Repository navigation
feat(runtime): add tool registry and execution policy boundary #252
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
JoTalbot
wants to merge
158
commits into
main
Choose a base branch
from
feat/vnext-tools-sandbox
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
Changes from 1 commit
Commits
Show all changes
158 commits
Select commit
Hold shift + click to select a range
2f3834e
feat(runtime): add policy-aware tool registry
JoTalbot 9510b30
feat(runtime): add tool execution policy boundary
JoTalbot 57f9249
test(runtime): cover tool permissions and sandbox boundary
JoTalbot 36ccb86
feat(runtime): add structured execution audit trail
JoTalbot 392f48b
feat(runtime): audit tool sandbox executions
JoTalbot cc497f1
test(runtime): cover tool execution audit trail
JoTalbot 7ab6c3b
feat(runtime): add agent execution adapter
JoTalbot bc7483e
feat(runtime): connect orchestrator to agent executor
JoTalbot aeff23d
fix(runtime): pass agent executor through scheduled task
JoTalbot c7c58b9
feat(kernel): execute scheduled tasks through agent executor
JoTalbot bc11aca
test(runtime): cover agent executor tool pipeline
JoTalbot 6fbe2b6
feat(runtime): connect orchestrator memory context
JoTalbot a452bc2
test(runtime): verify orchestrator tool execution path
JoTalbot 532c904
feat(runtime): add typed tool call result protocol
JoTalbot 0133483
feat(runtime): add timeout aware typed tool executor
JoTalbot c8a4982
test(runtime): cover typed tool results and timeout
JoTalbot 76dc790
refactor(runtime): use typed tool protocol in agent executor
JoTalbot d22b1d8
test(runtime): verify typed agent execution and retry
JoTalbot cacf1eb
feat(cognition): bridge tool failures into replanning
JoTalbot 8426821
test(cognition): verify tool failure reflection bridge
JoTalbot 77b5871
refactor(runtime): standardize execution context and correlation id
JoTalbot fa480e0
feat(runtime): add async event bus
JoTalbot 3a775e7
feat(runtime): add correlated execution event contract
JoTalbot 9c78330
feat(runtime): correlate audit events with execution context
JoTalbot f05a5cd
feat(runtime): define canonical lifecycle event types
JoTalbot f70118c
feat(runtime): correlate tool lifecycle events
JoTalbot 8d160ca
feat(runtime): propagate execution context through agent lifecycle
JoTalbot b441593
feat(runtime): add orchestration lifecycle event publisher
JoTalbot 33907df
feat(runtime): propagate lifecycle events through orchestrator
JoTalbot a3e0faf
feat(cognition): add orchestrator replan lifecycle
JoTalbot e193b89
feat(runtime): add bounded autonomous execution loop
JoTalbot 4217560
test(runtime): cover automatic replan execution loop
JoTalbot 525c4e8
feat(runtime): add persistent execution state store
JoTalbot ff0822f
test(runtime): verify persistent execution recovery
JoTalbot 49bcb58
feat(runtime): persist checkpoints and resume executions
JoTalbot ca9df87
test(runtime): verify restart-safe autonomous loop
JoTalbot ccb006a
feat(runtime): complete startup recovery manager
JoTalbot f5b533e
test(runtime): verify startup recovery manager
JoTalbot 1ea5698
feat(runtime): add startup runtime bootstrap recovery
JoTalbot 75b19fd
test(runtime): verify startup recovery orchestration
JoTalbot eeb2c64
fix(runtime): resume persisted executions through loop
JoTalbot 685f196
feat(runtime): wire bootstrap to restart-safe loop resume
JoTalbot 49cfced
test(runtime): add end-to-end startup recovery coverage
JoTalbot 1f92585
feat(runtime): add restart recovery execution lease
JoTalbot dfb1531
