remove allowExecutors from config, execute server, and agent JSONs

This commit is contained in:
ollie 2026-07-28 22:39:17 +02:00
parent dce77f0b8d
commit b26bd7f580
5 changed files with 4 additions and 45 deletions

View File

@ -93,10 +93,9 @@ func BuildRuntime(cfg *config.Config, d tools.Dispatcher, cwd string, env []stri
Verbosity: cfg.Verbosity,
}
maxSteps = cfg.MaxSteps
if len(cfg.AllowExecutors) > 0 || len(cfg.AllowTools) > 0 {
if len(cfg.AllowTools) > 0 {
if srv, ok := d.GetServer("execute"); ok {
if rs, ok := srv.(tools.ToolRestrictionSetter); ok {
rs.SetAllowExecutors(cfg.AllowExecutors)
rs.SetAllowTools(cfg.AllowTools)
}
}

View File

@ -64,7 +64,6 @@ type Config struct {
Backend string `json:"backend,omitempty"`
Model string `json:"model,omitempty"`
Tools *bool `json:"tools,omitempty"`
AllowExecutors []string `json:"allowExecutors,omitempty"`
AllowTools []string `json:"allowTools,omitempty"`
MaxTokens int `json:"maxTokens,omitempty"`
MaxCompletionTokens int `json:"maxCompletionTokens,omitempty"`

View File

@ -113,9 +113,7 @@ func (e *Server) Dispatch(ctx context.Context, name string, args json.RawMessage
if e.OnPreDispatch != nil {
e.OnPreDispatch()
}
if len(e.allowExecutors) > 0 && !e.allowExecutors[name] {
return "", fmt.Errorf("executor %q not permitted in this agent context", name)
}
switch name {
case "execute_code":
return dispatchExecuteCode(ctx, e, args)

View File

@ -54,10 +54,6 @@ type Server struct {
// Yolo skips the landrun sandbox for all execution.
Yolo bool
// allowExecutors restricts which executors (execute_code, call_tool, pipe)
// are available. Empty means all are allowed.
allowExecutors map[string]bool
// allowTools restricts which named tool scripts can be invoked via call_tool/pipe.
// Empty means all are allowed.
allowTools map[string]bool
@ -101,18 +97,6 @@ func (e *Server) SetOnExit(fn func(pid, exitCode int)) { e.OnExit = fn }
// WithOnEnvSet registers a hook called each time SetEnv is called.
func WithOnEnvSet(fn func(key, value string)) Option { return func(s *Server) { s.OnEnvSet = fn } }
// WithAllowExecutors restricts which executors are available.
func WithAllowExecutors(names []string) Option {
return func(s *Server) {
if len(names) > 0 {
s.allowExecutors = make(map[string]bool, len(names))
for _, n := range names {
s.allowExecutors[n] = true
}
}
}
}
// WithAllowTools restricts which tool scripts can be invoked.
func WithAllowTools(names []string) Option {
return func(s *Server) {
@ -316,15 +300,7 @@ Examples:
}`),
},
}
if len(e.allowExecutors) > 0 {
filtered := all[:0]
for _, t := range all {
if e.allowExecutors[t.Name] {
filtered = append(filtered, t)
}
}
return filtered, nil
}
if e.toolRegistry != nil && e.sessionID != "" {
all = append(all, e.toolRegistry.Loaded(e.sessionID)...)
}
@ -367,18 +343,6 @@ func (e *Server) SetCWD(dir string) {
e.wdMu.Unlock()
}
// SetAllowExecutors restricts which executors are available.
func (e *Server) SetAllowExecutors(names []string) {
if len(names) > 0 {
e.allowExecutors = make(map[string]bool, len(names))
for _, n := range names {
e.allowExecutors[n] = true
}
} else {
e.allowExecutors = nil
}
}
// SetAllowTools restricts which tool scripts can be invoked.
func (e *Server) SetAllowTools(names []string) {
if len(names) > 0 {

View File

@ -111,9 +111,8 @@ type LockDirSetter interface {
}
// ToolRestrictionSetter is implemented by tool servers that support restricting
// which executors and tool scripts are available.
// which tool scripts are available.
type ToolRestrictionSetter interface {
SetAllowExecutors(names []string)
SetAllowTools(names []string)
}