mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
Adds the agent half of the workspace context sources RFC. The agent now resolves instruction files, skills, and MCP configs into a typed `Snapshot`, watches the relevant paths recursively, exposes the source list over a workspace-agent HTTP API, and pushes each `Snapshot` to coderd over a new `PushContextState` RPC on Agent API v2.10. The coderd-side handler is a stub returning `Unimplemented` for now. Real persistence to `workspace_agent_context`, chatd hydration on dirty events, and the `KindMCPServer` MCP provider are tracked by [CODAGT-569](https://linear.app/codercom/issue/CODAGT-569/enable-agent-api-v210-pushcontextstate-bump-currentminor-wire-coderd). This matches the pattern used for v2.7 `ReportBoundaryLogs` in [#21293](https://github.com/coder/coder/pull/21293), which bumped the version and shipped a stub server so the wire and client could iterate before the persistence layer landed. ## What ships ### agent/agentcontext (new package) - `Source`, `Resource` (kinds `instruction_file`, `skill`, `mcp_config`, `mcp_server` plus reserved `plugin`/`hook`/`subagent`/`command`), `ResourceStatus`, `Snapshot`, `ComputeAggregateHash`. - `Manager` owns the in-memory source list, performs the initial resolve synchronously in `NewManager`, runs a re-resolve/watcher loop in `Run`, exposes `AddSource`/`RemoveSource`/`Sources`/`HasSource`/`Snapshot`/`SubscribeChanges`/`Resync`/`SeedSources`/`Close`. - `Resolver` walks scan roots, classifies recognized files, enforces 64 KiB per-resource, 2 MiB aggregate, and 500-resource caps with `StatusOversize`/`StatusExcluded`/`StatusUnreadable`/`StatusInvalid` outcomes, skips `node_modules`/`vendor`/etc., validates symlink targets stay inside the scan root, stamps `SourcePath` on user-derived resources, and optionally pulls MCP server tool lists via an `MCPProvider` interface. MCP config resources ship metadata only (size, hash) so secrets in env blocks never leave the agent. - `Watcher` is a recursive `fsnotify` wrapper with a 250 ms debounce, dynamic arming of newly created directories, and an ENOSPC-tolerant degraded mode that no-ops further syncs until the manager resyncs explicitly. - HTTP API for `GET/POST /sources`, `GET/DELETE /sources/{path}`, `POST /resync` mounted at `/api/v0/context`. - `Pusher` interface plus `RunPush` goroutine with exponential backoff capped at 30 s. `DRPCPusher` adapts the generated `DRPCAgentClient210` to `Pusher` and translates `drpcerr.Unimplemented` to `ErrPushUnimplemented` so the push loop exits cleanly when talking to coderd deployments that have not enabled the real handler. ### agent/proto (v2.10) - New messages `ContextResource`, `PushContextStateRequest`, `PushContextStateResponse` and the `PushContextState` RPC on `service Agent`. - Generated `DRPCAgentClient210` interface and `codersdk/agentsdk.Client.ConnectRPC210` / `ConnectRPC210WithRole`. - `tailnet/proto.CurrentMinor` bumped from `9` to `10`. ### Agent wiring - `agent.Options.Client` declares both v2.9 and v2.10 connectors; `run()` dials with `ConnectRPC210WithRole`. - `apiConnRoutineManager` holds a `DRPCAgentClient210`. Existing v2.8 routines keep their narrower `DRPCAgentClient28` signature thanks to interface embedding. - `startAgentAPI210` is the v2.10 counterpart to `startAgentAPI` for routines that need the new client. The push context state routine uses it. - A `contextManager` is constructed in `agent.init()`, seeded from the existing `CODER_AGENT_EXP_*_DIRS` env vars, started in its own goroutine under `gracefulCtx`, and closed in `agent.Close`. - `handleManifest` calls `Manager.SeedSources` for sources rooted at the manifest directory, then `Resync` after `manifest.Swap`, so the snapshot reflects the workspace working directory immediately instead of waiting for the next filesystem event. - HTTP routes mounted at `/api/v0/context` when the manager is up. ### Coderd stub `coderd/agentapi/context.go` returns `drpcerr.Unimplemented` for `PushContextState`. The real handler that persists `workspace_agent_context` rows, hydrates chats, and emits dirty events lives in CODAGT-569. ## Tests 24 tests across `agent/agentcontext` cover types, paths, resolver behavior with file caps, skill containers, MCP secret omission, symlink target validation, the recursive watcher firing on real fsnotify events, manager source CRUD / `Resync` / `SeedSources` / `Run` lifetime, the HTTP API, the DRPC adapter, and the push retry / initial-flag / unimplemented paths. Passes `go test -race -count=2`. `TestAgent_ContextStatePushed` boots a full agent against `agenttest.FakeAgentAPI` (which now records `PushContextState` traffic) and asserts the seeded `AGENTS.md` appears in a snapshot push with `schema_version = 1`. <details> <summary>Notes for reviewers</summary> - Source CRUD is workspace-agent-token only; coderd is not in the path for source mutation. - Per-resource cap 64 KiB, aggregate 2 MiB, count cap 500; resources past the cap ship with `StatusExcluded` and an empty payload so the aggregate hash still detects content edits. MCP-emitted resources enforce both a per-provider count cap and the aggregate byte cap. - Symlinks inside the scan root are followed; symlinks pointing outside (or broken) are rejected with `StatusExcluded` so credentials reachable via a stray symlink stay off the wire. - The initial push gates `lifecycle = ready` in the eventual full design. For this PR the `SeedSources` plus `handleManifest`-driven `Resync` keeps the snapshot fresh; the live push loop ships now and DRPCPusher translates the coderd `Unimplemented` stub into a clean exit. - The `PLUGIN`/`HOOK`/`SUBAGENT`/`COMMAND` kinds are reserved in proto and Go enums but unused; the Claude Code plugin resolver ships in a follow-up that does not need a schema migration. - Two follow-ups remain, both tracked by [CODAGT-569](https://linear.app/codercom/issue/CODAGT-569/enable-agent-api-v210-pushcontextstate-bump-currentminor-wire-coderd): (1) the chatd-side handler that persists snapshots and dirties chats; (2) the `coder exp chat context` CLI command set for `list`/`show`/`add`/`remove`/`refresh`. </details> _This PR was authored by Coder Agents on Kyle Carberry's behalf._
122 lines
3.5 KiB
Go
122 lines
3.5 KiB
Go
package agentcontext
|
|
|
|
import (
|
|
"os"
|
|
"path/filepath"
|
|
"strings"
|
|
|
|
"golang.org/x/xerrors"
|
|
)
|
|
|
|
// CanonicalizePath produces the canonical form of a user-
|
|
// supplied path. The result is absolute, has ~ expanded, has
|
|
// path-traversal segments collapsed, and has symlinks resolved
|
|
// when the target exists. The path is left lexically clean if
|
|
// it does not yet exist (so adding a not-yet-created directory
|
|
// remains possible).
