mirror of
https://github.com/garrytan/gbrain.git
synced 2026-08-16 09:52:22 +00:00
Compare commits
2
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
76589d3ddc | ||
|
|
d6b0253c59 |
@@ -223,16 +223,14 @@ export GBRAIN_REMOTE_CLIENT_ID=<Alice's client_id>
|
||||
export GBRAIN_REMOTE_CLIENT_SECRET=<Alice's client_secret>
|
||||
export GBRAIN_REMOTE_MCP_URL=https://brain.acme-co.com/mcp
|
||||
|
||||
gbrain search "performance review"
|
||||
gbrain search "performance review" --remote
|
||||
```
|
||||
|
||||
(On a thin-client install every shared op routes through the remote MCP server automatically — no flag needed. The env vars select whose credentials the call uses.)
|
||||
|
||||
Alice should see results only from `customers` and `shared`. The performance-review notes live in `internal`, which she's not scoped to read. She shouldn't see them.
|
||||
|
||||
```bash
|
||||
# Terminal 2, as Bob (export his credentials similarly)
|
||||
gbrain search "performance review"
|
||||
gbrain search "performance review" --remote
|
||||
```
|
||||
|
||||
Bob should see the performance-review notes from `internal`, plus anything related from `shared`. He shouldn't see anything that lives only in `customers`.
|
||||
@@ -516,7 +514,7 @@ The first sync embeds every page, which takes time. Check `gbrain sources status
|
||||
|
||||
### "I see a page I shouldn't see"
|
||||
|
||||
This shouldn't happen, but if you suspect it, run `gbrain search <query> --json` as the constrained client (thin-client install, with the client's `GBRAIN_REMOTE_*` env exported) and inspect the `source_id` field on every returned result. Every row should be in the client's `--federated-read` set. If one isn't, file an issue with the exact slug and source IDs.
|
||||
This shouldn't happen, but if you suspect it, run `gbrain search <query> --remote --json` as the constrained client and inspect the `source_id` field on every returned result. Every row should be in the client's `--federated-read` set. If one isn't, file an issue with the exact slug and source IDs.
|
||||
|
||||
### "The synthesized answer is wrong"
|
||||
|
||||
|
||||
+5
-84
@@ -464,11 +464,7 @@ async function main() {
|
||||
// routed path. Date → ISO string; bigint → string (postgres.js shape);
|
||||
// Buffer → object. Microsecond-cost; eliminates a whole drift bug class.
|
||||
const result = JSON.parse(JSON.stringify(rawResult, bigintToStringReplacer));
|
||||
// #380 pass-through: `--json` (undeclared on most ops, promised by docs)
|
||||
// emits the raw op result instead of the human formatter.
|
||||
const output = params.json === true
|
||||
? JSON.stringify(result, null, 2) + '\n'
|
||||
: formatResult(op.name, result);
|
||||
const output = formatResult(op.name, result);
|
||||
if (output) process.stdout.write(output);
|
||||
} catch (e: unknown) {
|
||||
// v0.42.20.0 (codex D4): on error, set exitCode + return so the `finally`
|
||||
@@ -551,10 +547,7 @@ async function runThinClientRouted(
|
||||
signal: sigintController.signal,
|
||||
});
|
||||
const result = unpackToolResult(raw);
|
||||
// #380: same --json seam as the local-engine path (renderer parity).
|
||||
const output = params.json === true
|
||||
? JSON.stringify(result, null, 2) + '\n'
|
||||
: formatResult(op.name, result);
|
||||
const output = formatResult(op.name, result);
|
||||
if (output) process.stdout.write(output);
|
||||
} catch (e: unknown) {
|
||||
if (e instanceof RemoteMcpError) {
|
||||
@@ -764,28 +757,10 @@ export function resolveQueryImage(
|
||||
return { path: imagePath, base64, mime };
|
||||
}
|
||||
|
||||
/**
|
||||
* #380: undeclared flags that are honored DOWNSTREAM of parseOpArgs and must
|
||||
* keep passing through when unknown flags become hard errors:
|
||||
* - source → makeContext's resolveSourceId (the --source axis)
|
||||
* - brain → the mount/brain routing axis (docs promise the flag)
|
||||
* - dry_run → makeContext's ctx.dryRun (ops without a declared dry_run)
|
||||
* - json → raw-JSON output seam (local + thin-client paths)
|
||||
*/
|
||||
const PASSTHROUGH_VALUE_FLAGS = new Set(['source', 'brain']);
|
||||
const PASSTHROUGH_BOOL_FLAGS = new Set(['dry_run', 'json']);
|
||||
|
||||
export function parseOpArgs(op: Operation, args: string[]): Record<string, unknown> {
|
||||
const params: Record<string, unknown> = {};
|
||||
const positional = op.cliHints?.positional || [];
|
||||
let posIdx = 0;
|
||||
const cliName = op.cliHints?.name || op.name;
|
||||
const MAX_STDIN = 5_000_000; // 5MB cap, shared by stdin and --file
|
||||
// #380: `--file <path>` fills the op's declared stdin param (put's `content`)
|
||||
// from a file. Driven by cliHints.stdin — no per-op hard-coding — and
|
||||
// disabled when the op declares a real `file` param of its own.
