2026-01-13 06:32:59 +00:00
|
|
|
import { describe, expect, it } from "vitest";
|
2026-02-16 01:52:03 +00:00
|
|
|
import type { OpenClawConfig } from "../config/config.js";
|
2026-02-18 01:29:02 +00:00
|
|
|
import { isToolAllowed, resolveSandboxToolPolicyForAgent } from "./sandbox/tool-policy.js";
|
2026-02-18 01:34:35 +00:00
|
|
|
import type { SandboxToolPolicy } from "./sandbox/types.js";
|
2026-02-16 01:09:07 +00:00
|
|
|
import { TOOL_POLICY_CONFORMANCE } from "./tool-policy.conformance.js";
|
2026-02-16 01:31:06 +00:00
|
|
|
import {
|
|
|
|
|
applyOwnerOnlyToolPolicy,
|
|
|
|
|
expandToolGroups,
|
|
|
|
|
isOwnerOnlyToolName,
|
|
|
|
|
normalizeToolName,
|
|
|
|
|
resolveToolProfilePolicy,
|
|
|
|
|
TOOL_GROUPS,
|
|
|
|
|
} from "./tool-policy.js";
|
2026-02-18 01:34:35 +00:00
|
|
|
import type { AnyAgentTool } from "./tools/common.js";
|
2026-01-13 06:32:59 +00:00
|
|
|
|
2026-02-16 14:52:09 +00:00
|
|
|
function createOwnerPolicyTools() {
|
|
|
|
|
return [
|
|
|
|
|
{
|
|
|
|
|
name: "read",
|
|
|
|
|
// oxlint-disable-next-line typescript/no-explicit-any
|
|
|
|
|
execute: async () => ({ content: [], details: {} }) as any,
|
|
|
|
|
},
|
2026-02-19 14:37:56 +01:00
|
|
|
{
|
|
|
|
|
name: "cron",
|
2026-02-19 15:27:45 +01:00
|
|
|
ownerOnly: true,
|
2026-02-19 14:37:56 +01:00
|
|
|
// oxlint-disable-next-line typescript/no-explicit-any
|
|
|
|
|
execute: async () => ({ content: [], details: {} }) as any,
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
name: "gateway",
|
2026-02-19 15:27:45 +01:00
|
|
|
ownerOnly: true,
|
2026-02-19 14:37:56 +01:00
|
|
|
// oxlint-disable-next-line typescript/no-explicit-any
|
|
|
|
|
execute: async () => ({ content: [], details: {} }) as any,
|
|
|
|
|
},
|
2026-02-16 14:52:09 +00:00
|
|
|
{
|
|
|
|
|
name: "whatsapp_login",
|
|
|
|
|
// oxlint-disable-next-line typescript/no-explicit-any
|
|
|
|
|
execute: async () => ({ content: [], details: {} }) as any,
|
|
|
|
|
},
|
|
|
|
|
] as unknown as AnyAgentTool[];
|
|
|
|
|
}
|
|
|
|
|
|
2026-01-13 06:32:59 +00:00
|
|
|
describe("tool-policy", () => {
|
|
|
|
|
it("expands groups and normalizes aliases", () => {
|
2026-01-14 14:31:43 +00:00
|
|
|
const expanded = expandToolGroups(["group:runtime", "BASH", "apply-patch", "group:fs"]);
|
2026-01-13 06:32:59 +00:00
|
|
|
const set = new Set(expanded);
|
|
|
|
|
expect(set.has("exec")).toBe(true);
|
|
|
|
|
expect(set.has("process")).toBe(true);
|
2026-01-24 01:21:50 -06:00
|
|
|
expect(set.has("bash")).toBe(false);
|
2026-01-13 06:32:59 +00:00
|
|
|
expect(set.has("apply_patch")).toBe(true);
|
|
|
|
|
expect(set.has("read")).toBe(true);
|
|
|
|
|
expect(set.has("write")).toBe(true);
|
|
|
|
|
expect(set.has("edit")).toBe(true);
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
it("resolves known profiles and ignores unknown ones", () => {
|
|
|
|
|
const coding = resolveToolProfilePolicy("coding");
|
2026-02-22 23:55:59 -06:00
|
|
|
expect(coding?.allow).toContain("read");
|
2026-01-13 06:32:59 +00:00
|
|
|
expect(resolveToolProfilePolicy("nope")).toBeUndefined();
|
|
|
|
|
});
|
|
|
|
|
|
2026-01-30 03:15:10 +01:00
|
|
|
it("includes core tool groups in group:openclaw", () => {
|
|
|
|
|
const group = TOOL_GROUPS["group:openclaw"];
|
2026-01-13 06:32:59 +00:00
|
|
|
expect(group).toContain("browser");
|
|
|
|
|
expect(group).toContain("message");
|
Agents: add nested subagent orchestration controls and reduce subagent token waste (#14447)
* Agents: add subagent orchestration controls
* Agents: add subagent orchestration controls (WIP uncommitted changes)
* feat(subagents): add depth-based spawn gating for sub-sub-agents
