mirror of
https://github.com/fabro-sh/fabro.git
synced 2026-08-28 05:27:41 +00:00
# Interpolation foundation (InterpString v2)
First step of unifying config-string interpolation across Fabro. This PR
is the
**behavior-neutral foundation** only — it introduces the type machinery
and a
clippy gate, but changes no field's interpolation behavior. The actual
field
work follows as separate stacked PRs, sequenced **reduce-first**:
narrowing
changes (demote fields that shouldn't interpolate, de-template DOT
attrs) land
before capability additions (resolve env in MCP / prepare / hooks).
## Why
Config strings interpolate `{{ ... }}` inconsistently today — some
fields
resolve `{{ env.X }}`, others are typed as if they do but silently pass
the
literal template text downstream. We're converging on three field types
(`String`, `InterpString`, and later an importable template for
prompts/goals)
with four namespaces (`env`, `vars`, `secrets`, `inputs`). This PR lays
the
`InterpString` foundation; it does not migrate any field.
## What's in it
- Segments generalize to `Token { namespace, name }` with a `Namespace`
enum
(`env`/`vars`/`secrets`/`inputs`). `secrets`/`inputs` are **reserved** —
parsed as tokens ahead of their resolvers.
- `ResolveCtx` with per-namespace lookups. `resolve_with()` fails loudly
(`Unavailable`) for a token whose namespace isn't provided in context;
`substitute_with()` substitutes provided namespaces and preserves the
rest.
`resolve()` / `substitute_variables()` are thin wrappers over one core
path.
- `ResolveEnvError` → `ResolveError { namespace, name, kind: Missing |
Unavailable }`
(message text unchanged for env/vars; the kind no longer bakes the
namespace
in, so it scales to four namespaces without an enum explosion).
- `Provenance` tracks secret-sourced names alongside env-sourced, for
uniform
redaction later.
- **`as_source()` is clippy-gated** (`disallowed-methods`). It keeps its
name;
every call site carries an `#[expect(..., reason)]` classifying it
(serialization, error display, known-leak-pending-fix, demotion-pending,
test). The lint turns the leak surface into a greppable, reasoned
work-list
and the method stays for its permanent uses (serde round-trip of the
unresolved template + diagnostics).
- fabro-server: five duplicate `process_env_var` facades and two
duplicate
`resolve_interp` helpers consolidated into one `crate::interp` module.
## Behavior changes (honest list)
- **`{{ secrets.* }}` / `{{ inputs.* }}` are now reserved.** On main
they
weren't recognized as tokens → silent literal passthrough. Now, at
`resolve()` consumers they **fail loud** (`Unavailable`) instead of
passing
the literal string through (nobody wants the literal characters as a
value —
strictly better, but technically a change). At `as_source` sites they
round-trip unchanged. Actual resolution lands in later enhancing PRs.
- Some fabro-server resolution errors gain a `"failed to resolve
<source>"`
context line.
Otherwise behavior-neutral: every field resolves exactly as it did on
main.
## What's deferred to follow-up PRs (reduce-first order)
- **Reducing / cleanup (next):** demote leak fields to `String`
(`run.model.*`, `cli.exec.model.*`, `run.git.author.*`,
`run.scm.owner/repository`); de-template `condition`/`label`/`model`/
`provider`/`speed` and `output_schema`.
- **Enhancing (after):** resolve `{{ env.* }}` in MCP transports,
prepare
steps, and hooks; wire `secrets`/`inputs`.
## Verification
- `cargo build --workspace`
- `cargo nextest run --workspace` → 6449 passed, 181 skipped
- `cargo +nightly fmt --check --all`
- `cargo +nightly clippy --workspace --all-targets -- -D warnings` →
clean
## Reviewer notes
- The reserved-namespace `Unavailable` error for `secrets`/`inputs` is
**intentional**, not a missing case — they're parsed ahead of their
resolvers so misuse fails loud instead of leaking.
