessage.
Fix: hoist the open-draft check to the top of send() (ahead of the
explicit-platform branch) AND add it to send_for_platform() — an open
native stream absorbs the turn-final regardless of which egress door it
arrives through. The stream IS the message.
* fix(relay): failed seal falls back to plain send (PR 85796 AI-review point 1)
A turn-final seal that fails at the transport must never swallow the
final answer: the stream consumer has already disabled the draft
transport for the run, so a failed _seal_open_draft returning
success=False meant the user got NOTHING. Both seal-interception sites
(send + send_for_platform) now fall through to the regular plain-send
path on seal failure, with a warning receipt. Also mitigates AI-review
point 2 (sticky _open_draft_by_chat after an abandoned turn): a stale
entry's failed seal no longer blocks the next turn's delivery.
* fix(relay): arm seal-interception optimistically; never disarm on ambiguous failure (audit G-D1)
Deep-audit defect G-D1 (HIGH): the outbound leg is at-most-once on the
wire but its ack channel is lossy — send_outbound timeout (30s) and
WS-drop 'failures' frequently mean the frame WAS delivered and the
connector stream is open. send_draft popped _open_draft_by_chat on any
failure, disarming seal-interception while the connector stream lived:
the turn-final went out as a plain send → orphaned mid-word stream +
complete duplicate final (intermittent; needs a drop/timeout inside the
draft window).
Fix: arm the entry BEFORE the transport call and keep it armed on
failure/exception. Safe in every case: sealing a non-existent stream
opens+seals a single complete message connector-side, and a truly failed
seal already falls back to plain send at both interception sites.
Stale-entry damage is self-healing (one warning + plain send).
* fix(relay): gateway-side sealed-draft tombstone — G-D1 arming must not resurrect sealed streams
Regression fix on G-D1 (live: 'worse than before' — escalating frozen
prefixes). Optimistic arming had no seal-awareness: a straggler frame
arriving AFTER the seal re-armed _open_draft_by_chat for the already-
sealed draft_id; the next send was converted to draft(final=true) on the
tombstoned connector key, which CLEARED the connector tombstone (final
frame = new-turn signal), re-opened a stream with cumulative content,
and left it frozen — repeating per straggler: 4-5 escalating frozen
snapshots. Mirror the connector: _sealed_draft_by_chat records the
sealed draft_id per chat (tombstoned BEFORE the seal's transport call);
send_draft for a sealed draft_id is a success no-op (content already in
the sealed message) and never arms. A new turn's fresh draft_id arms
normally.
* fix(relay): key stream/card state per (chat, turn anchor) — parallel turns must not collide (finding #10)
Live finding #10 (Alice; three concurrent turns in one flat DM): all
coordination state was keyed per CHAT on a one-active-turn assumption.
Three parallel turns produced: turn B's task card merged into turn A's
(both were card 'turn:root' — reply_to is None in flat DMs), B left
cardless, and _open/_sealed_draft_by_chat clobbered across writers (3x
duplicate finals on the last turn). Per-turn machinery was correct;
the keys were not.
Fix: _draft_key(chat, metadata) = chat + the turn's thread anchor
(inbound stamps thread_ts = event.thread_ts or ts on every top-level
message, so each turn has one even in flat DMs). draft arming, seal
tombstones, both interception sites, and the task-card id all derive
from the same anchor. New trace test pins two interleaved turns:
distinct cards, own-stream seals, no leaked plain send, no cross-turn
tombstone drops (289 tests green).
* fix(gateway): preserve cumulative native stream across tools
* fix(gateway): consumer-declared final — the seal carries the true final
Three composed fixes for the Slack live-cards duplicate-final class:
1. finish(final_text): TurnRunner passes the completed final_response
(verifier footer, completion explainer included) as the authoritative
finalize payload. The native-stream seal delivers the TRUE final, so
post-stream mutation no longer forks a corrective plain send (#11).
2. Interim-send contract: commentary and segment-tail sends carry a
gateway-internal _interim_send marker; relay seal-interception skips
them at both egress doors. A mid-turn interim send can no longer seal
the live stream and orphan the real final into a duplicate.
3. Queued-follow-up lane reconciles an unconfirmed final by EDITING the
consumer's delivered message in place (sealed stream = regular
message, chat.update live-verified); plain send only as fallback.
This was the actual duplicate lane in the parallel canaries — every
duplicated turn logged 'final stream delivery not confirmed; sending
first response' (subagent-completion queued inbound), not parallelism.
Also: draft frames stay prefix-stable gateway-side (no fence-closing, no
segment state reset, no commentary reset for stream-is-the-message
adapters; MagicMock-safe 'is True' guards).
* test+docs: streaming-contract coverage completeness + maintenance guidelines
Coverage: two gaps closed on the consumer-declared-final contract —
(1) send_for_platform (the delivery-resolver egress door) honors the
_interim_send contract: no seal, marker stripped before the wire;
(2) finish(final_text) on a turn that never streamed does not adopt the
final (delivery ownership stays with the gateway's normal send path for
non-streaming models / tool-only turns).
Docs: AGENTS.md 'Known Pitfalls' gains the streaming delivery contract —
the four invariants of stream-is-the-message adapters (prefix-stable
frames, consumer-declared final, interim-send marker, reconcile-by-edit),
each traced to its live incident, plus the live-probed Slack streaming
API ground truth and the MagicMock 'is True' guard-style note.
* fix(relay): seal transport failure must never silently lose the final (review B1)
Two halves of one silent-loss path, live-probed on the review branch:
1. adapter: _seal_open_draft did not catch transport exceptions. A socket
drop at seal time raised out of send(), skipping the fail-open plain
send entirely. Now: retry the SAME idempotent final frame once (the
connector's sealed-key tombstone returns the original stream ts for a
repeated final — a retry can never open a second stream or duplicate),
then report failure so the caller's fail-open path runs.
2. consumer: the turn-final retry (elif not _already_sent) called
_send_or_edit with finalize=False, which re-entered the DRAFT-FRAME
branch. Its no-op dedupe compared the adopted final against the last
unsealed frame, matched, and returned True with ZERO transport calls —
final_response_sent went green, delivered_final_matches reconciled,
the gateway suppressed its fallback, and the user never received the
answer. finalize=True keeps this retry out of the draft branch.
Regression suite: tests/gateway/test_relay_seal_failure.py (3 tests).