test(runtime): verify exclusive execution recovery lease
JoTalbot dc0e7de
feat(runtime): enforce exclusive leases during startup recovery
JoTalbot cb4579a
test(runtime): verify exclusive bootstrap recovery leases
JoTalbot b2d2595
feat(runtime): add execution lease renewal and ownership checks
JoTalbot 1e41129
test(runtime): verify execution lease renewal ownership
JoTalbot c22e6f7
feat(runtime): add automatic recovery lease heartbeat
JoTalbot 6a96296
test(runtime): verify recovery lease heartbeat lifecycle
JoTalbot 64de1a5
test(runtime): simulate crash and takeover recovery
JoTalbot 4005bd3
feat(runtime): add explicit recovery checkpoint lifecycle
JoTalbot f3cfded
feat(runtime): integrate recovery checkpoints into execution loop
JoTalbot c5c925a
test(runtime): add checkpoint integration coverage
JoTalbot 051d200
fix(test): complete checkpoint integration assertions
JoTalbot beec171
feat(runtime): guard checkpoints with execution lease ownership
JoTalbot 92ffba6
fix(runtime): restore loop compatibility after lease-aware checkpoint
JoTalbot 72e3584
test(runtime): cover stale-owner checkpoint rejection
JoTalbot f3b89bc
fix(runtime): use RecoveryCheckpoint in lease-aware adapter
JoTalbot 05c14af
feat(runtime): provide lease-aware autonomous runtime factory
JoTalbot 665b790
feat(runtime): add unified runtime lifecycle orchestrator
JoTalbot 0d2d48e
test(runtime): verify unified runtime lifecycle
JoTalbot 25a9912
fix(runtime): make orchestrator startup failure-safe
JoTalbot a51a83c
test(runtime): verify startup failure rollback
JoTalbot ecbdcf6
feat(runtime): implement graceful shutdown lifecycle
JoTalbot 043c5ad
test(runtime): verify graceful shutdown lifecycle
JoTalbot fafa412
feat(runtime): wire graceful shutdown into orchestrator
JoTalbot 122c240
feat(runtime): guarantee lease release during graceful shutdown
JoTalbot 04f51f2
fix(runtime): release owned leases on orchestrator shutdown
JoTalbot dcf233c
test(runtime): verify shutdown releases recovery leases
JoTalbot 6d1f551
fix(test): remove invalid asyncio dependency from shutdown test
JoTalbot ed3f0b5
feat(runtime): enforce explicit execution state machine
JoTalbot 4665a2e
test(runtime): add execution state machine coverage
JoTalbot 585f9b8
fix(runtime): route loop lifecycle through validated state transitions
JoTalbot 8c247ea
test(runtime): cover loop state transition integration
JoTalbot 228c6e9
fix(test): assert persisted loop state after validated retry
JoTalbot 9d05c81
feat(runtime): extract execution state machine domain
JoTalbot 2963fd5
refactor(runtime): delegate execution transitions to domain state mac…
JoTalbot c6037e6
test(runtime): cover domain state machine and store injection
JoTalbot 49fb631
feat(runtime): make execution audit append-only and lifecycle-aware
JoTalbot 08db54b
test(runtime): verify persistent lifecycle audit trail
JoTalbot 7c04741
feat(runtime): emit immutable audit events from state persistence
JoTalbot 98ad15e
fix(runtime): preserve existing audit API alongside lifecycle events
JoTalbot 85f80ee
feat(runtime): add audit event identity and idempotency
JoTalbot 1402e28
feat(runtime): propagate correlation identity through execution persi…
JoTalbot 5d63512
test(runtime): verify audit idempotency and correlation propagation
JoTalbot 81db960
feat(runtime): add durable execution commit coordinator
JoTalbot d35b58d
feat(runtime): add crash reconciliation for execution commits
JoTalbot 85c0331
test(runtime): cover durable execution commit and crash reconciliation
JoTalbot cc09b66
feat(runtime): reconcile interrupted commits before startup recovery
