Files
goclaw/internal/agent/loop_tools.go
T
bd5adc61c8 feat(bitrix24): imbot.v2 migration, 2-way media, openline sender-tag echo, and hardening (#1236)
* refactor(bitrix24): rename "Path B" framing to maintainer-specified naming [B24:2794]

Per maintainer hard rule #10 (no generic "Path A/B" framing) from PR #1061
review. The Bitrix24 MCP auto-onboard flow is Bitrix-specific glue
("Bitrix24 OAuth -> existing mcp_user_credentials bridge"), NOT a generic
MCP architecture pattern.

Naming convention applied consistently:
- First mention per file: full "Bitrix24 OAuth -> existing
  mcp_user_credentials bridge" (matches maintainer comment verbatim).
- Subsequent mentions in same file: shortened "mcp_user_credentials bridge".
- Test/log context referencing literal endpoint /api/auto-onboard: keep
  "auto-onboard" reference (it's the actual API endpoint name).

Changes are documentation-only:
- Rename in code comments + test descriptions + plan docs.
- Clarify framing in mcp_client.go + provisioner.go doc comments to
  emphasize Bitrix-specific glue (not generic MCP infra).
- Reuse existing mcp_user_credentials table + MCPServerStore methods
  (no schema / store / abstraction change).

Files:
- cmd/gateway.go (factory registration doc)
- internal/channels/bitrix24/{channel,factory,mcp_client,provisioner}.go
- internal/channels/bitrix24/{mcp_client,provisioner}_test.go
- plan/goclaw-mcp-integration.md (21 occurrences)

Verified: go build + MCP-related tests pass (TestProvision*,
TestInitMCPProvisioner*, TestMCPClient*).

Phase 1 of Path C execution per
plans/reports/decision-log-260519-1555-bitrix24-pr-fork-decision.md.

* fix: confine outbound media paths to agent workspace [B24:2794]

Tool MEDIA:<path> output reached channel file-upload sinks (Bitrix
imbot.v2.File.upload, Telegram sendDocument, etc.) verbatim via
parseMediaResult, with no workspace-boundary check. A malicious or buggy
tool emitting MEDIA:/etc/passwd could exfiltrate arbitrary files to chat.

Extract the EvalSymlinks+Rel containment from extractMediaFromContent into
a shared confineToWorkspace helper and apply it at the parseMediaResult
sink in processToolResult. Fixing at the source/egress boundary protects
every channel at once rather than per-channel. Paths that escape the
workspace are dropped and logged (security.media_path_rejected).

Add TestConfineToWorkspace (boundary unit) and
TestParseMediaResultConfinedToWorkspace (sink regression for H2).

* feat(bitrix24): support inbound + outbound media via imbot.v2 File API [B24:2794]

Bitrix24 channel was text-only; attachments were parsed but dropped.
- Inbound: download chat files via imbot.v2.File.download (one-time URL),
  forward to the agent with MIME preserved (internal/channels/bitrix24/download.go).
- Outbound: upload agent media to the chat via imbot.v2.File.upload
  (internal/channels/bitrix24/send_media.go).
- Add BaseChannel.HandleMessageMedia to preserve MIME/filename through the bus.
- Per-channel media_max_mb cap (default 20) applies to both directions.

Tests: 92 pass (internal/channels/bitrix24 + internal/channels), go vet clean (PG + sqliteonly).

* refactor(bitrix24): migrate messaging/bot-list/unregister to imbot v2 API [B24:2794]

Move outbound REST calls to the imbot v2 family (keeps register on v1):
- imbot.message.add -> imbot.v2.Chat.Message.send (fields.message shape, live-verified)
- imbot.bot.list (+ legacy imbot.list fallback) -> imbot.v2.Bot.list; add botListRows
  to normalize the v2 {bots:[...]} envelope, legacy array, and id-keyed map forms
- imbot.unregister -> imbot.v2.Bot.unregister

Bot registration stays on v1 imbot.register: v2 imbot.v2.Bot.register changes the
event-delivery model (per-event handler URLs -> eventMode), which would require
rewriting the inbound event parser. No user-facing behavior change.

