mirror of
https://github.com/openclaw/openclaw.git
synced 2026-08-04 15:21:41 +00:00
* refactor(agents): require explicit roster defaults * feat(onboard): create named first roster agent * refactor(agents): remove runtime main fallbacks * style(agents): apply roster refactor formatting * refactor(agents): finish roster-only runtime sweep * fix(doctor): migrate legacy main session sqlite * fix(doctor): harden roster session migrations * fix(onboard): commit first agent atomically * fix(config): support empty-roster analysis * fix(agents): preserve legacy main state during creation * fix(setup): materialize baseline agent roster * fix(agents): harden legacy default transfer recovery * fix(agents): simplify roster-only legacy compatibility * fix(agents): preserve staged first-agent entries * fix(config): migrate persisted implicit-main rosters * fix(config): preserve staged empty rosters * fix(agents): finalize roster-only upgrade paths * fix(sessions): close legacy main migration outcomes * fix(config): migrate legacy roster markers at load * fix(sessions): preserve roster upgrade history * refactor(sessions): restore lean legacy main compatibility * fix(setup): prepare first-agent credentials before publish * fix(config): stabilize roster snapshot migration * refactor(sessions): shrink legacy main compatibility * fix(agents): restore roster compatibility fidelity * fix(sessions): preserve divergent legacy history * refactor(agents): narrow roster-only scope * fix(config): isolate roster migration * test(agents): align roster-only fixtures * fix(agents): keep main agent undeletable * fix(agents): harden roster migration invariants * fix(agents): close setup and audit scope gaps * fix(cron): scope session reaper throttles by agent * fix(agents): preserve scoped owner precedence * fix(config): preserve authored config ownership * fix(setup): keep default workspace and roster in sync * fix(setup): preserve default entry workspace on bare runs * fix(agents): adapt roster rebase to keyed entries * fix(agents): honor both roster representations * fix(agents): route roster reads through shared helpers * fix(config): preserve canonical roster writes * fix(cron): resolve dynamic default for session reaper * fix(agents): close dynamic default migration gaps * fix(agents): align scoped session ownership * fix(sessions): preserve legacy main directory casing * fix(agents): align cron and legacy auth ownership * fix(setup): provision the committed default workspace * fix(cron): align scoped ownership and reaping * fix(cron): treat blank agent ids as absent * fix(cron): retain configured session-store owners * fix(agents): repair roster-aware CI boundaries * fix(cron): preserve scoped ownership resolution * fix(agents): preserve rosterless maintenance paths * fix(agents): propagate roster ownership through runtime boundaries * fix(agents): preserve roster ownership across runtime paths * fix(agents): harden roster diagnostics and legacy routing * fix(agents): remove redundant diagnostic import * test(agents): type CLI policy fixture explicitly * fix(config): preserve canonical roster mutation identity * fix(doctor): read canonical agent rosters consistently * fix(config): resolve compound roster unsets safely * fix(config): finalize main-session reconciliation * fix(doctor): read canonical session state safely * fix(sessions): preserve current visibility alias * fix(config): track roster include provenance * test(config): type roster provenance cases * fix(config): refine roster include ownership * fix(agents): preserve staged roster invariants * test(config): align fixtures with explicit roster ownership * test(node-host): preserve optional plan typing * fix(config): preserve authored roster projections * test(config): keep raw roster fixtures explicit * test(config): normalize rosters at runtime fixtures * fix(config): protect