Files
LLeMbas/tests/test_tool_activity.py
T
Jaroslav Beneš 82a7ef5b58 Change part of a file without rewriting it
file_write replaces a file entirely, so a model wanting to change one line
either rewrote the whole thing from memory -- silently dropping everything it
did not happen to recall -- or shelled out to sed. file_edit takes a unified
diff instead, and services/agent/patch.py applies it.

Four behaviours carry that module, and each exists because of how models
actually write patches rather than how the format is specified.

Fuzzy offset, exact content. A hunk header is a hint: models count from a
truncated read or from the file as it was three edits ago and get the numbers
wrong, and get the context lines right. So the hinted position is tried, then
the file is scanned outward for an exact match of the context block. One match
wins; more than one refuses, because guessing between two identical blocks is
the one failure that silently corrupts a file.

Line endings are normalised in and restored out, or every hunk on a CRLF file
fails on context that looks identical in the error message. A blank context
line that lost its leading space is read as blank, because trailing whitespace
is stripped by half the things a model's output passes through. And nothing is
written unless every hunk applies: a half-applied file is worse than a refused
one, and the model cannot tell the difference without reading it again.

It refuses a file this reply has not read, in those words. A patch written from
memory either fails on context -- the good case -- or matches something it did
not mean. AgentContext.read_paths records what was read; it lives there because
runners never see a Generation and a read path is a fact about the machine, and
it is shared with the approved copy because as_approved is dataclasses.replace,
which copies field references. It resets each reply, and that is right rather
than a limitation: tool_calls_json is never replayed, so on the next turn the
model does not have the contents either.

Writes and edits both render a git-style diff in the transcript now, escaped
like everything else there and bounded at write time -- a generated file's diff
can be larger than the file, and it sits on the row forever. That costs
file_write one extra SFTP round trip to read the old contents, on the hottest
agent operation, and it is a conscious trade: it is the difference between
seeing what an agent did and having to go and look. It earns its keep twice,
because that read also counts as having read the file.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-03 11:05:36 +02:00