Tests: bitrix24 package green; go vet ./... clean.

* feat(bitrix24): route whisper via v1 SKIP_CONNECTOR + add v2 replyId [B24:2794]

Bot was leaking HiddenMessage (whisper) replies to the external Zalo
connector because every outbound call went through imbot.v2.Chat.Message.send,
which has no equivalent of the v1 SKIP_CONNECTOR flag. Branch the outbound
path on inbound visibility:

  whisper → imbot.message.add + SKIP_CONNECTOR=Y  (v1, send_v1.go)
  public  → imbot.v2.Chat.Message.send + fields.replyId  (v2, send_v2.go)

Pipeline:
  events.go        parse data[PARAMS][PARAMS][COMPONENT_ID]=HiddenMessage
                   into EventParams.IsHiddenMessage (form + JSON variants)
  handle.go        set bitrix_visibility on InboundMessage.Metadata
  consumer         forward visibility + message_id into OutboundMessage
  send.go          resolveSendOptions + sendChunk dispatcher +
                   shared callWithRateLimitRetry helper
  metadata_keys.go single source of truth for the keys + values

Defaults preserve pre-refactor behaviour: callers that don't populate
bitrix_visibility still go through v2 public, and replyId is omitted
unless a numeric bitrix_message_id arrives in metadata.

Tests:
  TestParseEvent_FormURLEncoded_IsHiddenMessage  (3 cases)
  TestParseEvent_JSON_IsHiddenMessage             (3 cases)
  TestResolveSendOptions                          (8 cases)
  TestSend_BranchesOnVisibility                   (4 cases)

* feat(bitrix24): openline sender-tag echo on replies [B24:2794]

Openline sender-tag echo (this change):
- Capture the connector sender tag ("[name #id]:" or "[name] #id:") from
  inbound openline group messages, strip it from the body the agent sees,
  and re-prepend the canonical "[name] #id:" form to the reply so the Open
  Channel connector routes the answer back to the right external user.
- New sender_prefix.go helper (+ test) accepts both inbound layouts and
  emits one canonical form; scoped to messages carrying the tag, so plain
  chats are unaffected.
- metadata_keys.go: MetaKeySenderPrefix; handle.go capture/strip/stash;
  gateway_consumer_normal.go forwards the key; send.go prepends it on the
  first chunk before chunking.

Bundled bitrix24 channel-core work already on this branch:
- handle.go: @mention is the sole trigger for both staff and connector
  customers; unmentioned traffic is dropped (was: drop all connector msgs).
- isGroupMessageType: treat SONET_GROUP "B" as a group.
- handle_test.go, mcp_client_test.go: cover the above.

* feat(bitrix24): accept colon-less openline sender tag, echo [name] #id [B24:2794]

The Open Channel connector dropped the trailing colon from its sender tag:
inbound now arrives as "[Name] #id <msg>" (was "[Name] #id: <msg>"). The
id-bearing patterns required the colon, so the tag fell through to the
name-only branch and the reply echoed "[Name]" — dropping the #id the
connector needs to route the answer back.

- sender_prefix.go: make the trailing ":" optional on both id layouts
  ([name #id] / [name] #id, with or without colon) and echo the canonical
  "[name] #id" (no colon) to match the connector's current format. Bare
  "[name]" (no id) still echoes "[name]" for Open Channel only.
- handle.go: gate the bare name-only layout to Open Channel (isOpenChannel)
  so ordinary group chats starting with "[x] ..." are left untouched.
- sender_prefix_test.go: cover colon/no-colon x id-inside/id-outside, the
  name-only openline case, and the non-openline no-op.