|
||||
const fileParam = op.cliHints?.stdin && !op.params.file ? op.cliHints.stdin : undefined;
|
||||
let filePath: string | undefined;
|
||||
|
||||
for (let i = 0; i < args.length; i++) {
|
||||
const arg = args[i];
|
||||
@@ -799,42 +774,12 @@ export function parseOpArgs(op: Operation, args: string[]): Record<string, unkno
|
||||
}
|
||||
}
|
||||
const key = arg.slice(2).replace(/-/g, '_');
|
||||
if (fileParam && key === 'file') {
|
||||
if (i + 1 >= args.length) {
|
||||
console.error(`Error: ${arg} requires a value.`);
|
||||
process.exit(1);
|
||||
}
|
||||
filePath = args[++i];
|
||||
continue;
|
||||
}
|
||||
const paramDef = op.params[key];
|
||||
if (!paramDef) {
|
||||
if (PASSTHROUGH_BOOL_FLAGS.has(key)) {
|
||||
params[key] = true;
|
||||
continue;
|
||||
}
|
||||
if (PASSTHROUGH_VALUE_FLAGS.has(key)) {
|
||||
if (i + 1 >= args.length) {
|
||||
console.error(`Error: ${arg} requires a value.`);
|
||||
process.exit(1);
|
||||
}
|
||||
params[key] = args[++i];
|
||||
continue;
|
||||
}
|
||||
// #380: unknown flags were silently swallowed into params, so typos
|
||||
// like `put --file` created empty pages instead of erroring.
|
||||
console.error(`Unknown option for gbrain ${cliName}: ${arg}`);
|
||||
console.error(`Run 'gbrain ${cliName} --help' for valid flags.`);
|
||||
process.exit(1);
|
||||
}
|
||||
if (paramDef.type === 'boolean') {
|
||||
if (paramDef?.type === 'boolean') {
|
||||
params[key] = true;
|
||||
} else if (i + 1 < args.length) {
|
||||
params[key] = args[++i];
|
||||
if (paramDef.type === 'number') params[key] = Number(params[key]);
|
||||
} else {
|
||||
console.error(`Error: ${arg} requires a value.`);
|
||||
process.exit(1);
|
||||
if (paramDef?.type === 'number') params[key] = Number(params[key]);
|
||||
}
|
||||
} else if (posIdx < positional.length) {
|
||||
const key = positional[posIdx++];
|
||||
@@ -843,30 +788,10 @@ export function parseOpArgs(op: Operation, args: string[]): Record<string, unkno
|
||||
}
|
||||
}
|
||||
|
||||
// #380: resolve --file AFTER the loop so --file/--content conflicts are
|
||||
// caught in either order.
|
||||
if (filePath !== undefined && fileParam) {
|
||||
if (params[fileParam] !== undefined) {
|
||||
console.error(`Error: use only one of --file, --${fileParam}, or stdin for gbrain ${cliName}.`);
|
||||
process.exit(1);
|
||||
}
|
||||
let fileContent: string;
|
||||
try {
|
||||
fileContent = readFileSync(filePath, 'utf-8');
|
||||
} catch (e) {
|
||||
console.error(`Error: cannot read --file ${filePath}: ${e instanceof Error ? e.message : String(e)}`);
|
||||
process.exit(1);
|
||||
}
|
||||
if (Buffer.byteLength(fileContent, 'utf-8') > MAX_STDIN) {
|
||||
console.error(`Error: file content exceeds ${MAX_STDIN} bytes. Split into smaller inputs.`);
|
||||
process.exit(1);
|
||||
}
|
||||
params[fileParam] = fileContent;
|
||||
}
|
||||
|
||||
// Read stdin for content params
|
||||
if (op.cliHints?.stdin && !params[op.cliHints.stdin] && !process.stdin.isTTY) {
|
||||
const stdinContent = readFileSync(0, 'utf-8');
|
||||
const MAX_STDIN = 5_000_000; // 5MB
|
||||
if (Buffer.byteLength(stdinContent, 'utf-8') > MAX_STDIN) {
|
||||
console.error(`Error: stdin content exceeds ${MAX_STDIN} bytes. Split into smaller inputs.`);
|
||||
process.exit(1);
|
||||
@@ -2328,10 +2253,6 @@ export function printOpHelp(op: Operation, invokedName?: string) {
|
||||
const prefix = isPos ? ` <${key}>` : ` --${key.replace(/_/g, '-')}`;
|
||||
console.log(`${prefix.padEnd(28)} ${def.description || ''}${req}`);
|
||||
}
|
||||
// #380: ops that read stdin also accept --file <path> (parseOpArgs).
|
||||
if (op.cliHints?.stdin && !op.params.file) {
|
||||
console.log(`${' --file <path>'.padEnd(28)} Read ${op.cliHints.stdin} from a file (alternative to --${op.cliHints.stdin} or stdin)`);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
@@ -908,6 +908,10 @@ export const KNOWN_CONFIG_KEYS: readonly string[] = [
|
||||
'facts.extraction_model',
|
||||
// #2113: output-token cap for the per-turn facts extractor (default 4000).
|
||||
'facts.extraction_max_tokens',
|
||||
// Owner opt-in: let the local stdio MCP pipe read this owner's private facts
|
||||
// (find_trajectory / recall). Default off; HTTP transport ignores it. See
|
||||
// src/core/facts/reader-trust.ts.