* feat(subagents): tool policy, registry, and announce chain for nested agents
* feat(subagents): system prompt, docs, changelog for nested sub-agents
* fix(subagents): prevent model fallback override, show model during active runs, and block context overflow fallback
Bug 1: When a session has an explicit model override (e.g., gpt/openai-codex),
the fallback candidate logic in resolveFallbackCandidates silently appended the
global primary model (opus) as a backstop. On reinjection/steer with a transient
error, the session could fall back to opus which has a smaller context window
and crash. Fix: when storedModelOverride is set, pass fallbacksOverride ?? []
instead of undefined, preventing the implicit primary backstop.
Bug 2: Active subagents showed 'model n/a' in /subagents list because
resolveModelDisplay only read entry.model/modelProvider (populated after run
completes). Fix: fall back to modelOverride/providerOverride fields which are
populated at spawn time via sessions.patch.
Bug 3: Context overflow errors (prompt too long, context_length_exceeded) could
theoretically escape runEmbeddedPiAgent and be treated as failover candidates
in runWithModelFallback, causing a switch to a model with a smaller context
window. Fix: in runWithModelFallback, detect context overflow errors via
isLikelyContextOverflowError and rethrow them immediately instead of trying the
next model candidate.
* fix(subagents): track spawn depth in session store and fix announce routing for nested agents
* Fix compaction status tracking and dedupe overflow compaction triggers
* fix(subagents): enforce depth block via session store and implement cascade kill
* fix: inject group chat context into system prompt
* fix(subagents): always write model to session store at spawn time
* Preserve spawnDepth when agent handler rewrites session entry
* fix(subagents): suppress announce on steer-restart
* fix(subagents): fallback spawned session model to runtime default
* fix(subagents): enforce spawn depth when caller key resolves by sessionId
* feat(subagents): implement active-first ordering for numeric targets and enhance task display
- Added a test to verify that subagents with numeric targets follow an active-first list ordering.
- Updated `resolveSubagentTarget` to sort subagent runs based on active status and recent activity.
- Enhanced task display in command responses to prevent truncation of long task descriptions.
- Introduced new utility functions for compacting task text and managing subagent run states.
* fix(subagents): show model for active runs via run record fallback
When the spawned model matches the agent's default model, the session
store's override fields are intentionally cleared (isDefault: true).
The model/modelProvider fields are only populated after the run
completes. This left active subagents showing 'model n/a'.
Fix: store the resolved model on SubagentRunRecord at registration
time, and use it as a fallback in both display paths (subagents tool
and /subagents command) when the session store entry has no model info.
Changes:
- SubagentRunRecord: add optional model field
- registerSubagentRun: accept and persist model param
- sessions-spawn-tool: pass resolvedModel to registerSubagentRun
- subagents-tool: pass run record model as fallback to resolveModelDisplay
- commands-subagents: pass run record model as fallback to resolveModelDisplay
* feat(chat): implement session key resolution and reset on sidebar navigation
- Added functions to resolve the main session key and reset chat state when switching sessions from the sidebar.
- Updated the `renderTab` function to handle session key changes when navigating to the chat tab.