Mutation evidence in follow-up verification: reverting either half sends
the suite red.
* fix(relay): draft ids unique across gateway incarnations (review B3)
The relay connector tombstones sealed streams by (channel, draft_id) and
keeps up to 512 of them; they outlive the gateway process. Relay gateways
are disposable BY DESIGN (scale-to-zero), and _draft_id_counter restarted
at zero every incarnation — so the first turns after every scale-from-zero
in a recently-active channel replayed already-sealed wire identities. The
connector answered those frames straight out of the old tombstone: zero
Slack API calls, the OLD message ts returned as the new turn's identity,
the new answer silently dropped while gateway-side flags recorded success.
Seed the counter from wall-clock milliseconds at process start. Ids stay
plain ints within the existing contract op; incarnations cannot overlap
for realistic turn counts and restart gaps.
Regression: tests/gateway/test_draft_id_restart_uniqueness.py — the seed
test fails on the old code (seed 0 is not epoch-scale).
* fix(relay): stream/card state keyed per TURN, not per thread anchor (review B2)
The thread anchor is the wrong coordination identity — simultaneously:
- too coarse: two parallel turns replying INSIDE ONE Slack thread share
thread_ts. Live-probed on the review branch: turn A's final sealed turn
B's stream with A's content while A's own stream stayed open, and B's
final degraded to a plain send.
- too fragile: a flat DM with no thread metadata degraded to the bare
chat id, re-creating the original finding-#10 collision the anchor was
meant to fix.
_draft_key now prefers the triggering inbound message id (message_id /
reply_to_message_id — per-turn by construction; the gateway's Slack
thread metadata and the consumer's send path both stamp it), falling back
to the thread anchor, then the bare chat. The consumer stamps the same
reply_to_message_id on draft frames so frames and the turn-final resolve
to one key. Task-card ids share the derivation via _card_key (one helper
for send AND stop, so the stop always hits the stream the send opened).
Legacy resolver-lane callers with placement-only metadata still seal via
_match_open_draft's fallback — but ONLY when exactly one stream is open.
With several open, an identity-less send stays a plain send: a duplicate
message is recoverable, sealing someone else's stream is not.
Regression: tests/gateway/relay/test_relay_turn_keying.py (7 tests).
* fix(relay): stream-is-the-message is a Slack semantic, gate it on the descriptor (review B4)
draft_stream_is_message was hardcoded True on the relay adapter class,
i.e. for EVERY relay platform. The base send_draft contract is
Telegram-shaped — the draft clears client-side and the final arrives as
a separate real send that becomes the history message. With the flag
forced on, any non-Slack connector advertising the draft op had its
turn-final intercepted into draft(final=true): probed on the review
branch with a telegram descriptor, the op stream was
[draft(final=false), draft(final=true)] and NO send — no history message
would ever be posted.
Gate the flag on the negotiated descriptor platform (slack), and skip
arming seal-interception entirely when it is off. A future platform with
genuine stream-is-the-message native streaming should advertise it via
the descriptor rather than widening the platform check by guesswork.
Regression: tests/gateway/relay/test_relay_stream_semantics_gating.py
(4 tests: gating both ways, telegram final is a real send, slack final
still seals).
* fix(gateway): mark every mid-turn status lane interim — heartbeats must not seal the stream (review B5)
Seal-interception treats the first unmarked send to an armed (chat, turn)
key as the turn-final. The consumer's own interim lanes (commentary, tail
flush) carry _interim_send, but four gateway-side lanes that fire DURING
a streaming turn did not:
- long-running heartbeat (default every 180s — probed live: at 3 minutes
it sealed the live stream with '⏳ Working — 3 min', the real final
posted as a duplicate, and later frames were silently swallowed by the
seal tombstone)
- inactivity warning
- plain-text approval fallback (button lane failed)
- background-review notice
Add _interim_metadata() beside _non_conversational_metadata and wrap all
four call sites. The marker is gateway-internal; the relay adapter strips
it before the wire (existing behavior, pinned by test).
Note for follow-up: the opt-out shape remains fragile — any FUTURE
unmarked mid-turn send lane re-creates this bug. Inverting the contract
(explicitly mark the one turn-final send) is the durable fix but touches
every adapter's final-delivery path; deliberately kept out of this
review-fix series.
Regression: tests/gateway/test_interim_send_lanes.py (4 tests).
* fix(gateway): interrupted/incomplete turns must not adopt the diagnostic as the stream final (review B6)
The finish(final_text) adoption gate checked only 'not failed', but the
interrupt/abort returns in agent/conversation_loop.py are
{completed: False, interrupted: True, final_response: 'Operation
interrupted during …'} with NO failed key. Adopting that diagnostic:
1. sealed the user's streamed partial answer over with the interrupt
text (stream-is-the-message: the seal rewrites the whole message), and
2. recorded the diagnostic as the turn-final payload, so
delivered_final_matches reconciled and the gateway suppressed its own
error-delivery path — the diagnostic became the ONLY thing delivered.
Enumerated all 27 final_response-bearing return shapes in
conversation_loop.py: every non-happy-path shape carries completed:
False (several with a diagnostic final_response and neither failed nor
interrupted — retry exhaustion, truncation, codex-incomplete); the happy
path routes through turn_finalizer.finalize_turn (completed=True). Gate
is therefore: not failed AND not interrupted AND completed is not False.
Results lacking the completed key entirely (older callers/test doubles)
keep the previous behavior.
Regression: tests/gateway/test_stream_final_adoption_gate.py (6 tests,
incl. a source-level pin on the run.py call site).
* fix(relay): task-card transport failures degrade to failed SendResults (review B7)
send_native_task_card_progress and stop_native_task_card_progress let
transport exceptions escape. The stop runs inside the progress loop's
finally block on the turn-cleanup path, and the post-cancel awaits in
gateway/run.py caught only CancelledError — a socket drop during a card
publish/stop therefore aborted cleanup BEFORE the final-delivery
bookkeeping ran.
Three layers, outermost defends any adapter:
- both adapter methods catch transport exceptions and return failed
SendResults (progress is advisory; the TurnRunner's text fallback
already handles failure results)
- the progress loop's finally wraps the stop (best-effort; the connector
seals orphaned card streams on its own via recycling/eviction)
- the cleanup awaits log-and-continue on non-cancellation errors so
final-delivery bookkeeping always runs
Regression: tests/gateway/relay/test_relay_task_card_failures.py.
