mirror of
https://github.com/openclaw/openclaw.git
synced 2026-05-28 22:26:48 +00:00
* refactor: extract agent core package Introduce packages/agent-core as the OpenClaw-owned home for reusable agent loop, harness, session, prompt, and runtime dependency contracts. * refactor: extract shared llm runtime Move provider model registries, stream wrappers, OAuth helpers, and LLM utilities into src/llm with plugin-sdk barrels instead of depending on the old embedded runtime layout. * refactor: remove pi runtime internals Rename remaining Pi-shaped agent surfaces to OpenClaw agent runtime names, delete obsolete Pi docs and package graph checks, and add the third-party notice for incorporated code. * refactor: tighten agent session runtime Make agent-core/runtime dependencies explicit, consolidate compaction and session transcript helpers, and move model/session helpers behind OpenClaw-owned contracts. * refactor: remove static model and pi auth paths Drop static model catalogs and Pi auth bridges, move model/provider facts to manifest-owned runtime contracts, and harden internal embedded-agent utilities. * refactor: remove legacy provider compat paths * docs: remove agent parity notes * fix: skip provider wildcard metadata parsing * refactor: share session extension sdk loading * refactor: inline acpx proxy error formatter * refactor: fold edit recovery into edit tool * fix: accept extension batch separator * test: align startup provider plugin expectations * fix: restore provider-scoped release discovery * test: align static asset packaging expectations * fix: run static provider catalogs during scoped discovery * fix: add provider entry catalogs for scoped live discovery * fix: load lightweight provider catalog entries * fix: refresh provider-scoped plugin metadata * fix: keep provider catalog entries on release live path * fix: keep static manifest models in release live checks * fix: harden release model discovery * fix: reduce OpenAI live cache probe reasoning * fix: disable OpenAI cache probe reasoning * ci: extend OpenAI gateway live timeout * fix: extend live gateway model budget * fix: stabilize release validation regressions * fix: honor provider aliases in model rows * fix: stabilize release validation lanes * fix: stabilize release memory qa * ci: stabilize release validation lanes * ci: prefer ipv4 for live docker node calls * fix: restore shared tool-call stream wrapper * ci: remove legacy pi test shard alias * fix: clean up embedded agent test drift * fix: stabilize runtime alias status * fix: clean up embedded agent ci drift * fix: restore release ci invariants * fix: clean up post-rebase runtime drift * fix: restore release ci checks * fix: restore release ci after rebase * fix: remove stale pi runtime path * test: align compaction runtime expectations * test: update plugin prerelease expectations * fix: handle claude live tool approvals * fix: stabilize release validation gates * fix: finish agent runtime import * test: finish post-rebase agent runtime mocks * fix: keep codex compaction native * fix: stabilize codex app-server hook tests * test: isolate codex diagnostic active run * test: remove codex diagnostic completion race # Conflicts: # extensions/codex/src/app-server/run-attempt.test.ts * ci: fix full release manifest performance run id * refactor: narrow llm plugin sdk boundary * chore: drop generated google boundary stamps * fix: repair rebase fallout * fix: clean up rebased runtime references * fix: decode codex jwt payloads as base64url * fix: preserve shipped pi runtime alias * fix: add scoped sdk virtual modules * fix: decode llm codex oauth jwt as base64url * fix: avoid stale vertex adc negative cache * fix: harden tool arg decoding and codeql path * fix: keep vertex adc negative checks live * refactor: consolidate codex jwt and edit helpers * fix: await codex oauth node runtime imports * fix: preserve sdk tool and notice contracts * fix: preserve shipped compat config boundaries * fix: align codex oauth callback host * fix: terminate agent-core loop streams on failure * fix: keep codex oauth callback alive during fallback * ci: include session tools in critical codeql scans * fix: keep Cloudflare Anthropic provider auth header * docs: redirect legacy pi runtime pages * fix: honor bundled web provider compat discovery * fix: protect session output spill files * fix: keep legacy agent dir env blocked * fix: contain auto-discovered skill symlinks * fix: harden agent core sdk proxy surfaces * fix: restore approval reaction sdk compat * fix: keep live docker runs bounded * fix: keep codex oauth redirect host aligned * fix: resolve post-rebase agent runtime drift * fix: redact anthropic oauth parse failures * fix: preserve responses strict tool shaping * fix: repair agent runtime rebase cleanup * docs: redirect retired parity pages * fix: bound auto-discovered resources to roots * fix: repair post-rebase agent test drift * fix: preserve bundled provider allowlist migration * fix: preserve manifest-owned provider aliases * fix: declare photon image dependency * fix: keep provider headers out of proxy body * fix: preserve shipped env aliases * fix: refresh control ui i18n generated state * fix: quote read fallback paths * fix: preview edits through configured backend * test: satisfy core test typecheck * fix: preserve ZAI usage auth fallback * test: repair codex diagnostic test * fix: repair agent runtime rebase drift * test: finish embedded runner import rename * fix: repair agent runtime rebase integrations * test: align compaction oauth fallback expectations * fix: allow sdk-auth session models * fix: update doctor tool schema import * fix: preserve bedrock plugin region * fix: stream harmony-like prose immediately * ci: include session runtime in codeql shards * fix: repair latest rebase integrations * fix: honor explicit codex websocket transport * fix: keep openai-compatible credentials provider-scoped * fix: refresh sdk api baseline after rebase * fix: route cli runtime aliases through openclaw harness * test: rename stale harness mock expectation * test: rename embedded agent overflow calls * test: clean embedded auth test wording * test: use openclaw stream types in deepinfra cache test * fix: refresh sdk api baseline on latest main * fix: honor bundled discovery compat allowlists * fix: refresh sdk api baseline after latest rebase * fix: remove stale rebase imports * test: rename stale model catalog mock * test: mock renamed doctor runtime modules * fix: map canonical kimi env auth * fix: use internal model registry in bench script * fix: migrate deepinfra provider catalog entry * fix: enforce builtin tool suppression * fix: route compaction auth and proxy payloads safely * refactor: prune unused llm registry leftovers * test: update codex hooks session import * test: fix model picker ci coverage * test: align model picker auth mock types
207 lines
7.1 KiB
TypeScript
207 lines
7.1 KiB
TypeScript
// OpenClaw bundle MCP tools Docker harness.