|
||||
'facts.trust_local_reads',
|
||||
// Dream cycle config
|
||||
'dream.synthesize.session_corpus_dir',
|
||||
'dream.synthesize.meeting_transcripts_dir',
|
||||
|
||||
@@ -591,6 +591,8 @@ export interface TrajectoryOpts {
|
||||
sourceIds?: string[];
|
||||
/** When true, filters to visibility='world' only. Set by MCP layer from ctx.remote. */
|
||||
remote?: boolean;
|
||||
/** Owner opt-in: read private facts despite `remote`. See facts/reader-trust.ts. */
|
||||
trustedFactReads?: boolean;
|
||||
/** Metric filter. When set, only facts with this canonical metric label participate. */
|
||||
metric?: string;
|
||||
/**
|
||||
|
||||
@@ -17,6 +17,7 @@
|
||||
import type { OperationContext } from './../operations.ts';
|
||||
import type { FactRow } from './../engine.ts';
|
||||
import { effectiveConfidence } from './decay.ts';
|
||||
import { readableFactVisibilities } from './reader-trust.ts';
|
||||
|
||||
const DEFAULT_TTL_MS = 30_000;
|
||||
const DEFAULT_TOP_K = 10;
|
||||
@@ -50,7 +51,13 @@ export async function getBrainHotMemoryMeta(
|
||||
const sessionId = (ctx as { source_session?: string }).source_session
|
||||
?? null;
|
||||
const allowListHash = hashAllowList(ctx.takesHoldersAllowList);
|
||||
const cacheKey = `${sourceId}::${sessionId ?? '_'}::${allowListHash}`;
|
||||
// Visibility tier: untrusted remote → world-only; trusted local +
|
||||
// owner-trusted reads → all rows. Folded into the cache key (the header's
|
||||
// "cache entries don't bleed across tiers" invariant): trustedFactReads is
|
||||
// re-read from config per call, so a mid-session opt-out must not keep
|
||||
// serving a private-inclusive cached payload for the TTL window.
|
||||
const visibility = readableFactVisibilities(ctx);
|
||||
const cacheKey = `${sourceId}::${sessionId ?? '_'}::${allowListHash}::${visibility ? 'world' : 'all'}`;
|
||||
|
||||
const ttl = Math.max(1000, opts.ttlMs ?? DEFAULT_TTL_MS);
|
||||
const topK = Math.max(1, Math.min(opts.topK ?? DEFAULT_TOP_K, 25));
|
||||
@@ -61,10 +68,6 @@ export async function getBrainHotMemoryMeta(
|
||||
return cached.payload;
|
||||
}
|
||||
|
||||
// Build a fresh payload. Visibility tier: remote → world-only;
|
||||
// local → all rows.
|
||||
const visibility = ctx.remote === false ? undefined : ['world'] as ('world' | 'private')[];
|
||||
|
||||
let rows: FactRow[] = [];
|
||||
if (sessionId) {
|
||||
rows = await ctx.engine.listFactsBySession(sourceId, sessionId, {
|
||||
|
||||
@@ -0,0 +1,48 @@
|
||||
/**
|
||||
* Fact-read visibility trust.
|
||||
*
|
||||
* Fact rows are tagged `private` | `world`. Remote/untrusted callers
|
||||
* (`remote === true`) see only `world` rows — the posture that keeps a
|
||||
* published or HTTP-served brain from leaking private claims to strangers.
|
||||
*
|
||||
* But the stdio MCP server is an unauthenticated LOCAL pipe: on a single-owner
|
||||
* machine the caller IS the owner, yet it still defaults `remote: true` for
|
||||
* safety, so the owner's own agent is denied the owner's own private facts
|
||||
* (e.g. `find_trajectory` returns empty over MCP even though the facts exist).
|
||||
*
|
||||
* `trustedFactReads` is a narrow, READ-ONLY trust elevation, deliberately
|
||||
* DECOUPLED from `remote` so every other remote protection — file_upload
|
||||
* confinement, source isolation, fence stripping, takes-holder scoping — stays
|
||||
* fully in force. The stdio MCP server sets it ONLY when the brain owner opts
|
||||
* in via the `facts.trust_local_reads` config (default off). The HTTP/published
|
||||
* transport never sets it, so a served brain stays world-only regardless.
|
||||
*/
|
||||
export interface FactReaderTrust {
|
||||
/**
|
||||
* Mirrors OperationContext.remote. FAIL-CLOSED: anything not strictly
|
||||
* `false` is treated as remote/untrusted (CLAUDE.md trust invariant).
|
||||
*/
|
||||
remote?: boolean;
|
||||
/** Owner opt-in: this remote caller may read private facts. */
|
||||
trustedFactReads?: boolean;
|
||||
}
|
||||
|
||||
/**
|
||||
* True when the reader is restricted to `visibility = 'world'` rows.
|
||||
* Fail-closed: an unset/undefined `remote` is untrusted — only an explicit
|
||||
* `remote: false` (trusted local CLI) or an explicit owner opt-in
|
||||
* (`trustedFactReads: true`) reads private rows.
