mirror of
https://github.com/outbackdingo/optimclaw.git
synced 2026-08-26 15:40:18 +00:00
* feat: port NPA psychographic profiling system into IronClaw
Port the complete psychographic profiling system from NPA into IronClaw,
including enriched profile schema, conversational onboarding, profile
evolution, and three-tier prompt augmentation.
Personal onboarding moved from wizard Step 9 to first assistant
interaction per maintainer feedback — the First Contact system prompt
block now instructs the LLM to conduct a natural onboarding conversation
that builds the psychographic profile via memory_write.
Changes:
- Enrich profile.rs with 5 new structs, 9-dimension analysis framework,
custom deserializers for backward compatibility, and rendering methods
- Add conversational onboarding engine with one-step-removed questioning
technique, personality framework, and confidence-scored profile generation
- Add profile evolution with confidence gating, analysis metadata tracking,
and weekly update routine
- Replace thin interaction style injection with three-tier system gated on
confidence > 0.6 and profile recency
- Replace wizard Step 9 with First Contact system prompt block that drives
conversational onboarding during the user's first interaction
- Add autonomy progression to SOUL.md seed and personality framework to
AGENTS.md seed
Co-Authored-By: Claude Opus 4.6 <[email protected]>
* feat: replace chat-based onboarding with bootstrap greeting and workspace seeds
Remove the interactive onboarding_chat.rs engine in favor of a simpler
bootstrap flow: fresh workspaces get a proactive LLM greeting that
naturally profiles the user. Identity files are now seeded from
src/workspace/seeds/ instead of being hardcoded. Also removes the
identity-file write protection (seeds are now managed), adds routine
advisor integration, and includes an e2e trace for bootstrap greeting.
Co-Authored-By: Claude Opus 4.6 <[email protected]>
* feat(safety): sanitize identity file writes via Sanitizer to prevent prompt injection
Identity files (SOUL.md, AGENTS.md, USER.md, IDENTITY.md) are injected into
every system prompt. Rather than hard-blocking writes (which broke onboarding),
scan content through the existing Sanitizer and reject writes with High/Critical
severity injection patterns. Medium/Low warnings are logged but allowed.
Also clarifies AGENTS.md identity file roles (USER.md = user info, IDENTITY.md =
agent identity) and adds IDENTITY.md setup as an explicit bootstrap step.
Co-Authored-By: Claude Opus 4.6 <[email protected]>
* docs: update profile_onboarding_completed comment to reflect current wiring
The field is now actively used by the agent loop to suppress BOOTSTRAP.md
injection — remove the stale "not yet wired" TODO.
[skip-regression-check]
Co-Authored-By: Claude Opus 4.6 <[email protected]>
* fix(setup): use env_or_override for NEARAI_API_KEY in model fetch config
When the user authenticates via NEAR AI Cloud API key (option 4),
api_key_login() stores the key via set_runtime_env(). But
build_nearai_model_fetch_config() was using std::env::var() which
doesn't check the runtime overlay — so model listing fell back to
session-token auth and re-triggered the interactive NEAR AI
authentication menu.
Switch to env_or_override() which checks both real env vars and the
runtime overlay.
Co-Authored-By: Claude Opus 4.6 <[email protected]>
* fix(agent): correct channel/user_id in bootstrap greeting persist call
persist_assistant_response was called with channel="default",
user_id="system" but the assistant thread was created via
get_or_create_assistant_conversation("default", "gateway") which owns
the conversation as user_id="default", channel="gateway". The mismatch
caused ensure_writable_conversation to reject the write with:
WARN Rejected write for unavailable thread id user=system channel=default
[skip-regression-check]
Co-Authored-By: Claude Opus 4.6 <[email protected]>
* fix(web): remove all inline event handlers for CSP compliance
The Content-Security-Policy header (added in f48fe95) blocks inline JS
via script-src 'self'. All onclick/onchange attributes in index.html
are replaced with getElementById().addEventListener() calls. Dynamic
inline handlers in app.js (jobs, routines, memory breadcrumb, code
blocks, TEE report) are replaced with data-action attributes and a
single delegated click handler on document.