authored roster ownership * fix(agents): require explicit session ownership * fix(agents): enforce scoped roster ownership * fix(sessions): merge fixed-store agent partitions * fix(agents): harden roster ownership boundaries * fix(config): reject ambiguous roster projections * fix(sessions): preserve persisted store ownership * fix(sessions): keep collision diagnostics additive * fix(security): scan malformed roster workspaces * test(config): align snapshot fixtures after rebase * test(agents): use explicit roster fixtures * fix(config): harden roster diagnostic boundaries * fix(sessions): isolate fixed-store agent databases * test(agents): type malformed default markers * refactor(sessions): extract store collision resolution * test(system-agent): split oversized setup coverage * style(system-agent): format split setup suite * fix(sessions): preserve promoted store ownership * fix(sessions): derive scoped owner before target * fix(sessions): preserve explicit sqlite ownership * fix(agents): restore roster compatibility across CI * fix(agents): enforce roster-owned runtime boundaries * fix(agents): satisfy default lookup lint * test(sessions): split known-owner coverage * fix(state): satisfy path identity lint * fix(agents): preserve malformed roster safety boundaries * fix(agents): restore roster compatibility at runtime boundaries * fix(config): satisfy roster boundary type checks * fix(agents): preserve roster ownership across runtime probes Setup inference probes now execute as the configured roster owner. Malformed agent-prefixed session rows are intentionally omitted by the fail-closed visibility contract rather than normalized by tests. * fix(agents): satisfy session list owner lint * fix(agents): preserve roster-owned runtime boundaries Restore shared logical rows for exact SQLite session locators while keeping their physical database owner separate. The ownership regression test now constructs an explicit sole-owner database directly instead of relying on first-touch capture, matching the intentional shared-store contract. * fix(sessions): preserve multiply owned exact stores * fix(sessions): restore runtime owner boundaries Keep incognito sentinels agent-owned, fold default-agent approvals into the global snapshot, and preserve the configless legacy-main CLI policy fallback. Also repair the existing CLI watchdog test lifecycle so the compact shard observes its timeout without an unawaited assertion or async timer stall; product behavior is unchanged by that test-only fix. * test(ci): align owner-scoped fixtures These assertions are unchanged. The fixtures now declare the intended non-default runner, expose the session-key constant imported by production status code, and select the main approvals bucket explicitly on Windows. * fix(agents): close final roster ownership gaps
332 lines
8.1 KiB
TypeScript
332 lines
8.1 KiB
TypeScript
// Verifies exec host, sandbox, and approval-default resolution for embedded agents.
|
|
import { beforeEach, describe, expect, it, vi } from "vitest";
|
|
import type { SessionEntry } from "../config/sessions.js";
|
|
import type { OpenClawConfig } from "../config/types.openclaw.js";
|
|
import * as execApprovals from "../infra/exec-approvals.js";
|
|
import { resolveExecDefaults, resolveNodeExecEligibility } from "./exec-defaults.js";
|
|
|
|
function withDefaultAgent(config: OpenClawConfig): OpenClawConfig {
|
|
return {
|
|
...config,
|
|
agents: { ...config.agents, list: [{ id: "main", default: true }] },
|
|
};
|
|
}
|
|
|
|
describe("resolveExecDefaults", () => {
|
|
beforeEach(() => {
|
|
vi.restoreAllMocks();
|
|
vi.spyOn(execApprovals, "loadExecApprovals").mockReturnValue({
|
|
version: 1,
|
|
agents: {},
|
|
});
|
|
});
|
|
|
|
it("does not advertise node routing when exec host is pinned to gateway", () => {
|
|
expect(
|
|
resolveExecDefaults({
|
|