- Introduced a test to verify that the session resets to "main" when opening chat from the sidebar navigation.
* fix: subagent timeout=0 passthrough and fallback prompt duplication
Bug 1: runTimeoutSeconds=0 now means 'no timeout' instead of applying 600s default
- sessions-spawn-tool: default to undefined (not 0) when neither timeout param
is provided; use != null check so explicit 0 passes through to gateway
- agent.ts: accept 0 as valid timeout (resolveAgentTimeoutMs already handles
0 → MAX_SAFE_TIMEOUT_MS)
Bug 2: model fallback no longer re-injects the original prompt as a duplicate
- agent.ts: track fallback attempt index; on retries use a short continuation
message instead of the full original prompt since the session file already
contains it from the first attempt
- Also skip re-sending images on fallback retries (already in session)
* feat(subagents): truncate long task descriptions in subagents command output
- Introduced a new utility function to format task previews, limiting their length to improve readability.
- Updated the command handler to use the new formatting function, ensuring task descriptions are truncated appropriately.
- Adjusted related tests to verify that long task descriptions are now truncated in the output.
* refactor(subagents): update subagent registry path resolution and improve command output formatting
- Replaced direct import of STATE_DIR with a utility function to resolve the state directory dynamically.
- Enhanced the formatting of command output for active and recent subagents, adding separators for better readability.
- Updated related tests to reflect changes in command output structure.
* fix(subagent): default sessions_spawn to no timeout when runTimeoutSeconds omitted
The previous fix (75a791106) correctly handled the case where
runTimeoutSeconds was explicitly set to 0 ("no timeout"). However,
when models omit the parameter entirely (which is common since the
schema marks it as optional), runTimeoutSeconds resolved to undefined.
undefined flowed through the chain as:
sessions_spawn → timeout: undefined (since undefined != null is false)
→ gateway agent handler → agentCommand opts.timeout: undefined
→ resolveAgentTimeoutMs({ overrideSeconds: undefined })
→ DEFAULT_AGENT_TIMEOUT_SECONDS (600s = 10 minutes)
This caused subagents to be killed at exactly 10 minutes even though
the user's intent (via TOOLS.md) was for subagents to run without a
timeout.
Fix: default runTimeoutSeconds to 0 (no timeout) when neither
runTimeoutSeconds nor timeoutSeconds is provided by the caller.
Subagent spawns are long-running by design and should not inherit the
600s agent-command default timeout.
* fix(subagent): accept timeout=0 in agent-via-gateway path (second 600s default)
* fix: thread timeout override through getReplyFromConfig dispatch path
getReplyFromConfig called resolveAgentTimeoutMs({ cfg }) with no override,
always falling back to the config default (600s). Add timeoutOverrideSeconds
to GetReplyOptions and pass it through as overrideSeconds so callers of the
dispatch chain can specify a custom timeout (0 = no timeout).
This complements the existing timeout threading in agentCommand and the
cron isolated-agent runner, which already pass overrideSeconds correctly.
* feat(model-fallback): normalize OpenAI Codex model references and enhance fallback handling
- Added normalization for OpenAI Codex model references, specifically converting "gpt-5.3-codex" to "openai-codex" before execution.
- Updated the `resolveFallbackCandidates` function to utilize the new normalization logic.
- Enhanced tests to verify the correct behavior of model normalization and fallback mechanisms.
- Introduced a new test case to ensure that the normalization process works as expected for various input formats.
* feat(tests): add unit tests for steer failure behavior in openclaw-tools
- Introduced a new test file to validate the behavior of subagents when steer replacement dispatch fails.
- Implemented tests to ensure that the announce behavior is restored correctly and that the suppression reason is cleared as expected.
- Enhanced the subagent registry with a new function to clear steer restart suppression.
- Updated related components to support the new test scenarios.
* fix(subagents): replace stop command with kill in slash commands and documentation
- Updated the `/subagents` command to replace `stop` with `kill` for consistency in controlling sub-agent runs.
- Modified related documentation to reflect the change in command usage.
