Files
openclaw/src/agents/exec-defaults.test.ts
Peter Steinberger 82d1a03f25 refactor(agents): move implicit-main fallback into load-time roster injection (#112678)
* refactor(agents): require explicit roster defaults

* feat(onboard): create named first roster agent

* refactor(agents): remove runtime main fallbacks

* style(agents): apply roster refactor formatting

* refactor(agents): finish roster-only runtime sweep

* fix(doctor): migrate legacy main session sqlite

* fix(doctor): harden roster session migrations

* fix(onboard): commit first agent atomically

* fix(config): support empty-roster analysis

* fix(agents): preserve legacy main state during creation

* fix(setup): materialize baseline agent roster

* fix(agents): harden legacy default transfer recovery

* fix(agents): simplify roster-only legacy compatibility

* fix(agents): preserve staged first-agent entries

* fix(config): migrate persisted implicit-main rosters

* fix(config): preserve staged empty rosters

* fix(agents): finalize roster-only upgrade paths

* fix(sessions): close legacy main migration outcomes

* fix(config): migrate legacy roster markers at load

* fix(sessions): preserve roster upgrade history

* refactor(sessions): restore lean legacy main compatibility

* fix(setup): prepare first-agent credentials before publish

* fix(config): stabilize roster snapshot migration

* refactor(sessions): shrink legacy main compatibility

* fix(agents): restore roster compatibility fidelity

* fix(sessions): preserve divergent legacy history

* refactor(agents): narrow roster-only scope

* fix(config): isolate roster migration

* test(agents): align roster-only fixtures

* fix(agents): keep main agent undeletable

* fix(agents): harden roster migration invariants

* fix(agents): close setup and audit scope gaps

* fix(cron): scope session reaper throttles by agent

* fix(agents): preserve scoped owner precedence

* fix(config): preserve authored config ownership

* fix(setup): keep default workspace and roster in sync

* fix(setup): preserve default entry workspace on bare runs

* fix(agents): adapt roster rebase to keyed entries

* fix(agents): honor both roster representations

* fix(agents): route roster reads through shared helpers

* fix(config): preserve canonical roster writes

* fix(cron): resolve dynamic default for session reaper

* fix(agents): close dynamic default migration gaps

* fix(agents): align scoped session ownership

* fix(sessions): preserve legacy main directory casing

* fix(agents): align cron and legacy auth ownership

* fix(setup): provision the committed default workspace

* fix(cron): align scoped ownership and reaping

* fix(cron): treat blank agent ids as absent

* fix(cron): retain configured session-store owners

* fix(agents): repair roster-aware CI boundaries

* fix(cron): preserve scoped ownership resolution

* fix(agents): preserve rosterless maintenance paths

* fix(agents): propagate roster ownership through runtime boundaries

* fix(agents): preserve roster ownership across runtime paths

* fix(agents): harden roster diagnostics and legacy routing

* fix(agents): remove redundant diagnostic import

* test(agents): type CLI policy fixture explicitly

* fix(config): preserve canonical roster mutation identity

* fix(doctor): read canonical agent rosters consistently

* fix(config): resolve compound roster unsets safely

* fix(config): finalize main-session reconciliation

* fix(doctor): read canonical session state safely

* fix(sessions): preserve current visibility alias

* fix(config): track roster include provenance

* test(config): type roster provenance cases

* fix(config): refine roster include ownership

* fix(agents): preserve staged roster invariants

* test(config): align fixtures with explicit roster ownership

* test(node-host): preserve optional plan typing

* fix(config): preserve authored roster projections

* test(config): keep raw roster fixtures explicit

* test(config): normalize rosters at runtime fixtures

* fix(config): protect authored roster ownership

* fix(agents): require explicit session ownership

* fix(agents): enforce scoped roster ownership

* fix(sessions): merge fixed-store agent partitions

* fix(agents): harden roster ownership boundaries

* fix(config): reject ambiguous roster projections

* fix(sessions): preserve persisted store ownership

* fix(sessions): keep collision diagnostics additive

* fix(security): scan malformed roster workspaces

* test(config): align snapshot fixtures after rebase

* test(agents): use explicit roster fixtures

* fix(config): harden roster diagnostic boundaries

* fix(sessions): isolate fixed-store agent databases

* test(agents): type malformed default markers

* refactor(sessions): extract store collision resolution

* test(system-agent): split oversized setup coverage

* style(system-agent): format split setup suite

* fix(sessions): preserve promoted store ownership

* fix(sessions): derive scoped owner before target

* fix(sessions): preserve explicit sqlite ownership

* fix(agents): restore roster compatibility across CI

* fix(agents): enforce roster-owned runtime boundaries

* fix(agents): satisfy default lookup lint

* test(sessions): split known-owner coverage

* fix(state): satisfy path identity lint

* fix(agents): preserve malformed roster safety boundaries

* fix(agents): restore roster compatibility at runtime boundaries

* fix(config): satisfy roster boundary type checks

* fix(agents): preserve roster ownership across runtime probes

Setup inference probes now execute as the configured roster owner. Malformed agent-prefixed session rows are intentionally omitted by the fail-closed visibility contract rather than normalized by tests.

* fix(agents): satisfy session list owner lint

* fix(agents): preserve roster-owned runtime boundaries

Restore shared logical rows for exact SQLite session locators while keeping their physical database owner separate. The ownership regression test now constructs an explicit sole-owner database directly instead of relying on first-touch capture, matching the intentional shared-store contract.

* fix(sessions): preserve multiply owned exact stores

* fix(sessions): restore runtime owner boundaries

Keep incognito sentinels agent-owned, fold default-agent approvals into the global snapshot, and preserve the configless legacy-main CLI policy fallback. Also repair the existing CLI watchdog test lifecycle so the compact shard observes its timeout without an unawaited assertion or async timer stall; product behavior is unchanged by that test-only fix.

* test(ci): align owner-scoped fixtures

These assertions are unchanged. The fixtures now declare the intended non-default runner, expose the session-key constant imported by production status code, and select the main approvals bucket explicitly on Windows.