JoTalbot 6362b29
feat(runtime): wire commit reconciliation into orchestrator bootstrap
JoTalbot a723134
feat(runtime): expose reconciliation results in recovery report
JoTalbot 61f1a9e
test(runtime): verify bootstrap reconciliation reporting
JoTalbot 0b56ac0
feat(runtime): make commit journal replay stateful and bounded
JoTalbot 67bbd80
feat(runtime): add commit journal integrity and quarantine
JoTalbot ffe983d
feat(runtime): add deterministic recovery policy engine
JoTalbot 2a7ce2d
test(runtime): cover recovery policy decisions
JoTalbot c6324fc
feat(runtime): enforce recovery policy during bootstrap
JoTalbot 7040e19
test(runtime): integrate recovery policy with bootstrap
JoTalbot 47f6ef9
feat(runtime): add persistent recovery operator queues
JoTalbot f0ef956
feat(runtime): persist quarantine and manual-review recovery queues
JoTalbot c67a989
test(runtime): persist manual recovery decisions
JoTalbot 12346c6
feat(runtime): add operator recovery queue service
JoTalbot fc09c60
fix(runtime): make recovery queue resolution durable
JoTalbot 9e35149
fix(runtime): use durable queue resolution in operator service
JoTalbot 7265487
feat(runtime): add operator recovery HTTP transport
JoTalbot fa97330
feat(api): add FastAPI application factory and operator boundary
JoTalbot 4847993
test(api): verify recovery HTTP authorization boundary
JoTalbot af99a76
fix(api): enforce request auth and typed recovery payloads
JoTalbot 5a583f9
feat(api): add health readiness and control-plane wiring
JoTalbot 0742f19
test(api): cover health readiness and request-aware auth
JoTalbot 47bd2c6
feat(api): add production control-plane entrypoint
JoTalbot cb0f67c
feat(runtime): add durable operator audit trail
JoTalbot 7b37a63
test(api): verify production operator authentication boundary
JoTalbot 2559236
feat(runtime): audit operator recovery actions
JoTalbot 091837a
fix(runtime): audit durable recovery resolution result
JoTalbot 84eb62b
feat(api): expose operator audit endpoint
JoTalbot e7c8b02
feat(api): wire operator audit and dependency readiness
JoTalbot 8e28bdf
feat(api): add control-plane security context and RBAC
JoTalbot e7ff7dd
feat(api): enforce viewer RBAC on operator audit endpoint
JoTalbot a9d21ab
feat(runtime): type operator audit actions and outcomes
JoTalbot b3ee5a4
fix(runtime): preserve correlation ids in operator audit
JoTalbot df4537d
feat(api): add unified operator security context and RBAC
JoTalbot bd903d2
feat(api): add role dependencies for recovery control plane
JoTalbot a9588d4
feat(api): inject unified operator context into control plane
JoTalbot 6bf8ea5
feat(api): enforce RBAC and propagate operator context
JoTalbot 1fc0063
fix(api): use canonical security context for recovery
JoTalbot 3de591c
test(api): add recovery RBAC matrix and audit propagation
JoTalbot d1b7570
refactor(api): make SecurityContext canonical with correlation id
JoTalbot 61115ee
refactor(api): remove duplicate operator context model
JoTalbot 53eba10
fix(api): use canonical SecurityContext in app factory
JoTalbot 50c3317
fix(api): remove stale recovery RBAC context types
JoTalbot 272d917
fix(api): use canonical authentication at uvicorn entrypoint
JoTalbot c0ef54a
test(api): cover canonical context and correlation propagation
JoTalbot eaa841e
security(api): prevent header-based identity and role escalation
JoTalbot 0324ea3
test(security): harden identity, role and correlation handling
JoTalbot 1b17e32
ci(security): add control-plane security regression workflow
JoTalbot ee0a84d