* fix(relay): a dying turn seals its native stream instead of orphaning it (review B8)
Stale-generation exits (/new, /stop mid-stream) and cancellations
returned from the consumer's run() with the native stream still open:
- the Slack message kept its live streaming indicator forever (the
cancellation best-effort edit only runs when _message_id exists, and
the native draft path deliberately keeps it None);
- the adapter's armed interception state survived the turn, so the next
turn on the same key could inherit it and seal a dead draft_id.
New adapter op abandon_open_draft(chat, content): seals in place with
the text already on screen (the consumer passes its last delivered
frame) — the seal adds nothing and claims nothing; delivery flags are
never set, so the gateway's normal paths still own whatever happens
next. Best-effort by contract (failure reported, never raised); the
connector reaps truly orphaned streams via recycling/eviction.
The consumer calls it from both death paths: the stale-generation early
return and the CancelledError handler.
Regression: tests/gateway/test_stream_abandon_on_turn_death.py (4 tests,
incl. the next-turn-inheritance hazard).
* fix(relay): bound the draft/seal coordination dicts (review M1)
_sealed_draft_by_chat's key embeds a per-turn identity, so every
completed turn wrote a permanent entry — unbounded growth for the life
of a long-running gateway process (the docstring said 'one entry per
chat', which stopped being true when the key gained the turn anchor).
_open_draft_by_chat could grow the same way via abandoned entries.
FIFO-evict both at 512 entries — the same idiom as the sibling bounded
cache (_auto_thread_by_chat, capped at 256) and the same size as the
connector's own tombstone store. The straggler window the tombstone
exists for is seconds long; FIFO is more than enough.
Regression: tests/gateway/relay/test_relay_state_bounds.py.
* fix(relay): explicit connector rejection disarms interception; exceptions stay armed (review P3)
The G-D1 optimistic-arming change silently dropped disarm-on-failure
entirely: after an EXPLICIT connector rejection (success=False result —
not a transport ambiguity), interception stayed armed even though the
stream consumer disables the draft transport on that failure and falls
back to edit-based streaming. Its turn-final would then be converted
into a seal on a stream the connector just told us is unusable.
test_draft_failure_result_propagates claimed to cover this ('must NOT
leave seal-interception armed') but passed for an unrelated reason: the
stub's canned failure also failed the SEAL, whose fail-open path did the
plain send.
Split the two semantics and pin each honestly:
- explicit rejection (result success=False): disarm — turn-final is a
real send (test_draft_failure_result_propagates, now testing what its
comment says)
- transport exception: ambiguous, stay armed — turn-final still seals
(test_draft_transport_exception_keeps_interception_armed, the G-D1
contract)
Also corrects commit ba3a24a's claim ('a failed frame disarms
interception so the edit-based fallback's real send goes through
untouched') to hold again for the rejection case it described.
* fix(relay): lost acks are ambiguous, not rejections — on the RESULT channel too (review r2, finding 1)
The production ws transport does not raise on ack timeout — it returns
{"success": False, "error": "relay outbound timed out"}. The round-1
ambiguity handling keyed entirely on the exception channel, so the shape
production actually produces was misclassified as a definite connector
rejection. Probed on the head:
- lost SEAL ack: skipped the idempotent retry, fell straight to a plain
send — duplicate final whenever the seal had actually applied;
- lost FRAME ack: the round-1 disarm-on-rejection fired — interception
disarmed, frozen native stream beside a plain final. This re-created
the original G-D1 ambiguous-ack defect on the result channel.
Contract now spans both channels:
- transport: the ack-timeout branch tags ambiguous=True. The fail-fast
branches (closing / not connected) never sent anything and stay
unmarked — they are definite non-delivery.
- adapter frame path: ambiguous results keep interception armed (same
as exceptions); only definite rejections disarm.
- adapter seal path: one shared _attempt() classifier — exception and
ambiguous result both mean "unknown"; the SAME idempotent frame is
retried once (connector tombstone returns the original stream ts for
a repeated final). Only after both attempts stay ambiguous does the
caller's fail-open plain send run: a possible duplicate after double
ack loss beats a silent loss, and double ack loss on one socket
almost always means the transport is down for the plain send too.
Regression: tests/gateway/relay/test_relay_ack_ambiguity.py (6 tests,
incl. a source-of-truth check that the transport tags the timeout branch
and leaves fail-fast branches unmarked).
* fix(relay): stream semantics + draft capability resolve per CHAT, not per primary (review r2, finding 2)
One RelayAdapter fronts N platforms (Phase 1.5): descriptors accumulate
per platform on the transport and egress is tagged per chat — but the
round-1 gate keyed draft_stream_is_message and supports_draft_streaming()
off the PRIMARY scalar descriptor. Probed on the head:
- Slack primary + Telegram chat: the Telegram chat's turn-final was
intercepted into draft(final=true) — no real Telegram history message;
- Telegram primary + Slack chat: the Slack chat was denied native
streaming entirely.
Resolve both through _descriptor_for_chat — the same per-chat machinery
max_message_length already uses (added for the identical class of bug:
the primary's 39000-char cap over-sending into Discord 400s):
- new stream_is_message_for_chat(chat_id) on the adapter; arming and
NotImplementedError gating use it. The class attribute remains as the
single-platform value and legacy-probe fallback.
- supports_draft_streaming() gains an optional chat_id kwarg (base
signature updated; single-platform adapters ignore it). The consumer
passes chat_id with a TypeError fallback for out-of-tree adapters.
- the consumer's four draft_stream_is_message reads collapse into one
_stream_is_message() helper that prefers the per-chat probe
(class-resolved, MagicMock-safe) over the attribute.
Platform-name inference ("slack") stays deliberate: a descriptor-level
semantic field is the right eventual contract but is a cross-repo wire
change — noted for the gg follow-up so future platforms advertise the
semantic explicitly.
Regression: tests/gateway/relay/test_relay_multiplatform_semantics.py
(5 tests: both starvation directions, scalar fallback, per-chat
capability gate).
* fix(gateway): split delivery + authoritative footer reconciles by suffix, not full resend (review r2, finding 3)
The _FINAL_TEXT adoption guard refuses wholesale adoption on split turns
— correct (#78541: sealed heads would repeat inside the tail) but it was
absolute: a post-split verifier footer never entered the ledger,
delivered_final_matches() reported a mismatch, and the gateway resent
the ENTIRE body+footer after the split chunks (the #11 duplicate class,
one level up).
