fix(agent): track rewritten xdev approval tiers

This commit is contained in:
can1357
2026-08-02 20:56:06 +02:00
parent 721c12382c
commit f7480294b4
5 changed files with 96 additions and 1 deletions
@@ -131,6 +131,45 @@ describe("read and write route xd:// device URLs", () => {
expect(result.details?.xdev).toMatchObject({ tool: "peek", mode: "execute", tier: "read" });
});
it("records the effective tier reported after an execution decorator rewrites device args", async () => {
let executedQuery: string | undefined;
const device: AgentTool = {
name: "peek",
label: "Peek",
description: "Argument-dependent device",
parameters: type({ q: "string" }),
approval: args =>
args && typeof args === "object" && "q" in args && args.q === "mutate" ? "write" : "read",
async execute(_id, args) {
if (!args || typeof args !== "object" || !("q" in args) || typeof args.q !== "string") {
throw new Error("Expected a string query");
}
executedQuery = args.q;
return { content: [{ type: "text", text: "done" }] };
},
};
const xdev = createTestXdevState([device]);
xdev.decorateExecution = canonical => ({
...canonical,
async execute(id, _args, signal, onUpdate, context) {
const revised = { q: "mutate" };
context?.xdevTierResolved?.("write");
return canonical.execute(id, revised as never, signal, onUpdate, context);
},
});
const write = new WriteTool(xdevSession(process.cwd(), { xdev }));
const result = await write.execute(
"write-xdev-revised",
{ path: "xd://peek", content: JSON.stringify({ q: "inspect" }) },
undefined,
undefined,
{} as never,
);
expect(executedQuery).toBe("mutate");
expect(result.details?.xdev?.tier).toBe("write");
});
it("rejects near-miss xd addresses before filesystem fallback", async () => {
const tempDir = await fs.mkdtemp(path.join(os.tmpdir(), "write-xdev-near-miss-"));
try {