Files
multica/server/pkg/agent/pi_test.go
Kagura 702c48209b fix(agent): stop filtering Pi extension tools via hardcoded --tools allowlist (#2379) (#2381)
The Pi backend hardcoded `--tools read,bash,edit,write,grep,find,ls` in
buildPiArgs. Pi's SDK treats --tools as a restrictive allowlist: only the
listed tools pass through `_refreshToolRegistry()`, silently filtering
out any user-installed extension tools registered via `pi.registerTool()`.

Omitting --tools makes Pi's `allowedToolNames` undefined, so the
`isAllowedTool()` filter becomes a no-op and all tools — built-in and
extension — are available. This matches Pi's standalone behavior.

Users who want to restrict tools can still pass --tools via custom_args
(it is not in piBlockedArgs).

Closes #2379
2026-05-11 16:11:32 +08:00

56 lines
1.7 KiB
Go

package agent
import (
"log/slog"
"strings"
"testing"
)
func TestBuildPiArgsNoToolAllowlist(t *testing.T) {
// Extension tools registered via Pi's registerTool() must not be
// filtered out by a hardcoded --tools allowlist. Omitting --tools
// lets Pi use its full tool registry. See #2379.
args := buildPiArgs("test prompt", "/tmp/session.jsonl", ExecOptions{}, slog.Default())
for i, arg := range args {
if arg == "--tools" {
t.Errorf("buildPiArgs emits --tools %q; should not restrict tool registry (see #2379)", args[i+1])
}
}
}
func TestBuildPiArgsBasicFlags(t *testing.T) {
args := buildPiArgs("hello world", "/tmp/s.jsonl", ExecOptions{
Model: "anthropic/claude-sonnet-4-20250514",
SystemPrompt: "be helpful",
}, slog.Default())
joined := strings.Join(args, " ")
for _, want := range []string{"-p", "--mode json", "--session /tmp/s.jsonl", "--provider anthropic", "--model claude-sonnet-4-20250514", "--append-system-prompt"} {
if !strings.Contains(joined, want) {
t.Errorf("expected %q in args, got: %v", want, args)
}
}
// Prompt must be the last positional argument.
if args[len(args)-1] != "hello world" {
t.Errorf("prompt should be last arg, got %q", args[len(args)-1])
}
}
func TestBuildPiArgsCustomArgsAppended(t *testing.T) {
// Users can still restrict tools via custom_args if desired.
args := buildPiArgs("prompt", "/tmp/s.jsonl", ExecOptions{
CustomArgs: []string{"--tools", "read,bash"},
}, slog.Default())
found := false
for i, arg := range args {
if arg == "--tools" && i+1 < len(args) && args[i+1] == "read,bash" {
found = true
}
}
if !found {
t.Errorf("custom --tools should pass through via custom_args, got: %v", args)
}
}