- Removed legacy timeoutSeconds references from the sessions-spawn-tool schema and tests to streamline timeout handling.
- Enhanced tests to ensure correct behavior of the updated commands and their interactions.
* feat(tests): add unit tests for readLatestAssistantReply function
- Introduced a new test file for the `readLatestAssistantReply` function to validate its behavior with various message scenarios.
- Implemented tests to ensure the function correctly retrieves the latest assistant message and handles cases where the latest message has no text.
- Mocked the gateway call to simulate different message histories for comprehensive testing.
* feat(tests): enhance subagent kill-all cascade tests and announce formatting
- Added a new test to verify that the `kill-all` command cascades through ended parents to active descendants in subagents.
- Updated the subagent announce formatting tests to reflect changes in message structure, including the replacement of "Findings:" with "Result:" and the addition of new expectations for message content.
- Improved the handling of long findings and stats in the announce formatting logic to ensure concise output.
- Refactored related functions to enhance clarity and maintainability in the subagent registry and tools.
* refactor(subagent): update announce formatting and remove unused constants
- Modified the subagent announce formatting to replace "Findings:" with "Result:" and adjusted related expectations in tests.
- Removed constants for maximum announce findings characters and summary words, simplifying the announcement logic.
- Updated the handling of findings to retain full content instead of truncating, ensuring more informative outputs.
- Cleaned up unused imports in the commands-subagents file to enhance code clarity.
* feat(tests): enhance billing error handling in user-facing text
- Added tests to ensure that normal text mentioning billing plans is not rewritten, preserving user context.
- Updated the `isBillingErrorMessage` and `sanitizeUserFacingText` functions to improve handling of billing-related messages.
- Introduced new test cases for various scenarios involving billing messages to ensure accurate processing and output.
- Enhanced the subagent announce flow to correctly manage active descendant runs, preventing premature announcements.
* feat(subagent): enhance workflow guidance and auto-announcement clarity
- Added a new guideline in the subagent system prompt to emphasize trust in push-based completion, discouraging busy polling for status updates.
- Updated documentation to clarify that sub-agents will automatically announce their results, improving user understanding of the workflow.
- Enhanced tests to verify the new guidance on avoiding polling loops and to ensure the accuracy of the updated prompts.
* fix(cron): avoid announcing interim subagent spawn acks
* chore: clean post-rebase imports
* fix(cron): fall back to child replies when parent stays interim
* fix(subagents): make active-run guidance advisory
* fix(subagents): update announce flow to handle active descendants and enhance test coverage
- Modified the announce flow to defer announcements when active descendant runs are present, ensuring accurate status reporting.
- Updated tests to verify the new behavior, including scenarios where no fallback requester is available and ensuring proper handling of finished subagents.
- Enhanced the announce formatting to include an `expectFinal` flag for better clarity in the announcement process.
* fix(subagents): enhance announce flow and formatting for user updates
- Updated the announce flow to provide clearer instructions for user updates based on active subagent runs and requester context.
- Refactored the announcement logic to improve clarity and ensure internal context remains private.
- Enhanced tests to verify the new message expectations and formatting, including updated prompts for user-facing updates.
- Introduced a new function to build reply instructions based on session context, improving the overall announcement process.