[skip-regression-check]
Co-Authored-By: Claude Opus 4.6 <[email protected]>
* fix(agent): align bootstrap message user/channel and update fixture schema field
- Bootstrap IncomingMessage now uses ("default", "gateway") consistently
with persist and session registration calls
- Update bootstrap_greeting.json fixture: schema_version → version to
match current PROFILE_JSON_SCHEMA
[skip-regression-check]
Co-Authored-By: Claude Opus 4.6 <[email protected]>
* style: cargo fmt
[skip-regression-check]
Co-Authored-By: Claude Opus 4.6 <[email protected]>
* fix(safety): address PR review — expand injection scanning and harden profile sync
- BOOTSTRAP.md: fix target "profile" → "context/profile.json" so the
write hits the correct path and triggers profile sync
- IDENTITY_FILES: add context/assistant-directives.md to the scanned
set since it is also injected into the system prompt
- sync_profile_documents(): scan derived USER.md and assistant-directives
content through Sanitizer before writing, rejecting High/Critical
injection patterns
- profile_evolution_prompt(): wrap recent_messages_summary in <user_data>
delimiters with untrusted-data instruction to mitigate indirect
prompt injection
- routine-advisor skill: update cron examples from 6-field to standard
5-field format for consistency with routine_create tool docs
[skip-regression-check]
Co-Authored-By: Claude Opus 4.6 <[email protected]>
* style: cargo fmt
[skip-regression-check]
Co-Authored-By: Claude Opus 4.6 <[email protected]>
* fix(setup): detect env-provided LLM keys during quick-mode onboarding
Quick-mode wizard now checks LLM_BACKEND, NEARAI_API_KEY,
ANTHROPIC_API_KEY, and OPENAI_API_KEY env vars to pre-populate
the provider setting, so users aren't re-prompted for credentials
they already supplied. Also teaches setup_nearai() to recognize
NEARAI_API_KEY from env (previously only checked session tokens).
Includes web UI cleanup (remove duplicate event listeners) and
e2e test response count adjustment.
Co-Authored-By: Claude Opus 4.6 (1M context) <[email protected]>
* fix(test): update routine_create_list to expect 7-field normalized cron
The cron normalizer now always expands to 7-field format, so the
stored schedule is "0 0 9 * * * *" not "0 0 9 * * *".
[skip-regression-check]
Co-Authored-By: Claude Opus 4.6 (1M context) <[email protected]>
* feat(setup): skip LLM provider prompts when NEARAI_API_KEY is present
In quick mode, if NEARAI_API_KEY is set in the environment and the
backend was auto-detected as nearai, skip the interactive inference
provider and model selection steps. The API key is persisted to the
secrets store and a default model is set automatically.
Also simplify the static fallback model list for nearai to a single
default entry.
Co-Authored-By: Claude Opus 4.6 (1M context) <[email protected]>
* fix: unify default model, static bootstrap greeting, and web UI cleanup
- Add DEFAULT_MODEL const and default_models() fallback list in
llm/nearai_chat.rs; use from config, wizard, and .env.example so the
default model is defined in one place
- Restore multi-model fallback list in setup wizard (was reduced to 1)
- Move BOOTSTRAP_GREETING to module-level const (out of run() body)
- Replace LLM-based bootstrap with static greeting (persist to DB before
channels start, then broadcast — eliminates startup LLM call and race)
- Fix double env::var read for NEARAI_API_KEY in quick setup path
- Move thread sidebar buttons into threads-section-header (web UI)
- Remove orphaned .thread-sidebar-header CSS and fix double blank line
- Update bootstrap e2e test for static greeting (no LLM trace needed)
Co-Authored-By: Claude Opus 4.6 (1M context) <[email protected]>
* fix(safety): move prompt injection scanning into Workspace write/append
Addresses PR #927 review comments (#1, #3) — identity file write
protection and unsanitized profile fields in system prompt.
