mirror of
https://github.com/pewdiepie-archdaemon/odysseus.git
synced 2026-10-07 15:32:21 +02:00
merge: reconcile PR 40 with current lab
Integrate lab fff55a78 into PR #40 (cc25d5ba). Lab's modular email backend/frontend, modular settings, split stylesheets (static/style.css stays deleted), procfs compatibility, and request-scoped TurnContract authority win; PR #40's routing classifiers, editor/email/task features, and style.css changes are ported into lab's module and stylesheet homes. Integration fixes: - settings/api.js imports ui.js under its canonical versioned URL - browser observations keep legacy CAPTCHA/access-block evidence - artifact turns do not re-trigger broad-web research recovery - env reference documents PR test-tool variables; page regenerated PR #40 defects surfaced by lab gates and fixed here: - web_fetch generic schema drops top-level anyOf (OpenAI contract); the compact preview contract still requires url or urls - get_weather registered as a brokered network read - new lazy editor modules precached for offline use - SearXNG pin mirrored into GPU standalone compose files - image model picker again skips offline endpoints Tests updated where PR #40 changed behaviour on purpose, and PR tests moved onto lab's document_source helpers.
This commit is contained in:
@@ -231,6 +231,7 @@ def _wrap_workspace_namespace(
|
||||
cwd: str,
|
||||
*,
|
||||
chdir: str = "/workspace",
|
||||
interpreter_prefix: str | None = None,
|
||||
) -> str | None:
|
||||
"""Run a shell command with the active workspace mounted at /workspace.
|
||||
|
||||
@@ -254,8 +255,53 @@ def _wrap_workspace_namespace(
|
||||
"--dir", "/tmp", "--tmpfs", "/tmp",
|
||||
"--dev-bind", "/dev", "/dev", "--proc", "/proc",
|
||||
"--dir", "/workspace", "--bind", cwd, "/workspace",
|
||||
"--chdir", chdir, "/bin/bash", "-lc", content,
|
||||
]
|
||||
# setup-python installs interpreters under /opt, and local CI virtualenvs
|
||||
# can live under /tmp. Those paths are hidden by the private root/tmpfs.
|
||||
# Expose only the active interpreter environment, read-only, so Python
|
||||
# tools keep their installed packages without exposing the host /tmp.
|
||||
if interpreter_prefix:
|
||||
prefix = os.path.abspath(interpreter_prefix)
|
||||
resolved_prefix = os.path.realpath(prefix)
|
||||
mounted_roots = ("/usr", "/home", "/mnt")
|
||||
reserved_roots = {
|
||||
"/", "/tmp", "/var", "/opt", "/etc", "/workspace",
|
||||
"/root", "/run", "/proc", "/dev", "/sys", *mounted_roots,
|
||||
}
|
||||
already_visible = any(
|
||||
prefix == root or prefix.startswith(root + os.sep)
|
||||
for root in mounted_roots
|
||||
)
|
||||
# A prefix is trusted only when it names a specific interpreter tree.
|
||||
# In particular, never overlay the private root, tmpfs, or workspace
|
||||
# with a broad host directory. Reject symlinked prefixes too: bwrap
|
||||
# would otherwise bind the resolved source at a different destination.
|
||||
has_environment_layout = (
|
||||
os.path.isfile(os.path.join(prefix, "pyvenv.cfg"))
|
||||
or (
|
||||
os.path.isfile(os.path.join(prefix, "bin", "python"))
|
||||
and os.path.isdir(os.path.join(
|
||||
prefix, "lib", f"python{sys.version_info.major}.{sys.version_info.minor}",
|
||||
))
|
||||
)
|
||||
)
|
||||
if (
|
||||
not already_visible
|
||||
and prefix == resolved_prefix
|
||||
and prefix not in reserved_roots
|
||||
and len(prefix.split(os.sep)) >= 3
|
||||
and os.path.isdir(prefix)
|
||||
and has_environment_layout
|
||||
):
|
||||
parents = []
|
||||
parent = os.path.dirname(prefix)
|
||||
while parent not in ("/", "/tmp", "/etc", "/workspace", *mounted_roots):
|
||||
parents.append(parent)
|
||||
parent = os.path.dirname(parent)
|
||||
for directory in reversed(parents):
|
||||
args.extend(("--dir", directory))
|
||||
args.extend(("--ro-bind", prefix, prefix))
|
||||
args.extend(("--chdir", chdir, "/bin/bash", "-lc", content))
|
||||
return shlex.join(args)
|
||||
|
||||
|
||||
@@ -940,6 +986,7 @@ class PythonTool:
|
||||
python_command,
|
||||
agent_cwd(),
|
||||
chdir="/workspace",
|
||||
interpreter_prefix=sys.prefix,
|
||||
)
|
||||
if needs_virtual_namespace
|
||||
else None
|
||||
|
||||
@@ -18,6 +18,7 @@ import urllib.request
|
||||
from pathlib import Path
|
||||
from typing import Dict, Any
|
||||
|
||||
from core import platform_compat
|
||||
from src.constants import MAX_OUTPUT_CHARS
|
||||
|
||||
PDF_EXTRACT_MAX_BYTES = 80_000_000
|
||||
@@ -119,6 +120,47 @@ def _browser_pid_file_candidates(
|
||||
)
|
||||
return list(dict.fromkeys(candidates))
|
||||
|
||||
|
||||
# Linux exposes one command line per pid under /proc; macOS and Windows do not.
|
||||
# Kept as a module attribute so the procfs-dependent paths stay testable on a
|
||||
# host that has no procfs, and on one that does.
|
||||
|
||||
|
||||
def _process_command_line(pid: int) -> str | None:
|
||||
"""Command line of a running process, or ``None`` when it cannot be read.