|
||||
*/
|
||||
export function factsWorldOnly(t: FactReaderTrust): boolean {
|
||||
return t.remote !== false && t.trustedFactReads !== true;
|
||||
}
|
||||
|
||||
/**
|
||||
* Visibility filter for list-style fact reads: `['world']` when the reader is
|
||||
* world-only, `undefined` (no filter — all rows) when it is trusted.
|
||||
*/
|
||||
export function readableFactVisibilities(
|
||||
t: FactReaderTrust,
|
||||
): ('private' | 'world')[] | undefined {
|
||||
return factsWorldOnly(t) ? ['world'] : undefined;
|
||||
}
|
||||
+16
-16
@@ -18,6 +18,7 @@ import { captureEvalCandidate, isEvalCaptureEnabled, isEvalScrubEnabled } from '
|
||||
import type { HybridSearchMeta } from './types.ts';
|
||||
import { extractPageLinks, isAutoLinkEnabled, isAutoTimelineEnabled, isGlobalBasenameEnabled, parseTimelineEntries, makeResolver, type UnresolvedFrontmatterRef } from './link-extraction.ts';
|
||||
import { isFactsBackstopEligible } from './facts/eligibility.ts';
|
||||
import { readableFactVisibilities } from './facts/reader-trust.ts';
|
||||
import { stripTakesFence } from './takes-fence.ts';
|
||||
import { stripFactsFence } from './facts-fence.ts';
|
||||
import { getContentFlag } from './quarantine.ts';
|
||||
@@ -332,6 +333,15 @@ export interface OperationContext {
|
||||
* remote/untrusted (defense in depth in case the type is bypassed via cast).
|
||||
*/
|
||||
remote: boolean;
|
||||
/**
|
||||
* Owner opt-in (`facts.trust_local_reads`): allow this remote caller to read
|
||||
* `private` facts. A NARROW, read-only trust elevation decoupled from
|
||||
* `remote` — every other remote protection (file confinement, source
|
||||
* isolation, fence stripping, takes scoping) stays in force. Set ONLY by the
|
||||
* stdio MCP server when the config is on; the HTTP transport never sets it.
|
||||
* Consulted via `src/core/facts/reader-trust.ts`.
|
||||
*/
|
||||
trustedFactReads?: boolean;
|
||||
/**
|
||||
* Subagent runtime context (v0.16+). Set by the subagent tool dispatcher when
|
||||
* dispatching an op as a tool call from an LLM loop. Used to enforce per-op
|
||||
@@ -769,7 +779,7 @@ const get_page: Operation = {
|
||||
|
||||
const put_page: Operation = {
|
||||
name: 'put_page',
|
||||
description: 'Write/update a page (markdown with frontmatter). Chunks, embeds, reconciles tags, and (when auto_link/auto_timeline are enabled) extracts + reconciles graph links and timeline entries. On the CLI, `gbrain put SLUG --file PATH` reads content from a file (also `--content` or stdin). For provenance write-through and a binary-NUL guard, prefer `gbrain capture --file PATH --slug SLUG` (v0.39.3.0).',
|
||||
description: 'Write/update a page (markdown with frontmatter). Chunks, embeds, reconciles tags, and (when auto_link/auto_timeline are enabled) extracts + reconciles graph links and timeline entries. For large content on Windows (pipe-buffer limit ~45KB) or any file-as-input workflow, use `gbrain capture --file PATH --slug SLUG` — capture reads the file as a Buffer with a binary-NUL guard and adds provenance write-through (v0.39.3.0).',
|
||||
params: {
|
||||
slug: { type: 'string', required: true, description: 'Page slug' },
|
||||
content: { type: 'string', required: true, description: 'Full markdown content with YAML frontmatter' },
|
||||
@@ -1384,10 +1394,7 @@ const list_pages: Operation = {
|
||||
params: {
|
||||
type: { type: 'string', description: 'Filter by page type' },
|
||||
tag: { type: 'string', description: 'Filter by tag' },
|
||||
limit: { type: 'number', description: 'Max results (default 50, capped at 100 — use offset to paginate beyond)' },
|
||||
// #2876: the 100-row cap was silent and there was no way past it even
|
||||
// though both engines already support OFFSET on listPages.
|
||||
offset: { type: 'number', description: 'Skip first N results (pagination; pair with limit)' },
|
||||
limit: { type: 'number', description: 'Max results (default 50)' },
|
||||
// v0.29 — surface filter that already exists on PageFilters.
|
||||
updated_after: {
|
||||
type: 'string',
|
||||
@@ -1418,10 +1425,6 @@ const list_pages: Operation = {
|
||||
type: p.type as any,
|
||||
tag: p.tag as string,
|
||||
limit: clampSearchLimit(p.limit as number | undefined, 50, 100),
|
||||
// #2876: thread pagination through (engines already honor offset).
|
||||
offset: Number.isFinite(p.offset as number) && (p.offset as number) > 0
|
||||
? Math.floor(p.offset as number)
|
||||
: undefined,
|
||||
includeDeleted: (p.include_deleted as boolean) === true,
|
||||
updated_after: typeof p.updated_after === 'string' ? p.updated_after : undefined,
|
||||
sort,
|
||||
@@ -3636,6 +3639,7 @@ const find_trajectory: Operation = {
|
||||
entitySlug: p.entity_slug,
|
||||
...scope,
|
||||
remote: ctx.remote === true,
|
||||
trustedFactReads: ctx.trustedFactReads === true,
|
||||
metric,
|
||||
kind,
|
||||
since,
|
||||
@@ -3996,13 +4000,9 @@ const recall: Operation = {
|
||||
const includeExpired = p.include_expired === true;
|
||||
const grep = typeof p.grep === 'string' ? p.grep.toLowerCase() : null;
|
||||
|
||||
// Visibility filter: remote callers see world-only unless their token
|
||||
// grants elevated visibility (future-proofing; v0.31 ships world-only
|
||||
// for remote, all for local CLI).
