* feat(web-fetch): add web_fetch tool to read a specific URL's content * test(web-fetch): add SSRF coverage and fail closed on empty DNS resolution Add explicit SSRF regression tests for the web_fetch path covering loopback, private LAN ranges, link-local/metadata, IPv6 private/local, redirect-into-private, and unsupported schemes. Harden _public_http_url to fail closed when a hostname resolves to no addresses.
135 lines
4.7 KiB
Python
135 lines
4.7 KiB
Python
"""
|
|
agent_tools.py — Facade module.
|
|
|
|
Re-exports tool parsing, schemas, execution, and implementations
|
|
for backward compatibility. All importers continue to work unchanged.
|
|
|
|
Sub-modules:
|
|
- tool_parsing.py: regex patterns, parse/strip functions
|
|
- tool_schemas.py: FUNCTION_TOOL_SCHEMAS, function_call_to_tool_block
|
|
- tool_execution.py: execute_tool_block, format_tool_result, MCP helpers
|
|
- tool_implementations.py: all do_* tool functions
|
|
"""
|
|
|
|
import logging
|
|
from collections import namedtuple
|
|
|
|
logger = logging.getLogger(__name__)
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# Constants (kept here — sub-modules import from here)
|
|
# ---------------------------------------------------------------------------
|
|
MAX_AGENT_ROUNDS = 20
|
|
SHELL_TIMEOUT = 60
|
|
PYTHON_TIMEOUT = 30
|
|
MAX_OUTPUT_CHARS = 10_000
|
|
MAX_READ_CHARS = 20_000
|
|
|
|
# Tool types that trigger execution
|
|
TOOL_TAGS = {"bash", "python", "web_search", "web_fetch", "read_file", "write_file",
|
|
"create_document", "update_document", "edit_document",
|
|
"search_chats",
|
|
"chat_with_model", "create_session", "list_sessions",
|
|
"send_to_session",
|
|
"pipeline",
|
|
"manage_session", "manage_memory", "list_models",
|
|
"ui_control", "generate_image",
|
|
"manage_tasks", "api_call", "ask_teacher", "manage_skills",
|
|
"suggest_document",
|
|
"manage_endpoints", "manage_mcp", "manage_webhooks",
|
|
"manage_tokens", "manage_documents", "manage_settings",
|
|
"manage_notes", "manage_calendar",
|
|
"resolve_contact", "manage_contact", "list_email_accounts", "send_email", "list_emails",
|
|
"read_email", "reply_to_email", "bulk_email", "archive_email",
|
|
"delete_email", "mark_email_read",
|
|
# Cookbook tools (LLM serving + downloads). Without these
|
|
# entries, native function calls to e.g. list_served_models
|
|
# are rejected as "Unknown function call" before reaching
|
|
# the dispatcher — silent failure for the whole cookbook
|
|
# surface.
|
|
"download_model", "serve_model",
|
|
"list_served_models", "stop_served_model",
|
|
"list_downloads", "cancel_download",
|
|
"search_hf_models", "list_cached_models",
|
|
"list_serve_presets", "serve_preset", "adopt_served_model",
|
|
"list_cookbook_servers",
|
|
# Other tools the agent reaches for that were also missing.
|
|
"edit_image", "trigger_research", "manage_research",
|
|
# Generic loopback to any UI-button endpoint (cookbook,
|
|
# gallery, email folders, etc.) — agent uses this when
|
|
# there's no named tool wrapper for the action.
|
|
"app_api"}
|
|
|
|
ToolBlock = namedtuple("ToolBlock", ["tool_type", "content"])
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# MCP Manager (kept here — used by execution and agent_loop)
|
|
# ---------------------------------------------------------------------------
|
|
_mcp_manager = None
|
|
|
|
def set_mcp_manager(manager):
|
|
"""Set the global MCP manager instance."""
|
|
global _mcp_manager
|
|
_mcp_manager = manager
|
|
|
|
def get_mcp_manager():
|
|
"""Get the global MCP manager instance."""
|
|
return _mcp_manager
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# Helpers (kept here — used by sub-modules)
|
|
# ---------------------------------------------------------------------------
|
|
def _truncate(text: str, limit: int = MAX_OUTPUT_CHARS) -> str:
|
|
if len(text) > limit:
|
|
return text[:limit] + f"\n... (truncated, {len(text)} chars total)"
|
|
return text
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# Re-exports from sub-modules
|
|
# ---------------------------------------------------------------------------
|
|
|
|
# Parsing
|
|
from src.tool_parsing import ( # noqa: E402, F401
|
|
parse_tool_blocks,
|
|
strip_tool_blocks,
|
|
_TOOL_NAME_MAP,
|
|
_TOOL_BLOCK_RE,
|
|
_TOOL_CALL_RE,
|
|
_XML_TOOL_CALL_RE,
|
|
_XML_INVOKE_RE,
|
|
_XML_PARAM_RE,
|
|
)
|
|
|
|
# Schemas
|
|
from src.tool_schemas import ( # noqa: E402, F401
|
|
FUNCTION_TOOL_SCHEMAS,
|
|
function_call_to_tool_block,
|
|
)
|
|
|
|
# Execution
|
|
from src.tool_execution import ( # noqa: E402, F401
|
|
execute_tool_block,
|
|
format_tool_result,
|
|
)
|
|
|
|
# Implementations
|
|
from src.tool_implementations import ( # noqa: E402, F401
|
|
set_active_document,
|
|
set_active_model,
|
|
get_active_document,
|
|
do_create_document,
|
|
do_update_document,
|
|
do_edit_document,
|
|
do_suggest_document,
|
|
do_search_chats,
|
|
do_manage_skills,
|
|
do_manage_tasks,
|
|
do_manage_endpoints,
|
|
do_manage_mcp,
|
|
do_manage_webhooks,
|
|
do_manage_tokens,
|
|
do_manage_documents,
|
|
do_manage_settings,
|
|
do_api_call,
|
|
)
|