* fix(agents): close final roster ownership gaps
2026-07-24 22:38:09 -07:00

332 lines
8.1 KiB
TypeScript

// Verifies exec host, sandbox, and approval-default resolution for embedded agents.
import { beforeEach, describe, expect, it, vi } from "vitest";
import type { SessionEntry } from "../config/sessions.js";
import type { OpenClawConfig } from "../config/types.openclaw.js";
import * as execApprovals from "../infra/exec-approvals.js";
import { resolveExecDefaults, resolveNodeExecEligibility } from "./exec-defaults.js";
function withDefaultAgent(config: OpenClawConfig): OpenClawConfig {
return {
...config,
agents: { ...config.agents, list: [{ id: "main", default: true }] },
};
}
describe("resolveExecDefaults", () => {
beforeEach(() => {
vi.restoreAllMocks();
vi.spyOn(execApprovals, "loadExecApprovals").mockReturnValue({
version: 1,
agents: {},
});
});
it("does not advertise node routing when exec host is pinned to gateway", () => {
expect(
resolveExecDefaults({
cfg: withDefaultAgent({
tools: {
exec: {
host: "gateway",
},
},
}),
sandboxAvailable: false,
}).canRequestNode,
).toBe(false);
});
it("does not advertise node routing when exec host is auto and sandbox is available", () => {
const defaults = resolveExecDefaults({
cfg: withDefaultAgent({
tools: {
exec: {
host: "auto",
},
},
}),
sandboxAvailable: true,
});
expect(defaults.host).toBe("auto");
expect(defaults.effectiveHost).toBe("sandbox");
expect(defaults.canRequestNode).toBe(false);
});
it("keeps node routing available when exec host is auto without sandbox", () => {
const defaults = resolveExecDefaults({
cfg: withDefaultAgent({
tools: {
exec: {
host: "auto",
},
},
}),
sandboxAvailable: false,
});
expect(defaults.host).toBe("auto");
expect(defaults.effectiveHost).toBe("gateway");
expect(defaults.canRequestNode).toBe(true);
});
it("honors session-level exec host overrides", () => {
const sessionEntry = {
execHost: "node",
} as SessionEntry;
expect(
resolveExecDefaults({
cfg: withDefaultAgent({
tools: {
exec: {
host: "gateway",
},
},
}),
sessionEntry,
sandboxAvailable: false,
}).canRequestNode,
).toBe(true);
});
it("uses host approval defaults for gateway when exec policy is unset", () => {
const defaults = resolveExecDefaults({
cfg: withDefaultAgent({
tools: {
exec: {
host: "auto",
},
},
}),
sandboxAvailable: false,
});
expect(defaults.host).toBe("auto");
expect(defaults.effectiveHost).toBe("gateway");
expect(defaults.mode).toBe("full");
expect(defaults.security).toBe("full");
expect(defaults.ask).toBe("off");
});
it("keeps sandbox deny by default when auto resolves to sandbox", () => {
const defaults = resolveExecDefaults({
cfg: withDefaultAgent({
tools: {
exec: {
host: "auto",
},
},
}),
sandboxAvailable: true,
});
expect(defaults.host).toBe("auto");
expect(defaults.effectiveHost).toBe("sandbox");
expect(defaults.mode).toBe("deny");
expect(defaults.security).toBe("deny");
expect(defaults.ask).toBe("off");
});
it("ignores host approval defaults when auto resolves to sandbox", () => {
vi.mocked(execApprovals.loadExecApprovals).mockReturnValue({
version: 1,
defaults: {