|
||||
const visibility =
|
||||
ctx.remote === false
|
||||
? undefined
|
||||
: ['world'] as ('private' | 'world')[];
|
||||
// Visibility filter: world-only for untrusted remote callers; all rows for
|
||||
// trusted local CLI and owner-trusted reads (facts.trust_local_reads).
|
||||
const visibility = readableFactVisibilities(ctx);
|
||||
|
||||
let rows: Awaited<ReturnType<typeof ctx.engine.listFactsByEntity>> = [];
|
||||
|
||||
|
||||
@@ -18,6 +18,7 @@ import type {
|
||||
} from './engine.ts';
|
||||
import { MAX_SEARCH_LIMIT, clampSearchLimit } from './engine.ts';
|
||||
import { withRetry, BULK_RETRY_OPTS, resolveBulkRetryOpts, computeNextDelay, type BatchAuditSite } from './retry.ts';
|
||||
import { factsWorldOnly } from './facts/reader-trust.ts';
|
||||
import { logBatchRetry as auditLogBatchRetry, logBatchExhausted as auditLogBatchExhausted } from './audit/batch-retry-audit.ts';
|
||||
import { runMigrations } from './migrate.ts';
|
||||
import { PGLITE_SCHEMA_SQL, getPGLiteSchema } from './pglite-schema.ts';
|
||||
@@ -4318,7 +4319,10 @@ export class PGLiteEngine implements BrainEngine {
|
||||
const useArray = Array.isArray(opts.sourceIds) && opts.sourceIds.length > 0;
|
||||
const sourceIds = useArray ? opts.sourceIds! : null;
|
||||
const sourceId = opts.sourceId ?? 'default';
|
||||
const remoteFilter = opts.remote === true;
|
||||
// Direct-engine contract: unset `remote` here means a trusted in-process
|
||||
// caller (CLI/tests) — the fail-closed default lives in the op layer, which
|
||||
// always passes explicit booleans. Normalize before the fail-closed helper.
|
||||
const remoteFilter = factsWorldOnly({ remote: opts.remote === true, trustedFactReads: opts.trustedFactReads === true });
|
||||
|
||||
// Build SQL dynamically. PGLite uses $N positional params; we
|
||||
// assemble the WHERE clauses + params array in tandem to keep them
|
||||
|
||||
@@ -14,6 +14,7 @@ import type {
|
||||
SourceRow,
|
||||
} from './engine.ts';
|
||||
import { withRetry, BULK_RETRY_OPTS, resolveBulkRetryOpts, computeNextDelay, type BatchAuditSite } from './retry.ts';
|
||||
import { factsWorldOnly } from './facts/reader-trust.ts';
|
||||
import { logBatchRetry as auditLogBatchRetry, logBatchExhausted as auditLogBatchExhausted } from './audit/batch-retry-audit.ts';
|
||||
import type {
|
||||
DomainBankSampleOpts, CorpusSampleOpts, DomainBankRow,
|
||||
@@ -4532,7 +4533,10 @@ export class PostgresEngine implements BrainEngine {
|
||||
const useArray = Array.isArray(opts.sourceIds) && opts.sourceIds.length > 0;
|
||||
const sourceIds = useArray ? opts.sourceIds! : null;
|
||||
const sourceId = opts.sourceId ?? 'default';
|
||||
const remoteFilter = opts.remote === true;
|
||||
// Direct-engine contract: unset `remote` here means a trusted in-process
|
||||
// caller (CLI/tests) — the fail-closed default lives in the op layer, which
|
||||
// always passes explicit booleans. Normalize before the fail-closed helper.
|
||||
const remoteFilter = factsWorldOnly({ remote: opts.remote === true, trustedFactReads: opts.trustedFactReads === true });
|
||||
|
||||
// Source-scope predicate: array path (federated) wins over scalar.
|
||||
// Engine.ts contract: returns chronological points; regressions +
|
||||
|
||||
@@ -30,6 +30,13 @@ export interface ToolResult {
|
||||
export interface DispatchOpts {
|
||||
/** Defaults to true (remote/untrusted). Local CLI callers (`gbrain call`) pass false. */
|
||||
remote?: boolean;
|
||||
/**
|
||||
* Owner opt-in (`facts.trust_local_reads`): let this remote caller read
|
||||
* `private` facts. Set ONLY by the stdio MCP server; the HTTP transport
|
||||
* leaves it unset so a served brain stays world-only. See
|
||||
* `src/core/facts/reader-trust.ts`.