Instead of scanning at the tool layer (memory.rs) or the sync layer
(sync_profile_documents), injection scanning now lives in
Workspace::write() and Workspace::append() for all files that are
injected into the system prompt. This ensures every code path that
writes to these files is protected, including future ones.
- Add SYSTEM_PROMPT_FILES const and reject_if_injected() in workspace
- Add WorkspaceError::InjectionRejected variant
- Add map_write_err() in memory.rs to convert InjectionRejected to
ToolError::NotAuthorized
- Remove redundant IDENTITY_FILES/Sanitizer from memory.rs
- Remove redundant sanitizer calls from sync_profile_documents()
- Move sanitization tests to workspace::tests
- Existing integration test (test_memory_write_rejects_injection)
continues to pass through the new path
Co-Authored-By: Claude Opus 4.6 (1M context) <[email protected]>
* style: cargo fmt
Co-Authored-By: Claude Opus 4.6 (1M context) <[email protected]>
* fix: address Copilot review — merge marker order, orphan thread, stale fixture
- merge_profile_section: search for END marker after BEGIN position to
avoid matching a stray END earlier in the file
- Bootstrap phase 2: use get_or_create_session + Thread::with_id instead
of resolve_thread(None) to avoid creating an orphan thread
- setup_nearai: use env_or_override for NEARAI_API_KEY consistency with
runtime overlay
- Delete orphaned bootstrap_greeting.json fixture (no test references it)
- Add test_merge_end_marker_must_follow_begin regression test
Co-Authored-By: Claude Opus 4.6 (1M context) <[email protected]>
* style: cargo fmt
Co-Authored-By: Claude Opus 4.6 (1M context) <[email protected]>
* style: fmt agent_loop.rs (CI stable rustfmt)
Co-Authored-By: Claude Opus 4.6 (1M context) <[email protected]>
* fix: lazy-init sanitizer, check profile non-empty before skipping bootstrap
Address Copilot review:
- Use LazyLock<Sanitizer> to avoid rebuilding Aho-Corasick + regexes
on every workspace write
- has_profile check now requires non-empty content, not just file
existence, to prevent empty profile.json from suppressing onboarding
- Add seed_tests integration tests (libsql-backed) verifying:
- Empty profile.json does not suppress BOOTSTRAP.md seeding
- Non-empty profile.json correctly suppresses bootstrap for upgrades
Co-Authored-By: Claude Opus 4.6 (1M context) <[email protected]>
* style: cargo fmt
Co-Authored-By: Claude Opus 4.6 (1M context) <[email protected]>
* fix: duplicate language handler, empty LLM_BACKEND, test_rig style
Address Copilot review on PR #927:
- Remove duplicate language-option click listeners (delegated
data-action handler already covers them)
- Guard LLM_BACKEND env prefill against empty string to prevent
suppressing API-key-based auto-detection
- Use destructured local `keep_bootstrap` instead of `self.keep_bootstrap`
in test_rig for consistency after destructure
Co-Authored-By: Claude Opus 4.6 (1M context) <[email protected]>
* fix: update stale BOOTSTRAP.md write-protection comment [skip-regression-check]
BOOTSTRAP.md is now in SYSTEM_PROMPT_FILES and gets injection scanning
on write. The old comment incorrectly stated it was not write-protected.
Co-Authored-By: Claude Opus 4.6 (1M context) <[email protected]>
* fix: replace debug_assert panics with graceful error returns [skip-regression-check]
debug_assert! in execute_tool_with_safety and JobContext::transition_to
panicked in test builds before the graceful error path could run.
Existing tests (test_cancel_job_completed, test_execute_empty_tool_name_returns_not_found)
already cover these paths — they were the ones failing.
Co-Authored-By: Claude Opus 4.6 (1M context) <[email protected]>
* fix: address Copilot review — schema label, env var check, path normalization, profile validation
1. Label ANALYSIS_FRAMEWORK and PROFILE_JSON_SCHEMA sections separately
in bootstrap prompt so the LLM knows which blob is the target structure.
2. Wizard quick-mode backend auto-detection now rejects empty env vars
(std::env::var().is_ok_and(|v| !v.is_empty())) to avoid selecting the
wrong backend when e.g. NEARAI_API_KEY="" is set.