security: "full",
ask: "always",
},
agents: {},
});
const defaults = resolveExecDefaults({
cfg: withDefaultAgent({
tools: {
exec: {
host: "auto",
},
},
}),
sandboxAvailable: true,
});
// Sandbox mode is intentionally self-contained: gateway approval floors
// must not leak into the local deny-by-default sandbox contract.
expect(defaults.effectiveHost).toBe("sandbox");
expect(defaults.security).toBe("deny");
expect(defaults.ask).toBe("off");
expect(execApprovals.loadExecApprovals).not.toHaveBeenCalled();
});
it("maps normalized auto mode to allowlist plus on-miss approvals", () => {
expect(
resolveExecDefaults({
cfg: withDefaultAgent({
tools: {
exec: {
mode: "auto",
},
},
}),
sandboxAvailable: false,
}),
).toMatchObject({
mode: "auto",
security: "allowlist",
ask: "on-miss",
});
});
it("reports host approval floors after normalized exec modes", () => {
vi.mocked(execApprovals.loadExecApprovals).mockReturnValue({
version: 1,
defaults: {
security: "deny",
ask: "off",
},
agents: {},
});
// Approval floors clamp normalized mode upward/downward after config mode
// mapping so persisted host policy remains the final safety boundary.
expect(
resolveExecDefaults({
cfg: withDefaultAgent({
tools: {
exec: {
mode: "auto",
},
},
}),
sandboxAvailable: false,
}),
).toMatchObject({
mode: "deny",
security: "deny",
ask: "on-miss",
});
});
it("reports agent-scoped host approval floors", () => {
vi.mocked(execApprovals.loadExecApprovals).mockReturnValue({
version: 1,
agents: {
"agent-a": {
security: "full",
ask: "always",
},
},
});
expect(
resolveExecDefaults({
cfg: {
tools: {
exec: {
mode: "full",
},
},
agents: { list: [{ id: "agent-a", default: true }] },
},
agentId: "agent-a",
sandboxAvailable: false,
}),
).toMatchObject({
mode: "ask",
security: "full",
ask: "always",
});
});
it("keeps agent mode overrides ahead of the global mode", () => {
expect(
resolveExecDefaults({
cfg: {
tools: {
exec: {
mode: "auto",
},
},
agents: {
list: [
{
id: "agent-a",
default: true,
tools: {
exec: {
mode: "full",
},
},
},
],
},
},
agentId: "agent-a",
sandboxAvailable: false,
}),
).toMatchObject({
mode: "full",
security: "full",
ask: "off",
});
});
it("derives security fields from an agent mode override", () => {
expect(
resolveExecDefaults({
cfg: {
tools: {
exec: {
mode: "auto",
},
},
agents: {
list: [
{
id: "agent-a",
default: true,
tools: {
exec: {
mode: "allowlist",
},
},
},
],
},
},
agentId: "agent-a",
sandboxAvailable: false,
}),
).toMatchObject({
mode: "allowlist",
security: "allowlist",
ask: "off",
});
});
it("blocks node skill eligibility for deny policy and preserves node bindings", () => {
expect(
resolveNodeExecEligibility({
cfg: withDefaultAgent({
tools: {
exec: {
host: "node",
mode: "deny",
node: "build-mac",
},
},
}),
}),
).toEqual({ canExec: false, node: "build-mac" });
});
it("blocks node skill eligibility when the gateway denies system.run", () => {
expect(
resolveNodeExecEligibility({
cfg: withDefaultAgent({
gateway: { nodes: { commands: { deny: [" system.run "] } } },
tools: { exec: { host: "node", mode: "full" } },
}),
}),
).toEqual({ canExec: false });
});
});