|
||||
*/
|
||||
trustedFactReads?: boolean;
|
||||
/** Override the default stderr logger (e.g. CLI uses console.* directly). */
|
||||
logger?: OperationContext['logger'];
|
||||
/**
|
||||
@@ -203,6 +210,7 @@ export function buildOperationContext(
|
||||
logger: opts.logger || stderrLogger,
|
||||
dryRun: !!params.dry_run,
|
||||
remote: opts.remote ?? true,
|
||||
trustedFactReads: opts.trustedFactReads === true,
|
||||
takesHoldersAllowList: opts.takesHoldersAllowList,
|
||||
// v0.34 D4: sourceId is REQUIRED at the type level. Auto-fill 'default'
|
||||
// for single-source brains and any caller who didn't resolve a sourceId.
|
||||
|
||||
@@ -35,6 +35,16 @@ export async function startMcpServer(engine: BrainEngine) {
|
||||
// shape and cast through `any` (the SDK accepts it via the ServerResult union).
|
||||
server.setRequestHandler(CallToolRequestSchema, async (request: any): Promise<any> => {
|
||||
const { name, arguments: params } = request.params;
|
||||
// Owner opt-in: the stdio pipe is local + unauthenticated, so on a
|
||||
// single-owner machine its caller is the owner. When facts.trust_local_reads
|
||||
// is on, let fact reads (find_trajectory / recall) see this owner's own
|
||||
// private facts. Narrow + read-only — every other remote protection stays
|
||||
// on (remote stays true). HTTP transport never sets this. Best-effort: a
|
||||
// config read blip falls back to the safe world-only default.
|
||||
let trustedFactReads = false;
|
||||
try {
|
||||
trustedFactReads = (await engine.getConfig('facts.trust_local_reads')) === 'true';
|
||||
} catch { /* keep world-only default */ }
|
||||
// v0.28: stdio MCP has no per-token auth (local pipe). Default the
|
||||
// takes-holder allow-list to ['world'] so agent-facing callers don't
|
||||
// see private hunches via takes_list / takes_search / query. Operators
|
||||
@@ -42,6 +52,7 @@ export async function startMcpServer(engine: BrainEngine) {
|
||||
// `gbrain call <op>` (sets remote=false in src/cli.ts).
|
||||
return dispatchToolCall(engine, name, params, {
|
||||
remote: true,
|
||||
trustedFactReads,
|
||||
takesHoldersAllowList: ['world'],
|
||||
// v0.31: source defaults to 'default' for stdio (no per-token scope).
|
||||
// Operators who want a different source on stdio MCP should set
|
||||
|
||||
@@ -1,41 +1,8 @@
|
||||
import { describe, expect, test } from 'bun:test';
|
||||
import { mkdtempSync, rmSync, writeFileSync } from 'fs';
|
||||
import { tmpdir } from 'os';
|
||||
import { join } from 'path';
|
||||
import { parseOpArgs } from '../src/cli.ts';
|
||||
import { operationsByName } from '../src/core/operations.ts';
|
||||
|
||||
describe('parseOpArgs', () => {
|
||||
// #380: `gbrain put SLUG --file PATH` reads content from the file instead
|
||||
// of silently swallowing the flag and creating an empty page.
|
||||
test('put --file reads the stdin param (content) from a file', () => {
|
||||
const dir = mkdtempSync(join(tmpdir(), 'gbrain-put-file-'));
|
||||
try {
|
||||
const pagePath = join(dir, 'page.md');
|
||||
writeFileSync(pagePath, '# From file\n\nBody loaded from --file.\n');
|
||||
const params = parseOpArgs(operationsByName.put_page, ['concepts/from-file', '--file', pagePath]);
|
||||
expect(params.slug).toBe('concepts/from-file');
|
||||
expect(params.content).toBe('# From file\n\nBody loaded from --file.\n');
|
||||
} finally {
|
||||
rmSync(dir, { recursive: true, force: true });
|
||||
}
|
||||
});
|
||||
|
||||
// #380 regression guard: undeclared-but-honored flags must keep passing
|
||||
// through when unknown flags become hard errors (--source is read by
|
||||
// makeContext; --json by the output seam; --dry-run by ctx.dryRun).
|
||||
test('pass-through allowlist flags survive on ops that do not declare them', () => {
|
||||
const params = parseOpArgs(operationsByName.get_page, [
|
||||
'people/alice-example', '--source', 'wiki', '--json', '--dry-run',
|
||||
]);
|
||||
expect(params).toEqual({
|
||||
slug: 'people/alice-example',
|
||||
source: 'wiki',
|
||||
json: true,
|
||||
dry_run: true,
|
||||
});
|
||||
});
|
||||
|
||||
test('--no-<boolean> maps to false without consuming the next flag', () => {
|
||||
const params = parseOpArgs(operationsByName.query, [
|
||||
'freshEmbedSourceScope code source',
|
||||
|
||||
+1
-71
@@ -1,5 +1,5 @@
|
||||
import { describe, test, expect } from 'bun:test';
|
||||
import { existsSync, mkdtempSync, readFileSync, rmSync, writeFileSync } from 'fs';
|
||||
import { existsSync, mkdtempSync, readFileSync, rmSync } from 'fs';
|
||||
import { tmpdir } from 'os';
|
||||
import { join } from 'path';
|
||||
|
||||
@@ -120,76 +120,6 @@ describe('CLI dispatch integration', () => {
|
||||
expect(exitCode).toBe(0);
|
||||
});
|
||||
|
||||
// #380 / PR #856: put --help documents the --file input path.
