-
Notifications
You must be signed in to change notification settings - Fork 51
refactor(agent): cut the agent's outside edges and fence them #1297
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
3be61a8
9ce7899
f15dc7a
53bddf8
54f8e4b
85ed50e
a88c581
0b98bd3
856b613
13fa0a2
5cffae6
0cf68a2
112fce5
dcf418a
3c7dfb5
c26e22d
d81afb9
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change | ||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|
@@ -30,6 +30,81 @@ module.exports = { | |||||||||||||||||||||||||||||||||||||||||||||||||
| 'prettier', | ||||||||||||||||||||||||||||||||||||||||||||||||||
| ], | ||||||||||||||||||||||||||||||||||||||||||||||||||
| overrides: [ | ||||||||||||||||||||||||||||||||||||||||||||||||||
| { | ||||||||||||||||||||||||||||||||||||||||||||||||||
| // The agent surface. It takes resolved data in, reports through | ||||||||||||||||||||||||||||||||||||||||||||||||||
| // progress events and asks through an injected answerer, so nothing | ||||||||||||||||||||||||||||||||||||||||||||||||||
| // here may import a UI, the session, detection, the CLI or a program. | ||||||||||||||||||||||||||||||||||||||||||||||||||
| // Only direct static imports are checked. Program types stay importable | ||||||||||||||||||||||||||||||||||||||||||||||||||
| // until B1 moves PROGRAM_BINDINGS to programs. Today's paths; A2b | ||||||||||||||||||||||||||||||||||||||||||||||||||
| // collapses them to src/agent/**. | ||||||||||||||||||||||||||||||||||||||||||||||||||
| files: [ | ||||||||||||||||||||||||||||||||||||||||||||||||||
| 'src/lib/agent/**/*.ts', | ||||||||||||||||||||||||||||||||||||||||||||||||||
| 'src/lib/middleware/**/*.ts', | ||||||||||||||||||||||||||||||||||||||||||||||||||
| 'src/lib/wizard-tools/**/*.ts', | ||||||||||||||||||||||||||||||||||||||||||||||||||
| 'src/lib/gateway-session.ts', | ||||||||||||||||||||||||||||||||||||||||||||||||||
| 'src/lib/safe-tools.ts', | ||||||||||||||||||||||||||||||||||||||||||||||||||
| 'src/lib/wizard-ask-bridge.ts', | ||||||||||||||||||||||||||||||||||||||||||||||||||
| 'src/lib/yara-hooks.ts', | ||||||||||||||||||||||||||||||||||||||||||||||||||
| 'src/lib/yara-policy.ts', | ||||||||||||||||||||||||||||||||||||||||||||||||||
| ], | ||||||||||||||||||||||||||||||||||||||||||||||||||
| excludedFiles: ['**/__tests__/**'], | ||||||||||||||||||||||||||||||||||||||||||||||||||
| rules: { | ||||||||||||||||||||||||||||||||||||||||||||||||||
| '@typescript-eslint/no-restricted-imports': [ | ||||||||||||||||||||||||||||||||||||||||||||||||||
|
Collaborator
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Here's the potential issue: The import rule blocks static UI imports but allows the same dependency through a dynamic import.
Suggested fix: Apply the same dependency restrictions to static and dynamic imports.