* fix: security and robustness fixes from the bitrix24 channel review [B24:2794]

- download.go: block redirect-based SSRF on inbound media. CheckRedirect
  re-validates each hop (http(s) only, reject private/loopback/link-local
  hosts, cap hops); the initial portal-domain pin is no longer bypassable
  via a 3xx to an internal service. Public-host redirects still allowed.
- handle.go: extract/echo the openline sender tag only for Open Channel
  sessions (was: any group chat), removing bogus prefixes in CRM group
  chats and narrowing the forged-tag misroute surface.
- loop_tools.go + loop_media.go: confine result.Media to the agent / team /
  tenant-allowed roots (new confineToAnyRoot) before a channel uploads it,
  so a prompt-injected out-of-workspace path (e.g. /etc/passwd) cannot
  exfiltrate, while legitimate cross-workspace media (team files, delegatee
  output) still flows.
- send_media.go: bounded outbound read via io.LimitReader replaces the
  os.Stat + os.ReadFile pair, closing the TOCTOU size-cap bypass; cap a
  single message's outbound attachments at 10 (mirrors inbound).
- register.go: paginate imbot.v2.Bot.list (limit/offset + hasNextPage,
  capped at 40 pages) so verify/lookup see bots past the first 50.
- mcp_client.go: redact access_token / refresh_token / client_secret from an
  echoed MCP error body before it is logged or returned (+ test).

* fix(security): validate resolved dial IP on Bitrix media redirects [B24:2794]

The inbound media download redirect guard only string-checked the redirect
hostname (isPrivateOrLoopback on req.URL.Hostname()), so a redirect to a public
hostname that resolves to 127.0.0.1 / 169.254.169.254 / an RFC1918 address — or a
DNS-rebinding swap between check and dial — still passed the guard and the client
would connect. Reported in PR review.

Add security.NewRedirectFollowingSafeClient: it follows redirects but validates
the RESOLVED destination IP of every hop at dial time via net.Dialer.Control,
reusing the existing blocked-CIDR list. The IP it checks is the IP actually
dialed, so both redirect-to-internal and DNS rebinding are refused, while
legitimate public CDN redirects still succeed. download.go now uses it instead of
the hostname-string guard.

Tests: deterministic dial-control table (loopback / link-local / private /
multicast / unspecified / public, v4 + v6), malformed/non-IP addr, test bypass,
loopback-dial-blocked client wiring, and redirect cap + scheme checks.

* feat(bitrix24): per-participant Zalo openline identity from 3-token sender tag [B24:2794]

Parse the connector's "[Name] #uid #msgId" sender tag so each external
customer in a shared Open Channel group gets its own contact + USER.md
instead of collapsing onto the connector proxy id. Identity minting is
gated on IS_CONNECTOR=Y to reject operator forged tags. Echo back the
msgId only ("#msgId") on replies; keep the legacy single-number and
name-only layouts unchanged. Zero DB migration.

- sender_prefix.go: parseOpenlineSenderTag() classifies 3-token / legacy / name-only
- handle.go: synthetic senderID "openlines:{instance}:{chat}:{uid}" + participant_user_id metadata, gated on FromIsConnector
- gateway_consumer_normal.go: deriveGroupUserID() routes participant -> per-person scope, group fallback otherwise
- send.go: buildAddressMention numeric-id guard so synthetic ids don't emit invalid [USER=...] BBCode
- MetaKeyMessageID kept as Bitrix MESSAGE_ID (drives v2 fields.replyId); connector msgId surfaced only via echo prefix

---------

Co-authored-by: DangTinh311 <dangtinh31193@gmail.com>
Co-authored-by: Chinh Dang <chinhdang@192.168.68.104>
2026-06-22 14:23:34 +07:00