- `as_source` is clippy-gated but keeps its name deliberately — the gate
is
the enforcement; renaming was avoided as unnecessary churn.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
528 lines
16 KiB
Rust
528 lines
16 KiB
Rust
use fabro_test::{fabro_json_snapshot, fabro_snapshot, test_context};
|
||
use httpmock::MockServer;
|
||
use insta::assert_snapshot;
|
||
use serde_json::json;
|
||
|
||
use super::support::{
|
||
fixture, output_stdout, remote_run_summary_json, resolve_run, run_count_for_test_case,
|
||
run_state,
|
||
};
|
||
use crate::support::unique_run_id;
|
||
|
||
fn resolved_run(settings: &fabro_types::WorkflowSettings) -> fabro_types::settings::RunNamespace {
|
||
settings.run.clone()
|
||
}
|
||
|
||
fn run_status_response(run_id: &str, status: &str) -> serde_json::Value {
|
||
let status = match status {
|
||
"submitted" => json!({ "kind": "submitted" }),
|
||
other => panic!("unsupported test status {other:?}"),
|
||
};
|
||
remote_run_summary_json(
|
||
run_id,
|
||
"Test Workflow",
|
||
"test-workflow",
|
||
"Test run",
|
||
&status,
|
||
"2026-04-05T12:00:00Z",
|
||
)
|
||
}
|
||
|
||
#[test]
|
||
fn help() {
|
||
let context = test_context!();
|
||
let mut cmd = context.command();
|
||
cmd.args(["create", "--help"]);
|
||
fabro_snapshot!(context.filters(), cmd, @"
|
||
success: true
|
||
exit_code: 0
|
||
----- stdout -----
|
||
Create a workflow run (allocate run dir, persist spec)
|
||
|
||
Usage: fabro create [OPTIONS] <WORKFLOW>
|
||
|
||
Arguments:
|
||
<WORKFLOW> Path to a .fabro workflow file or .toml task config
|
||
|
||
Options:
|
||
--json Output as JSON [env: FABRO_JSON=]
|
||
--server <SERVER> Fabro server target: http(s) URL or absolute Unix socket path [env: FABRO_SERVER=]
|
||
--debug Enable DEBUG-level logging (default is INFO) [env: FABRO_DEBUG=]
|
||
-I, --input <KEY=VALUE> Override a workflow input value (repeatable, format: KEY=VALUE)
|
||
--dry-run Execute with simulated LLM backend
|
||
--no-upgrade-check Disable automatic upgrade check [env: FABRO_NO_UPGRADE_CHECK=true]
|
||
--auto-approve Auto-approve all human gates
|
||
--quiet Suppress non-essential output [env: FABRO_QUIET=]
|
||
--goal <GOAL> Override the workflow goal (available as {{ goal }} in prompts)
|
||
--goal-file <GOAL_FILE> Read the workflow goal from a file
|
||
--model <MODEL> Override default LLM model
|
||
--provider <PROVIDER> Override default LLM provider
|
||
-v, --verbose Enable verbose output
|
||
--environment <ENVIRONMENT> Named environment for agent tools
|
||
--label <KEY=VALUE> Attach a label to this run (repeatable, format: KEY=VALUE)
|
||
--parent <RUN> Link this run to an existing orchestration parent run
|
||
--preserve-sandbox Keep the sandbox alive after the run finishes (for debugging)
|
||
-d, --detach Run the workflow in the background and print the run ID
|
||
-h, --help Print help
|
||
----- stderr -----
|
||
");
|
||
}
|
||
|
||
#[test]
|
||
fn create_uses_explicit_server_target_and_prints_remote_run_id() {
|
||
let context = test_context!();
|
||
let server = MockServer::start();
|
||
let run_id = unique_run_id();
|
||
let mock = server.mock(|when, then| {
|
||
when.method("POST").path("/api/v1/runs");
|
||
then.status(201)
|
||
