test(k8s): record the full-launch wire fixture from the desktop's emitter

`deploy-full-launch.request.json` was derived by reading the desktop's
emitters rather than executing them, and carried four values no desktop
can produce: `respond_to` held a pubkey where `RespondTo` serializes a
kebab-case enum; the allowlist entries and `launch.owner_pubkey` failed
`validate_respond_to_allowlist`'s 64-hex rule (`types.rs:897`, re-checked
on every spawn at `runtime.rs:385`); `policy_env` used an invented
`BUZZ_ACP_PARALLELISM` where the emitter writes `BUZZ_ACP_AGENTS`
(`runtime.rs:729`, read back by `buzz-acp` `config.rs:292`); and
`launch.env` held a `LAYERED` key belonging to no layer of
`resolve_effective_harness_descriptor`.

The agent object is now transcribed verbatim from a run of the real
`build_launch_block` -> `deploy_payload_json` path, so it is the complete
emitted shape — including the always-serialized top-level keys with their
null values, whose absence from `policy_env` is what proves them null.

This provider is indifferent to every one of those fields, which is why
its own tests could not notice: `respond_to` is an `Option<String>`, the
allowlist an opaque `Vec<String>`, `policy_env` an arbitrary map, and
`the_full_desktop_payload_is_accepted` passes on invented data exactly as
happily as on recorded data. The README now says so, and points at the
desktop's whole-object equality test as the enforcement — a completeness
guard stops a case from going missing, it cannot tell you a case is false.

Co-authored-by: Dawn (sprout agent) <c6237ef84fa537c78dcee78efd2d4e59f728859c7f194da42ac51ededfa0be05@sprout-oss.stage.blox.sqprod.co>
Signed-off-by: tlongwell-block <109685178+tlongwell-block@users.noreply.github.com>
This commit is contained in:
tlongwell-block
2026-08-02 01:00:12 -04:00
co-authored by Dawn
parent 02b860dd1c
commit 5e11451a1e
2 changed files with 59 additions and 16 deletions
@@ -8,10 +8,28 @@ Each `*.request.json` is a request the desktop can emit; each matching
provider side is asserted by `tests/wire_fixtures.rs`; the desktop side should
assert that its emitted payloads parse as the corresponding request.
Two rules keep these useful rather than decorative:
Three rules keep these useful rather than decorative:
* **Requests are recorded, not invented.** A fixture that no caller emits
tests a contract nobody has.
tests a contract nobody has. "Recorded" means *executed and transcribed* —
`deploy-full-launch.request.json` is the output of the desktop's real
`build_launch_block` → `deploy_payload_json` path, not a shape derived by
reading those functions. Deriving it is how this fixture acquired four
impossible values at once: a `respond_to` that was a pubkey where the
desktop serializes a kebab-case `RespondTo` enum, allowlist and owner
values failing `validate_respond_to_allowlist`'s 64-hex rule
(`types.rs:897`), an invented `BUZZ_ACP_PARALLELISM` where the emitter
writes `BUZZ_ACP_AGENTS` (`runtime.rs:729`), and a `launch.env` key from
no layer of `resolve_effective_harness_descriptor`.
* **The provider cannot police this file, so the desktop must.** Every field
above is one this provider is deliberately indifferent to — `respond_to` is
an opaque `Option<String>`, the allowlist an opaque `Vec<String>`,
`policy_env` an arbitrary map — so `the_full_desktop_payload_is_accepted`
passes on invented data exactly as happily as on recorded data. The
enforcement is the desktop's whole-object equality test, which *builds* the
payload and compares it to this file. A completeness guard (the case-list
directory scan in `wire_fixtures.rs`) stops a case from going missing; it
cannot tell you a case is false.
* **Responses are byte-compared after key-sorted re-serialization**, so a
field rename or a type change fails here rather than in a desktop that
silently reads `undefined`.
@@ -2,23 +2,48 @@
"op": "deploy",
"request_id": "req-6",
"agent": {
"name": "worker",
"relay_url": "wss://relay.example",
"private_key_nsec": "nsec1vl029mgpspedva04g90vltkh6fvh240zqtv9k0t9af8935ke9laqsnlfe5",
"agent_args": [],
"agent_command": "goose",
"auth_tag": "tag-1",
"respond_to": "npub1abc",
"respond_to_allowlist": ["npub1def", "npub1ghi"],
"env_vars": {"USER_KEY": "user-value"},
"model": "gpt-5",
"provider": "openai",
"turn_timeout_seconds": 300,
"env_vars": {
"USER_KEY": "user-value"
},
"idle_timeout_seconds": null,
"launch": {
"args": [
"run",
"--session"
],
"command": "goose",
"args": ["run", "--session"],
"env": {"LAYERED": "from-launch"},
"policy_env": {"BUZZ_ACP_PARALLELISM": "10"},
"owner_pubkey": "beefcafe"
}
"env": {
"GOOSE_MODEL": "gpt-5",
"GOOSE_PROVIDER": "openai",
"USER_KEY": "user-value"
},
"owner_pubkey": "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa",
"policy_env": {
"BUZZ_ACP_AGENTS": "10",
"BUZZ_ACP_LAZY_POOL": "true",
"BUZZ_ACP_MODEL": "gpt-5",
"BUZZ_ACP_RELAY_OBSERVER": "true",
"BUZZ_ACP_SESSION_TITLE": "worker",
"GOOSE_MODE": "auto"
}
},
"max_turn_duration_seconds": null,
"model": "gpt-5",
"name": "worker",
"parallelism": 10,
"private_key_nsec": "nsec1vl029mgpspedva04g90vltkh6fvh240zqtv9k0t9af8935ke9laqsnlfe5",
"provider": "openai",
"relay_url": "wss://relay.example",
"respond_to": "allowlist",
"respond_to_allowlist": [
"aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa",
"bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb"
],
"system_prompt": null,
"turn_timeout_seconds": 300
},
"provider_config": {
"namespace": "buzz-agents-test",