feat(discord): read-only tools for the Discord Sage through a Mosaic pi extension confined to declared roots (#1509)
A binding may declare `tools` with named roots. pi starts with --no-builtin-tools and the package's own extension, allowlisting list_dir, read_file and search. src/tools.mjs holds the rules: names not paths, per-segment lstat walk, one checked descriptor read that refuses symlinks, swaps, FIFOs, hard links and oversize files, credential shapes refusing the whole read, and a per-message call budget. The engine settles on agent_end and records tool calls in the turn record. Jason's rulings R1-R7 in the brief, section 7. rev-code-02 approved round 2 (comment 26276) on tree 43f0329b after four round 1 fixes. Suite 48/48, node tests 116. Not pushed. Co-Authored-By: Claude Opus 5 <[email protected]>
This commit is contained in:
@@ -179,7 +179,7 @@ export function fakeEngine({ replies = [], delayMs = 0, hold = false } = {}) {
|
||||
const run = () => gate.then(() => new Promise((resolve, reject) => {
|
||||
setTimeout(() => {
|
||||
if (r.error) reject(Object.assign(new Error(r.error), { details: { code: r.code || "fake" } }));
|
||||
else resolve({ text: r.text, message: null, usage: r.usage || { input: 1, output: 1 }, model: null, provider: null });
|
||||
else resolve({ text: r.text, message: null, tools: r.tools || [], turns: r.turns ?? 1, usage: r.usage || { input: 1, output: 1 }, model: null, provider: null });
|
||||
}, r.delayMs ?? delayMs);
|
||||
}));
|
||||
const p = chain.then(run, run);
|
||||
|
||||
Reference in New Issue
Block a user