When the authoritative final strictly prefix-extends the split ledger,
the missing suffix is the only undelivered content: append it to the
live tail and the ledger, so the finalize carries it and the recorded
payload reconciles. Non-prefix rewrites keep the full-resend fallback —
a rewrite cannot be patched onto sealed heads.
Regression: tests/gateway/test_split_final_suffix_reconcile.py (3 tests:
suffix rides the tail + reconciles, rewrite still mismatches, unsplit
adoption unchanged).
* fix(relay): cancellation mid-seal restores open state so abandon can close the stream (review r2, finding 4)
_seal_open_draft pops the open entry and writes the local tombstone
BEFORE awaiting transport I/O — correct ordering for the straggler race,
but CancelledError is not an Exception: a cancel during the await
bypassed all failure handling, leaving the remote stream live (visible
streaming indicator until connector eviction) while the local state said
'nothing open'. The consumer's abandon pass — added for exactly this
turn-death case — found nothing to close and no-oped.
On CancelledError: restore the open entry, drop the premature tombstone
(only if it is still ours), re-raise. The abandon path then seals the
stream in place with the on-screen text.
Regression: tests/gateway/relay/test_relay_seal_cancellation.py (2
tests: state restoration, and end-to-end cancel→abandon→remote seal).
* fix(relay): thread anchors are placement, not turn identity — revive the placement-only fallback (review r2, finding 5)
_match_open_draft's single-open-stream fallback was dead for its primary
intended callers: metadata carrying thread_ts/thread_id (placement-only
resolver lanes) was classified as having 'turn identity', so those sends
never reached the fallback — probed: a plain final posted beside the
still-open turn-keyed stream.
Only per-turn MESSAGE ids are identity now. Thread-anchored and bare
callers share the fallback: absorb into the chat's open stream when
EXACTLY one is open; stay a plain send when several are (duplicate is
recoverable, wrong-stream seal is not). Callers WITH a message id whose
key misses never fall back — their identity is authoritative and a miss
means the stream belongs to a different turn.
Regression: 4 new tests in test_relay_turn_keying.py (thread-anchored
seal, both ambiguous-stay-plain shapes, id-mismatch never steals).
* fix(relay): random process nonce for draft-id seeding (review r2, follow-up 6)
The epoch-millisecond seed (round-1 B3 fix) mitigates the restart-replay
class but is not a uniqueness guarantee: two gateways starting in the
same millisecond, a forked process inheriting the class state, or a
clock step backwards can all mint colliding wire identities against the
connector's per-(channel, draft_id) tombstone store.
Seed from secrets.randbits(49) instead: collision probability negligible,
no clock dependence, and ids + realistic per-process turn counts stay
comfortably inside the connector's JS number range (draft_id?: number,
2^53). Regression test now spawns two real interpreters and asserts
their seeds differ — the exact scale-to-zero restart shape, and both
start within the same second so a clock-locked seed would fail it.
* fix(relay): stamp per-turn Slack egress identity — cache is fallback only (R3-5)
The connector (gateway-gateway#210) fills chat.startStream's
recipient_user_id / recipient_team_id — required by Slack when
streaming to a channel — from metadata.user_id / metadata.scope_id.
The gateway stamped only slack_team_id per-turn and left user_id (and
scope_id) to RelayAdapter._with_scope, whose per-chat caches are keyed
on chat_id alone and overwritten by every inbound message: with users
U1 and U2 running overlapping turns in one channel, U2's arrival
overwrote the cache before U1's stream opened, and U1's stream carried
U2 as recipient_user_id.
_thread_metadata_for_source now stamps scope_id and user_id from the
turn's OWN source (setdefault — explicit values win), so identity is
turn-scoped data on the wire. _with_scope is unchanged and fill-only:
the caches keep serving restart/synthetic sends that carry no per-turn
identity, which is all they were ever safe for.
Mutation evidence: reverting the run.py hunk sends
test_thread_metadata_stamps_per_turn_user_and_scope and
test_concurrent_turns_carry_their_own_identity red; restore returns
green. The _with_scope fill-only tests pass on both trees (existing
correct behavior, now pinned against regression).
---------
Co-authored-by: Ben Barclay <ben@nousresearch.com>
619 lines
24 KiB
Python
619 lines
24 KiB
Python
"""Regression coverage for #71643 — stale streamed finalize suppression.
|
|
|
|
A *successful* Telegram finalize edit can carry only the last streamed
|
|
preview snapshot: deltas generated between the last preview edit and stream
|
|
completion never reach any Bot API call, yet ``final_response_sent`` /
|
|
``final_content_delivered`` are set from the call's success and suppress the
|
|
gateway's normal final send. The missing tail is then lost with no retry.
|
|
|
|
These tests exercise the real gateway boundary (``GatewayRunner._run_agent``
|
|
with a live ``GatewayStreamConsumer``), per the review guidance on #71643:
|
|
|
|
1. fake agent emits a visible prefix through ``stream_delta_callback``;
|
|
2. the consumer successfully finalizes that prefix;
|
|
3. the agent returns a longer ``final_response`` containing a missing tail;
|
|
4. the result must NOT silently suppress — the complete final response must
|
|
reach the platform (reconciliation edit or normal final send);
|
|
5. control: when the streamed text exactly equals the final text, the
|
|
suppression still occurs (no duplicate delivery).
|
|
|
|
Plus unit coverage for ``GatewayStreamConsumer.delivered_final_matches``.
|
|
"""
|
|
|
|
import asyncio
|
|
import importlib
|
|
import sys
|
|
import types
|
|
from types import SimpleNamespace
|
|
|
|
import pytest
|
|
|
|
from gateway.config import Platform, PlatformConfig, StreamingConfig
|
|
from gateway.platforms.base import BasePlatformAdapter, SendResult
|
|
from gateway.session import SessionSource
|
|
from gateway.stream_consumer import GatewayStreamConsumer, StreamConsumerConfig
|
|
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# Boundary-test fakes
|
|
# ---------------------------------------------------------------------------
|
|
|
|
|
|
class FinalizeCaptureAdapter(BasePlatformAdapter):
|
|
"""Adapter that records every send/edit with its finalize flag."""