* fix: resolve prep blockers and changelog placement (#14447) (thanks @tyler6204)
* fix: restore cron delivery-plan import after rebase (#14447) (thanks @tyler6204)
* fix: resolve test failures from rebase conflicts (#14447) (thanks @tyler6204)
* fix: apply formatting after rebase (#14447) (thanks @tyler6204)
2026-02-14 22:03:45 -08:00
|
|
|
expect(group).toContain("subagents");
|
2026-01-13 06:32:59 +00:00
|
|
|
expect(group).toContain("session_status");
|
2026-02-22 23:55:59 -06:00
|
|
|
expect(group).toContain("tts");
|
2026-01-13 06:32:59 +00:00
|
|
|
});
|
2026-02-16 01:31:06 +00:00
|
|
|
|
|
|
|
|
it("normalizes tool names and aliases", () => {
|
|
|
|
|
expect(normalizeToolName(" BASH ")).toBe("exec");
|
|
|
|
|
expect(normalizeToolName("apply-patch")).toBe("apply_patch");
|
|
|
|
|
expect(normalizeToolName("READ")).toBe("read");
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
it("identifies owner-only tools", () => {
|
|
|
|
|
expect(isOwnerOnlyToolName("whatsapp_login")).toBe(true);
|
2026-02-19 14:37:56 +01:00
|
|
|
expect(isOwnerOnlyToolName("cron")).toBe(true);
|
|
|
|
|
expect(isOwnerOnlyToolName("gateway")).toBe(true);
|
2026-02-16 01:31:06 +00:00
|
|
|
expect(isOwnerOnlyToolName("read")).toBe(false);
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
it("strips owner-only tools for non-owner senders", async () => {
|
2026-02-16 14:52:09 +00:00
|
|
|
const tools = createOwnerPolicyTools();
|
2026-02-16 01:31:06 +00:00
|
|
|
const filtered = applyOwnerOnlyToolPolicy(tools, false);
|
|
|
|
|
expect(filtered.map((t) => t.name)).toEqual(["read"]);
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
it("keeps owner-only tools for the owner sender", async () => {
|
2026-02-16 14:52:09 +00:00
|
|
|
const tools = createOwnerPolicyTools();
|
2026-02-16 01:31:06 +00:00
|
|
|
const filtered = applyOwnerOnlyToolPolicy(tools, true);
|
2026-02-19 14:37:56 +01:00
|
|
|
expect(filtered.map((t) => t.name)).toEqual(["read", "cron", "gateway", "whatsapp_login"]);
|
2026-02-16 01:31:06 +00:00
|
|
|
});
|
2026-02-19 15:27:45 +01:00
|
|
|
|
|
|
|
|
it("honors ownerOnly metadata for custom tool names", async () => {
|
|
|
|
|
const tools = [
|
|
|
|
|
{
|
|
|
|
|
name: "custom_admin_tool",
|
|
|
|
|
ownerOnly: true,
|
|
|
|
|
// oxlint-disable-next-line typescript/no-explicit-any
|
|
|
|
|
execute: async () => ({ content: [], details: {} }) as any,
|
|
|
|
|
},
|
|
|
|
|
] as unknown as AnyAgentTool[];
|
|
|
|
|
expect(applyOwnerOnlyToolPolicy(tools, false)).toEqual([]);
|
|
|
|
|
expect(applyOwnerOnlyToolPolicy(tools, true)).toHaveLength(1);
|
|
|
|
|
});
|
2026-01-13 06:32:59 +00:00
|
|
|
});
|
2026-02-16 01:09:07 +00:00
|
|
|
|
|
|
|
|
describe("TOOL_POLICY_CONFORMANCE", () => {
|
|
|
|
|
it("matches exported TOOL_GROUPS exactly", () => {
|
|
|
|
|
expect(TOOL_POLICY_CONFORMANCE.toolGroups).toEqual(TOOL_GROUPS);
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
it("is JSON-serializable", () => {
|
|
|
|
|
expect(() => JSON.stringify(TOOL_POLICY_CONFORMANCE)).not.toThrow();
|
|
|
|
|
});
|
|
|
|
|
});
|
2026-02-16 01:52:03 +00:00
|
|
|
|
|
|
|
|
describe("sandbox tool policy", () => {
|
|
|
|
|
it("allows all tools with * allow", () => {
|
|
|
|
|
const policy: SandboxToolPolicy = { allow: ["*"], deny: [] };
|
|
|
|
|
expect(isToolAllowed(policy, "browser")).toBe(true);
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
it("denies all tools with * deny", () => {
|
|
|
|
|
const policy: SandboxToolPolicy = { allow: [], deny: ["*"] };