.header("Content-Type", "application/json")
|
||
.body(run_status_response(run_id.as_str(), "submitted").to_string());
|
||
});
|
||
|
||
let output = context
|
||
.create_cmd()
|
||
.args([
|
||
"--server",
|
||
&format!("{}/api/v1", server.base_url()),
|
||
"--dry-run",
|
||
fixture("simple.fabro").to_str().unwrap(),
|
||
])
|
||
.output()
|
||
.expect("command should execute");
|
||
|
||
assert!(
|
||
output.status.success(),
|
||
"command failed:\nstdout:\n{}\nstderr:\n{}",
|
||
String::from_utf8_lossy(&output.stdout),
|
||
String::from_utf8_lossy(&output.stderr)
|
||
);
|
||
mock.assert();
|
||
assert_eq!(output_stdout(&output).trim(), run_id.as_str());
|
||
}
|
||
|
||
#[test]
|
||
fn create_uses_configured_server_target_without_server_flag() {
|
||
let context = test_context!();
|
||
let server = MockServer::start();
|
||
let run_id = unique_run_id();
|
||
let mock = server.mock(|when, then| {
|
||
when.method("POST").path("/api/v1/runs");
|
||
then.status(201)
|
||
.header("Content-Type", "application/json")
|
||
.body(run_status_response(run_id.as_str(), "submitted").to_string());
|
||
});
|
||
context.set_http_target(&server.base_url());
|
||
|
||
let output = context
|
||
.create_cmd()
|
||
.args(["--dry-run", fixture("simple.fabro").to_str().unwrap()])
|
||
.output()
|
||
.expect("command should execute");
|
||
|
||
assert!(
|
||
output.status.success(),
|
||
"command failed:\nstdout:\n{}\nstderr:\n{}",
|
||
String::from_utf8_lossy(&output.stdout),
|
||
String::from_utf8_lossy(&output.stderr)
|
||
);
|
||
mock.assert();
|
||
assert_eq!(output_stdout(&output).trim(), run_id.as_str());
|
||
}
|
||
|
||
#[test]
|
||
fn create_parent_resolves_parent_and_sends_parent_id_in_manifest() {
|
||
let context = test_context!();
|
||
let server = MockServer::start();
|
||
let run_id = unique_run_id();
|
||
let parent_id = unique_run_id();
|
||
let resolve_mock = super::support::mock_resolved_run(&server, "nightly-parent", &parent_id);
|
||
let create_mock = server.mock(|when, then| {
|
||
when.method("POST")
|
||
.path("/api/v1/runs")
|
||
.json_body_includes(format!(r#"{{"parent_id":"{parent_id}"}}"#));
|
||
then.status(201)
|
||
.header("Content-Type", "application/json")
|
||
.body(run_status_response(run_id.as_str(), "submitted").to_string());
|
||
});
|
||
|
||
let output = context
|
||
.create_cmd()
|
||
.args([
|
||
"--server",
|
||
&format!("{}/api/v1", server.base_url()),
|
||
"--dry-run",
|
||
"--parent",
|
||
"nightly-parent",
|
||
fixture("simple.fabro").to_str().unwrap(),
|
||
])
|
||
.output()
|
||
.expect("command should execute");
|
||
|
||
assert!(
|
||
output.status.success(),
|
||
"command failed:\nstdout:\n{}\nstderr:\n{}",
|
||
String::from_utf8_lossy(&output.stdout),
|
||
String::from_utf8_lossy(&output.stderr)
|
||
);
|
||
resolve_mock.assert();
|
||
create_mock.assert();
|
||
assert_eq!(output_stdout(&output).trim(), run_id.as_str());
|
||
}
|
||
|
||
#[test]
|
||
fn create_rejects_storage_dir_flag() {
|
||
let context = test_context!();
|
||
let output = context
|
||
.create_cmd()
|
||
.args([
|
||
"--storage-dir",
|
||
"/tmp/fabro-create",
|
||
"--dry-run",
|
||
fixture("simple.fabro").to_str().unwrap(),
|
||
])
|
||
.output()
|
||