Collaborator
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Left for C2d: ESLint's import rule can't see |
||||||||||||||||||||||||||||||||||||||||||||||||||
| 'error', | ||||||||||||||||||||||||||||||||||||||||||||||||||
| { | ||||||||||||||||||||||||||||||||||||||||||||||||||
| paths: [ | ||||||||||||||||||||||||||||||||||||||||||||||||||
| { | ||||||||||||||||||||||||||||||||||||||||||||||||||
| name: '@utils/wizard-abort', | ||||||||||||||||||||||||||||||||||||||||||||||||||
| importNames: ['wizardAbort'], | ||||||||||||||||||||||||||||||||||||||||||||||||||
| message: | ||||||||||||||||||||||||||||||||||||||||||||||||||
| 'The agent never exits the process: return a failure in RunResult.', | ||||||||||||||||||||||||||||||||||||||||||||||||||
| }, | ||||||||||||||||||||||||||||||||||||||||||||||||||
| ], | ||||||||||||||||||||||||||||||||||||||||||||||||||
| patterns: [ | ||||||||||||||||||||||||||||||||||||||||||||||||||
| { | ||||||||||||||||||||||||||||||||||||||||||||||||||
| group: [ | ||||||||||||||||||||||||||||||||||||||||||||||||||
| '@ui', | ||||||||||||||||||||||||||||||||||||||||||||||||||
| '@ui/**', | ||||||||||||||||||||||||||||||||||||||||||||||||||
| '**/ui', | ||||||||||||||||||||||||||||||||||||||||||||||||||
| '**/ui/**', | ||||||||||||||||||||||||||||||||||||||||||||||||||
| '@lib/wizard-session', | ||||||||||||||||||||||||||||||||||||||||||||||||||
| '**/wizard-session', | ||||||||||||||||||||||||||||||||||||||||||||||||||
| '@lib/detection', | ||||||||||||||||||||||||||||||||||||||||||||||||||
| '@lib/detection/**', | ||||||||||||||||||||||||||||||||||||||||||||||||||
|
Collaborator
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Here's the potential issue: The import rule is meant to keep the agent separate from the UI and other layers, but directory imports can bypass it.
Suggested fix: Cover directory imports as well as files inside them, for both aliases and relative imports.
Collaborator
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Fixed: the fence now also matches the directories themselves and relative steps paths, so Lines 65 to 88 in 3c7dfb5
|
||||||||||||||||||||||||||||||||||||||||||||||||||
| '**/detection', | ||||||||||||||||||||||||||||||||||||||||||||||||||
| '**/detection/**', | ||||||||||||||||||||||||||||||||||||||||||||||||||
| '@lib/registry', | ||||||||||||||||||||||||||||||||||||||||||||||||||
| '**/lib/registry', | ||||||||||||||||||||||||||||||||||||||||||||||||||
| '@lib/runners', | ||||||||||||||||||||||||||||||||||||||||||||||||||
| '@lib/runners/**', | ||||||||||||||||||||||||||||||||||||||||||||||||||
| '**/runners', | ||||||||||||||||||||||||||||||||||||||||||||||||||
| '**/runners/**', | ||||||||||||||||||||||||||||||||||||||||||||||||||
| '**/commands/**', | ||||||||||||||||||||||||||||||||||||||||||||||||||
| '@steps', | ||||||||||||||||||||||||||||||||||||||||||||||||||
| '@steps/**', | ||||||||||||||||||||||||||||||||||||||||||||||||||
| '**/steps', | ||||||||||||||||||||||||||||||||||||||||||||||||||
| '**/steps/**', | ||||||||||||||||||||||||||||||||||||||||||||||||||
| '@frameworks/**', | ||||||||||||||||||||||||||||||||||||||||||||||||||
| '**/frameworks/**', | ||||||||||||||||||||||||||||||||||||||||||||||||||
| '@utils/setup-utils', | ||||||||||||||||||||||||||||||||||||||||||||||||||
| '**/setup-utils', | ||||||||||||||||||||||||||||||||||||||||||||||||||
| '@utils/oauth', | ||||||||||||||||||||||||||||||||||||||||||||||||||
| '**/utils/oauth', | ||||||||||||||||||||||||||||||||||||||||||||||||||
| ], | ||||||||||||||||||||||||||||||||||||||||||||||||||
| message: | ||||||||||||||||||||||||||||||||||||||||||||||||||