3. Normalize the target path before comparing with paths::PROFILE in
memory_write so non-canonical variants like "context//profile.json"
still trigger profile sync.
4. seed_if_empty now requires valid JSON parse of context/profile.json
before treating it as a populated profile. Corrupted content no longer
permanently suppresses bootstrap seeding.
Co-Authored-By: Claude Opus 4.6 (1M context) <[email protected]>
* style: cargo fmt
* fix: address Copilot review — append scan, profile validation, env_or_override
1. Workspace::append() now scans the combined content (existing + new)
for prompt injection, not just the appended chunk. Prevents split-
injection evasion across multiple appends.
2. seed_if_empty() now deserializes into PsychographicProfile instead of
serde_json::Value for profile validation. Stray/legacy JSON that
doesn't match the expected schema no longer suppresses bootstrap.
3. Wizard quick-mode backend auto-detection now uses env_or_override()
to honor runtime overlays and injected secrets. LLM_BACKEND value
is trimmed before storage.
Co-Authored-By: Claude Opus 4.6 (1M context) <[email protected]>
* test: add bootstrap_onboarding_clears_bootstrap E2E trace test
Exercises the full onboarding flow end-to-end:
1. Bootstrap greeting fires automatically on fresh workspace
2. User converses for 3 turns (name, tools, work style)
3. Agent writes psychographic profile to context/profile.json
4. Profile sync generates USER.md and assistant-directives.md
5. Agent writes IDENTITY.md (chosen persona)
6. Agent clears BOOTSTRAP.md via memory_write(target: "bootstrap")
Verifies:
- BOOTSTRAP.md is non-empty before onboarding, empty after
- bootstrap_completed flag is set
- Profile contains expected user data (name, profession, interests)
- USER.md contains profile-derived content (name, tone, profession)
- Assistant-directives.md references user and communication style
- IDENTITY.md contains agent's chosen persona name
- All memory_write calls succeed
Co-Authored-By: Claude Opus 4.6 (1M context) <[email protected]>
* fix: address Copilot review — slash collapse, env_or_override, cron trim [skip-regression-check]
1. memory.rs path normalization now uses the same char-by-char loop as
Workspace::normalize_path() to fully collapse consecutive slashes
(e.g. "context///profile.json" → "context/profile.json").
2. Quick-mode NEARAI_API_KEY check (line 239) now uses env_or_override()
consistently with the backend auto-detection block above it.
3. normalize_cron_expression() trims input before field counting so the
passthrough branch (7+ fields) also strips whitespace.
Co-Authored-By: Claude Opus 4.6 (1M context) <[email protected]>
---------
Co-authored-by: Jay Zalowitz <[email protected]>
Co-authored-by: Claude Opus 4.6 <[email protected]>
480 lines
14 KiB
Rust
480 lines
14 KiB
Rust
//! Shared tool execution pipeline.
|
|
//!
|
|
//! Provides a single implementation of the validate → timeout → execute → serialize
|
|
//! pipeline used by all agentic loop consumers (chat, job, container) and the
|
|
//! scheduler's subtask execution.
|
|
|
|
use crate::context::JobContext;
|
|
use crate::error::Error;
|
|
use crate::llm::ChatMessage;
|
|
use crate::safety::SafetyLayer;
|
|
use crate::tools::{ToolRegistry, prepare_tool_params, redact_params};
|
|
|
|
/// Execute a tool with safety checks: lookup → validate → timeout → execute → serialize.
|
|
///
|
|
/// This is the single canonical implementation of tool execution. All consumers
|
|
/// (chat dispatcher, job worker, container runtime, scheduler subtasks) use this
|
|
/// function instead of maintaining their own copies.
