refactor(tools): wire file_operations to extracted common/lint/search modules; restore literal security pins in lazy_deps
This commit is contained in:
@@ -72,7 +72,7 @@ class TestFileToolIntegration:
|
||||
"""file_tools must catch the mirror path before creating DockerEnvironment."""
|
||||
|
||||
def test_guard_uses_current_docker_config_before_env_exists(self, monkeypatch):
|
||||
import tools.file_tools as file_tools
|
||||
import tools.file_tools_write_guards as file_tools
|
||||
|
||||
monkeypatch.setattr(
|
||||
file_tools,
|
||||
|
||||
@@ -30,8 +30,9 @@ class TestReadTrackerCaps:
|
||||
def test_read_history_capped(self, monkeypatch):
|
||||
"""read_history set is bounded by _READ_HISTORY_CAP."""
|
||||
from tools import file_tools as ft
|
||||
from tools import file_tools_read_tracking as rt
|
||||
|
||||
monkeypatch.setattr(ft, "_READ_HISTORY_CAP", 10)
|
||||
monkeypatch.setattr(rt, "_READ_HISTORY_CAP", 10)
|
||||
task_data = {
|
||||
"last_key": None,
|
||||
"consecutive": 0,
|
||||
@@ -46,10 +47,11 @@ class TestReadTrackerCaps:
|
||||
def test_live_cap_applied_after_read_add(self, tmp_path, monkeypatch):
|
||||
"""Live read_file path enforces caps."""
|
||||
from tools import file_tools as ft
|
||||
from tools import file_tools_read_tracking as rt
|
||||
|
||||
monkeypatch.setattr(ft, "_READ_HISTORY_CAP", 3)
|
||||
monkeypatch.setattr(ft, "_DEDUP_CAP", 3)
|
||||
monkeypatch.setattr(ft, "_READ_TIMESTAMPS_CAP", 3)
|
||||
monkeypatch.setattr(rt, "_READ_HISTORY_CAP", 3)
|
||||
monkeypatch.setattr(rt, "_DEDUP_CAP", 3)
|
||||
monkeypatch.setattr(rt, "_READ_TIMESTAMPS_CAP", 3)
|
||||
|
||||
# Create 10 distinct files and read each once.
|
||||
for i in range(10):
|
||||
|
||||
File diff suppressed because it is too large
Load Diff
@@ -308,7 +308,7 @@ class SearchMixin:
|
||||
existing, missing = [], []
|
||||
for p in parts:
|
||||
expanded = self._expand_path(p)
|
||||
(existing if self._path_exists(expanded) else missing).append(expanded)
|
||||
(existing if "exists" in self._path_exists_probe(expanded) else missing).append(expanded)
|
||||
if not existing:
|
||||
return None
|
||||
|
||||
|
||||
@@ -45,10 +45,10 @@ logger = logging.getLogger(__name__)
|
||||
|
||||
# Allowlist: "namespace.backend" -> pip specs matching the pyproject extra.
|
||||
# Pins are exact (no ranges, security posture); bump here AND in pyproject.
|
||||
# Shared patched floors (prior CVEs + GHSA-cq5v-8q36-5273/GHSA-mfx4-hv73-q22v/
|
||||
# GHSA-mq44-7p77-q5h7; CVE-2026-48710 BadHost) — keep in sync with pyproject.
|
||||
_AIOHTTP_PIN = "aiohttp==3.14.3"
|
||||
_STARLETTE_PIN = "starlette==1.3.1"
|
||||
# Shared patched floors, spelled out as literals in every feature because
|
||||
# tests/test_packaging_metadata.py checks them by AST: aiohttp==3.14.3 (prior
|
||||
# CVEs + GHSA-cq5v-8q36-5273/GHSA-mfx4-hv73-q22v/GHSA-mq44-7p77-q5h7) and
|
||||
# starlette==1.3.1 (CVE-2026-48710 BadHost) — keep in sync with pyproject.
|
||||
|
||||
LAZY_DEPS: dict[str, tuple[str, ...]] = {
|
||||
# ─── Inference providers ───────────────────────────────────────────────
|
||||
@@ -140,19 +140,19 @@ LAZY_DEPS: dict[str, tuple[str, ...]] = {
|
||||
"platform.discord": (
|
||||
"discord.py[voice]==2.7.1",
|
||||
"brotlicffi==1.2.0.1",
|
||||
_AIOHTTP_PIN,
|
||||
"aiohttp==3.14.3",
|
||||
),
|
||||
"platform.slack": (
|
||||
"slack-bolt==1.30.0",
|
||||
"slack-sdk==3.43.0",
|
||||
_AIOHTTP_PIN,
|
||||
"aiohttp==3.14.3",
|
||||
),
|
||||
"platform.matrix": (
|
||||
"mautrix[encryption]==0.21.1",
|
||||
"aiosqlite==0.22.1",
|
||||
"asyncpg==0.31.0",
|
||||
"aiohttp-socks==0.11.0",
|
||||
_AIOHTTP_PIN,
|
||||
"aiohttp==3.14.3",
|
||||
),
|
||||
"platform.dingtalk": (
|
||||
"dingtalk-stream==0.24.3",
|
||||
@@ -166,7 +166,7 @@ LAZY_DEPS: dict[str, tuple[str, ...]] = {
|
||||
# WeCom callback adapter parses untrusted XML POST bodies -> defusedxml.
|
||||
"platform.wecom_callback": ("defusedxml==0.7.1",),
|
||||
# Teams pulls a heavy tree (msal, dependency-injector); also the `teams` extra.
|
||||
"platform.teams": ("microsoft-teams-apps==2.0.13.4", _AIOHTTP_PIN),
|
||||
"platform.teams": ("microsoft-teams-apps==2.0.13.4", "aiohttp==3.14.3"),
|
||||
|
||||
# ─── Terminal backends ─────────────────────────────────────────────────
|
||||
"terminal.modal": ("modal==1.3.4",),
|
||||
@@ -191,7 +191,7 @@ LAZY_DEPS: dict[str, tuple[str, ...]] = {
|
||||
"tool.dashboard": (
|
||||
"fastapi==0.133.1",
|
||||
"uvicorn[standard]==0.41.0",
|
||||
_STARLETTE_PIN,
|
||||
"starlette==1.3.1",
|
||||
"python-multipart==0.0.32", # FastAPI UploadFile/Form streaming uploads
|
||||
),
|
||||
# Pillow and firecrawl-anydoc are CORE deps; these entries are the self-heal
|
||||
@@ -204,7 +204,7 @@ LAZY_DEPS: dict[str, tuple[str, ...]] = {
|
||||
"tool.computer_use": (
|
||||
"mcp==2.0.0",
|
||||
"httpx2==2.7.0", # mcp 2.x HTTP stack — sync with pyproject [computer-use]
|
||||
_STARLETTE_PIN,
|
||||
"starlette==1.3.1",
|
||||
),
|
||||
# huggingface-hub is SHARED with transformers (>=1.5.0,<2 via Hindsight) and
|
||||
# active_features() marks it active on mere presence, so `hermes update`
|
||||
|
||||
Reference in New Issue
Block a user