|
||||
test('put --help documents --file input', async () => {
|
||||
const proc = Bun.spawn(['bun', 'run', 'src/cli.ts', 'put', '--help'], {
|
||||
cwd: repoRoot,
|
||||
stdout: 'pipe',
|
||||
stderr: 'pipe',
|
||||
});
|
||||
const stdout = await new Response(proc.stdout).text();
|
||||
const exitCode = await proc.exited;
|
||||
expect(stdout).toContain('Usage: gbrain put');
|
||||
expect(stdout).toContain('--file <path>');
|
||||
expect(exitCode).toBe(0);
|
||||
});
|
||||
|
||||
// #380: unknown flags on shared ops are a hard error (previously silently
|
||||
// swallowed into params — `put --file` created empty pages). parseOpArgs
|
||||
// runs BEFORE engine connect, so the error must fire without a brain.
|
||||
test('unknown shared-op flags fail before DB connection', async () => {
|
||||
const home = mkdtempSync(join(tmpdir(), 'gbrain-cli-unknown-flag-'));
|
||||
try {
|
||||
const proc = Bun.spawn(['bun', 'run', 'src/cli.ts', 'get', 'people/alice', '--bogus'], {
|
||||
cwd: repoRoot,
|
||||
stdout: 'pipe',
|
||||
stderr: 'pipe',
|
||||
env: isolatedEnv(home),
|
||||
});
|
||||
const stderr = await new Response(proc.stderr).text();
|
||||
const exitCode = await proc.exited;
|
||||
expect(stderr).toContain('Unknown option for gbrain get: --bogus');
|
||||
expect(stderr).not.toContain('No brain configured');
|
||||
expect(exitCode).toBe(1);
|
||||
} finally {
|
||||
rmSync(home, { recursive: true, force: true });
|
||||
}
|
||||
});
|
||||
|
||||
test('put rejects combining --file and --content', async () => {
|
||||
const home = mkdtempSync(join(tmpdir(), 'gbrain-cli-put-conflict-'));
|
||||
try {
|
||||
const pagePath = join(home, 'page.md');
|
||||
writeFileSync(pagePath, 'file body\n');
|
||||
const proc = Bun.spawn(
|
||||
['bun', 'run', 'src/cli.ts', 'put', 'a/b', '--content', 'inline', '--file', pagePath],
|
||||
{ cwd: repoRoot, stdout: 'pipe', stderr: 'pipe', env: isolatedEnv(home) },
|
||||
);
|
||||
const stderr = await new Response(proc.stderr).text();
|
||||
const exitCode = await proc.exited;
|
||||
expect(stderr).toContain('use only one of --file, --content, or stdin');
|
||||
expect(exitCode).toBe(1);
|
||||
} finally {
|
||||
rmSync(home, { recursive: true, force: true });
|
||||
}
|
||||
});
|
||||
|
||||
test('put --file with a missing path errors instead of writing an empty page', async () => {
|
||||
const home = mkdtempSync(join(tmpdir(), 'gbrain-cli-put-missing-file-'));
|
||||
try {
|
||||
const proc = Bun.spawn(
|
||||
['bun', 'run', 'src/cli.ts', 'put', 'a/b', '--file', join(home, 'nope.md')],
|
||||
{ cwd: repoRoot, stdout: 'pipe', stderr: 'pipe', env: isolatedEnv(home) },
|
||||
);
|
||||
const stderr = await new Response(proc.stderr).text();
|
||||
const exitCode = await proc.exited;
|
||||
expect(stderr).toContain('cannot read --file');
|
||||
expect(exitCode).toBe(1);
|
||||
} finally {
|
||||
rmSync(home, { recursive: true, force: true });
|
||||
}
|
||||
});
|
||||
|
||||
test('upgrade --help prints usage without running upgrade', async () => {
|
||||
const proc = Bun.spawn(['bun', 'run', 'src/cli.ts', 'upgrade', '--help'], {
|
||||
cwd: repoRoot,
|
||||
|
||||
@@ -165,6 +165,22 @@ describe('findTrajectory — visibility filter (D-CDX-1 / R6)', () => {
|
||||
const all = await engine.findTrajectory({ entitySlug: 'traj-vis-default' });
|
||||
expect(all.length).toBe(2);
|
||||
});
|
||||
|
||||
test('remote=true + trustedFactReads bypasses world-only (owner-trusted reads)', async () => {
|
||||
await insertTyped({ entity_slug: 'traj-vis-trusted', metric: 'mrr', value: 50000, visibility: 'private', valid_from: new Date('2026-01-15') });
|
||||
await insertTyped({ entity_slug: 'traj-vis-trusted', metric: 'mrr', value: 99999, visibility: 'world', valid_from: new Date('2026-04-12') });
|
||||
|
||||
// Untrusted remote: world only.
|
||||
const untrusted = await engine.findTrajectory({ entitySlug: 'traj-vis-trusted', remote: true });
|
||||
expect(untrusted.length).toBe(1);
|
||||
expect(untrusted[0].value).toBe(99999);
|
||||
|
||||
// Owner-trusted remote: sees the private point too. remote stays true — only
|
||||
// fact-read visibility is elevated.
