remove allowExecutors from config, execute server, and agent JSONs
This commit is contained in:
parent
dce77f0b8d
commit
b26bd7f580
|
|
@ -93,10 +93,9 @@ func BuildRuntime(cfg *config.Config, d tools.Dispatcher, cwd string, env []stri
|
|||
Verbosity: cfg.Verbosity,
|
||||
}
|
||||
maxSteps = cfg.MaxSteps
|
||||
if len(cfg.AllowExecutors) > 0 || len(cfg.AllowTools) > 0 {
|
||||
if len(cfg.AllowTools) > 0 {
|
||||
if srv, ok := d.GetServer("execute"); ok {
|
||||
if rs, ok := srv.(tools.ToolRestrictionSetter); ok {
|
||||
rs.SetAllowExecutors(cfg.AllowExecutors)
|
||||
rs.SetAllowTools(cfg.AllowTools)
|
||||
}
|
||||
}
|
||||
|
|
|
|||
|
|
@ -64,7 +64,6 @@ type Config struct {
|
|||
Backend string `json:"backend,omitempty"`
|
||||
Model string `json:"model,omitempty"`
|
||||
Tools *bool `json:"tools,omitempty"`
|
||||
AllowExecutors []string `json:"allowExecutors,omitempty"`
|
||||
AllowTools []string `json:"allowTools,omitempty"`
|
||||
MaxTokens int `json:"maxTokens,omitempty"`
|
||||
MaxCompletionTokens int `json:"maxCompletionTokens,omitempty"`
|
||||
|
|
|
|||
|
|
@ -113,9 +113,7 @@ func (e *Server) Dispatch(ctx context.Context, name string, args json.RawMessage
|
|||
if e.OnPreDispatch != nil {
|
||||
e.OnPreDispatch()
|
||||
}
|
||||
if len(e.allowExecutors) > 0 && !e.allowExecutors[name] {
|
||||
return "", fmt.Errorf("executor %q not permitted in this agent context", name)
|
||||
}
|
||||
|
||||
switch name {
|
||||
case "execute_code":
|
||||
return dispatchExecuteCode(ctx, e, args)
|
||||
|
|
|
|||
|
|
@ -54,10 +54,6 @@ type Server struct {
|
|||
// Yolo skips the landrun sandbox for all execution.
|
||||
Yolo bool
|
||||
|
||||
// allowExecutors restricts which executors (execute_code, call_tool, pipe)
|
||||
// are available. Empty means all are allowed.
|
||||
allowExecutors map[string]bool
|
||||
|
||||
// allowTools restricts which named tool scripts can be invoked via call_tool/pipe.
|
||||
// Empty means all are allowed.
|
||||
allowTools map[string]bool
|
||||
|
|
@ -101,18 +97,6 @@ func (e *Server) SetOnExit(fn func(pid, exitCode int)) { e.OnExit = fn }
|
|||
// WithOnEnvSet registers a hook called each time SetEnv is called.
|
||||
func WithOnEnvSet(fn func(key, value string)) Option { return func(s *Server) { s.OnEnvSet = fn } }
|
||||
|
||||
// WithAllowExecutors restricts which executors are available.
|
||||
func WithAllowExecutors(names []string) Option {
|
||||
return func(s *Server) {
|
||||
if len(names) > 0 {
|
||||
s.allowExecutors = make(map[string]bool, len(names))
|
||||
for _, n := range names {
|
||||
s.allowExecutors[n] = true
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// WithAllowTools restricts which tool scripts can be invoked.
|
||||
func WithAllowTools(names []string) Option {
|
||||
return func(s *Server) {
|
||||
|
|
@ -316,15 +300,7 @@ Examples:
|
|||
}`),
|
||||
},
|
||||
}
|
||||
if len(e.allowExecutors) > 0 {
|
||||
filtered := all[:0]
|
||||
for _, t := range all {
|
||||
if e.allowExecutors[t.Name] {
|
||||
filtered = append(filtered, t)
|
||||
}
|
||||
}
|
||||
return filtered, nil
|
||||
}
|
||||
|
||||
if e.toolRegistry != nil && e.sessionID != "" {
|
||||
all = append(all, e.toolRegistry.Loaded(e.sessionID)...)
|
||||
}
|
||||
|
|
@ -367,18 +343,6 @@ func (e *Server) SetCWD(dir string) {
|
|||
e.wdMu.Unlock()
|
||||
}
|
||||
|
||||
// SetAllowExecutors restricts which executors are available.
|
||||
func (e *Server) SetAllowExecutors(names []string) {
|
||||
if len(names) > 0 {
|
||||
e.allowExecutors = make(map[string]bool, len(names))
|
||||
for _, n := range names {
|
||||
e.allowExecutors[n] = true
|
||||
}
|
||||
} else {
|
||||
e.allowExecutors = nil
|
||||
}
|
||||
}
|
||||
|
||||
// SetAllowTools restricts which tool scripts can be invoked.
|
||||
func (e *Server) SetAllowTools(names []string) {
|
||||
if len(names) > 0 {
|
||||
|
|
|
|||
|
|
@ -111,9 +111,8 @@ type LockDirSetter interface {
|
|||
}
|
||||
|
||||
// ToolRestrictionSetter is implemented by tool servers that support restricting
|
||||
// which executors and tool scripts are available.
|
||||
// which tool scripts are available.
|
||||
type ToolRestrictionSetter interface {
|
||||
SetAllowExecutors(names []string)
|
||||
SetAllowTools(names []string)
|
||||
}
|
||||
|
||||
|
|
|
|||
Reference in New Issue