.expect("command should execute");
|
||
|
||
assert!(
|
||
!output.status.success(),
|
||
"command should reject --storage-dir"
|
||
);
|
||
let stderr = String::from_utf8_lossy(&output.stderr);
|
||
assert!(stderr.contains("unexpected argument '--storage-dir'"));
|
||
}
|
||
|
||
#[test]
|
||
fn create_cli_server_target_overrides_configured_server_target() {
|
||
let context = test_context!();
|
||
let config_server = MockServer::start();
|
||
let config_mock = config_server.mock(|when, then| {
|
||
when.method("POST").path("/api/v1/runs");
|
||
then.status(500)
|
||
.body("configured-server-should-not-be-used");
|
||
});
|
||
let cli_server = MockServer::start();
|
||
let run_id = unique_run_id();
|
||
let cli_mock = cli_server.mock(|when, then| {
|
||
when.method("POST").path("/api/v1/runs");
|
||
then.status(201)
|
||
.header("Content-Type", "application/json")
|
||
.body(run_status_response(run_id.as_str(), "submitted").to_string());
|
||
});
|
||
context.set_http_target(&config_server.base_url());
|
||
|
||
let output = context
|
||
.create_cmd()
|
||
.args([
|
||
"--server",
|
||
&format!("{}/api/v1", cli_server.base_url()),
|
||
"--dry-run",
|
||
fixture("simple.fabro").to_str().unwrap(),
|
||
])
|
||
.output()
|
||
.expect("command should execute");
|
||
|
||
assert!(
|
||
output.status.success(),
|
||
"command failed:\nstdout:\n{}\nstderr:\n{}",
|
||
String::from_utf8_lossy(&output.stdout),
|
||
String::from_utf8_lossy(&output.stderr)
|
||
);
|
||
cli_mock.assert();
|
||
config_mock.assert_calls(0);
|
||
assert_eq!(output_stdout(&output).trim(), run_id.as_str());
|
||
}
|
||
|
||
#[test]
|
||
fn create_persists_directory_workflow_slug_and_cached_graph() {
|
||
let context = test_context!();
|
||
context.ensure_home_server_auth_methods();
|
||
let run_id = unique_run_id();
|
||
let workflow_path = context.temp_dir.join("sluggy/workflow.fabro");
|
||
|
||
context.write_temp(
|
||
"sluggy/workflow.fabro",
|
||
"\
|
||
digraph BarBaz {
|
||
start [shape=Mdiamond, label=\"Start\"]
|
||
exit [shape=Msquare, label=\"Exit\"]
|
||
start -> exit
|
||
}
|
||
",
|
||
);
|
||
|
||
context
|
||
.command()
|
||
.args([
|
||
"create",
|
||
"--dry-run",
|
||
"--auto-approve",
|
||
"--run-id",
|
||
run_id.as_str(),
|
||
workflow_path.to_str().unwrap(),
|
||
])
|
||
.assert()
|
||
.success();
|
||
|
||
let run_dir = context.find_run_dir(&run_id);
|
||
let state = run_state(&run_dir);
|
||
let run = &state.spec;
|
||
fabro_json_snapshot!(
|
||
context,
|
||
serde_json::json!({
|
||
"workflow_slug": run.workflow_slug,
|
||
"graph_name": run.graph.name,
|
||
"cached_graph_lines": state.spec.graph_source.as_ref().expect("graph should exist").lines().collect::<Vec<_>>(),
|
||
}),
|
||
@r#"
|
||
{
|
||
"workflow_slug": "sluggy",
|
||
"graph_name": "BarBaz",
|
||
"cached_graph_lines": [
|
||
"digraph BarBaz {",
|
||
" start [shape=Mdiamond, label=\"Start\"]",
|
||
" exit [shape=Msquare, label=\"Exit\"]",
|
||
" start -> exit",
|
||
"}"
|
||
]
|
||
}
|
||
"#
|
||
);
|
||
}
|
||
|
||
#[test]
|
||
fn create_persists_file_stem_slug_for_standalone_file() {
|
||
let context = test_context!();
|
||
context.ensure_home_server_auth_methods();
|
||
let run_id = unique_run_id();
|
||
let workflow_path = context.temp_dir.join("alpha.fabro");
