fix workspace write path disclosure

This commit is contained in:
pewdiepie-archdaemon
2026-09-18 14:36:09 +00:00
parent 9e505ef341
commit 3254a55227
2 changed files with 23 additions and 2 deletions
+5 -2
View File
@@ -242,7 +242,7 @@ class ReadFileTool:
class WriteFileTool:
async def execute(self, content: str, ctx: dict) -> dict:
from src.tool_execution import _resolve_tool_path, _resolve_search_root, _truncate
from src.tool_execution import _display_tool_path, _resolve_tool_path, _resolve_search_root, _truncate
lines = content.split("\n", 1)
raw_path = lines[0].strip()
body = lines[1] if len(lines) > 1 else ""
@@ -339,7 +339,10 @@ class WriteFileTool:
except OSError as e:
return {"error": f"write_file: {path}: {e}", "exit_code": 1}
diff = _unified_diff(old_content, body, path)
result = {"output": f"Wrote {size} bytes to {path}", "exit_code": 0}
result = {
"output": f"Wrote {size} bytes to {_display_tool_path(path)}",
"exit_code": 0,
}
if diff:
result["diff"] = diff
return result
@@ -94,6 +94,24 @@ async def test_write_file_still_rewrites_existing_text_file(tmp_path, monkeypatc
assert target.read_text(encoding="utf-8") == "new"
@pytest.mark.asyncio
async def test_write_file_keeps_workspace_results_on_the_stable_virtual_path(tmp_path):
from src.tool_execution import _active_workspace
token = _active_workspace.set(str(tmp_path))
try:
result = await WriteFileTool().execute(
'{"path":"/workspace/results/report.txt","content":"done"}', {}
)
finally:
_active_workspace.reset(token)
assert result["exit_code"] == 0
assert "/workspace/results/report.txt" in result["output"]
assert str(tmp_path) not in result["output"]
assert (tmp_path / "results" / "report.txt").read_text() == "done"
@pytest.mark.asyncio
async def test_write_file_unwraps_markdown_fence_for_html_artifact(tmp_path, monkeypatch):
import src.tool_execution as tool_execution