From 3254a55227435754c50b307836f61a75c062ab62 Mon Sep 17 00:00:00 2001 From: pewdiepie-archdaemon Date: Fri, 18 Sep 2026 14:36:09 +0000 Subject: [PATCH] fix workspace write path disclosure --- src/agent_tools/filesystem_tools.py | 7 +++++-- ...test_filesystem_tool_argument_validation.py | 18 ++++++++++++++++++ 2 files changed, 23 insertions(+), 2 deletions(-) diff --git a/src/agent_tools/filesystem_tools.py b/src/agent_tools/filesystem_tools.py index e0991ca7c..be0cd9f90 100644 --- a/src/agent_tools/filesystem_tools.py +++ b/src/agent_tools/filesystem_tools.py @@ -242,7 +242,7 @@ class ReadFileTool: class WriteFileTool: async def execute(self, content: str, ctx: dict) -> dict: - from src.tool_execution import _resolve_tool_path, _resolve_search_root, _truncate + from src.tool_execution import _display_tool_path, _resolve_tool_path, _resolve_search_root, _truncate lines = content.split("\n", 1) raw_path = lines[0].strip() body = lines[1] if len(lines) > 1 else "" @@ -339,7 +339,10 @@ class WriteFileTool: except OSError as e: return {"error": f"write_file: {path}: {e}", "exit_code": 1} diff = _unified_diff(old_content, body, path) - result = {"output": f"Wrote {size} bytes to {path}", "exit_code": 0} + result = { + "output": f"Wrote {size} bytes to {_display_tool_path(path)}", + "exit_code": 0, + } if diff: result["diff"] = diff return result diff --git a/tests/test_filesystem_tool_argument_validation.py b/tests/test_filesystem_tool_argument_validation.py index 0958d55a1..ee7848c02 100644 --- a/tests/test_filesystem_tool_argument_validation.py +++ b/tests/test_filesystem_tool_argument_validation.py @@ -94,6 +94,24 @@ async def test_write_file_still_rewrites_existing_text_file(tmp_path, monkeypatc assert target.read_text(encoding="utf-8") == "new" +@pytest.mark.asyncio +async def test_write_file_keeps_workspace_results_on_the_stable_virtual_path(tmp_path): + from src.tool_execution import _active_workspace + + token = _active_workspace.set(str(tmp_path)) + try: + result = await WriteFileTool().execute( + '{"path":"/workspace/results/report.txt","content":"done"}', {} + ) + finally: + _active_workspace.reset(token) + + assert result["exit_code"] == 0 + assert "/workspace/results/report.txt" in result["output"] + assert str(tmp_path) not in result["output"] + assert (tmp_path / "results" / "report.txt").read_text() == "done" + + @pytest.mark.asyncio async def test_write_file_unwraps_markdown_fence_for_html_artifact(tmp_path, monkeypatch): import src.tool_execution as tool_execution