Stop shell Excel builds, default write_file paths, and cap short-intent tool rounds.

Refuse openpyxl/pandas-to_excel via run_command, auto-write content-only files under tmp/, and limit WhatsApp ops short intents to 8 tool rounds by default.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
oliver 2026-08-10 23:21:23 +08:00
parent a5ebabbaae
commit d8bc08ee0d
6 changed files with 162 additions and 13 deletions

View file

@ -993,3 +993,44 @@ def test_group_focus_system_hint_only_for_shared_group_scope() -> None:
assert "current sender" in hint
assert OclawGateway._group_focus_system_hint(per_user, "en") == ""
assert OclawGateway._group_focus_system_hint(dm, "en") == ""
def test_ops_short_intent_caps_tool_rounds(tmp_path) -> None:
from runtime.types import StandardMessage
from svc.persistence.sqlite_store import SqliteStore
store = SqliteStore(str(tmp_path / "rounds.sqlite"))
gw = OclawGateway(store=store)
short = StandardMessage(
session_id="s1",
tenant_id="t1",
user_id="u1",
role="member",
channel="whatsapp",
text="fiber cut report",
attachments=[],
metadata={},
)
long = StandardMessage(
session_id="s1",
tenant_id="t1",
user_id="u1",
role="member",
channel="whatsapp",
text="Please investigate the full OSPF adjacency flap history across all PE routers and draft a long RCA.",
attachments=[],
metadata={},
)
admin = StandardMessage(
session_id="s1",
tenant_id="t1",
user_id="u1",
role="member",
channel="admin",
text="fiber cut report",
attachments=[],
metadata={},
)
assert gw._resolve_max_tool_rounds(short, base=100) == 8
assert gw._resolve_max_tool_rounds(long, base=100) == 100
assert gw._resolve_max_tool_rounds(admin, base=100) == 100

View file

@ -24,3 +24,18 @@ def test_run_command_accepts_cmd_alias(monkeypatch) -> None:
out = spec.handler(filtered)
assert out.get("ok") is True
assert calls[0]["command"] == "echo hi"
def test_run_command_blocks_openpyxl_xlsx() -> None:
from runtime.tools.public.run_command_tool import _looks_like_xlsx_via_shell
assert _looks_like_xlsx_via_shell("python -c \"import openpyxl; wb=openpyxl.Workbook()\"")
assert _looks_like_xlsx_via_shell("python -c \"df.to_excel('a.xlsx')\"")
assert not _looks_like_xlsx_via_shell("echo hello")
spec = run_command_tool()
out = spec.handler({"command": "python -c \"import openpyxl; openpyxl.Workbook()\""})
assert out.get("ok") is False
assert out.get("error_code") == "xlsx_via_shell_forbidden"
assert out.get("retry_forbidden") is True
assert "write_xlsx" in (out.get("fallback_tools") or [])

View file

@ -1,5 +1,7 @@
from __future__ import annotations
from pathlib import Path
from runtime.tools.public.write_file_tool import write_file_tool
from runtime.tools.tool_validation import filter_arguments_to_schema, validate_tool_arguments
@ -27,7 +29,24 @@ def test_write_file_schema_allows_aliases() -> None:
def test_write_file_path_required_message() -> None:
spec = write_file_tool()
out = spec.handler({"content": "x"})
out = spec.handler({})
assert out.get("ok") is False
assert out.get("error") == "path_required"
assert "example" in out
def test_write_file_defaults_path_when_content_only(tmp_path, monkeypatch) -> None:
def _resolve(raw: str):
return tmp_path / "workspace" / str(raw).replace("\\", "/").lstrip("/")
monkeypatch.setattr(
"runtime.tools.public.write_file_tool.resolve_workspace_path",
_resolve,
)
spec = write_file_tool()
out = spec.handler({"content": "hello-auto"})
assert out.get("ok") is True
assert out.get("auto_path") is True
path = Path(str(out.get("path") or ""))
assert path.name.startswith("write_")
assert path.read_text(encoding="utf-8") == "hello-auto"