|
|
// Imports packaged dist modules so tool materialization is verified against the
|
|
// npm tarball installed in the functional image.
|
|
import { randomUUID } from "node:crypto";
|
|
import fs from "node:fs/promises";
|
|
import { createRequire } from "node:module";
|
|
import os from "node:os";
|
|
import path from "node:path";
|
|
import { materializeBundleMcpToolsForRun } from "../../dist/agents/agent-bundle-mcp-materialize.js";
|
|
import {
|
|
disposeAllSessionMcpRuntimes,
|
|
getOrCreateSessionMcpRuntime,
|
|
} from "../../dist/agents/agent-bundle-mcp-runtime.js";
|
|
import { applyFinalEffectiveToolPolicy } from "../../dist/agents/embedded-agent-runner/effective-tool-policy.js";
|
|
import { splitSdkTools } from "../../dist/agents/embedded-agent-runner/tool-split.js";
|
|
import type { OpenClawConfig } from "../../dist/config/types.openclaw.js";
|
|
import { getPluginToolMeta } from "../../dist/plugins/tools.js";
|
|
|
|
const require = createRequire(import.meta.url);
|
|
|
|
function assert(condition: unknown, message: string): asserts condition {
|
|
if (!condition) {
|
|
throw new Error(message);
|
|
}
|
|
}
|
|
|
|
async function writeProbeServer(serverPath: string) {
|
|
const sdkMcpServerPath = require.resolve("@modelcontextprotocol/sdk/server/mcp.js");
|
|
const sdkStdioServerPath = require.resolve("@modelcontextprotocol/sdk/server/stdio.js");
|
|
await fs.writeFile(
|
|
serverPath,
|
|
`#!/usr/bin/env node
|
|
import { McpServer } from ${JSON.stringify(sdkMcpServerPath)};
|
|
import { StdioServerTransport } from ${JSON.stringify(sdkStdioServerPath)};
|
|
|
|
const server = new McpServer({ name: "agent-bundle-mcp-tools-probe", version: "1.0.0" });
|
|
server.tool("docker_probe", "Docker OpenClaw MCP tool availability probe", async () => ({
|
|
content: [{ type: "text", text: "agent-bundle-mcp-tools-ok" }],
|
|
}));
|
|
|
|
await server.connect(new StdioServerTransport());
|
|
`,
|
|
{ encoding: "utf-8", mode: 0o755 },
|
|
);
|
|
}
|
|
|
|
function applyPolicy(params: {
|
|
tools: Awaited<ReturnType<typeof materializeBundleMcpToolsForRun>>["tools"];
|
|
config: OpenClawConfig;
|
|
}) {
|
|
const warnings: string[] = [];
|
|
return {
|
|
tools: applyFinalEffectiveToolPolicy({
|
|
bundledTools: params.tools,
|
|
config: params.config,
|
|
sessionKey: "agent:main:docker-agent-bundle-mcp",
|
|
agentId: "main",
|
|
senderIsOwner: true,
|
|
warn: (message) => {
|
|
warnings.push(message);
|
|
},
|
|
}),
|
|
warnings,
|
|
};
|
|
}
|
|
|
|
async function main() {
|
|
const stateDir =
|
|
process.env.OPENCLAW_STATE_DIR?.trim() ||
|
|
path.join(os.tmpdir(), `openclaw-agent-bundle-mcp-${process.pid}`);
|
|
const probeDir = path.join(stateDir, "agent-bundle-mcp-tools");
|
|
const serverPath = path.join(probeDir, "probe-server.mjs");
|
|
await fs.mkdir(probeDir, { recursive: true });
|
|
await writeProbeServer(serverPath);
|
|
|
|
const cfg: OpenClawConfig = {
|
|
tools: {
|
|
profile: "coding",
|
|
},
|
|
mcp: {
|
|
servers: {
|
|
dockerProbe: {
|
|
command: "node",
|
|
args: [serverPath],
|
|
cwd: probeDir,
|
|
connectionTimeoutMs: 5000,
|
|
},
|
|
},
|
|
},
|
|
};
|
|
|
|
try {
|
|
const runtime = await getOrCreateSessionMcpRuntime({
|
|
sessionId: `docker-agent-bundle-mcp-${randomUUID()}`,
|
|
sessionKey: "agent:main:docker-agent-bundle-mcp",
|
|
workspaceDir: probeDir,
|
|
cfg,
|
|
});
|
|
const materialized = await materializeBundleMcpToolsForRun({ runtime });
|
|
const probeTool = materialized.tools.find((tool) => tool.name === "dockerProbe__docker_probe");
|
|
assert(probeTool, "expected dockerProbe__docker_probe to materialize");