| 'The agent reports through progress events and asks through AgentInteraction; it takes everything else through RunConfig and RunInput.', | ||||||||||||||||||||||||||||||||||||||||||||||||||
| }, | ||||||||||||||||||||||||||||||||||||||||||||||||||
| { | ||||||||||||||||||||||||||||||||||||||||||||||||||
| group: ['@lib/programs/**', '**/programs/**'], | ||||||||||||||||||||||||||||||||||||||||||||||||||
| allowTypeImports: true, | ||||||||||||||||||||||||||||||||||||||||||||||||||
| message: | ||||||||||||||||||||||||||||||||||||||||||||||||||
| 'The agent takes program data through RunConfig. Types only, until B1 moves PROGRAM_BINDINGS to programs.', | ||||||||||||||||||||||||||||||||||||||||||||||||||
| }, | ||||||||||||||||||||||||||||||||||||||||||||||||||
| ], | ||||||||||||||||||||||||||||||||||||||||||||||||||
| }, | ||||||||||||||||||||||||||||||||||||||||||||||||||
| ], | ||||||||||||||||||||||||||||||||||||||||||||||||||
| }, | ||||||||||||||||||||||||||||||||||||||||||||||||||
| }, | ||||||||||||||||||||||||||||||||||||||||||||||||||
| { | ||||||||||||||||||||||||||||||||||||||||||||||||||
| files: [ | ||||||||||||||||||||||||||||||||||||||||||||||||||
| '*.test.js', | ||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,58 @@ | ||
| import fs from 'fs'; | ||
| import { WIZARD_YARA_REPORT_FILE } from '@utils/paths'; | ||
|
|
||
| // The flush runs inside the agent, which has no UI: the report line is | ||
| // returned to the caller, who decides where it goes. | ||
| vi.mock('@ui', () => ({ | ||
| getUI: () => { | ||
| throw new Error('agent code reached the UI'); | ||
| }, | ||
| })); | ||
| vi.mock('@utils/debug'); | ||
| vi.mock('@utils/analytics', () => ({ | ||
| analytics: { wizardCapture: vi.fn(), captureException: vi.fn() }, | ||
| })); | ||
| vi.mock('fs', async (importOriginal) => { | ||
| const actual = await importOriginal<typeof import('fs')>(); | ||
| return { | ||
| ...actual, | ||
| default: { ...actual, writeFileSync: vi.fn() }, | ||
| writeFileSync: vi.fn(), | ||
| }; | ||
| }); | ||
|
|
||
| import { | ||
| flushScanReport, | ||
| recordExternalScan, | ||
| resetScanReport, | ||
| } from '@lib/yara-hooks'; | ||
|
|
||
| describe('flushScanReport', () => { | ||
| beforeEach(() => { | ||
| resetScanReport(); | ||
| vi.mocked(fs.writeFileSync).mockClear(); | ||
| }); | ||
|
|
||
| it('returns the report line once when a report was requested', () => { | ||
| recordExternalScan('PostToolUse', 'Write', [], 'warned'); | ||
|
|
||
| const line = flushScanReport({ yaraReport: true }); | ||
|
|
||
| expect(line).toContain(`YARA scan report: ${WIZARD_YARA_REPORT_FILE}`); | ||
| expect(line).toContain('1 tool calls scanned, 0 violations detected'); | ||
| expect(fs.writeFileSync).toHaveBeenCalledWith( | ||
| WIZARD_YARA_REPORT_FILE, | ||
| expect.stringContaining('"totalScans": 1'), | ||
| ); | ||
| // Idempotent: the first flush zeroed the scan state. | ||
| expect(flushScanReport({ yaraReport: true })).toBeUndefined(); | ||
| }); | ||
|
|
||
| it('returns nothing without --yara-report, but still flushes the state', () => { | ||
| recordExternalScan('PostToolUse', 'Write', [], 'warned'); | ||
|
|
||
| expect(flushScanReport({ yaraReport: false })).toBeUndefined(); | ||
| expect(fs.writeFileSync).not.toHaveBeenCalled(); | ||
| expect(flushScanReport({ yaraReport: true })).toBeUndefined(); | ||
| }); | ||
| }); |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This will thrash a lot, so consider this a transitional state
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
It is: A2b narrows this fence to
src/agent/**, and C2d deletes it for per-layer TypeScript configs, where the agent'spathsmap only@env,@sharedand@utils:wizard/src/agent/tsconfig.layer.json
Lines 7 to 16 in 548ef5f