206 lines
7.4 KiB
Go

package agent
import (
"context"
"log/slog"
"path/filepath"
"github.com/nextlevelbuilder/goclaw/internal/providers"
"github.com/nextlevelbuilder/goclaw/internal/tools"
"github.com/nextlevelbuilder/goclaw/pkg/protocol"
)
// toolResultAction describes what the caller should do after processing a tool result.
type toolResultAction int
const (
toolResultContinue toolResultAction = iota // proceed normally
toolResultWarning // injected warning message, continue
toolResultBreak // critical loop detected, break iteration
)
// processToolResult handles post-execution bookkeeping for a single tool result:
// loop detection, event emission, media collection, deliverables, and message building.
// Used by both single-tool and parallel-tool paths to eliminate duplication.
//
// Returns the tool message, an optional warning message to inject, and an action signal.
// The caller must append toolMsg and warningMsg to messages/pendingMsgs, and break if action == toolResultBreak.
func (l *Loop) processToolResult(
ctx context.Context,
rs *runState,
req *RunRequest,
emitRun func(AgentEvent),
tc providers.ToolCall,
registryName string,
result *tools.Result,
hadBootstrap bool,
) (toolMsg providers.Message, warningMsgs []providers.Message, action toolResultAction) {
// Record for loop detection.
argsHash := rs.loopDetector.record(registryName, tc.Arguments)
rs.loopDetector.recordResult(argsHash, result.ForLLM)
rs.loopDetector.recordMutation(registryName, tc.Arguments)
if result.Async {
rs.asyncToolCalls = append(rs.asyncToolCalls, tc.Name)
}
if result.IsError {
errMsg := result.ForLLM
if len(errMsg) > 200 {
errMsg = errMsg[:200] + "..."
}
slog.Warn("tool error", "agent", l.id, "tool", tc.Name, "error", errMsg)
}
// Count successful spawn calls for orphan detection (post-execution).
if registryName == "spawn" && !result.IsError {
if tid, _ := tc.Arguments["team_task_id"].(string); tid != "" {
rs.teamTaskSpawns++
}
}
if hadBootstrap && bootstrapToolAllowlist[registryName] {
rs.bootstrapWriteDetected = true
}
// Emit tool result event.
toolResultPayload := map[string]any{
"name": tc.Name,
"id": tc.ID,
"is_error": result.IsError,
"arguments": tc.Arguments,
"result": truncateStr(result.ForLLM, 1000),
}
if result.IsError && result.ForLLM != "" {
toolResultPayload["content"] = result.ForLLM
}
emitRun(AgentEvent{
Type: protocol.AgentEventToolResult,
AgentID: l.id,
RunID: req.RunID,
Payload: toolResultPayload,
})
l.scanWebToolResult(tc.Name, result)
// Collect MEDIA: paths from tool results.
// Prefer result.Media (explicit) over ForLLM MEDIA: prefix (legacy) to avoid duplicates.
if len(result.Media) > 0 {
// Egress containment: a tool that sets result.Media[].Path to a path
// outside every allowed scope (e.g. /etc/passwd from a prompt-injected
// path) must not reach a channel's file-upload sink. Confine here at the
// source so every channel is covered. The allowed roots mirror what the
// producing tools (create_*, send_file, delegate) may legitimately write
// to — agent workspace, team workspace, and tenant-allowed paths — so a
// cross-workspace file (e.g. a teammate-produced file in the shared team
// workspace, or a synchronous delegatee's output) is not wrongly dropped.
mediaRoots := append([]string{
tools.ToolWorkspaceFromCtx(ctx),
tools.ToolTeamWorkspaceFromCtx(ctx),
}, l.tenantAllowedPaths...)
for i, mf := range result.Media {
cleaned, ok := confineToAnyRoot(mf.Path, mediaRoots)
if !ok {
slog.Warn("security.media_path_rejected",
"agent", l.id, "tool", tc.Name, "path", mf.Path,
"reason", "outside agent workspace")
