mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
Adds the agent half of the workspace context sources RFC. The agent now resolves instruction files, skills, and MCP configs into a typed `Snapshot`, watches the relevant paths recursively, exposes the source list over a workspace-agent HTTP API, and pushes each `Snapshot` to coderd over a new `PushContextState` RPC on Agent API v2.10. The coderd-side handler is a stub returning `Unimplemented` for now. Real persistence to `workspace_agent_context`, chatd hydration on dirty events, and the `KindMCPServer` MCP provider are tracked by [CODAGT-569](https://linear.app/codercom/issue/CODAGT-569/enable-agent-api-v210-pushcontextstate-bump-currentminor-wire-coderd). This matches the pattern used for v2.7 `ReportBoundaryLogs` in [#21293](https://github.com/coder/coder/pull/21293), which bumped the version and shipped a stub server so the wire and client could iterate before the persistence layer landed. ## What ships ### agent/agentcontext (new package) - `Source`, `Resource` (kinds `instruction_file`, `skill`, `mcp_config`, `mcp_server` plus reserved `plugin`/`hook`/`subagent`/`command`), `ResourceStatus`, `Snapshot`, `ComputeAggregateHash`. - `Manager` owns the in-memory source list, performs the initial resolve synchronously in `NewManager`, runs a re-resolve/watcher loop in `Run`, exposes `AddSource`/`RemoveSource`/`Sources`/`HasSource`/`Snapshot`/`SubscribeChanges`/`Resync`/`SeedSources`/`Close`. - `Resolver` walks scan roots, classifies recognized files, enforces 64 KiB per-resource, 2 MiB aggregate, and 500-resource caps with `StatusOversize`/`StatusExcluded`/`StatusUnreadable`/`StatusInvalid` outcomes, skips `node_modules`/`vendor`/etc., validates symlink targets stay inside the scan root, stamps `SourcePath` on user-derived resources, and optionally pulls MCP server tool lists via an `MCPProvider` interface. MCP config resources ship metadata only (size, hash) so secrets in env blocks never leave the agent. - `Watcher` is a recursive `fsnotify` wrapper with a 250 ms debounce, dynamic arming of newly created directories, and an ENOSPC-tolerant degraded mode that no-ops further syncs until the manager resyncs explicitly. - HTTP API for `GET/POST /sources`, `GET/DELETE /sources/{path}`, `POST /resync` mounted at `/api/v0/context`. - `Pusher` interface plus `RunPush` goroutine with exponential backoff capped at 30 s. `DRPCPusher` adapts the generated `DRPCAgentClient210` to `Pusher` and translates `drpcerr.Unimplemented` to `ErrPushUnimplemented` so the push loop exits cleanly when talking to coderd deployments that have not enabled the real handler. ### agent/proto (v2.10) - New messages `ContextResource`, `PushContextStateRequest`, `PushContextStateResponse` and the `PushContextState` RPC on `service Agent`. - Generated `DRPCAgentClient210` interface and `codersdk/agentsdk.Client.ConnectRPC210` / `ConnectRPC210WithRole`. - `tailnet/proto.CurrentMinor` bumped from `9` to `10`. ### Agent wiring - `agent.Options.Client` declares both v2.9 and v2.10 connectors; `run()` dials with `ConnectRPC210WithRole`. - `apiConnRoutineManager` holds a `DRPCAgentClient210`. Existing v2.8 routines keep their narrower `DRPCAgentClient28` signature thanks to interface embedding. - `startAgentAPI210` is the v2.10 counterpart to `startAgentAPI` for routines that need the new client. The push context state routine uses it. - A `contextManager` is constructed in `agent.init()`, seeded from the existing `CODER_AGENT_EXP_*_DIRS` env vars, started in its own goroutine under `gracefulCtx`, and closed in `agent.Close`. - `handleManifest` calls `Manager.SeedSources` for sources rooted at the manifest directory, then `Resync` after `manifest.Swap`, so the snapshot reflects the workspace working directory immediately instead of waiting for the next filesystem event. - HTTP routes mounted at `/api/v0/context` when the manager is up. ### Coderd stub `coderd/agentapi/context.go` returns `drpcerr.Unimplemented` for `PushContextState`. The real handler that persists `workspace_agent_context` rows, hydrates chats, and emits dirty events lives in CODAGT-569. ## Tests 24 tests across `agent/agentcontext` cover types, paths, resolver behavior with file caps, skill containers, MCP secret omission, symlink target validation, the recursive watcher firing on real fsnotify events, manager source CRUD / `Resync` / `SeedSources` / `Run` lifetime, the HTTP API, the DRPC adapter, and the push retry / initial-flag / unimplemented paths. Passes `go test -race -count=2`. `TestAgent_ContextStatePushed` boots a full agent against `agenttest.FakeAgentAPI` (which now records `PushContextState` traffic) and asserts the seeded `AGENTS.md` appears in a snapshot push with `schema_version = 1`. <details> <summary>Notes for reviewers</summary> - Source CRUD is workspace-agent-token only; coderd is not in the path for source mutation. - Per-resource cap 64 KiB, aggregate 2 MiB, count cap 500; resources past the cap ship with `StatusExcluded` and an empty payload so the aggregate hash still detects content edits. MCP-emitted resources enforce both a per-provider count cap and the aggregate byte cap. - Symlinks inside the scan root are followed; symlinks pointing outside (or broken) are rejected with `StatusExcluded` so credentials reachable via a stray symlink stay off the wire. - The initial push gates `lifecycle = ready` in the eventual full design. For this PR the `SeedSources` plus `handleManifest`-driven `Resync` keeps the snapshot fresh; the live push loop ships now and DRPCPusher translates the coderd `Unimplemented` stub into a clean exit. - The `PLUGIN`/`HOOK`/`SUBAGENT`/`COMMAND` kinds are reserved in proto and Go enums but unused; the Claude Code plugin resolver ships in a follow-up that does not need a schema migration. - Two follow-ups remain, both tracked by [CODAGT-569](https://linear.app/codercom/issue/CODAGT-569/enable-agent-api-v210-pushcontextstate-bump-currentminor-wire-coderd): (1) the chatd-side handler that persists snapshots and dirties chats; (2) the `coder exp chat context` CLI command set for `list`/`show`/`add`/`remove`/`refresh`. </details> _This PR was authored by Coder Agents on Kyle Carberry's behalf._
143 lines
4.5 KiB
Go
143 lines
4.5 KiB
Go
package agentcontext_test
|
|
|
|
import (
|
|
"os"
|
|
"path/filepath"
|
|
"runtime"
|
|
"strings"
|
|
"testing"
|
|
|
|
"github.com/stretchr/testify/require"
|
|
|
|
"github.com/coder/coder/v2/agent/agentcontext"
|
|
)
|
|
|
|
// switchHomeEnv overrides the platform-specific environment
|
|
// variable consulted by os.UserHomeDir for the duration of the
|
|
// test. Windows reads USERPROFILE; Linux and macOS read HOME.
|
|
func switchHomeEnv(t *testing.T, dir string) {
|
|
t.Helper()
|
|
switch runtime.GOOS {
|
|
case "windows":
|
|
t.Setenv("USERPROFILE", dir)
|
|
default:
|
|
t.Setenv("HOME", dir)
|
|
}
|
|
}
|
|
|
|
func TestCanonicalizePath_AbsoluteCleansAndResolves(t *testing.T) {
|
|
t.Parallel()
|
|
dir := t.TempDir()
|
|
got, err := agentcontext.CanonicalizePath(filepath.Join(dir, "a", "..", "b"))
|
|
require.NoError(t, err)
|
|
// Path does not exist; EvalSymlinks fails. Result is
|
|
// lexically cleaned: filepath.Clean drops the "..".
|
|
require.Equal(t, filepath.Join(dir, "b"), got)
|
|
}
|
|
|
|
func TestCanonicalizePath_RelativeRejected(t *testing.T) {
|
|
t.Parallel()
|
|
_, err := agentcontext.CanonicalizePath("relative/path")
|
|
require.Error(t, err)
|
|
}
|
|
|
|
//nolint:paralleltest,tparallel // Uses t.Setenv.
|
|
func TestCanonicalizePath_TildeExpansion(t *testing.T) {
|
|
home := t.TempDir()
|
|
switchHomeEnv(t, home)
|
|
got, err := agentcontext.CanonicalizePath("~/.coder")
|
|
require.NoError(t, err)
|
|
require.Equal(t, filepath.Join(home, ".coder"), got)
|
|
}
|
|
|
|
//nolint:paralleltest,tparallel // Uses t.Setenv.