|
||||
|
||||
``None`` means "this host cannot tell", not "the process is gone". Off
|
||||
Linux there is no procfs to read a command line from, so callers must not
|
||||
treat it as proof that the process exited.
|
||||
"""
|
||||
|
||||
try:
|
||||
return (platform_compat.PROC_ROOT / str(pid) / "cmdline").read_bytes().replace(
|
||||
b"\0", b" "
|
||||
).decode("utf-8", errors="replace")
|
||||
except (OSError, UnicodeError):
|
||||
return None
|
||||
|
||||
|
||||
def _process_is_alive(pid: int) -> bool:
|
||||
"""Whether a pid currently exists.
|
||||
|
||||
Delegates to ``core.platform_compat.pid_alive`` rather than probing with
|
||||
``os.kill(pid, 0)`` directly. That probe is POSIX-only: CPython's Windows
|
||||
``os.kill`` calls ``TerminateProcess(handle, sig)`` for any signal other
|
||||
than CTRL_C / CTRL_BREAK, so it would *kill* the daemon it is asked about.
|
||||
Windows is also where there is no procfs, which is precisely when this
|
||||
function gets called at all.
|
||||
|
||||
``pid_alive`` reads False for a pid that ``os.kill`` reports with
|
||||
``PermissionError`` — a live process owned by another user. Neither caller
|
||||
here wants a different answer: the sweep only unlinks a pid file it wrote
|
||||
itself, and treating somebody else's pid as "not our daemon" is the safe
|
||||
reading in both.
|
||||
"""
|
||||
|
||||
return platform_compat.pid_alive(pid)
|
||||
|
||||
_SCHOLARLY_METADATA_CUE_RE = re.compile(
|
||||
r"\b(?:accept(?:ed|ance)?|publish(?:ed|ing|cation)?|venue|conference|"
|
||||
r"journal|proceedings|doi)\b",
|
||||
@@ -2366,8 +2408,14 @@ class PrivateBrowserTool:
|
||||
except OSError:
|
||||
return
|
||||
profile_prefix = str(tmpdir / "agent-browser-chrome-")
|
||||
if not platform_compat.has_procfs():
|
||||
# Without procfs there is no way to match a reparented Chrome by
|
||||
# its command line, and the sweep is an optimisation rather than a
|
||||
# correctness requirement. Leave those trees to the daemon's own
|
||||
# lifecycle instead of failing the whole shutdown path.
|
||||
return
|
||||
pids: list[int] = []
|
||||
for entry in Path("/proc").iterdir():
|
||||
for entry in platform_compat.PROC_ROOT.iterdir():
|
||||
if not entry.name.isdigit():
|
||||
continue
|
||||
try:
|
||||
@@ -2397,16 +2445,18 @@ class PrivateBrowserTool:
|
||||
for pid_file in pid_files:
|
||||
try:
|
||||
pid = int(pid_file.read_text().strip())
|
||||
command_line = (Path("/proc") / str(pid) / "cmdline").read_bytes().replace(
|
||||
b"\0", b" "
|
||||
).decode("utf-8", errors="replace")
|
||||
except FileNotFoundError:
|
||||
# The daemon may have exited between writing its pid file and
|
||||
# this cleanup pass. The exact file is still ours to remove.
|
||||
with contextlib.suppress(FileNotFoundError, PermissionError, OSError):
|
||||
pid_file.unlink()
|
||||
except (OSError, ValueError):
|
||||
continue
|
||||
except (OSError, UnicodeError, ValueError):
|
||||
command_line = _process_command_line(pid)
|
||||
if command_line is None:
|
||||
# Either the daemon exited between writing its pid file and
|
||||
# this pass, or this host has no procfs to ask. Only the first
|
||||
# justifies forgetting the pid file. Without procfs we cannot
|
||||
# confirm the process is ours, so we neither kill it nor drop
|
||||
# the record that would let a later pass find it.
|
||||
if not _process_is_alive(pid):
|
||||
with contextlib.suppress(FileNotFoundError, PermissionError, OSError):
|
||||
pid_file.unlink()
|
||||
continue
|
||||
if "agent-browser" in command_line:
|
||||
with contextlib.suppress(ProcessLookupError, PermissionError, OSError):
|
||||
@@ -2433,10 +2483,17 @@ class PrivateBrowserTool:
|
||||
for pid_file in _browser_pid_file_candidates(runtime_dir, namespace, session_id):
|
||||
try:
|
||||
pid = int(pid_file.read_text().strip())
|
||||
command_line = (Path("/proc") / str(pid) / "cmdline").read_bytes().replace(
|
||||
b"\0", b" "
|
||||
).decode("utf-8", errors="replace")
|
||||
except (FileNotFoundError, OSError, UnicodeError, ValueError):
|
||||
except (OSError, ValueError):
|
||||
continue
|
||||
command_line = _process_command_line(pid)
|
||||
if command_line is None:
|
||||
# Without procfs we can only tell that something with this pid
|
||||
# is alive, not that it is agent-browser. The pid file is our
|
||||
# own namespaced one, so treat a live pid as a match: answering
|
||||
# "no daemon" here is what lets `close` bootstrap a fresh one
|
||||
# and wait on its browser forever.
|
||||
if _process_is_alive(pid):
|
||||
return True
|
||||
continue
|
||||
if "agent-browser" in command_line:
|
||||
return True
|
||||
|
||||
Reference in New Issue
Block a user