|
|
assert(
|
|
getPluginToolMeta(probeTool)?.pluginId === "bundle-mcp",
|
|
"expected materialized MCP tool to be tagged as bundle-mcp",
|
|
);
|
|
|
|
const result = await probeTool.execute("docker-mcp-probe", {}, undefined, undefined);
|
|
assert(
|
|
result.content.some(
|
|
(item) => item.type === "text" && item.text === "agent-bundle-mcp-tools-ok",
|
|
),
|
|
"expected materialized MCP tool execution result",
|
|
);
|
|
|
|
const coding = applyPolicy({ tools: materialized.tools, config: cfg });
|
|
assert(
|
|
coding.tools.some((tool) => tool.name === probeTool.name),
|
|
"expected coding profile to keep bundle MCP tools",
|
|
);
|
|
|
|
const messaging = applyPolicy({
|
|
tools: materialized.tools,
|
|
config: { ...cfg, tools: { profile: "messaging" } },
|
|
});
|
|
assert(
|
|
messaging.tools.some((tool) => tool.name === probeTool.name),
|
|
"expected messaging profile to keep bundle MCP tools",
|
|
);
|
|
|
|
const minimal = applyPolicy({
|
|
tools: materialized.tools,
|
|
config: { ...cfg, tools: { profile: "minimal" } },
|
|
});
|
|
assert(minimal.tools.length === 0, "expected minimal profile to filter bundle MCP tools");
|
|
|
|
const denied = applyPolicy({
|
|
tools: materialized.tools,
|
|
config: { ...cfg, tools: { profile: "coding", deny: ["bundle-mcp"] } },
|
|
});
|
|
assert(denied.tools.length === 0, "expected tools.deny bundle-mcp to filter MCP tools");
|
|
|
|
// The disputed boundary on #76063 is what reaches the SDK as `customTools`,
|
|
// since that is the exact value serialized to the outbound provider request.
|
|
// Prove the live stdio probe survives the materialize -> filter -> split chain
|
|
// through `splitSdkTools` for the same four profiles already asserted above.
|
|
const codingCustom = splitSdkTools({ tools: coding.tools, sandboxEnabled: false }).customTools;
|
|
const messagingCustom = splitSdkTools({
|
|
tools: messaging.tools,
|
|
sandboxEnabled: false,
|
|
}).customTools;
|
|
const minimalCustom = splitSdkTools({
|
|
tools: minimal.tools,
|
|
sandboxEnabled: false,
|
|
}).customTools;
|
|
const deniedCustom = splitSdkTools({ tools: denied.tools, sandboxEnabled: false }).customTools;
|
|
assert(
|
|
codingCustom.some((tool) => tool.name === probeTool.name),
|
|
"expected coding profile customTools to include bundle MCP tools",
|
|
);
|
|
assert(
|
|
messagingCustom.some((tool) => tool.name === probeTool.name),
|
|
"expected messaging profile customTools to include bundle MCP tools",
|
|
);
|
|
assert(
|
|
minimalCustom.length === 0,
|
|
"expected minimal profile customTools to exclude bundle MCP tools",
|
|
);
|
|
assert(
|
|
deniedCustom.length === 0,
|
|
"expected tools.deny bundle-mcp customTools to exclude bundle MCP tools",
|
|
);
|
|
|
|
process.stdout.write(
|
|
JSON.stringify(
|
|
{
|
|
ok: true,
|
|
tool: probeTool.name,
|
|
profileCounts: {
|
|
coding: coding.tools.length,
|
|
messaging: messaging.tools.length,
|
|
minimal: minimal.tools.length,
|
|
denied: denied.tools.length,
|
|
},
|
|
customToolsCounts: {
|
|
coding: codingCustom.length,
|
|
messaging: messagingCustom.length,
|
|
minimal: minimalCustom.length,
|
|
denied: deniedCustom.length,
|
|
},
|
|
customToolNames: {
|
|
coding: codingCustom.map((tool) => tool.name),
|
|
messaging: messagingCustom.map((tool) => tool.name),
|
|
minimal: minimalCustom.map((tool) => tool.name),
|
|
denied: deniedCustom.map((tool) => tool.name),
|
|
},
|
|
},
|
|
null,
|
|
2,
|
|
) + "\n",
|
|
);
|
|
} finally {
|
|
await disposeAllSessionMcpRuntimes();
|
|
}
|
|
}
|
|
|
|
await main();
|