|
|
pub async fn execute_tool_with_safety(
|
|
tools: &ToolRegistry,
|
|
safety: &SafetyLayer,
|
|
tool_name: &str,
|
|
params: &serde_json::Value,
|
|
job_ctx: &JobContext,
|
|
) -> Result<String, Error> {
|
|
if tool_name.is_empty() {
|
|
return Err(crate::error::ToolError::NotFound {
|
|
name: tool_name.to_string(),
|
|
}
|
|
.into());
|
|
}
|
|
let tool = tools
|
|
.get(tool_name)
|
|
.await
|
|
.ok_or_else(|| crate::error::ToolError::NotFound {
|
|
name: tool_name.to_string(),
|
|
})?;
|
|
|
|
let normalized_params = prepare_tool_params(tool.as_ref(), params);
|
|
|
|
// Validate tool parameters
|
|
let validation = safety.validator().validate_tool_params(&normalized_params);
|
|
if !validation.is_valid {
|
|
let details = validation
|
|
.errors
|
|
.iter()
|
|
.map(|e| format!("{}: {}", e.field, e.message))
|
|
.collect::<Vec<_>>()
|
|
.join("; ");
|
|
return Err(crate::error::ToolError::InvalidParameters {
|
|
name: tool_name.to_string(),
|
|
reason: format!("Invalid tool parameters: {}", details),
|
|
}
|
|
.into());
|
|
}
|
|
|
|
let safe_params = redact_params(&normalized_params, tool.sensitive_params());
|
|
tracing::debug!(
|
|
tool = %tool_name,
|
|
params = %safe_params,
|
|
"Tool call started"
|
|
);
|
|
|
|
// Execute with per-tool timeout
|
|
let timeout = tool.execution_timeout();
|
|
let start = std::time::Instant::now();
|
|
let result = tokio::time::timeout(timeout, async {
|
|
tool.execute(normalized_params.clone(), job_ctx).await
|
|
})
|
|
.await;
|
|
let elapsed = start.elapsed();
|
|
|
|
match &result {
|
|
Ok(Ok(output)) => {
|
|
let result_size = serde_json::to_string(&output.result)
|
|
.map(|s| s.len())
|
|
.unwrap_or(0);
|
|
tracing::debug!(
|
|
tool = %tool_name,
|
|
elapsed_ms = elapsed.as_millis() as u64,
|
|
result_size_bytes = result_size,
|
|
"Tool call succeeded"
|
|
);
|
|
}
|
|
Ok(Err(e)) => {
|
|
tracing::debug!(
|
|
tool = %tool_name,
|
|
elapsed_ms = elapsed.as_millis() as u64,
|
|
error = %e,
|
|
"Tool call failed"
|
|
);
|
|
}
|
|
Err(_) => {
|
|
tracing::debug!(
|
|
tool = %tool_name,
|
|
elapsed_ms = elapsed.as_millis() as u64,
|
|
timeout_secs = timeout.as_secs(),
|
|
"Tool call timed out"
|
|
);
|
|
}
|
|
}
|
|
|
|
let result = result
|
|
.map_err(|_| crate::error::ToolError::Timeout {
|
|
name: tool_name.to_string(),
|
|
timeout,
|
|
})?
|
|
.map_err(|e| crate::error::ToolError::ExecutionFailed {
|
|
name: tool_name.to_string(),
|
|
reason: e.to_string(),
|
|
})?;
|
|
|
|
serde_json::to_string_pretty(&result.result).map_err(|e| {
|
|
crate::error::ToolError::ExecutionFailed {
|
|
name: tool_name.to_string(),
|
|
reason: format!("Failed to serialize result: {}", e),
|
|
}
|
|
.into()
|
|
})
|
|
}
|
|
|
|
/// Process a tool result into a `ChatMessage::tool_result` with safety sanitization.
|
|
///
|
|
/// On success: sanitize → wrap → ChatMessage::tool_result.
|
|
/// On error: format error → ChatMessage::tool_result.
|
|
///
|
|
/// Returns the content string and the ChatMessage.
