#!/usr/bin/env bash set -uo pipefail # CASAN Plan-16 SEC-21 (ARCH-07) — bounded model timeout + per-run call budget. # # A 180s-per-call timeout across many steps let a hung model stall a run for tens # of minutes. Now the per-call timeout is lower + configurable, and total model # calls per run are capped so a wedged model cannot amplify into a DoS. Proves the # budget refuses once exhausted, and no cap set means no limit (dev default). # # Deterministic (budget is checked BEFORE any backend call, so it holds whether or # not a model is reachable). No network required. SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" source "$SCRIPT_DIR/../scripts/bash/casan-paths.sh" PROJECT_ROOT="$CASAN_APP_ROOT" MC="$CASAN_HARNESS_ROOT/scripts/bash/model-call.py" WORK="$(mktemp -d)" trap 'git -C "$PROJECT_ROOT" checkout -- .specify/logs/level5/provider-usage.jsonl 2>/dev/null; rm -rf "$WORK"' EXIT PASS=0; FAIL=0 pass() { echo "PASS: $1"; PASS=$((PASS + 1)); } fail() { echo "FAIL: $1"; FAIL=$((FAIL + 1)); } echo "===== Plan-16 SEC-21: model timeout + per-run call budget =====" # Per-call timeout is reduced from 180s and configurable. grep -q 'timeout=180' "$MC" && fail "hardcoded 180s timeout still present" \ || pass "no hardcoded 180s per-call timeout" grep -q 'CASAN_MODEL_TIMEOUT_SEC' "$MC" \ && pass "per-call timeout is configurable via CASAN_MODEL_TIMEOUT_SEC" \ || fail "timeout not configurable" # Budget: cap=1. Call 1 charges the budget (proceeds); call 2 is refused BEFORE any # backend work, with a clear budget error, regardless of model availability. echo "hello" > "$WORK/p.txt" CNT="$WORK/counter" export CASAN_MODEL_MAX_CALLS=1 CASAN_MODEL_CALL_COUNTER_FILE="$CNT" python3 "$MC" "$WORK/p.txt" "$WORK/o1.json" --role classify >/dev/null 2>&1 # charges to 1 ERR2="$(python3 "$MC" "$WORK/p.txt" "$WORK/o2.json" --role classify 2>&1 >/dev/null)"; RC2=$? if [[ "$RC2" -ne 0 ]] && echo "$ERR2" | grep -q "run_call_budget_exceeded"; then pass "call over budget is REFUSED (rc=$RC2, budget error)" else fail "over-budget call not refused (rc=$RC2 err='$ERR2')" fi # No cap set → no budget error (dev default unchanged). unset CASAN_MODEL_MAX_CALLS CASAN_MODEL_CALL_COUNTER_FILE ERR3="$(python3 "$MC" "$WORK/p.txt" "$WORK/o3.json" --role classify 2>&1 >/dev/null || true)" echo "$ERR3" | grep -q "run_call_budget_exceeded" \ && fail "budget error fired with no cap set" \ || pass "no cap set → no budget limit (dev default)" echo "" echo "===== SEC-21 SUMMARY: PASS=$PASS FAIL=$FAIL =====" [[ "$FAIL" -eq 0 ]] || exit 1