|
||
|
||
context.write_temp(
|
||
"alpha.fabro",
|
||
"\
|
||
digraph FooWorkflow {
|
||
start [shape=Mdiamond, label=\"Start\"]
|
||
exit [shape=Msquare, label=\"Exit\"]
|
||
start -> exit
|
||
}
|
||
",
|
||
);
|
||
|
||
context
|
||
.command()
|
||
.args([
|
||
"create",
|
||
"--dry-run",
|
||
"--auto-approve",
|
||
"--run-id",
|
||
run_id.as_str(),
|
||
workflow_path.to_str().unwrap(),
|
||
])
|
||
.assert()
|
||
.success();
|
||
|
||
let run_dir = context.find_run_dir(&run_id);
|
||
let state = run_state(&run_dir);
|
||
let run = &state.spec;
|
||
fabro_json_snapshot!(
|
||
context,
|
||
serde_json::json!({
|
||
"workflow_slug": run.workflow_slug,
|
||
"graph_name": run.graph.name,
|
||
"cached_graph_lines": state.spec.graph_source.as_ref().expect("graph should exist").lines().collect::<Vec<_>>(),
|
||
}),
|
||
@r#"
|
||
{
|
||
"workflow_slug": "alpha",
|
||
"graph_name": "FooWorkflow",
|
||
"cached_graph_lines": [
|
||
"digraph FooWorkflow {",
|
||
" start [shape=Mdiamond, label=\"Start\"]",
|
||
" exit [shape=Msquare, label=\"Exit\"]",
|
||
" start -> exit",
|
||
"}"
|
||
]
|
||
}
|
||
"#
|
||
);
|
||
}
|
||
|
||
#[expect(
|
||
clippy::disallowed_methods,
|
||
reason = "test asserts the raw template source"
|
||
)]
|
||
#[test]
|
||
fn create_persists_requested_overrides_into_store() {
|
||
let context = test_context!();
|
||
context.ensure_home_server_auth_methods();
|
||
let workflow = fixture("simple.fabro");
|
||
let mut cmd = context.command();
|
||
cmd.args([
|
||
"create",
|
||
"--dry-run",
|
||
"--auto-approve",
|
||
"--goal",
|
||
"Ship the release",
|
||
"--model",
|
||
"gpt-5",
|
||
"--provider",
|
||
"openai",
|
||
"--environment",
|
||
"default",
|
||
"--label",
|
||
"env=dev",
|
||
"--label",
|
||
"team=cli",
|
||
"--verbose",
|
||
"--preserve-sandbox",
|
||
workflow.to_str().unwrap(),
|
||
]);
|
||
let output = cmd.output().expect("command should execute");
|
||
assert!(
|
||
output.status.success(),
|
||
"command failed:\nstdout:\n{}\nstderr:\n{}",
|
||
String::from_utf8_lossy(&output.stdout),
|
||
String::from_utf8_lossy(&output.stderr)
|
||
);
|
||
|
||
let stdout = output_stdout(&output);
|
||
let run_id = stdout
|
||
.lines()
|
||
.find(|line| !line.trim().is_empty())
|
||
.map(str::trim)
|
||
.expect("create should print a run ID")
|
||
.to_string();
|
||
let run = resolve_run(&context, &run_id);
|
||
let state = run_state(&run.run_dir);
|
||
let run_spec = &state.spec;
|
||
let labels = json!({
|
||
"env": run_spec.labels.get("env"),
|
||
"team": run_spec.labels.get("team"),
|
||
});
|
||
let settings = &run_spec.settings;
|
||
let resolved_run = resolved_run(settings);
|
||
let compact = json!({
|
||
"workflow_slug": run_spec.workflow_slug,
|
||
"settings": {
|
||
"goal": match resolved_run.goal.as_ref() {
|
||
Some(fabro_types::settings::run::RunGoal::Inline(value)) => Some(value.as_source()),
|
||
_ => None,
|
||
},
|
||
"dry_run": resolved_run.execution.mode == fabro_types::settings::run::RunMode::DryRun,
|
||
"auto_approve": resolved_run.execution.approval == fabro_types::settings::run::ApprovalMode::Auto,
|
||
"llm": {
|
||
"model": resolved_run.model.name.as_ref().map(fabro_types::settings::InterpString::as_source),