|
|
|
|
def __init__(self, platform=Platform.TELEGRAM):
|
|
super().__init__(PlatformConfig(enabled=True, token="***"), platform)
|
|
self.sent = []
|
|
self.edits = []
|
|
self._next_id = 0
|
|
|
|
async def connect(self, *, is_reconnect: bool = False) -> bool:
|
|
return True
|
|
|
|
async def disconnect(self) -> None:
|
|
return None
|
|
|
|
def _mint_id(self) -> str:
|
|
self._next_id += 1
|
|
return f"m-{self._next_id}"
|
|
|
|
async def send(self, chat_id, content, reply_to=None, metadata=None) -> SendResult:
|
|
self.sent.append({"chat_id": chat_id, "content": content, "metadata": metadata})
|
|
return SendResult(success=True, message_id=self._mint_id())
|
|
|
|
async def edit_message(
|
|
self, chat_id, message_id, content, *, finalize: bool = False, metadata=None
|
|
) -> SendResult:
|
|
self.edits.append(
|
|
{
|
|
"chat_id": chat_id,
|
|
"message_id": message_id,
|
|
"content": content,
|
|
"finalize": finalize,
|
|
}
|
|
)
|
|
return SendResult(success=True, message_id=message_id)
|
|
|
|
async def send_typing(self, chat_id, metadata=None) -> None:
|
|
return None
|
|
|
|
async def stop_typing(self, chat_id) -> None:
|
|
return None
|
|
|
|
async def get_chat_info(self, chat_id: str):
|
|
return {"id": chat_id}
|
|
|
|
|
|
STREAMED_PREFIX = "The photo shows a dog on a beach"
|
|
MISSING_TAIL = " with a red frisbee in its mouth, mid-leap over the surf."
|
|
FULL_RESPONSE = STREAMED_PREFIX + MISSING_TAIL
|
|
|
|
|
|
class StalePrefixAgent:
|
|
"""Streams only a prefix; the completed response carries a longer tail.
|
|
|
|
Models the #71643 incident shape: the tail generated between the last
|
|
preview edit and stream completion never reaches the stream callback, so
|
|
the consumer's successful finalize edit carries stale preview text while
|
|
``final_response`` holds the complete answer.
|
|
"""
|
|
|
|
def __init__(self, **kwargs):
|
|
self.stream_delta_callback = kwargs.get("stream_delta_callback")
|
|
self.tools = []
|
|
|
|
def run_conversation(self, message, conversation_history=None, task_id=None):
|
|
if self.stream_delta_callback:
|
|
self.stream_delta_callback(STREAMED_PREFIX)
|
|
return {
|
|
"final_response": FULL_RESPONSE,
|
|
"response_previewed": False,
|
|
"messages": [],
|
|
"api_calls": 1,
|
|
}
|
|
|
|
|
|
class CompleteStreamAgent:
|
|
"""Control: the streamed text exactly equals the final response."""
|
|
|
|
def __init__(self, **kwargs):
|
|
self.stream_delta_callback = kwargs.get("stream_delta_callback")
|
|
self.tools = []
|
|
|
|
def run_conversation(self, message, conversation_history=None, task_id=None):
|
|
if self.stream_delta_callback:
|
|
self.stream_delta_callback(FULL_RESPONSE)
|
|
return {
|
|
"final_response": FULL_RESPONSE,
|
|
"response_previewed": False,
|
|
"messages": [],
|
|
"api_calls": 1,
|
|
}
|
|
|
|
|
|
def _make_runner(adapter):
|
|
gateway_run = importlib.import_module("gateway.run")
|
|
runner = object.__new__(gateway_run.GatewayRunner)
|
|
runner.adapters = {adapter.platform: adapter}
|
|
runner._voice_mode = {}
|
|
runner._prefill_messages = []
|
|
runner._ephemeral_system_prompt = ""
|
|
runner._reasoning_config = None
|
|
runner._provider_routing = {}
|
|
runner._fallback_model = None
|
|
runner._session_db = None
|
|
runner._running_agents = {}
|
|
runner._session_run_generation = {}
|
|
runner.session_store = SimpleNamespace(_entries={}, _save=lambda: None)
|
|
runner.hooks = SimpleNamespace(loaded_hooks=False)
|
|
runner.config = SimpleNamespace(
|
|
thread_sessions_per_user=False,
|
|
group_sessions_per_user=False,
|
|
stt_enabled=False,
|
|
streaming=StreamingConfig.from_dict(
|
|
{"enabled": True, "edit_interval": 0.01, "buffer_threshold": 1}
|
|
),
|
|
)
|
|
return runner
|
|
|
|
|
|
async def _run_streaming_turn(monkeypatch, tmp_path, agent_cls, session_id):
|
|
import yaml
|
|
|
|
(tmp_path / "config.yaml").write_text(
|
|
yaml.dump(
|
|
{
|
|
"display": {"tool_progress": "off", "interim_assistant_messages": False},
|
|
"streaming": {
|
|
"enabled": True,
|
|
"edit_interval": 0.01,
|
|
"buffer_threshold": 1,
|
|
},
|
|
}
|
|
),
|
|
encoding="utf-8",
|
|
)
|
|
|
|
fake_dotenv = types.ModuleType("dotenv")
|
|
fake_dotenv.load_dotenv = lambda *args, **kwargs: None
|
|
monkeypatch.setitem(sys.modules, "dotenv", fake_dotenv)
|
|
|
|
fake_run_agent = types.ModuleType("run_agent")
|
|
fake_run_agent.AIAgent = agent_cls
|
|
monkeypatch.setitem(sys.modules, "run_agent", fake_run_agent)
|
|
|
|
adapter = FinalizeCaptureAdapter()
|
|
runner = _make_runner(adapter)
|
|
gateway_run = importlib.import_module("gateway.run")
|
|
monkeypatch.setattr(gateway_run, "_hermes_home", tmp_path)
|
|
monkeypatch.setattr(
|
|
gateway_run, "_resolve_runtime_agent_kwargs", lambda: {"api_key": "***"}
|
|
)
|
|
|
|
source = SessionSource(
|
|
platform=Platform.TELEGRAM,
|
|
chat_id="-1001",
|
|
chat_type="group",
|
|
)
|
|
result = await runner._run_agent(
|
|
message="describe this photo",
|
|
context_prompt="",
|
|
history=[],
|
|
source=source,
|
|
session_id=session_id,
|
|
session_key="agent:main:telegram:group:-1001",
|
|
)
|
|
return adapter, result
|
|
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# Gateway-boundary regression (#71643)
|
|
# ---------------------------------------------------------------------------
|
|
|
|
|
|
@pytest.mark.asyncio
|
|
async def test_stale_finalize_does_not_suppress_complete_response(
|
|
monkeypatch, tmp_path
|
|
):
|
|
"""The complete response must reach the platform even when the finalize
|
|
edit succeeded with only the stale preview snapshot."""
