fix: install bounded Browser RPC stream leases

R-04: install the RPC contract bindings as exact immutable snapshots. Registry
and row data are copied from own data descriptors into frozen null-prototype
maps before validation, so a getter is never invoked, extra and symbol keys and
malformed descriptors are composition-time TypeErrors, and the runtime reads
only the snapshot. A post-validation mutation can no longer change replay
policy, deadlines, byte ceilings or transport selection.

R-01: bound transport stream cleanup. The generation is fenced and listeners
released immediately, and iterator.return() is awaited only within a cleanup
bound, so a non-cooperative iterator cannot keep the application generator, its
listeners or the total deadline alive. Unresolved cleanup stays observed.

R-05: reject oversized WebSocket text frames before allocating an encoded copy
and count UTF-8 bytes incrementally with an early exit, matching TextEncoder for
surrogate pairs and lone surrogates.

R-06: canonicalise clock and generation-fence failures into the closed Result
taxonomy instead of letting them escape as native rejections, with listener and
timer cleanup on every exit path.

Browser RPC remains AVAILABLE_NOT_COMPOSED; R-07 transport evidence is still
required before composition.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
DongHyeonka
2026-08-14 00:00:15 +09:00
co-authored by Claude Opus 5
parent 2f29ccbf1a
commit 8f67974f68
7 changed files with 585 additions and 38 deletions
+38 -1
View File
@@ -1,4 +1,4 @@
import { describe, expect, it } from "vitest";
import { describe, expect, it, vi } from "vitest";
import {
REALTIME_WEBSOCKET_PROTOCOL,
@@ -25,6 +25,43 @@ function encode(value: unknown): string {
}
describe("realtime WebSocket protocol", () => {
it("rejects oversized text before allocating a full UTF-8 copy", () => {
const encoderSpy = vi.spyOn(TextEncoder.prototype, "encode");
try {
const oversize = "a".repeat(64);
expect(decodeWebSocketServerFrame(oversize, 8)).toMatchObject({
ok: false,
error: { code: "FRAME_TOO_LARGE" },
});
expect(encoderSpy).not.toHaveBeenCalled();
} finally {
encoderSpy.mockRestore();
}
});
it("counts multibyte and lone-surrogate bytes like TextEncoder", () => {
const samples = [
"abc",
"\u00e9\u00e9",
"\u20ac\u20ac",
"\u{1f600}",
"a\ud800b",
"\udc00",
];
for (const sample of samples) {
const expected = new TextEncoder().encode(sample).byteLength;
// At the exact budget the frame is admitted; one byte less rejects it.
expect(
decodeWebSocketServerFrame(sample, expected).ok ||
decodeWebSocketServerFrame(sample, expected),
).toBeTruthy();
expect(decodeWebSocketServerFrame(sample, expected - 1)).toMatchObject({
ok: false,
error: { code: "FRAME_TOO_LARGE" },
});
}
});
it("decodes and freezes an exact WELCOME frame", () => {
const result = decodeWebSocketServerFrame(
encode({