test(security): add authentication hardening regression coverage
JoTalbot 2442e04
feat(api): add fail-closed control-plane auth config
JoTalbot 07eedce
test(api): cover fail-closed auth configuration
JoTalbot 218d8cb
refactor(api): authenticate through validated control-plane config
JoTalbot 3667c66
feat(api): fail closed at control-plane app startup
JoTalbot 45d3c43
fix(runtime): classify tool failures for safe retry
JoTalbot 9109411
fix(runtime): classify retryable tool execution failures
JoTalbot 9833b0e
fix(runtime): retry only explicitly retryable tool failures
JoTalbot e9bdae8
fix(runtime): isolate event subscriber failures
JoTalbot f6cf2c6
fix(kernel): preserve execution context through scheduler
JoTalbot 7c97fb6
fix(runtime): enforce agent authorization at tool sandbox boundary
JoTalbot 205b3d7
test(runtime): verify agent authorization boundary
JoTalbot 1127026
test(runtime): isolate event subscriber failures
JoTalbot 182f1eb
test(pr252): pin down API and execution contracts
JoTalbot 2ed54c7
test(pr252): verify scheduler to sandbox tool integration
JoTalbot d0ea9a4
test(pr252): enforce sandbox authorization at agent boundary
JoTalbot 52c0b0f
fix(ci): satisfy operator token length contract
JoTalbot 6593a78
fix(test): import execution transition error from state machine
JoTalbot 5fce4a7
fix(test): align sandbox authorization and execution contracts
JoTalbot 8fd83f3
fix(test): align recovery audit assertions with durable log contract
JoTalbot File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
test(runtime): cover typed tool results and timeout
- Loading branch information
commit c8a4982d0f709560aa0230a9060ba6442156faea
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,41 @@ | ||
| import asyncio | ||
|
|
||
| import pytest | ||
|
|
||
| from runtime.tool_executor import ToolExecutor | ||
| from runtime.tool_protocol import ToolCall | ||
| from runtime.tool_registry import ToolRegistry | ||
| from runtime.tool_sandbox import ToolSandbox | ||
|
|
||
|
|
||
| async def slow(): | ||
| await asyncio.sleep(0.05) | ||
| return "done" | ||
|
|
||
|
|
||
| async def fail(): | ||
| raise RuntimeError("broken") | ||
|
|
||
|
|
||
| @pytest.mark.asyncio | ||
| async def test_tool_executor_returns_typed_failure_on_error(): | ||
| registry = ToolRegistry() | ||
| registry.register("fail", fail) | ||
| result = await ToolExecutor(ToolSandbox(registry)).execute( | ||
| ToolCall("fail", call_id="c1"), | ||
| __import__("runtime.tool_sandbox", fromlist=["ToolExecutionContext"]).ToolExecutionContext("agent-1"), | ||
| ) | ||
| assert result.ok is False | ||
| assert result.call_id == "c1" | ||
|
|
||
|
|
||
| @pytest.mark.asyncio | ||
| async def test_tool_executor_enforces_timeout(): | ||
| registry = ToolRegistry() | ||
| registry.register("slow", slow) | ||
| result = await ToolExecutor(ToolSandbox(registry)).execute( | ||
| ToolCall("slow", call_id="c2", timeout=0.001), | ||
| __import__("runtime.tool_sandbox", fromlist=["ToolExecutionContext"]).ToolExecutionContext("agent-1"), | ||
| ) | ||
| assert result.ok is False | ||
| assert "Timeout" in (result.error or "") or "timeout" in (result.error or "").lower() | ||
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🔥 The Roast: Проверка
"Timeout" in (result.error or "")всегда падает, потому чтоasyncio.TimeoutErrorимеет пустую строковую репрезентацию. Ищете воду в пустыне.🩹 The Fix:
(Или лучше проверяйте
result.ok is Falseи отдельный флагtimed_out.)📏 Severity: critical
Reply with
@kilocode-bot fix itto have Kilo Code address this issue.