|
|
pub fn process_tool_result(
|
|
safety: &SafetyLayer,
|
|
tool_name: &str,
|
|
tool_call_id: &str,
|
|
result: &Result<String, impl std::fmt::Display>,
|
|
) -> (String, ChatMessage) {
|
|
let content = match result {
|
|
Ok(output) => {
|
|
let sanitized = safety.sanitize_tool_output(tool_name, output);
|
|
safety.wrap_for_llm(tool_name, &sanitized.content, sanitized.was_modified)
|
|
}
|
|
Err(e) => format!("Error: {}", e),
|
|
};
|
|
let message = ChatMessage::tool_result(tool_call_id, tool_name, content.clone());
|
|
(content, message)
|
|
}
|
|
|
|
/// Execute a tool with safety checks, returning a string error (for container runtime).
|
|
///
|
|
/// This is a thin wrapper around `execute_tool_with_safety` that converts
|
|
/// `Error` to `String` for the container runtime's simpler error model.
|
|
pub async fn execute_tool_simple(
|
|
tools: &ToolRegistry,
|
|
safety: &SafetyLayer,
|
|
tool_name: &str,
|
|
params: &serde_json::Value,
|
|
job_ctx: &JobContext,
|
|
) -> Result<String, String> {
|
|
execute_tool_with_safety(tools, safety, tool_name, params, job_ctx)
|
|
.await
|
|
.map_err(|e| e.to_string())
|
|
}
|
|
|
|
#[cfg(test)]
|
|
mod tests {
|
|
use super::*;
|
|
use crate::tools::tool::{Tool, ToolError, ToolOutput};
|
|
use std::sync::Arc;
|
|
use std::time::Duration;
|
|
|
|
struct EchoTool;
|
|
|
|
#[async_trait::async_trait]
|
|
impl Tool for EchoTool {
|
|
fn name(&self) -> &str {
|
|
"echo"
|
|
}
|
|
fn description(&self) -> &str {
|
|
"Echoes input"
|
|
}
|
|
fn parameters_schema(&self) -> serde_json::Value {
|
|
serde_json::json!({"type": "object", "properties": {}})
|
|
}
|
|
async fn execute(
|
|
&self,
|
|
params: serde_json::Value,
|
|
_ctx: &JobContext,
|
|
) -> Result<ToolOutput, ToolError> {
|
|
Ok(ToolOutput::success(params, Duration::default()))
|
|
}
|
|
fn requires_sanitization(&self) -> bool {
|
|
false
|
|
}
|
|
}
|
|
|
|
struct FailTool;
|
|
|
|
#[async_trait::async_trait]
|
|
impl Tool for FailTool {
|
|
fn name(&self) -> &str {
|
|
"fail_tool"
|
|
}
|
|
fn description(&self) -> &str {
|
|
"Always fails"
|
|
}
|
|
fn parameters_schema(&self) -> serde_json::Value {
|
|
serde_json::json!({"type": "object", "properties": {}})
|
|
}
|
|
async fn execute(
|
|
&self,
|
|
_: serde_json::Value,
|
|
_: &JobContext,
|
|
) -> Result<ToolOutput, ToolError> {
|
|
Err(ToolError::ExecutionFailed(
|
|
"intentional failure".to_string(),
|
|
))
|
|
}
|
|
fn requires_sanitization(&self) -> bool {
|
|
false
|
|
}
|
|
}
|
|
|
|
struct SlowTool;
|
|
|
|
#[async_trait::async_trait]
|
|
impl Tool for SlowTool {
|
|
fn name(&self) -> &str {
|
|
"slow_tool"
|
|
}
|
|
fn description(&self) -> &str {
|
|
"Sleeps forever"
|
|
}
|
|
fn parameters_schema(&self) -> serde_json::Value {
|
|
serde_json::json!({"type": "object", "properties": {}})
|
|
}
|
|
async fn execute(
|
|
&self,
|
|
_: serde_json::Value,
|
|
_: &JobContext,
|
|
) -> Result<ToolOutput, ToolError> {
|
|
tokio::time::sleep(Duration::from_secs(60)).await;
|
|
unreachable!()
|
|
}
|
|
fn execution_timeout(&self) -> Duration {
|
|
Duration::from_millis(50)
|
|