cfg: withDefaultAgent({
|
|
tools: {
|
|
exec: {
|
|
host: "gateway",
|
|
},
|
|
},
|
|
}),
|
|
sandboxAvailable: false,
|
|
}).canRequestNode,
|
|
).toBe(false);
|
|
});
|
|
|
|
it("does not advertise node routing when exec host is auto and sandbox is available", () => {
|
|
const defaults = resolveExecDefaults({
|
|
cfg: withDefaultAgent({
|
|
tools: {
|
|
exec: {
|
|
host: "auto",
|
|
},
|
|
},
|
|
}),
|
|
sandboxAvailable: true,
|
|
});
|
|
|
|
expect(defaults.host).toBe("auto");
|
|
expect(defaults.effectiveHost).toBe("sandbox");
|
|
expect(defaults.canRequestNode).toBe(false);
|
|
});
|
|
|
|
it("keeps node routing available when exec host is auto without sandbox", () => {
|
|
const defaults = resolveExecDefaults({
|
|
cfg: withDefaultAgent({
|
|
tools: {
|
|
exec: {
|
|
host: "auto",
|
|
},
|
|
},
|
|
}),
|
|
sandboxAvailable: false,
|
|
});
|
|
|
|
expect(defaults.host).toBe("auto");
|
|
expect(defaults.effectiveHost).toBe("gateway");
|
|
expect(defaults.canRequestNode).toBe(true);
|
|
});
|
|
|
|
it("honors session-level exec host overrides", () => {
|
|
const sessionEntry = {
|
|
execHost: "node",
|
|
} as SessionEntry;
|
|
expect(
|
|
resolveExecDefaults({
|
|
cfg: withDefaultAgent({
|
|
tools: {
|
|
exec: {
|
|
host: "gateway",
|
|
},
|
|
},
|
|
}),
|
|
sessionEntry,
|
|
sandboxAvailable: false,
|
|
}).canRequestNode,
|
|
).toBe(true);
|
|
});
|
|
|
|
it("uses host approval defaults for gateway when exec policy is unset", () => {
|
|
const defaults = resolveExecDefaults({
|
|
cfg: withDefaultAgent({
|
|
tools: {
|
|
exec: {
|
|
host: "auto",
|
|
},
|
|
},
|
|
}),
|
|
sandboxAvailable: false,
|
|
});
|
|
|
|
expect(defaults.host).toBe("auto");
|
|
expect(defaults.effectiveHost).toBe("gateway");
|
|
expect(defaults.mode).toBe("full");
|
|
expect(defaults.security).toBe("full");
|
|
expect(defaults.ask).toBe("off");
|
|
});
|
|
|
|
it("keeps sandbox deny by default when auto resolves to sandbox", () => {
|
|
const defaults = resolveExecDefaults({
|
|
cfg: withDefaultAgent({
|
|
tools: {
|
|
exec: {
|
|
host: "auto",
|
|
},
|
|
},
|
|
}),
|
|
sandboxAvailable: true,
|
|
});
|
|
|
|
expect(defaults.host).toBe("auto");
|
|
expect(defaults.effectiveHost).toBe("sandbox");
|
|
expect(defaults.mode).toBe("deny");
|
|
expect(defaults.security).toBe("deny");
|
|
expect(defaults.ask).toBe("off");
|
|
});
|
|
|
|
it("ignores host approval defaults when auto resolves to sandbox", () => {
|
|
vi.mocked(execApprovals.loadExecApprovals).mockReturnValue({
|
|
version: 1,
|
|
defaults: {
|
|
security: "full",
|
|
ask: "always",
|
|
},
|
|
agents: {},
|
|
});
|
|
|
|
const defaults = resolveExecDefaults({
|
|
cfg: withDefaultAgent({
|
|
tools: {
|
|
exec: {
|
|
host: "auto",
|
|
},
|
|
},
|
|
}),
|
|
sandboxAvailable: true,
|
|
});
|
|
|
|
// Sandbox mode is intentionally self-contained: gateway approval floors
|
|
// must not leak into the local deny-by-default sandbox contract.
|
|
expect(defaults.effectiveHost).toBe("sandbox");
|
|
expect(defaults.security).toBe("deny");
|
|
expect(defaults.ask).toBe("off");
|
|
expect(execApprovals.loadExecApprovals).not.toHaveBeenCalled();
|
|
});
|
|
|
|
it("maps normalized auto mode to allowlist plus on-miss approvals", () => {
|
|
expect(
|
|
resolveExecDefaults({
|
|
cfg: withDefaultAgent({
|
|
tools: {
|
|
exec: {
|
|
mode: "auto",
|
|
},
|
|
},
|
|
}),
|
|
sandboxAvailable: false,
|
|
}),
|
|
).toMatchObject({
|
|
mode: "auto",
|
|
security: "allowlist",
|
|
ask: "on-miss",
|
|
});
|
|
});
|
|
|
|
it("reports host approval floors after normalized exec modes", () => {
|
|
vi.mocked(execApprovals.loadExecApprovals).mockReturnValue({
|
|
version: 1,
|
|
defaults: {
|
|
security: "deny",
|
|
ask: "off",
|
|
},
|
|
agents: {},
|
|
});
|
|
|
|
// Approval floors clamp normalized mode upward/downward after config mode
|
|
// mapping so persisted host policy remains the final safety boundary.