252 lines
8.6 KiB
Python

"""Rendering what a tool did.
The block is written from four places and read from stored rows written by
earlier versions, so it has to render anything shaped roughly like an event --
and everything in it is third-party text.
"""
from __future__ import annotations
import re
from pathlib import Path
from lembas.services import tool_labels
from lembas.services import tools as tools_service
from lembas.services.agent import tools as agent_tools
from lembas.web.templating import templates
def _render(*events, live: bool = False) -> str:
return templates.get_template("chat/_tool_activity.html").render(
{"tool_events": list(events), "live": live}
)
def test_a_search_still_says_it_searched_the_web():
html = _render(
{
"name": "web_search",
"kind": "search",
"query": "mallorn",
"status": "ok",
"results": [
{
"title": "Mallorn",
"url": "https://a.test/m",
"host": "a.test",
"snippet": "A tree.",
}
],
}
)
assert "Searched the web for “mallorn”" in html
assert '<a class="tool-result__title" href="https://a.test/m"' in html
assert "1 result" in html
def test_a_library_tool_no_longer_claims_to_have_searched_the_web():
"""Stored rows predate `kind`, and every one of them used to render a globe
and "Searched the web for <the note title>"."""
html = _render({"name": "notes_search", "query": "shopping", "status": "ok", "results": []})
assert "Searched the web" not in html
assert "Notes searched" in html
def test_a_custom_tool_is_named_and_its_host_shown():
html = _render(
{
"name": "weather",
"kind": "custom",
"label": "Weather",
"query": "city='Minas Tirith'",
"detail": "GET api.test",
"status": "ok",
"results": [],
"text": "Sunny.",
}
)
assert "Weather" in html
assert "GET api.test" in html
assert "Sunny." in html
def test_a_tools_own_text_is_escaped_and_never_rendered_as_markdown():
"""Hard rule 6. A tool's reply is exactly as untrusted as a search result,
and markdown is the one path allowed to emit HTML."""
html = _render(
{
"name": "weather",
"kind": "custom",
"label": "Weather",
"status": "ok",
"results": [],
"text": "<img src=x onerror=alert(1)> [click](javascript:alert(1))",
}
)
assert "<img" not in html
assert "&lt;img" in html
# The markdown link is shown as the text it is, not turned into an anchor.
assert "<a " not in html
assert "[click](javascript:alert(1))" in html
def test_a_result_url_that_is_not_http_never_becomes_a_link():
html = _render(
{
"name": "web_search",
"kind": "search",
"status": "ok",
"results": [{"title": "Bad", "url": "javascript:alert(1)", "host": "", "snippet": ""}],
}
)
assert "<a " not in html
assert '<span class="tool-result__title">Bad</span>' in html
def test_a_result_with_no_url_at_all_does_not_explode():
html = _render(
{
"name": "notes_search",
"status": "ok",
"results": [{"title": "A note", "id": "abc"}],
}
)
assert "A note" in html
def test_a_failure_shows_its_reason():
html = _render(
{
"name": "weather",
"kind": "custom",
"label": "Weather",
"status": "error",
"error": "HTTP 503",
"results": [],
}
)
assert "tool-activity--error" in html
assert "Weather failed" in html
assert "HTTP 503" in html
# --- What a tool is called -----------------------------------------------------
def test_a_stored_profile_name_no_longer_becomes_the_label():
"""The whole point of the inversion.
Every agent event written before today carries `label` set to the SSH
profile's name, so the transcript said "homeserver · ls -la" and named the
machine rather than the thing that was done. Those rows are on disk and are
re-rendered on every page load, so the fix has to reach them -- which means
the static table wins over the stored value, not the other way round.
"""
html = _render(
{
"name": "shell_run",
"kind": "agent",
"label": "homeserver",
"query": "ls -la",
"detail": "homeserver:/srv/app",
"status": "ok",
"results": [],
}
)
summary = html.split("</summary>")[0]
assert "Bash" in summary
assert "homeserver" not in summary
# It is still shown, in the body, where "where this ran" belongs.
assert "homeserver:/srv/app" in html
def test_a_custom_tools_own_label_still_wins():
"""The other half of the same rule. A row-backed tool's name is per row and
cannot be tabulated, so nothing in the table shadows it."""
html = _render({"name": "weather", "kind": "custom", "label": "Weather", "results": []})
assert "Weather" in html
def test_every_builtin_and_agent_tool_has_a_label_and_an_icon():
"""A property, not markup. A tool added without an entry renders its own
function name at somebody, which is the state this replaced."""
names = [tool.name for tool in tools_service.REGISTRY.values()]
names += [tool.name for tool in agent_tools.tool_defs()]
# plan_submit is filtered out of tool_defs() outside Plan mode.
names.append("plan_submit")
missing = [name for name in names if name not in tool_labels.LABELS]
assert not missing, f"no label for {missing}"
missing = [name for name in names if name not in tool_labels.ICONS]
assert not missing, f"no icon for {missing}"
def test_every_icon_named_exists_in_the_sprite():
"""A typo'd symbol id renders an empty box and says nothing. This is the
only thing that catches it."""
sprite = Path(tools_service.__file__).parents[1] / "web/templates/partials/icons.html"
available = set(re.findall(r'id="i-([a-z-]+)"', sprite.read_text()))
wanted = set(tool_labels.ICONS.values()) | set(tool_labels.KIND_ICONS.values())
wanted.add(tool_labels.FALLBACK_ICON)
assert wanted <= available, f"not in the sprite: {sorted(wanted - available)}"
def test_an_unknown_tool_falls_back_to_its_name():
assert tool_labels.label_for({"name": "mcp_thing"}) == "mcp_thing"
assert tool_labels.icon_for({"name": "mcp_thing", "kind": "mcp"}) == "server"
assert tool_labels.icon_for({"name": "whatever"}) == tool_labels.FALLBACK_ICON
# --- Diffs -----------------------------------------------------------------------
def test_a_diff_renders_added_and_removed_lines():
html = _render(
{
"name": "file_edit",
"kind": "agent",
"query": "src/app.py",
"status": "ok",
"results": [],
"diff": "--- a/src/app.py\n+++ b/src/app.py\n@@ -1,2 +1,2 @@\n alpha\n-beta\n+BETA",
}
)
assert 'diff__line--del">-beta</span>' in html
assert 'diff__line--add">+BETA</span>' in html
assert 'diff__line--ctx"> alpha</span>' in html
assert 'diff__line--meta">@@ -1,2 +1,2 @@</span>' in html
def test_a_diff_header_is_not_an_addition():
"""`+++ b/x` at the top of every diff would otherwise render green, and
`--- a/x` red, which reads as the file being replaced by itself."""
html = _render(
{
"name": "file_edit",
"results": [],
"diff": "--- a/x.py\n+++ b/x.py\n@@ -1 +1 @@\n-a\n+b",
}
)
assert 'diff__line--meta">--- a/x.py</span>' in html
assert 'diff__line--meta">+++ b/x.py</span>' in html
def test_a_removed_line_of_dashes_is_still_a_removal():
"""A removed line whose own text begins with `--` produces exactly three
dashes, which is why the header test is against the a/ and b/ prefixes."""
html = _render({"name": "file_edit", "results": [], "diff": "@@ -1 +1 @@\n--- a dashed line"})
assert 'diff__line--del">--- a dashed line</span>' in html
def test_a_diff_line_is_escaped():
"""Hard rule 6. It is a file off somebody else's machine."""
html = _render(
{
"name": "file_edit",
"results": [],
"diff": "@@ -1 +1 @@\n+<script>alert(1)</script>",
}
)
assert "<script>" not in html
assert "&lt;script&gt;" in html
def test_an_event_with_no_diff_renders_none():
html = _render({"name": "file_read", "results": [], "text": "hello"})
assert "diff__line" not in html