continue
}
ct := mf.MimeType
if ct == "" {
ct = mimeFromExt(filepath.Ext(cleaned))
}
mr := MediaResult{Path: cleaned, ContentType: ct, Caption: mf.Caption}
if result.MediaPrompts != nil {
mr.Prompt = result.MediaPrompts[i]
}
rs.mediaResults = append(rs.mediaResults, mr)
}
} else if mr := parseMediaResult(result.ForLLM); mr != nil {
// Security (egress boundary): a tool's MEDIA:<path> output is taken
// verbatim, so confine it to the agent workspace before it can reach an
// outbound channel's file-upload sink (e.g. Bitrix imbot.v2.File.upload,
// Telegram sendDocument). A malicious or buggy tool emitting
// MEDIA:/etc/passwd is dropped here — fixing every channel at the source
// rather than per-channel. Mirrors extractMediaFromContent containment.
if cleaned, ok := confineToWorkspace(mr.Path, tools.ToolWorkspaceFromCtx(ctx)); ok {
mr.Path = cleaned
rs.mediaResults = append(rs.mediaResults, *mr)
} else {
slog.Warn("security.media_path_rejected",
"agent", l.id, "tool", tc.Name, "path", mr.Path,
"reason", "outside agent workspace")
}
}
// Auto-attach workspace media to task (covers create_image/audio/video).
if teamWs := tools.ToolTeamWorkspaceFromCtx(ctx); teamWs != "" {
for _, mf := range result.Media {
tools.AutoAttachWorkspaceFile(ctx, l.teamStore, teamWs, mf.Path)
}
}
if result.Deliverable != "" {
rs.deliverables = append(rs.deliverables, result.Deliverable)
}
toolMsg = providers.Message{
Role: "tool",
Content: result.ForLLM,
ToolCallID: tc.ID,
IsError: result.IsError,
}
action = toolResultContinue
// Check for tool call loop after recording result.
if level, msg := rs.loopDetector.detect(registryName, argsHash); level != "" {
if level == "critical" {
slog.Warn("tool loop critical", "agent", l.id, "tool", registryName, "message", msg)
rs.finalContent = "I was unable to complete this task — I got stuck repeatedly calling " + registryName + " without making progress. Please try rephrasing your request."
rs.loopKilled = true
return toolMsg, nil, toolResultBreak
}
slog.Warn("tool loop warning", "agent", l.id, "tool", registryName, "message", msg)
warningMsgs = append(warningMsgs, providers.Message{Role: "user", Content: msg})
action = toolResultWarning
}
// Check for same tool returning identical results with different args.
if rh := hashResult(result.ForLLM); rh != "" {
if level, msg := rs.loopDetector.detectSameResult(registryName, rh); level != "" {
if level == "critical" {
slog.Warn("tool loop critical: same result",
"tool", registryName, "agent", l.id, "run", req.RunID)
rs.finalContent = msg
rs.loopKilled = true
return toolMsg, nil, toolResultBreak
}
warningMsgs = append(warningMsgs, providers.Message{Role: "user", Content: msg})
action = toolResultWarning
}
}
return toolMsg, warningMsgs, action
}
// checkReadOnlyStreak detects when the agent is stuck in a read-only loop.
// Returns warning messages to inject and whether the loop should break.
func (l *Loop) checkReadOnlyStreak(rs *runState, req *RunRequest) (warningMsg *providers.Message, shouldBreak bool) {
level, msg := rs.loopDetector.detectReadOnlyStreak()
if level == "" {
return nil, false
}
if level == "critical" {
slog.Warn("tool loop critical: read-only streak",
"streak", rs.loopDetector.readOnlyStreak,
"unique", rs.loopDetector.readOnlyUnique,
"agent", l.id, "run", req.RunID)
rs.finalContent = msg
rs.loopKilled = true
return nil, true
}
slog.Warn("tool loop warning: read-only streak",
"streak", rs.loopDetector.readOnlyStreak, "agent", l.id, "run", req.RunID)
warnMsg := providers.Message{Role: "user", Content: msg}
return &warnMsg, false
}