|
||
"provider": resolved_run.model.provider.as_ref().map(fabro_types::settings::InterpString::as_source),
|
||
},
|
||
"environment": {
|
||
"id": resolved_run.environment.id,
|
||
"provider": resolved_run.environment.provider.to_string(),
|
||
"preserve": resolved_run.environment.lifecycle.preserve,
|
||
},
|
||
},
|
||
"labels": labels,
|
||
});
|
||
|
||
assert_snapshot!(serde_json::to_string_pretty(&compact).unwrap(), @r###"
|
||
{
|
||
"workflow_slug": "simple",
|
||
"settings": {
|
||
"goal": "Ship the release",
|
||
"dry_run": true,
|
||
"auto_approve": true,
|
||
"llm": {
|
||
"model": "gpt-5",
|
||
"provider": "openai"
|
||
},
|
||
"environment": {
|
||
"id": "default",
|
||
"provider": "docker",
|
||
"preserve": true
|
||
}
|
||
},
|
||
"labels": {
|
||
"env": "dev",
|
||
"team": "cli"
|
||
}
|
||
}
|
||
"###);
|
||
}
|
||
|
||
#[test]
|
||
fn create_json_does_not_imply_auto_approve() {
|
||
let context = test_context!();
|
||
context.ensure_home_server_auth_methods();
|
||
let workflow = fixture("simple.fabro");
|
||
let output = context
|
||
.command()
|
||
.args(["--json", "create", "--dry-run", workflow.to_str().unwrap()])
|
||
.output()
|
||
.expect("command should execute");
|
||
|
||
assert!(
|
||
output.status.success(),
|
||
"command failed:\nstdout:\n{}\nstderr:\n{}",
|
||
String::from_utf8_lossy(&output.stdout),
|
||
String::from_utf8_lossy(&output.stderr)
|
||
);
|
||
|
||
let value: serde_json::Value =
|
||
serde_json::from_slice(&output.stdout).expect("create JSON should parse");
|
||
let run_id = value["run_id"]
|
||
.as_str()
|
||
.expect("create JSON should include run_id");
|
||
let run = resolve_run(&context, run_id);
|
||
|
||
assert!(
|
||
resolved_run(&run_state(&run.run_dir).spec.settings,)
|
||
.execution
|
||
.approval
|
||
!= fabro_types::settings::run::ApprovalMode::Auto
|
||
);
|
||
}
|
||
|
||
#[test]
|
||
fn create_invalid_workflow_fails_without_creating_run() {
|
||
let context = test_context!();
|
||
let workflow = fixture("invalid.fabro");
|
||
let initial_run_count = run_count_for_test_case(&context);
|
||
let mut cmd = context.create_cmd();
|
||
cmd.arg(workflow.to_str().unwrap());
|
||
|
||
fabro_snapshot!(context.filters(), cmd, @"
|
||
success: false
|
||
exit_code: 1
|
||
----- stdout -----
|
||
----- stderr -----
|
||
× Validation failed
|
||
");
|
||
|
||
let run_count = run_count_for_test_case(&context);
|
||
assert_eq!(
|
||
run_count, initial_run_count,
|
||
"invalid create should not persist a run for this test case"
|
||
);
|
||
}
|
||
|
||
#[test]
|
||
fn create_rejects_unbound_template_inputs_without_creating_run() {
|
||
let context = test_context!();
|
||
let workflow = fixture("templated_unbound.fabro");
|
||
let initial_run_count = run_count_for_test_case(&context);
|
||
let mut cmd = context.create_cmd();
|
||
cmd.arg(workflow.to_str().unwrap());
|
||
|
||
fabro_snapshot!(context.filters(), cmd, @"
|
||
success: false
|
||
exit_code: 1
|
||
----- stdout -----
|
||
----- stderr -----
|
||
× Validation failed
|
||
");
|
||
|
||
let run_count = run_count_for_test_case(&context);
|
||
assert_eq!(
|
||
run_count, initial_run_count,
|
||
"invalid create should not persist a run for this test case"
|
||
);
|
||
}
|