|
|
adapter, result = await _run_streaming_turn(
|
|
monkeypatch, tmp_path, StalePrefixAgent, "sess-71643-stale-finalize"
|
|
)
|
|
|
|
assert result["final_response"] == FULL_RESPONSE
|
|
# The missing tail must appear in at least one platform call — either the
|
|
# reconciliation edit or the normal final send. On the buggy path it
|
|
# appears in NO call at all (message loss).
|
|
all_payloads = [c["content"] for c in adapter.sent] + [
|
|
e["content"] for e in adapter.edits
|
|
]
|
|
assert any(FULL_RESPONSE in payload for payload in all_payloads), (
|
|
f"complete response never reached the platform; payloads: {all_payloads!r}"
|
|
)
|
|
# The recovery must not duplicate: when the gateway suppressed its normal
|
|
# final send (already_sent), the complete response must have been the
|
|
# payload of the message that finalized on screen — either an in-place
|
|
# reconciliation/finalize edit, or (consumer-declared final contract,
|
|
# 2026-08-16) the primary send itself when the authoritative final was
|
|
# adopted before the first flush. Both shapes are single-message.
|
|
if result.get("already_sent"):
|
|
_edit_carried = any(
|
|
e["content"] == FULL_RESPONSE and e["finalize"] for e in adapter.edits
|
|
)
|
|
_send_carried = any(c["content"] == FULL_RESPONSE for c in adapter.sent)
|
|
assert _edit_carried or _send_carried, (
|
|
"already_sent=True but neither an edit nor the primary send "
|
|
"carried the complete response"
|
|
)
|
|
|
|
|
|
@pytest.mark.asyncio
|
|
async def test_equal_text_control_still_suppresses_duplicate_send(
|
|
monkeypatch, tmp_path
|
|
):
|
|
"""When the streamed text equals the final response, suppression must
|
|
keep working — no duplicate full-response send."""
|
|
adapter, result = await _run_streaming_turn(
|
|
monkeypatch, tmp_path, CompleteStreamAgent, "sess-71643-control-equal"
|
|
)
|
|
|
|
assert result["final_response"] == FULL_RESPONSE
|
|
assert result.get("already_sent") is True
|
|
# Exactly one platform message holds the answer: the streamed message
|
|
# (created by one send, then edited). No duplicate full send.
|
|
full_sends = [c for c in adapter.sent if FULL_RESPONSE in c["content"]]
|
|
assert len(full_sends) <= 1, f"duplicate final delivery: {full_sends!r}"
|
|
|
|
|
|
class _PayloadLessSplitConsumer(GatewayStreamConsumer):
|
|
"""Force the #78541 shape after a normal stream drain.
|
|
|
|
Claims final delivery via the multi-message split path but leaves no
|
|
recorded payload — the pre-fix gateway treated matcher ``None`` as
|
|
legacy trust and swallowed the complete ``final_response``.
|
|
"""
|
|
|
|
async def run(self):
|
|
await super().run()
|
|
self._final_response_sent = True
|
|
self._final_content_delivered = True
|
|
self._turn_split_delivery = True
|
|
self._delivered_final_text = None
|
|
self._stream_ledger = ""
|
|
|
|
|
|
@pytest.mark.asyncio
|
|
async def test_payload_less_split_does_not_suppress_complete_response(
|
|
monkeypatch, tmp_path
|
|
):
|
|
"""#78541 — payload-less split-delivery flags must not swallow the reply."""
|
|
import yaml
|
|
|
|
(tmp_path / "config.yaml").write_text(
|
|
yaml.dump(
|
|
{
|
|
"display": {"tool_progress": "off", "interim_assistant_messages": False},
|
|
"streaming": {
|
|
"enabled": True,
|
|
"edit_interval": 0.01,
|
|
"buffer_threshold": 1,
|
|
},
|
|
}
|
|
),
|
|
encoding="utf-8",
|
|
)
|
|
|
|
fake_dotenv = types.ModuleType("dotenv")
|
|
fake_dotenv.load_dotenv = lambda *args, **kwargs: None
|
|
monkeypatch.setitem(sys.modules, "dotenv", fake_dotenv)
|
|
|
|
fake_run_agent = types.ModuleType("run_agent")
|
|
fake_run_agent.AIAgent = StalePrefixAgent
|
|
monkeypatch.setitem(sys.modules, "run_agent", fake_run_agent)
|
|
|
|
gateway_run = importlib.import_module("gateway.run")
|
|
stream_consumer_mod = importlib.import_module("gateway.stream_consumer")
|
|
# run.py imports GatewayStreamConsumer locally inside _run_agent — patch
|
|
# the defining module so the local import picks up the sabotage subclass.
|
|
monkeypatch.setattr(
|
|
stream_consumer_mod, "GatewayStreamConsumer", _PayloadLessSplitConsumer
|
|
)
|
|
monkeypatch.setattr(gateway_run, "_hermes_home", tmp_path)
|
|
monkeypatch.setattr(
|
|
gateway_run, "_resolve_runtime_agent_kwargs", lambda: {"api_key": "***"}
|
|
)
|
|
|
|
adapter = FinalizeCaptureAdapter()
|
|
runner = _make_runner(adapter)
|
|
source = SessionSource(
|
|
platform=Platform.TELEGRAM,
|
|
chat_id="-1004492624436",
|
|
chat_type="group",
|
|
thread_id="1",
|
|
)
|
|
result = await runner._run_agent(
|
|
message="describe this photo",
|
|
context_prompt="",
|
|
history=[],
|
|
source=source,
|
|
session_id="sess-78541-payload-less-split",
|
|
session_key="agent:main:telegram:group:-1004492624436:1",
|
|
)
|
|
|
|
assert result["final_response"] == FULL_RESPONSE
|
|
all_payloads = [c["content"] for c in adapter.sent] + [
|
|
e["content"] for e in adapter.edits
|
|
]