}
|
|
fn requires_sanitization(&self) -> bool {
|
|
false
|
|
}
|
|
}
|
|
|
|
struct ArrayEchoTool;
|
|
|
|
#[async_trait::async_trait]
|
|
impl Tool for ArrayEchoTool {
|
|
fn name(&self) -> &str {
|
|
"array_echo"
|
|
}
|
|
fn description(&self) -> &str {
|
|
"Echoes normalized params"
|
|
}
|
|
fn parameters_schema(&self) -> serde_json::Value {
|
|
serde_json::json!({
|
|
"type": "object",
|
|
"properties": {
|
|
"values": {
|
|
"type": "array",
|
|
"items": { "type": "integer" }
|
|
}
|
|
}
|
|
})
|
|
}
|
|
async fn execute(
|
|
&self,
|
|
params: serde_json::Value,
|
|
_ctx: &JobContext,
|
|
) -> Result<ToolOutput, ToolError> {
|
|
Ok(ToolOutput::success(params, Duration::default()))
|
|
}
|
|
fn requires_sanitization(&self) -> bool {
|
|
false
|
|
}
|
|
}
|
|
|
|
fn test_safety() -> SafetyLayer {
|
|
SafetyLayer::new(&crate::config::SafetyConfig {
|
|
max_output_length: 100_000,
|
|
injection_check_enabled: false,
|
|
})
|
|
}
|
|
|
|
fn test_job_ctx() -> JobContext {
|
|
JobContext::default()
|
|
}
|
|
|
|
async fn registry_with(tools: Vec<Arc<dyn Tool>>) -> ToolRegistry {
|
|
let registry = ToolRegistry::new();
|
|
for tool in tools {
|
|
registry.register(tool).await;
|
|
}
|
|
registry
|
|
}
|
|
|
|
#[tokio::test]
|
|
async fn test_execute_empty_tool_name_returns_not_found() {
|
|
// Regression: execute_tool_with_safety must reject empty tool names
|
|
// gracefully via ToolError::NotFound (not a panic).
|
|
let registry = registry_with(vec![]).await;
|
|
let safety = test_safety();
|
|
|
|
let result = execute_tool_with_safety(
|
|
®istry,
|
|
&safety,
|
|
"",
|
|
&serde_json::json!({}),
|
|
&test_job_ctx(),
|
|
)
|
|
.await;
|
|
|
|
assert!(
|
|
matches!(
|
|
result,
|
|
Err(crate::error::Error::Tool(
|
|
crate::error::ToolError::NotFound { .. }
|
|
))
|
|
),
|
|
"Empty tool name should return ToolError::NotFound, got: {result:?}"
|
|
);
|
|
}
|
|
|
|
#[tokio::test]
|
|
async fn test_execute_success() {
|
|
let registry = registry_with(vec![Arc::new(EchoTool)]).await;
|
|
let safety = test_safety();
|
|
let params = serde_json::json!({"message": "hello"});
|
|
|
|
let result =
|
|
execute_tool_with_safety(®istry, &safety, "echo", ¶ms, &test_job_ctx()).await;
|
|
|
|
assert!(result.is_ok(), "Echo tool should succeed");
|
|
let output = result.unwrap();
|
|
assert!(
|
|
output.contains("hello"),
|
|
"Output should contain the echoed input"
|
|
);
|
|
}
|
|
|
|
#[tokio::test]
|
|
async fn test_execute_missing_tool() {
|
|
let registry = registry_with(vec![]).await;
|
|
let safety = test_safety();
|
|
|
|
let result = execute_tool_with_safety(
|
|
®istry,
|
|
&safety,
|
|
"nonexistent",
|
|
&serde_json::json!({}),
|
|
&test_job_ctx(),
|
|
)
|
|
.await;
|
|
|
|
assert!(result.is_err(), "Missing tool should return error");
|
|
let err = result.unwrap_err().to_string();
|
|
assert!(
|
|
err.contains("nonexistent") || err.contains("not found"),
|
|
"Error should mention the tool: {}",
|
|
err
|
|
);
|
|
}
|
|
|
|
#[tokio::test]
|
|
async fn test_execute_tool_failure() {
|
|
let registry = registry_with(vec![Arc::new(FailTool)]).await;