|
|
//
|
|
// CanonicalizePath returns the original input when it is empty.
|
|
func CanonicalizePath(raw string) (string, error) {
|
|
raw = strings.TrimSpace(raw)
|
|
if raw == "" {
|
|
return "", xerrors.New("path is empty")
|
|
}
|
|
|
|
// Expand ~ and ~/ prefixes against the current user's home
|
|
// directory. Other ~user forms are not supported on
|
|
// purpose; the agent runs as a known user.
|
|
if raw == "~" || strings.HasPrefix(raw, "~/") {
|
|
home, err := os.UserHomeDir()
|
|
if err != nil {
|
|
return "", xerrors.Errorf("expand home dir: %w", err)
|
|
}
|
|
if raw == "~" {
|
|
raw = home
|
|
} else {
|
|
raw = filepath.Join(home, raw[2:])
|
|
}
|
|
}
|
|
|
|
if !filepath.IsAbs(raw) {
|
|
// Fail closed: relative paths could mean different
|
|
// things depending on the agent's working directory at
|
|
// add-time, so require the caller to absolutize first.
|
|
return "", xerrors.Errorf("path %q is not absolute", raw)
|
|
}
|
|
|
|
cleaned := filepath.Clean(raw)
|
|
if resolved, err := filepath.EvalSymlinks(cleaned); err == nil {
|
|
return resolved, nil
|
|
}
|
|
return cleaned, nil
|
|
}
|
|
|
|
// ValidateSourcePath enforces the path-validation rules from
|
|
// the RFC's Authorization section. It rejects:
|
|
//
|
|
// - Paths containing ".." segments after expansion.
|
|
// - Paths resolving outside the supplied allowedRoots, unless
|
|
// allowedRoots is empty (which disables the check).
|
|
//
|
|
// allowedRoots are canonicalized lazily; missing roots are
|
|
// silently skipped so a workspace with no $HOME does not break
|
|
// validation for project-relative roots.
|
|
func ValidateSourcePath(canonical string, allowedRoots []string) error {
|
|
if canonical == "" {
|
|
return xerrors.New("path is empty")
|
|
}
|
|
// filepath.Clean drops "." but leaves ".." when no parent
|
|
// is available. Reject defensively.
|
|
for _, part := range strings.Split(canonical, string(os.PathSeparator)) {
|
|
if part == ".." {
|
|
return xerrors.Errorf("path %q contains parent traversal segments", canonical)
|
|
}
|
|
}
|
|
|
|
if len(allowedRoots) == 0 {
|
|
return nil
|
|
}
|
|
|
|
// Build canonical, deduplicated allowed roots. Missing
|
|
// roots (e.g. an unconfigured ~/.claude/) are skipped.
|
|
roots := make([]string, 0, len(allowedRoots))
|
|
seen := make(map[string]struct{}, len(allowedRoots))
|
|
for _, raw := range allowedRoots {
|
|
c, err := CanonicalizePath(raw)
|
|
if err != nil {
|
|
continue
|
|
}
|
|
if _, ok := seen[c]; ok {
|
|
continue
|
|
}
|
|
seen[c] = struct{}{}
|
|
roots = append(roots, c)
|
|
}
|
|
if len(roots) == 0 {
|
|
// All configured roots were invalid; treat as "deny
|
|
// everything" so misconfiguration fails closed.
|
|
return xerrors.Errorf("path %q is not inside any allowed root", canonical)
|
|
}
|
|
|
|
for _, root := range roots {
|
|
if pathHasPrefix(canonical, root) {
|
|
return nil
|
|
}
|
|
}
|
|
return xerrors.Errorf("path %q is not inside any allowed root", canonical)
|
|
}
|
|
|
|
// pathHasPrefix reports whether path is equal to or a
|
|
// descendant of prefix. Both arguments must already be clean,
|
|
// absolute paths.
|
|
func pathHasPrefix(path, prefix string) bool {
|
|
if path == prefix {
|
|
return true
|
|
}
|
|
withSep := prefix
|
|
if !strings.HasSuffix(withSep, string(os.PathSeparator)) {
|
|
withSep += string(os.PathSeparator)
|
|
}
|
|
return strings.HasPrefix(path, withSep)
|
|
}
|