Skip to content

Runtime robustness: shell execution, safety policy, permission asks, MCP startup, and tool-call handling - #951

Merged
alcholiclg merged 55 commits into
modelscope:mainfrom
alcholiclg:fix/runtime-robustness
Aug 27, 2026
Merged

Runtime robustness: shell execution, safety policy, permission asks, MCP startup, and tool-call handling#951
alcholiclg merged 55 commits into
modelscope:mainfrom
alcholiclg:fix/runtime-robustness

Conversation

@alcholiclg

Copy link
Copy Markdown
Collaborator

Change Summary

  • Shell safety policy: quote-aware redirect parsing (fixes the false Create path outside allowed directories: /dev/null) block), heredoc bodies treated as code rather than paths, subshell/brace-group unwrapping, OS temp dir writable by default; real violations (writes outside allowed dirs, glob creates, variable-expansion targets) still refused
  • New ask categories: interpreter_exec for inline interpreter code (python3 -c, heredocs) — rememberable per project via "always allow"; sensitive_read for credential paths (~/.ssh/*, *.pem, …) — denied in auto mode, never rememberable, kept separate from the write-protection list so e.g. .git/config stays readable
  • Ask handling: interactive mode waits indefinitely; full-access times out after 25 min with feedback that marks it a timeout, not a refusal; public pending-ask APIs (is_awaiting / awaiting_request_ids / resolve_matching / cancel_pending) so front-ends stop reading private state
  • Shell executor: commands run verbatim in a non-login shell — python3 -V and python3 -V ; true no longer resolve different interpreters; agent-friendly environment (PAGER=cat, GIT_TERMINAL_PROMPT=0, NO_COLOR=1, …) injected unconditionally; tool description states no state persists between calls
  • MCP: parallel connects under per-server owner tasks (anyio-safe teardown), stdio startup timeout, per-server failure isolation; Pydantic union errors deduplicated with actionable guidance prepended
  • Tool calls: schema-driven coercion of string-typed numerics ("19.5" → 19.5), unique-prefix tool-name resolution with candidate suggestions on miss, read_file re-reads return content with an "unchanged" note instead of a stub
  • Prompting: the system prompt documents framework-managed directories (sessions/, .ms_agent/) so transcript matches are not mistaken for user content
  • Tests: 6 new test files + 2 extended; suite baseline unchanged (25 pre-existing env/network failures); verified end-to-end through the WebUI (approval flows, policy blocks, MCP coercion, PATH/env)

Related issue number

Checklist

  • The pull request title is a good summary of the changes - it will be used in the changelog
  • Unit tests for the changes exist
  • Run pre-commit install and pre-commit run --all-files before git commit, and passed lint check.
  • Documentation reflects the changes where applicable

The orchestrator now owns the write discipline around a backend:
- schedule_add() runs the extraction-LLM + embedding cost (seconds) in a
  background task; flush_pending() is the teardown barrier so the last
  write is never dropped, and an inline fallback keeps writes when no
  loop is running.
- retrieval/ingestion/flush serialize on one per-store asyncio lock
  (embedded qdrant underneath is lock-free single-client code).
- a content-hash delta ledger (<base_dir>/ingest_state.json) makes each
  ingest send only messages the store has not seen; hashes are recorded
  only after a confirmed write, so a failed ingest retries naturally.
- ingest_status reports the last outcome (state/count/error/pending) so
  a UI can show memory working instead of silence.

Mem0Backend: per-turn retrieval cache (rounds 2..N of a tool-calling
turn reuse round 1's search instead of paying an embedding round-trip
each), on_messages returns the event count and propagates failures --
the orchestrator is the swallow-and-report layer now and needs the
exception to keep failed messages un-marked for retry.
…-side close

- add_memory(add_after_step) now fires only when a round closes the turn
  (assistant reply with no tool calls) and dispatches through the
  backend's schedule_add when available: tool rounds are intermediate
  state, and ingesting every round cost O(rounds x history) extraction
  calls where the closing ingest covers the whole turn.
- an interrupted round advances the ingest ledger WITHOUT ingesting
  (mark_ingested): a half-finished answer is not durable conversational
  truth and must not be swept into the next turn's delta.
- cleanup_tools drains scheduled ingestion (flush only -- memory
  instances are shared across agents of one store, so closing here would
  yank the store from a sibling agent); the new
  SharedMemoryManager.close_matching(base_dir) is the owner-of-last-
  resort that actually closes instances and releases the embedded
  store's exclusive file lock.
The number of recalled memories injected per turn was hardcoded twice
(search default 20, then a [:10] formatting slice). MemoryConfig gains
recall_top_k (default 10, read from the unified_memory node) and the
mem0 adapter threads it through search and formatting — consumers can
now size recall to their context budget.
…E) instead of scattered config fields, gated by personalization.enabled.

When those files change mid-conversation the next user turn carries a durable <system-reminder> naming them, so the model can tell a changed file from its own faulty memory.
…end's MEMORY.md snapshot in step with edits made outside the agent.

Also translates the memory tool descriptions and prompt headings to English.
# Conflicts:
#	.gitignore
#	ms_agent/memory/unified/backends/mem0_adapter.py
#	ms_agent/memory/unified/orchestrator.py
#	setup.py
…ts last entry deleted, instead of leaving the previous round's block in place.
- an interrupt marks only its own round, and never messages a scheduled
  ingest still owns (both lost the write silently)
- one shared instance per store, not per model, reconfigured in place
- close() is terminal: a straggler can no longer reopen a released store
- the store lock is per (loop, path), and search() takes it too
- search() honours its limit; injected memories carry their date
- memories are written in the language the user used
# Conflicts:
#	ms_agent/memory/unified/backends/mem0_adapter.py
…ters

Thinking support is per-model with no naming rule, and an unsupported model may
reject the whole request (DashScope returns 400) instead of ignoring the flag.
So we ask, and on a refusal retry once with it off, remembering the model.
…orwards, and read OpenRouter's reasoning field
…o a vision-disabled model neither claims nor disowns them
…x/runtime-robustness

# Conflicts:
#	ms_agent/agent/llm_agent.py
#	ms_agent/memory/unified/backends/mem0_adapter.py
#	ms_agent/memory/unified/orchestrator.py
…hat arrive mid-stream

- images go out only when the model's own switch says so; a provider's declared
  vision capability no longer implies it
- a 400 delivered on the first streamed chunk is repaired like an eager one
- thinking refusals are repaired on the Anthropic and Responses paths too
- a tool call the model is still writing is reported instead of nothing at all
- an unreadable managed MCP config is logged instead of silently yielding none
… tell the agent why a search failed instead of reporting no results
…ps cutting structured results into invalid JSON
… and gate interpreter execution and credential reads behind mode-aware asks
… unique tool-name prefixes, and return content instead of a stub on unchanged re-reads
…io startup timeouts and per-server failure isolation
…ranscript matches are not mistaken for user content
@alcholiclg
alcholiclg merged commit a8ad587 into modelscope:main Aug 27, 2026
1 check was pending
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants