mirror of
https://github.com/tiennm99/goclaw.git
synced 2026-07-26 02:19:51 +00:00
Wave 1 Phase 03. Wires the Phase 02 Goja handler into the dispatcher, widens
the DB schema for script + builtin sources, and refactors Dispatcher.Fire to
return a FireResult so builtin-source hooks can mutate event input.
Dispatcher:
- FireResult{Decision, UpdatedToolInput, UpdatedRawInput} replaces the plain
Decision return. stdDispatcher.runSync keeps a local evMut copy so a
builtin-source hook's updatedInput flows to downstream hooks in the chain
and to the caller; non-builtin (source=ui) script mutations are dropped +
WARN-logged (defense-in-depth; source tier enforced at the dispatcher, not
only at the handler).
- applyBuiltinMutation + placeholder builtinAllowlistFor (rawInput, toolInput)
— Phase 04 overrides the allowlist from builtins.yaml.
- noopDispatcher returns FireResult{DecisionAllow}.
- Script mutation tests: TestDispatcher_ScriptMutation_BuiltinSourceApplies,
TestDispatcher_ScriptMutation_UISourceDenied.
Pipeline + callers (14 Fire sites refactored):
- FireHook wrapper returns FireResult; context_stage.go:52 applies
UpdatedRawInput → state.Input.Message; tool_stage.go:52 applies
UpdatedToolInput → tc.Arguments before ExecuteToolCall.
- delegate_bridge + delegate_tool keep the Decision branch; Updated* ignored.
- dispatcher_test / delegate_bridge_test / delegate_tool_hooks_test /
integration test helpers updated for the new shape.
Validation:
- edition_gate allows HandlerScript on every edition (sandboxed, no shell
escape surface).
- config.validateHandler rejects empty source, source > 32 KiB, goja compile
error; validateTimeout rejects on_timeout=ask|defer (reserved).
- Six new config tests cover the script path.
Migrations:
- PG migration 000053 relaxes handler_type + source CHECKs and drops
uq_hooks_{global,tenant,agent} — scripts routinely want many small hooks
per event. RequiredSchemaVersion → 53.
- SQLite SchemaVersion → 21; patch 20 is a SELECT 1 placeholder because
SQLite can't ALTER a CHECK — rebuildAgentHooksV21 runs outside the
migration tx (parallel to backfillV16) to rename/recreate the table with
widened CHECKs. schema.sql fresh-DB path matches.
- H9 fix: PGHookStore.Create + SqliteHookStore.Create honor caller-provided
cfg.ID (uuid.Nil falls back to UUIDv7), unblocking Phase 04 idempotent
UUIDv5 seed. TestCreateHonorsFixedID on both stores.
Config:
- config.HooksConfig{ScriptConcurrency, ScriptPerTenantConcurrency,
ScriptCacheSize, BuiltinDisable}; buildHookHandlers wires the script
handler with the caps from appCfg.Hooks.
Gates green: go build ./... + sqliteonly, go test -race -count=1 across
hooks/pipeline/sqlitestore.
22 lines
1.1 KiB
SQL
22 lines
1.1 KiB
SQL
-- 000053 down — restore the pre-script constraints. Any rows with the new
|
|
-- values are deleted first so the restored CHECK won't reject valid historical
|
|
-- rows. Uniqueness indexes are recreated in their original form.
|
|
|
|
DELETE FROM agent_hooks WHERE handler_type = 'script' OR source = 'builtin';
|
|
|
|
ALTER TABLE agent_hooks DROP CONSTRAINT IF EXISTS agent_hooks_handler_type_check;
|
|
ALTER TABLE agent_hooks ADD CONSTRAINT agent_hooks_handler_type_check
|
|
CHECK (handler_type IN ('command', 'http', 'prompt'));
|
|
|
|
ALTER TABLE agent_hooks DROP CONSTRAINT IF EXISTS agent_hooks_source_check;
|
|
ALTER TABLE agent_hooks ADD CONSTRAINT agent_hooks_source_check
|
|
CHECK (source IN ('ui', 'api', 'seed'));
|
|
ALTER TABLE agent_hooks ALTER COLUMN source TYPE VARCHAR(8);
|
|
|
|
CREATE UNIQUE INDEX IF NOT EXISTS uq_hooks_global
|
|
ON agent_hooks (event, handler_type) WHERE scope = 'global';
|
|
CREATE UNIQUE INDEX IF NOT EXISTS uq_hooks_tenant
|
|
ON agent_hooks (tenant_id, event, handler_type) WHERE scope = 'tenant';
|
|
CREATE UNIQUE INDEX IF NOT EXISTS uq_hooks_agent
|
|
ON agent_hooks (tenant_id, agent_id, event, handler_type) WHERE scope = 'agent';
|