Files
roboco/tests/unit/gateway/test_dm_a2a_denied.py
T
6cf99a1b0a [beb8cae1] Type-gate tests/ under mypy — fix all errors and flip quality gate (#156) (#157)
* [420e5e68] Fix mypy errors in tests/unit/ and create tests/__init__.py (#154)

* [420e5e68] fix(tests): resolve all mypy errors in tests/unit/ and create tests/__init__.py

- Create tests/__init__.py as empty package marker
- Add Any import and fix list type annotation in test_flow_server_intent_public_mapping.py
- Move AsyncIterator to TYPE_CHECKING block and fix m.cls.__name__ attr error in test_app.py
- Add return type annotations to _stub_get_optimal, _source, and factory functions
- Implement abstract methods (index_type, prepare_metadata, build_source_uri) in _FakePlugin
- Add pyproject.toml per-file-ignore for ARG002 on test_optimal_grounding.py stub
- Remove 4 stale # type: ignore comments from test_rate_limit_tracker.py
- Fix method-assignment patterns in test_rate_limit_sweep.py via patch.object
- All 487 source files pass mypy with 0 errors; 2312 unit tests pass

* [420e5e68] fix(tests): move stdlib/third-party imports to TYPE_CHECKING blocks across tests/unit/

Resolves 6 remaining ruff TC002/TC003 errors from the quality gate:
- test_handlers.py: Iterator → TYPE_CHECKING
- test_quality_gate.py: pathlib → TYPE_CHECKING
- test_board_dispatch.py: AsyncIterator + httpx → TYPE_CHECKING
- test_streaming.py: Iterator → TYPE_CHECKING
- test_notification.py: AsyncIterator → TYPE_CHECKING

All files have from __future__ import annotations so annotations are strings
at runtime; no runtime NameError risk from moving to TYPE_CHECKING.

* [420e5e68] fix(tests): use forward-ref cast() and drop unused TYPE_CHECKING import in 4 test files

* [420e5e68] chore(Makefile): scope lint mypy target to roboco/ to match gate and quality targets

---------



* [b0c9d41b] Fix mypy errors in tests/integration/ tests/foundation/ tests/property/ and update Makefile quality gates (#155)

* [b0c9d41b] fix(tests): resolve all mypy errors in tests/integration/, tests/foundation/, tests/property/

- Add missing type annotations to inner functions (_override_db, _override_agent_id, _req, etc.)
- Use cast("UUID", ...) to fix SQLAlchemy UUID vs uuid.UUID arg-type mismatches
- Remove stale # type: ignore comments from test_full_lifecycle_real_db.py and test_task_service_lifecycle_misc.py
- Update Makefile quality/quality-fast targets to run mypy on roboco/ tests/
- No runtime logic changed — annotations and cast() only

* [b0c9d41b] fix(tests): apply ruff TC006 quoted-cast and AsyncGenerator[T] fixes to complete mypy gate

- Quote all cast() type arguments per ruff TC006 rule (cast("T", x))
- Change AsyncGenerator[T, None] to AsyncGenerator[T] (Python 3.12 form)
- Move runtime-only imports to TYPE_CHECKING blocks (Path, Table, Generator, etc.)
- No runtime logic changed — annotation-only changeset

* [b0c9d41b] fix(Makefile): align lint target mypy scope with gate target (roboco/ only)

The lint target used `uv run mypy .` (all files) while gate uses `uv run mypy
roboco/`. This inconsistency caused the pre-submit gate to fail on 161 pre-existing
tests/unit/ errors (being fixed by sibling task 420e5e68). The quality/quality-fast
targets already check `roboco/ tests/` — the lint target now matches gate scope.

---------



---------

Co-authored-by: Backend Developer 1 <be-dev-1@agents.roboco.dev>
Co-authored-by: Backend Developer 2 <be-dev-2@agents.roboco.dev>
2026-06-14 13:43:46 +02:00

81 lines
2.8 KiB
Python

"""Smoke-7: dm catches A2AAccessDeniedError as Envelope.not_authorized.
Original bug: be-qa called dm(recipient='qa-all', ...) — 'qa-all' is a
channel slug, not an agent slug. A2A enforcement raised
A2AAccessDeniedError. It propagated past dm(), past content_actions,
and got caught by FastAPI's middleware which renders RobocoError.to_dict()
as `{'error': {'code': ..., 'message': ..., 'details': ...}}`.
do_server's circuit-breaker check then did
`dict_error in _CIRCUIT_REJECTION_KINDS` and crashed with
`TypeError: unhashable type: 'dict'`. The agent saw a generic
"Error executing tool dm: unhashable type: 'dict'" and got stuck.
The do_server defense-in-depth test lives in
tests/unit/mcp_servers/test_do_server_circuit_breaker.py.
"""
from __future__ import annotations
from unittest.mock import AsyncMock, MagicMock
from uuid import uuid4
import pytest
from roboco.enforcement.a2a_access import A2AAccessDeniedError
from roboco.services.gateway.content_actions import ContentActions, ContentActionsDeps
def _make_deps(**overrides: object) -> ContentActionsDeps:
base: dict[str, object] = {
"task": AsyncMock(),
"git": AsyncMock(),
"messaging": AsyncMock(),
"a2a": AsyncMock(),
"journal": AsyncMock(),
"workspace": AsyncMock(),
"notifications": AsyncMock(),
}
base.update(overrides)
return ContentActionsDeps(**base)
@pytest.mark.asyncio
async def test_dm_a2a_denied_returns_envelope_not_authorized() -> None:
"""A2AAccessDeniedError is caught and returned as Envelope.not_authorized."""
agent_id = uuid4()
task_id = uuid4()
task_obj = MagicMock(id=task_id, status="in_progress", assigned_to=agent_id)
task_svc = AsyncMock()
task_svc.agent_for.return_value = MagicMock(role="qa")
task_svc.get_journal_context_task_for_agent.return_value = task_obj
task_svc.get_active_task_for_agent.return_value = task_obj
task_svc.get.return_value = task_obj
a2a_svc = AsyncMock()
a2a_svc.send.side_effect = A2AAccessDeniedError(
from_agent="be-qa",
to_agent="qa-all",
reason="Cannot A2A unknown. Route: be-qa → be-pm → main-pm.",
route_hint="be-qa → be-pm → main-pm",
)
deps = _make_deps(task=task_svc, a2a=a2a_svc)
actions = ContentActions(deps)
env = await actions.dm(
agent_id=agent_id,
recipient="qa-all",
text="PASS notice",
task_id=task_id,
)
assert env.error == "not_authorized", (
f"A2A denial must surface as not_authorized envelope, got {env.error!r}. "
"If it escapes to FastAPI middleware, RobocoError.to_dict() renders the "
"error as a dict and the do_server circuit breaker crashes."
)
assert env.message is not None
assert "be-qa" in env.message
assert env.remediate is not None