|
|
func TestCanonicalizePath_BareTildeExpandsToHome(t *testing.T) {
|
|
home := t.TempDir()
|
|
switchHomeEnv(t, home)
|
|
got, err := agentcontext.CanonicalizePath("~")
|
|
require.NoError(t, err)
|
|
// Canonicalize the same home path through the function under
|
|
// test so the comparison handles platform-specific behavior of
|
|
// EvalSymlinks (Windows can fail to resolve directories that
|
|
// Linux/macOS resolve cleanly).
|
|
want, err := agentcontext.CanonicalizePath(home)
|
|
require.NoError(t, err)
|
|
require.Equal(t, want, got)
|
|
}
|
|
|
|
func TestCanonicalizePath_FollowsSymlinks(t *testing.T) {
|
|
t.Parallel()
|
|
if runtime.GOOS == "windows" {
|
|
t.Skip("os.Symlink requires developer mode or admin on Windows")
|
|
}
|
|
dir := t.TempDir()
|
|
realDir := filepath.Join(dir, "real")
|
|
link := filepath.Join(dir, "link")
|
|
require.NoError(t, os.MkdirAll(realDir, 0o755))
|
|
require.NoError(t, os.Symlink(realDir, link))
|
|
|
|
got, err := agentcontext.CanonicalizePath(link)
|
|
require.NoError(t, err)
|
|
// On macOS the temp dir is itself symlinked; both realDir and got
|
|
// pass through the same EvalSymlinks so they line up.
|
|
want, err := filepath.EvalSymlinks(realDir)
|
|
require.NoError(t, err)
|
|
require.Equal(t, want, got)
|
|
}
|
|
|
|
func TestValidateSourcePath_RejectsParentSegments(t *testing.T) {
|
|
t.Parallel()
|
|
root := t.TempDir()
|
|
// Build /a/../b underneath a real allowed root so the path is
|
|
// absolute on every platform. Validation must still reject the
|
|
// embedded ".." segment before it ever touches allowedRoots.
|
|
bad := filepath.Join(root, "a") + string(os.PathSeparator) + ".." + string(os.PathSeparator) + "b"
|
|
err := agentcontext.ValidateSourcePath(bad, []string{root})
|
|
require.Error(t, err)
|
|
require.Contains(t, err.Error(), "parent traversal")
|
|
}
|
|
|
|
func TestValidateSourcePath_AllowsInsideRoot(t *testing.T) {
|
|
t.Parallel()
|
|
dir := t.TempDir()
|
|
child := filepath.Join(dir, "child")
|
|
require.NoError(t, os.MkdirAll(child, 0o755))
|
|
|
|
require.NoError(t, agentcontext.ValidateSourcePath(child, []string{dir}))
|
|
require.NoError(t, agentcontext.ValidateSourcePath(dir, []string{dir}))
|
|
}
|
|
|
|
func TestValidateSourcePath_RejectsOutsideRoot(t *testing.T) {
|
|
t.Parallel()
|
|
root := t.TempDir()
|
|
other := t.TempDir()
|
|
err := agentcontext.ValidateSourcePath(other, []string{root})
|
|
require.Error(t, err)
|
|
require.Contains(t, err.Error(), "not inside any allowed root")
|
|
}
|
|
|
|
func TestValidateSourcePath_EmptyAllowedRootsBypass(t *testing.T) {
|
|
t.Parallel()
|
|
require.NoError(t, agentcontext.ValidateSourcePath("/anywhere", nil))
|
|
}
|
|
|
|
func TestValidateSourcePath_InvalidRootsFailClosed(t *testing.T) {
|
|
t.Parallel()
|
|
// All allowed roots are relative and therefore invalid;
|
|
// validation must fail closed.
|
|
err := agentcontext.ValidateSourcePath("/anywhere", []string{"relative-only"})
|
|
require.Error(t, err)
|
|
}
|
|
|
|
func TestValidateSourcePath_PathPrefixIsPathAware(t *testing.T) {
|
|
t.Parallel()
|
|
// "/a-prefix" is not inside "/a", even though it starts
|
|
// with the same bytes.
|
|
dir := t.TempDir()
|
|
sibling := strings.TrimRight(dir, string(os.PathSeparator)) + "-sibling"
|
|
require.NoError(t, os.MkdirAll(sibling, 0o755))
|
|
t.Cleanup(func() { _ = os.RemoveAll(sibling) })
|
|
err := agentcontext.ValidateSourcePath(sibling, []string{dir})
|
|
require.Error(t, err)
|
|
}
|