|
|
expect(
|
|
resolveExecDefaults({
|
|
cfg: withDefaultAgent({
|
|
tools: {
|
|
exec: {
|
|
mode: "auto",
|
|
},
|
|
},
|
|
}),
|
|
sandboxAvailable: false,
|
|
}),
|
|
).toMatchObject({
|
|
mode: "deny",
|
|
security: "deny",
|
|
ask: "on-miss",
|
|
});
|
|
});
|
|
|
|
it("reports agent-scoped host approval floors", () => {
|
|
vi.mocked(execApprovals.loadExecApprovals).mockReturnValue({
|
|
version: 1,
|
|
agents: {
|
|
"agent-a": {
|
|
security: "full",
|
|
ask: "always",
|
|
},
|
|
},
|
|
});
|
|
|
|
expect(
|
|
resolveExecDefaults({
|
|
cfg: {
|
|
tools: {
|
|
exec: {
|
|
mode: "full",
|
|
},
|
|
},
|
|
agents: { list: [{ id: "agent-a", default: true }] },
|
|
},
|
|
agentId: "agent-a",
|
|
sandboxAvailable: false,
|
|
}),
|
|
).toMatchObject({
|
|
mode: "ask",
|
|
security: "full",
|
|
ask: "always",
|
|
});
|
|
});
|
|
|
|
it("keeps agent mode overrides ahead of the global mode", () => {
|
|
expect(
|
|
resolveExecDefaults({
|
|
cfg: {
|
|
tools: {
|
|
exec: {
|
|
mode: "auto",
|
|
},
|
|
},
|
|
agents: {
|
|
list: [
|
|
{
|
|
id: "agent-a",
|
|
default: true,
|
|
tools: {
|
|
exec: {
|
|
mode: "full",
|
|
},
|
|
},
|
|
},
|
|
],
|
|
},
|
|
},
|
|
agentId: "agent-a",
|
|
sandboxAvailable: false,
|
|
}),
|
|
).toMatchObject({
|
|
mode: "full",
|
|
security: "full",
|
|
ask: "off",
|
|
});
|
|
});
|
|
|
|
it("derives security fields from an agent mode override", () => {
|
|
expect(
|
|
resolveExecDefaults({
|
|
cfg: {
|
|
tools: {
|
|
exec: {
|
|
mode: "auto",
|
|
},
|
|
},
|
|
agents: {
|
|
list: [
|
|
{
|
|
id: "agent-a",
|
|
default: true,
|
|
tools: {
|
|
exec: {
|
|
mode: "allowlist",
|
|
},
|
|
},
|
|
},
|
|
],
|
|
},
|
|
},
|
|
agentId: "agent-a",
|
|
sandboxAvailable: false,
|
|
}),
|
|
).toMatchObject({
|
|
mode: "allowlist",
|
|
security: "allowlist",
|
|
ask: "off",
|
|
});
|
|
});
|
|
|
|
it("blocks node skill eligibility for deny policy and preserves node bindings", () => {
|
|
expect(
|
|
resolveNodeExecEligibility({
|
|
cfg: withDefaultAgent({
|
|
tools: {
|
|
exec: {
|
|
host: "node",
|
|
mode: "deny",
|
|
node: "build-mac",
|
|
},
|
|
},
|
|
}),
|
|
}),
|
|
).toEqual({ canExec: false, node: "build-mac" });
|
|
});
|
|
|
|
it("blocks node skill eligibility when the gateway denies system.run", () => {
|
|
expect(
|
|
resolveNodeExecEligibility({
|
|
cfg: withDefaultAgent({
|
|
gateway: { nodes: { commands: { deny: [" system.run "] } } },
|
|
tools: { exec: { host: "node", mode: "full" } },
|
|
}),
|
|
}),
|
|
).toEqual({ canExec: false });
|
|
});
|
|
});
|