|
|
let safety = test_safety();
|
|
|
|
let result = execute_tool_with_safety(
|
|
®istry,
|
|
&safety,
|
|
"fail_tool",
|
|
&serde_json::json!({}),
|
|
&test_job_ctx(),
|
|
)
|
|
.await;
|
|
|
|
assert!(result.is_err(), "FailTool should return error");
|
|
let err = result.unwrap_err().to_string();
|
|
assert!(
|
|
err.contains("intentional failure"),
|
|
"Error should contain the failure reason: {}",
|
|
err
|
|
);
|
|
}
|
|
|
|
#[tokio::test]
|
|
async fn test_execute_tool_timeout() {
|
|
let registry = registry_with(vec![Arc::new(SlowTool)]).await;
|
|
let safety = test_safety();
|
|
|
|
let start = std::time::Instant::now();
|
|
let result = execute_tool_with_safety(
|
|
®istry,
|
|
&safety,
|
|
"slow_tool",
|
|
&serde_json::json!({}),
|
|
&test_job_ctx(),
|
|
)
|
|
.await;
|
|
let elapsed = start.elapsed();
|
|
|
|
assert!(result.is_err(), "SlowTool should timeout");
|
|
let err = result.unwrap_err().to_string();
|
|
assert!(
|
|
err.to_lowercase().contains("timeout") || err.to_lowercase().contains("timed out"),
|
|
"Error should mention timeout: {}",
|
|
err
|
|
);
|
|
assert!(
|
|
elapsed < Duration::from_secs(1),
|
|
"Should timeout quickly, not wait 60s"
|
|
);
|
|
}
|
|
|
|
#[tokio::test]
|
|
async fn test_execute_normalizes_stringified_array_params() {
|
|
let registry = registry_with(vec![Arc::new(ArrayEchoTool)]).await;
|
|
let safety = test_safety();
|
|
|
|
let result = execute_tool_with_safety(
|
|
®istry,
|
|
&safety,
|
|
"array_echo",
|
|
&serde_json::json!({"values": "[\"1\", \"2\", 3]"}),
|
|
&test_job_ctx(),
|
|
)
|
|
.await
|
|
.expect("array_echo should succeed"); // safety: test-only assertion
|
|
|
|
let output: serde_json::Value =
|
|
serde_json::from_str(&result).expect("tool result should be valid JSON"); // safety: test-only assertion
|
|
assert_eq!(output["values"], serde_json::json!([1, 2, 3])); // safety: test-only assertion
|
|
}
|
|
|
|
#[test]
|
|
fn test_process_tool_result_success() {
|
|
let safety = test_safety();
|
|
let result: Result<String, String> = Ok("tool output data".to_string());
|
|
|
|
let (content, message) = process_tool_result(&safety, "echo", "call_1", &result);
|
|
|
|
assert!(
|
|
content.contains("tool_output"),
|
|
"Content should be XML-wrapped: {}",
|
|
content
|
|
);
|
|
assert!(
|
|
content.contains("tool output data"),
|
|
"Content should contain the output: {}",
|
|
content
|
|
);
|
|
assert_eq!(message.role, crate::llm::Role::Tool);
|
|
assert_eq!(message.name.as_deref(), Some("echo"));
|
|
}
|
|
|
|
#[test]
|
|
fn test_process_tool_result_error() {
|
|
let safety = test_safety();
|
|
let result: Result<String, String> = Err("something went wrong".to_string());
|
|
|
|
let (content, message) = process_tool_result(&safety, "echo", "call_1", &result);
|
|
|
|
assert!(
|
|
content.contains("Error:"),
|
|
"Error content should start with 'Error:': {}",
|
|
content
|
|
);
|
|
assert!(
|
|
content.contains("something went wrong"),
|
|
"Error content should contain the message: {}",
|
|
content
|
|
);
|
|
assert_eq!(message.role, crate::llm::Role::Tool);
|
|
}
|
|
}
|