refactor(tools): wire file_operations to extracted common/lint/search modules; restore literal security pins in lazy_deps

This commit is contained in:
Teknium
2026-09-02 10:06:41 -07:00
parent 14a64ea985
commit ec49ae7c0f
5 changed files with 76 additions and 1811 deletions

View File

@@ -72,7 +72,7 @@ class TestFileToolIntegration:
"""file_tools must catch the mirror path before creating DockerEnvironment."""
def test_guard_uses_current_docker_config_before_env_exists(self, monkeypatch):
import tools.file_tools as file_tools
import tools.file_tools_write_guards as file_tools
monkeypatch.setattr(
file_tools,

View File

@@ -30,8 +30,9 @@ class TestReadTrackerCaps:
def test_read_history_capped(self, monkeypatch):
"""read_history set is bounded by _READ_HISTORY_CAP."""
from tools import file_tools as ft
from tools import file_tools_read_tracking as rt
monkeypatch.setattr(ft, "_READ_HISTORY_CAP", 10)
monkeypatch.setattr(rt, "_READ_HISTORY_CAP", 10)
task_data = {
"last_key": None,
"consecutive": 0,
@@ -46,10 +47,11 @@ class TestReadTrackerCaps:
def test_live_cap_applied_after_read_add(self, tmp_path, monkeypatch):
"""Live read_file path enforces caps."""
from tools import file_tools as ft
from tools import file_tools_read_tracking as rt
monkeypatch.setattr(ft, "_READ_HISTORY_CAP", 3)
monkeypatch.setattr(ft, "_DEDUP_CAP", 3)
monkeypatch.setattr(ft, "_READ_TIMESTAMPS_CAP", 3)
monkeypatch.setattr(rt, "_READ_HISTORY_CAP", 3)
monkeypatch.setattr(rt, "_DEDUP_CAP", 3)
monkeypatch.setattr(rt, "_READ_TIMESTAMPS_CAP", 3)
# Create 10 distinct files and read each once.
for i in range(10):

File diff suppressed because it is too large Load Diff

View File

@@ -308,7 +308,7 @@ class SearchMixin:
existing, missing = [], []
for p in parts:
expanded = self._expand_path(p)
(existing if self._path_exists(expanded) else missing).append(expanded)
(existing if "exists" in self._path_exists_probe(expanded) else missing).append(expanded)
if not existing:
return None

View File

@@ -45,10 +45,10 @@ logger = logging.getLogger(__name__)
# Allowlist: "namespace.backend" -> pip specs matching the pyproject extra.
# Pins are exact (no ranges, security posture); bump here AND in pyproject.
# Shared patched floors (prior CVEs + GHSA-cq5v-8q36-5273/GHSA-mfx4-hv73-q22v/
# GHSA-mq44-7p77-q5h7; CVE-2026-48710 BadHost) — keep in sync with pyproject.
_AIOHTTP_PIN = "aiohttp==3.14.3"
_STARLETTE_PIN = "starlette==1.3.1"
# Shared patched floors, spelled out as literals in every feature because
# tests/test_packaging_metadata.py checks them by AST: aiohttp==3.14.3 (prior
# CVEs + GHSA-cq5v-8q36-5273/GHSA-mfx4-hv73-q22v/GHSA-mq44-7p77-q5h7) and
# starlette==1.3.1 (CVE-2026-48710 BadHost) — keep in sync with pyproject.
LAZY_DEPS: dict[str, tuple[str, ...]] = {
# ─── Inference providers ───────────────────────────────────────────────
@@ -140,19 +140,19 @@ LAZY_DEPS: dict[str, tuple[str, ...]] = {
"platform.discord": (
"discord.py[voice]==2.7.1",
"brotlicffi==1.2.0.1",
_AIOHTTP_PIN,
"aiohttp==3.14.3",
),
"platform.slack": (
"slack-bolt==1.30.0",
"slack-sdk==3.43.0",
_AIOHTTP_PIN,
"aiohttp==3.14.3",
),
"platform.matrix": (
"mautrix[encryption]==0.21.1",
"aiosqlite==0.22.1",
"asyncpg==0.31.0",
"aiohttp-socks==0.11.0",
_AIOHTTP_PIN,
"aiohttp==3.14.3",
),
"platform.dingtalk": (
"dingtalk-stream==0.24.3",
@@ -166,7 +166,7 @@ LAZY_DEPS: dict[str, tuple[str, ...]] = {
# WeCom callback adapter parses untrusted XML POST bodies -> defusedxml.
"platform.wecom_callback": ("defusedxml==0.7.1",),
# Teams pulls a heavy tree (msal, dependency-injector); also the `teams` extra.
"platform.teams": ("microsoft-teams-apps==2.0.13.4", _AIOHTTP_PIN),
"platform.teams": ("microsoft-teams-apps==2.0.13.4", "aiohttp==3.14.3"),
# ─── Terminal backends ─────────────────────────────────────────────────
"terminal.modal": ("modal==1.3.4",),
@@ -191,7 +191,7 @@ LAZY_DEPS: dict[str, tuple[str, ...]] = {
"tool.dashboard": (
"fastapi==0.133.1",
"uvicorn[standard]==0.41.0",
_STARLETTE_PIN,
"starlette==1.3.1",
"python-multipart==0.0.32", # FastAPI UploadFile/Form streaming uploads
),
# Pillow and firecrawl-anydoc are CORE deps; these entries are the self-heal
@@ -204,7 +204,7 @@ LAZY_DEPS: dict[str, tuple[str, ...]] = {
"tool.computer_use": (
"mcp==2.0.0",
"httpx2==2.7.0", # mcp 2.x HTTP stack — sync with pyproject [computer-use]
_STARLETTE_PIN,
"starlette==1.3.1",
),
# huggingface-hub is SHARED with transformers (>=1.5.0,<2 via Hindsight) and
# active_features() marks it active on mere presence, so `hermes update`