|
|
# The contract is "the complete reply is not swallowed", which has two
|
|
# legitimate shapes: _run_agent puts the full text on the wire itself
|
|
# (reconcile edit), or it declines to claim delivery so the caller's normal
|
|
# final send delivers it. A multi-message split takes the second shape --
|
|
# the reconcile edit is deliberately skipped there because it would repeat
|
|
# every sealed head chunk inside the tail message (#78541). Asserting only
|
|
# the first shape would pin the recovery route rather than the guarantee.
|
|
delivered_here = any(FULL_RESPONSE in payload for payload in all_payloads)
|
|
assert delivered_here or not result.get("already_sent"), (
|
|
"complete response was neither delivered nor left to the normal final "
|
|
f"send; already_sent={result.get('already_sent')!r} payloads={all_payloads!r}"
|
|
)
|
|
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# Consumer unit coverage: delivered_final_matches tri-state
|
|
# ---------------------------------------------------------------------------
|
|
|
|
|
|
def _consumer():
|
|
adapter = FinalizeCaptureAdapter()
|
|
return GatewayStreamConsumer(
|
|
adapter, "chat-1", StreamConsumerConfig(cursor=" ▉")
|
|
)
|
|
|
|
|
|
class TestDeliveredFinalMatches:
|
|
def test_no_record_returns_none(self):
|
|
consumer = _consumer()
|
|
assert consumer.delivered_final_matches("anything") is None
|
|
|
|
def test_matching_record_returns_true(self):
|
|
consumer = _consumer()
|
|
consumer._record_turn_final_payload(FULL_RESPONSE)
|
|
assert consumer.delivered_final_matches(FULL_RESPONSE) is True
|
|
|
|
def test_stale_prefix_record_returns_false(self):
|
|
consumer = _consumer()
|
|
consumer._record_turn_final_payload(STREAMED_PREFIX)
|
|
assert consumer.delivered_final_matches(FULL_RESPONSE) is False
|
|
|
|
def test_payload_less_split_delivery_returns_false(self):
|
|
"""#78541 — payload-less split must not inherit legacy trust."""
|
|
consumer = _consumer()
|
|
consumer._turn_split_delivery = True
|
|
consumer._delivered_final_text = None
|
|
assert consumer.delivered_final_matches(FULL_RESPONSE) is False
|
|
|
|
def test_split_delivery_with_matching_ledger_returns_true(self):
|
|
"""Complete overflow split that recorded its ledger still suppresses."""
|
|
consumer = _consumer()
|
|
consumer._turn_split_delivery = True
|
|
consumer._stream_ledger = FULL_RESPONSE
|
|
consumer._record_turn_final_payload(STREAMED_PREFIX) # tail only; ledger wins
|
|
assert consumer.delivered_final_matches(FULL_RESPONSE) is True
|
|
|
|
def test_split_delivery_with_stale_ledger_returns_false(self):
|
|
consumer = _consumer()
|
|
consumer._turn_split_delivery = True
|
|
consumer._stream_ledger = STREAMED_PREFIX
|
|
consumer._record_turn_final_payload(STREAMED_PREFIX)
|
|
assert consumer.delivered_final_matches(FULL_RESPONSE) is False
|
|
|
|
def test_empty_final_text_returns_none(self):
|
|
consumer = _consumer()
|
|
consumer._record_turn_final_payload(STREAMED_PREFIX)
|
|
assert consumer.delivered_final_matches("") is None
|
|
|
|
def test_segment_delivered_text_still_matches(self):
|
|
consumer = _consumer()
|
|
consumer._record_turn_final_payload(STREAMED_PREFIX)
|
|
# A prior segment delivered the exact final text.
|
|
consumer._delivered_segment_texts.append(FULL_RESPONSE)
|
|
assert consumer.delivered_final_matches(FULL_RESPONSE) is True
|
|
|
|
def test_reset_segment_state_clears_record(self):
|
|
consumer = _consumer()
|
|
consumer._record_turn_final_payload(STREAMED_PREFIX)
|
|
consumer._reset_segment_state()
|
|
assert consumer._delivered_final_text is None
|
|
assert consumer._turn_split_delivery is False
|
|
assert consumer._stream_ledger == ""
|
|
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# End-to-end split delivery: drive the real overflow-split loop (no hand-set
|
|
# private flags) and assert the no-duplicate / no-swallow contract on both
|
|
# sides. These are the shapes that #78541's boundary fix has to not regress:
|
|
# a genuine complete split must still suppress, and an incomplete one must not.
|
|
# ---------------------------------------------------------------------------
|
|
|
|
|
|
class _SplittingAdapter(FinalizeCaptureAdapter):
|
|
"""Small message cap so real prose trips the consumer's overflow split.
|
|
|
|
Also records deletions and can be told to fail edits, so the fresh-final
|
|
and flood-control paths can be driven without patching internals.
|
|
"""
|
|
|
|
MAX_MESSAGE_LENGTH = 220
|
|
|
|
def __init__(self, platform=Platform.TELEGRAM):
|
|
super().__init__(platform)
|
|
self.deleted = []
|
|
self.fail_edits = False
|
|
|
|
async def edit_message(
|
|
self, chat_id, message_id, content, *, finalize: bool = False, metadata=None
|
|
) -> SendResult:
|
|
if self.fail_edits:
|
|
return SendResult(
|
|
success=False, error="Flood control exceeded. Retry in 12 seconds"
|
|
)
|
|
return await super().edit_message(
|
|
chat_id, message_id, content, finalize=finalize, metadata=metadata
|
|
)
|
|
|
|
async def delete_message(self, chat_id, message_id) -> bool:
|
|
self.deleted.append(message_id)
|
|
return True
|
|
|
|
def truncate_message(self, text, limit, len_fn=len):
|
|
chunks, rest = [], text
|
|
while len_fn(rest) > limit:
|
|
cut = rest.rfind("\n", 0, limit)
|
|
if cut < limit // 2:
|
|
cut = limit
|
|
chunks.append(rest[:cut])
|
|
rest = rest[cut:].lstrip("\n")
|
|
chunks.append(rest)
|
|
return chunks
|
|
|
|
|
|
def _split_consumer():
|
|
adapter = _SplittingAdapter()
|
|
consumer = GatewayStreamConsumer(
|
|
adapter,
|
|
"chat-split",
|
|
StreamConsumerConfig(
|
|
edit_interval=0.0, buffer_threshold=1, cursor="",
|
|
fresh_final_after_seconds=0.0,
|
|
),
|
|
)
|
|
return adapter, consumer
|
|
|
|
|
|
async def _drain_split_turn(consumer, lines):
|
|
task = asyncio.create_task(consumer.run())
|
|
for line in lines:
|
|
consumer.on_delta(line + "\n")
|
|
await asyncio.sleep(0.005)
|
|
consumer.finish()
|
|
await asyncio.wait_for(task, timeout=10)
|
|
|
|
|
|
@pytest.mark.asyncio
|
|
async def test_complete_overflow_split_still_suppresses_duplicate():
|
|
"""A fully delivered multi-message reply must NOT be re-sent (#45517)."""