|
|
|
|
|
expect(isToolAllowed(policy, "read")).toBe(false);
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
it("supports wildcard patterns", () => {
|
|
|
|
|
const policy: SandboxToolPolicy = { allow: ["web_*"] };
|
|
|
|
|
expect(isToolAllowed(policy, "web_fetch")).toBe(true);
|
|
|
|
|
expect(isToolAllowed(policy, "read")).toBe(false);
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
it("applies deny before allow", () => {
|
|
|
|
|
const policy: SandboxToolPolicy = { allow: ["*"], deny: ["web_*"] };
|
|
|
|
|
expect(isToolAllowed(policy, "web_fetch")).toBe(false);
|
|
|
|
|
expect(isToolAllowed(policy, "read")).toBe(true);
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
it("treats empty allowlist as allow-all (with deny exceptions)", () => {
|
|
|
|
|
const policy: SandboxToolPolicy = { allow: [], deny: ["web_*"] };
|
|
|
|
|
expect(isToolAllowed(policy, "web_fetch")).toBe(false);
|
|
|
|
|
expect(isToolAllowed(policy, "read")).toBe(true);
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
it("expands tool groups + aliases in patterns", () => {
|
|
|
|
|
const policy: SandboxToolPolicy = {
|
|
|
|
|
allow: ["group:fs", "BASH"],
|
|
|
|
|
deny: ["apply_*"],
|
|
|
|
|
};
|
|
|
|
|
expect(isToolAllowed(policy, "read")).toBe(true);
|
|
|
|
|
expect(isToolAllowed(policy, "exec")).toBe(true);
|
|
|
|
|
expect(isToolAllowed(policy, "apply_patch")).toBe(false);
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
it("normalizes whitespace + case", () => {
|
|
|
|
|
const policy: SandboxToolPolicy = { allow: [" WEB_* "] };
|
|
|
|
|
expect(isToolAllowed(policy, "WEB_FETCH")).toBe(true);
|
|
|
|
|
});
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
describe("resolveSandboxToolPolicyForAgent", () => {
|
|
|
|
|
it("keeps allow-all semantics when allow is []", () => {
|
|
|
|
|
const cfg = {
|
|
|
|
|
tools: { sandbox: { tools: { allow: [], deny: ["browser"] } } },
|
|
|
|
|
} as unknown as OpenClawConfig;
|
|
|
|
|
|
|
|
|
|
const resolved = resolveSandboxToolPolicyForAgent(cfg, undefined);
|
|
|
|
|
expect(resolved.sources.allow).toEqual({
|
|
|
|
|
source: "global",
|
|
|
|
|
key: "tools.sandbox.tools.allow",
|
|
|
|
|
});
|
|
|
|
|
expect(resolved.allow).toEqual([]);
|
|
|
|
|
expect(resolved.deny).toEqual(["browser"]);
|
|
|
|
|
|
|
|
|
|
const policy: SandboxToolPolicy = { allow: resolved.allow, deny: resolved.deny };
|
|
|
|
|
expect(isToolAllowed(policy, "read")).toBe(true);
|
|
|
|
|
expect(isToolAllowed(policy, "browser")).toBe(false);
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
it("auto-adds image to explicit allowlists unless denied", () => {
|
|
|
|
|
const cfg = {
|
|
|
|
|
tools: { sandbox: { tools: { allow: ["read"], deny: ["browser"] } } },
|
|
|
|
|
} as unknown as OpenClawConfig;
|
|
|
|
|
|
|
|
|
|
const resolved = resolveSandboxToolPolicyForAgent(cfg, undefined);
|
|
|
|
|
expect(resolved.allow).toEqual(["read", "image"]);
|
|
|
|
|
expect(resolved.deny).toEqual(["browser"]);
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
it("does not auto-add image when explicitly denied", () => {
|
|
|
|
|
const cfg = {
|
|
|
|
|
tools: { sandbox: { tools: { allow: ["read"], deny: ["image"] } } },
|
|
|
|
|
} as unknown as OpenClawConfig;
|
|
|
|
|
|
|
|
|
|
const resolved = resolveSandboxToolPolicyForAgent(cfg, undefined);
|
|
|
|
|
expect(resolved.allow).toEqual(["read"]);
|
|
|
|
|
expect(resolved.deny).toEqual(["image"]);
|
|
|
|
|
});
|
|
|
|
|
});
|