feat: direct tool invocation via /tool_name(arg=val) + wire Curry as real tools
Adds synapse/slash_commands.py: a chat message that's nothing but /tool_name(arg=val, arg=val) dispatches straight through tools.dispatch(), skipping model selection, RAG/playbook context assembly, and the ask-policy approval round-trip entirely. A human typing this IS the approval - there's no one else to ask - so it's a deliberate, reviewed bypass of the approval step specifically, not of anything a tool validates internally (path boundaries, size caps, Curry's own sandbox checks all still run). Argument values parse via ast.literal_eval only: strings/numbers/bools/None/literal containers, no names, no calls, no attribute access - a malformed or hostile-looking argument fails to parse rather than executing anything. Wired into chat_stream_endpoint (main.py) as an early short-circuit, before any of the RAG/model-selection work that a slash-command doesn't need. Web needed no changes (it already forwards raw text unchanged); the TUI previously swallowed every leading "/" locally and never reached the backend with it, so tui_app.py's _handle_slash now falls through to _start_chat for anything shaped like a tool call while still handling its own local meta-commands (/help, /model, /new, ...) exactly as before. Also finally wires Curry in as ten real tools (curry_declare_constant, curry_get_constant/_latest, curry_list_constants, curry_retire_constant, curry_declare_function, curry_get_function, curry_list_functions, curry_call_function, curry_retire_function) - deferred from the vendoring pass. The five write/execute ones are ACTION tools in the same always-ask-regardless-of-global-policy floor as edit_source (ALWAYS_ASK_ACTION_TOOLS, generalized in tools.py from the old self_edit-only ALWAYS_ASK_TOOLS so future tool families share one place to register into). curry_call_function is gated as an action for the same reason run_snippet is: it executes code, even sandboxed. Fixed a real bug surfaced while wiring this up: curry_db is a long-lived singleton holding one sqlite3 connection (unlike NexusOS's own memory store, which opens/closes a fresh connection per call specifically to dodge this), and sqlite3 forbids using a connection from a different thread than created it. That's a non-issue in production (uvicorn's single event-loop thread), but Starlette's TestClient runs the ASGI app through an anyio portal thread, so it broke immediately under test. Fixed at the source (curry_core.py, Curry.__init__) with check_same_thread=False, documented as a second deliberate vendoring deviation alongside the PR #4 sandbox fix - there was never real concurrent access here, just an overly strict same-thread assertion tripping on a thread-identity change with only one logical caller. Verified: 244 backend tests pass (18 new for the parser + endpoint wiring + curry tool registration, 4 new for the TUI passthrough); the 12 pre-existing C/C++/Rust toolchain failures are unrelated and unchanged. Confirmed by hand over the real HTTP endpoint: successful dispatch, zero tool_request events (approval bypass working as designed), a format()-dunder exploit attempt still rejected by the vendored sandbox fix even through the new tool registration, malformed arguments rejected before ever reaching dispatch, and an unknown tool name rejected cleanly. Wheel rebuilt and content-checked (bin/check.sh's gate now also asserts slash_commands.py ships). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -301,3 +301,86 @@ def test_interrupt_cancels_silent_stream_and_accepts_next_message(monkeypatch):
|
||||
|
||||
def test_escape_round_trip_helper():
|
||||
assert "[" in _escape("x[y]") or "\\[" in _escape("x[y]")
|
||||
|
||||
|
||||
def test_slash_tool_call_shape_forwards_to_start_chat(monkeypatch):
|
||||
"""/tool_name(arg=val) isn't a local meta-command — it must reach the
|
||||
backend (synapse/slash_commands.py + chat_stream_endpoint dispatch it),
|
||||
not fall into the generic 'unknown command' branch."""
|
||||
pytest.importorskip("textual")
|
||||
from nexusos_cli.tui_app import NexusTUI
|
||||
|
||||
app = NexusTUI.build_app(api_url="http://127.0.0.1:9")
|
||||
calls: list[str] = []
|
||||
monkeypatch.setattr(app, "_start_chat", lambda text: calls.append(text))
|
||||
|
||||
async def _run():
|
||||
async with app.run_test():
|
||||
text = '/curry_call_function(name="double", version=1, args={"x": 21})'
|
||||
app._handle_slash(text)
|
||||
assert calls == [text]
|
||||
log = app.query_one("#log")
|
||||
assert not any("unknown command" in line.text for line in log.lines)
|
||||
|
||||
asyncio.run(_run())
|
||||
|
||||
|
||||
def test_slash_malformed_tool_call_still_forwards_for_the_backend_error(monkeypatch):
|
||||
"""Even a malformed /tool(...) is forwarded rather than swallowed locally
|
||||
— the backend's parser gives a clearer, more specific error than the
|
||||
TUI's generic 'unknown command' would."""
|
||||
pytest.importorskip("textual")
|
||||
from nexusos_cli.tui_app import NexusTUI
|
||||
|
||||
app = NexusTUI.build_app(api_url="http://127.0.0.1:9")
|
||||
calls: list[str] = []
|
||||
monkeypatch.setattr(app, "_start_chat", lambda text: calls.append(text))
|
||||
|
||||
async def _run():
|
||||
async with app.run_test():
|
||||
text = "/curry_call_function(x=__import__('os'))"
|
||||
app._handle_slash(text)
|
||||
assert calls == [text]
|
||||
|
||||
asyncio.run(_run())
|
||||
|
||||
|
||||
def test_slash_local_meta_commands_still_handled_locally(monkeypatch):
|
||||
"""A known local command must still be handled in-TUI, never forwarded —
|
||||
the new tool-call passthrough is strictly the fallback branch."""
|
||||
pytest.importorskip("textual")
|
||||
from nexusos_cli.tui_app import NexusTUI
|
||||
|
||||
app = NexusTUI.build_app(api_url="http://127.0.0.1:9")
|
||||
calls: list[str] = []
|
||||
monkeypatch.setattr(app, "_start_chat", lambda text: calls.append(text))
|
||||
|
||||
async def _run():
|
||||
async with app.run_test():
|
||||
app._handle_slash("/help")
|
||||
assert calls == []
|
||||
log = app.query_one("#log")
|
||||
assert any("this list" in line.text for line in log.lines)
|
||||
|
||||
asyncio.run(_run())
|
||||
|
||||
|
||||
def test_slash_unknown_bare_command_still_rejected(monkeypatch):
|
||||
"""A genuinely unknown command (no parens, not a local command) keeps the
|
||||
existing 'unknown command' behavior rather than silently forwarding
|
||||
anything that starts with /."""
|
||||
pytest.importorskip("textual")
|
||||
from nexusos_cli.tui_app import NexusTUI
|
||||
|
||||
app = NexusTUI.build_app(api_url="http://127.0.0.1:9")
|
||||
calls: list[str] = []
|
||||
monkeypatch.setattr(app, "_start_chat", lambda text: calls.append(text))
|
||||
|
||||
async def _run():
|
||||
async with app.run_test():
|
||||
app._handle_slash("/frobnicate")
|
||||
assert calls == []
|
||||
log = app.query_one("#log")
|
||||
assert any("unknown command" in line.text for line in log.lines)
|
||||
|
||||
asyncio.run(_run())
|
||||
|
||||
Reference in New Issue
Block a user