|
||||
const trusted = await engine.findTrajectory({ entitySlug: 'traj-vis-trusted', remote: true, trustedFactReads: true });
|
||||
expect(trusted.length).toBe(2);
|
||||
expect(trusted.map(p => p.value).sort((a, b) => (a! - b!))).toEqual([50000, 99999]);
|
||||
});
|
||||
});
|
||||
|
||||
describe('findTrajectory — metric + since + until filters', () => {
|
||||
|
||||
@@ -0,0 +1,43 @@
|
||||
import { describe, test, expect } from 'bun:test';
|
||||
import {
|
||||
factsWorldOnly,
|
||||
readableFactVisibilities,
|
||||
} from '../src/core/facts/reader-trust.ts';
|
||||
|
||||
describe('factsWorldOnly', () => {
|
||||
test('FAIL-CLOSED: unset remote is untrusted (world-only)', () => {
|
||||
expect(factsWorldOnly({})).toBe(true);
|
||||
expect(factsWorldOnly({ remote: undefined })).toBe(true);
|
||||
expect(factsWorldOnly({ trustedFactReads: false })).toBe(true);
|
||||
});
|
||||
|
||||
test('explicit remote=false (trusted local CLI) sees all', () => {
|
||||
expect(factsWorldOnly({ remote: false })).toBe(false);
|
||||
expect(factsWorldOnly({ remote: false, trustedFactReads: false })).toBe(false);
|
||||
});
|
||||
|
||||
test('untrusted remote callers are world-only', () => {
|
||||
expect(factsWorldOnly({ remote: true })).toBe(true);
|
||||
expect(factsWorldOnly({ remote: true, trustedFactReads: false })).toBe(true);
|
||||
});
|
||||
|
||||
test('owner-trusted remote reads bypass the world-only filter', () => {
|
||||
expect(factsWorldOnly({ remote: true, trustedFactReads: true })).toBe(false);
|
||||
});
|
||||
|
||||
test('trustedFactReads is a no-op for an already-trusted local caller', () => {
|
||||
expect(factsWorldOnly({ remote: false, trustedFactReads: true })).toBe(false);
|
||||
});
|
||||
});
|
||||
|
||||
describe('readableFactVisibilities', () => {
|
||||
test("world-only readers get the ['world'] filter (incl. unset remote)", () => {
|
||||
expect(readableFactVisibilities({ remote: true })).toEqual(['world']);
|
||||
expect(readableFactVisibilities({})).toEqual(['world']);
|
||||
});
|
||||
|
||||
test('trusted readers get undefined (no filter — all rows)', () => {
|
||||
expect(readableFactVisibilities({ remote: false })).toBeUndefined();
|
||||
expect(readableFactVisibilities({ remote: true, trustedFactReads: true })).toBeUndefined();
|
||||
});
|
||||
});
|
||||
@@ -1,55 +0,0 @@
|
||||
import { describe, test, expect } from 'bun:test';
|
||||
import { operationsByName } from '../src/core/operations.ts';
|
||||
|
||||
/**
|
||||
* #2876: `gbrain list --limit` silently clamped at 100 with no pagination.
|
||||
* list_pages now declares `offset` (both engines already supported it on
|
||||
* PageFilters) and the limit description discloses the 100-row cap.
|
||||
*/
|
||||
describe('list_pages pagination (#2876)', () => {
|
||||
const listPagesOp = operationsByName.list_pages;
|
||||
|
||||
function makeCtx(captured: unknown[]) {
|
||||
return {
|
||||
engine: {
|
||||
listPages: async (filters: unknown) => {
|
||||
captured.push(filters);
|
||||
return [];
|
||||
},
|
||||
},
|
||||
config: { engine: 'pglite' },
|
||||
logger: { info() {}, warn() {}, error() {} },
|
||||
dryRun: false,
|
||||
remote: false,
|
||||
sourceId: 'default',
|
||||
} as any;
|
||||
}
|
||||
|
||||
test('declares offset param and discloses the 100-row cap on limit', () => {
|
||||
expect(listPagesOp.params.offset).toBeDefined();
|
||||
expect(listPagesOp.params.offset.type).toBe('number');
|
||||
expect(listPagesOp.params.limit.description).toContain('100');
|
||||
});
|
||||
|
||||
test('threads offset through to engine.listPages', async () => {
|
||||
const captured: any[] = [];
|
||||
await listPagesOp.handler(makeCtx(captured), { limit: 10, offset: 30 });
|
||||
expect(captured[0].offset).toBe(30);
|
||||
expect(captured[0].limit).toBe(10);
|
||||
});
|
||||
|
||||
test('drops negative, non-finite, and zero offsets', async () => {
|
||||
const captured: any[] = [];
|
||||
const ctx = makeCtx(captured);
|
||||
await listPagesOp.handler(ctx, { offset: -5 });
|
||||
await listPagesOp.handler(ctx, { offset: Infinity });
|
||||
await listPagesOp.handler(ctx, { offset: 0 });
|
||||
for (const f of captured) expect(f.offset).toBeUndefined();
|
||||
});
|
||||
|
||||
test('floors fractional offsets', async () => {
|
||||
const captured: any[] = [];
|
||||
await listPagesOp.handler(makeCtx(captured), { offset: 7.9 });
|
||||
expect(captured[0].offset).toBe(7);
|
||||
});
|
||||
});
|
||||
Reference in New Issue
Block a user