|
|
adapter, consumer = _split_consumer()
|
|
lines = [f"line {i} " + "x" * 60 for i in range(12)]
|
|
await _drain_split_turn(consumer, lines)
|
|
|
|
complete = "\n".join(lines)
|
|
assert consumer._turn_split_delivery is True, "overflow split never triggered"
|
|
# The user received the whole answer across several messages, so the
|
|
# gateway must keep suppressing its own final send.
|
|
assert consumer.delivered_final_matches(complete) is True
|
|
|
|
|
|
@pytest.mark.asyncio
|
|
async def test_split_delivery_missing_tail_does_not_suppress():
|
|
"""#78541 — when the completed response exceeds what the split delivered,
|
|
the matcher must report a mismatch so the gateway still sends it."""
|
|
adapter, consumer = _split_consumer()
|
|
lines = [f"line {i} " + "x" * 60 for i in range(12)]
|
|
await _drain_split_turn(consumer, lines)
|
|
|
|
never_streamed = "\n".join(lines) + "\n\n" + "tail the user never saw " * 8
|
|
assert consumer._turn_split_delivery is True
|
|
assert consumer.delivered_final_matches(never_streamed) is False
|
|
|
|
|
|
@pytest.mark.asyncio
|
|
async def test_split_delivery_keeps_sealed_heads_on_fresh_final():
|
|
"""The fresh-final route must not delete sealed head messages.
|
|
|
|
``_try_fresh_final`` replaces every tracked preview with one fresh message,
|
|
which only holds the whole answer on a single-message turn. After a split
|
|
the sealed heads carry text that the fresh message does not, so deleting
|
|
them would drop delivered content (#78541).
|
|
"""
|
|
adapter, consumer = _split_consumer()
|
|
head_id = await consumer._send_new_chunk("HEAD text. " * 12, None, final=False)
|
|
consumer._turn_split_delivery = True
|
|
|
|
assert head_id in consumer._preview_message_ids
|
|
assert await consumer._try_fresh_final("TAIL text. " * 12) is False
|
|
assert head_id not in adapter.deleted, "sealed head chunk was deleted"
|
|
|
|
|
|
@pytest.mark.asyncio
|
|
async def test_failed_final_edit_after_split_records_visible_payload():
|
|
"""A flood-controlled cosmetic final edit must not cause a duplicate.
|
|
|
|
The complete answer is already on screen; only the cursor-strip edit
|
|
failed. Recording the visible payload keeps the gateway suppressing its
|
|
own send instead of posting the whole answer twice (#36965 / #25349).
|
|
"""
|
|
adapter = _SplittingAdapter()
|
|
cursor = " \u2589"
|
|
consumer = GatewayStreamConsumer(
|
|
adapter,
|
|
"chat-split",
|
|
StreamConsumerConfig(
|
|
edit_interval=0.0, buffer_threshold=1, cursor=cursor,
|
|
fresh_final_after_seconds=0.0,
|
|
),
|
|
)
|
|
full = "The complete answer. " * 8
|
|
# Streaming already put the whole answer on screen, cursor and all.
|
|
await consumer._send_or_edit(full + cursor)
|
|
assert consumer._last_sent_text.endswith(cursor)
|
|
consumer._turn_split_delivery = True
|
|
consumer._stream_ledger = full
|
|
adapter.fail_edits = True
|
|
|
|
# The cosmetic cursor-strip edit is rate-limited and fails.
|
|
assert await consumer._send_or_edit(full, finalize=True) is False
|
|
assert consumer._final_content_delivered is True
|
|
assert consumer.delivered_final_matches(full) is True
|
|
|
|
|
|
@pytest.mark.asyncio
|
|
async def test_empty_fallback_final_after_split_records_only_what_survives():
|
|
"""A recovery that DELETES the sealed heads must not claim them as delivered.
|
|
|
|
``_send_empty_fallback_final`` replaces the active segment: it sends the
|
|
completed text as a fresh message and deletes every tracked segment
|
|
preview -- including the sealed head chunks of an overflow split. Only the
|
|
new message is left on screen, so the recorded payload must be that message
|
|
verbatim, NOT the stream ledger. Recording the ledger would claim delivery
|
|
for text this path just removed, and the gateway would suppress its own
|
|
send and leave the user with a fraction of the answer (#78541).
|
|
"""
|
|
adapter = _SplittingAdapter()
|
|
consumer = GatewayStreamConsumer(
|
|
adapter,
|
|
"chat-split",
|
|
StreamConsumerConfig(
|
|
edit_interval=0.0, buffer_threshold=1, cursor="",
|
|
fresh_final_after_seconds=0.0,
|
|
),
|
|
)
|
|
head = "HEAD text. " * 40
|
|
tail = "TAIL text. " * 6
|
|
complete = head + tail
|
|
|
|
# Sealed head chunk is on screen and tracked as a segment preview.
|
|
head_id = await consumer._send_new_chunk(head, None, final=False)
|
|
consumer._turn_split_delivery = True
|
|
consumer._stream_ledger = complete
|
|
assert head_id in consumer._segment_preview_message_ids
|
|
|
|
# The recovery commits only ``tail`` and deletes the sealed head.
|
|
assert await consumer._send_empty_fallback_final(tail) == "delivered"
|
|
assert head_id in adapter.deleted, "expected the recovery to delete the head"
|
|
|
|
# The head is gone from the chat, so the complete answer was NOT delivered:
|
|
# the gateway must be told this is a mismatch and send it.
|
|
assert consumer.delivered_final_matches(complete) is False
|