Repository navigation
Support asynchronous HTML extraction in web_fetch #60
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
02d9337
f6280a5
fa61666
4a8d0b1
479a7a0
547956c
f3d1783
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -7,7 +7,8 @@ Host-independent building blocks for agent tools, extracted from OpenHuman. | |
| | `file_state` | Process-wide read/write stamps so parallel agents detect stale or partial reads before overwriting a file. The host decides whether the guard is on (`init_global(enabled)`); read tools pass `record_read` an `Instant` captured before their I/O. | | ||
| | `url_guard` | URL validation with SSRF checks for outbound network tools. `validate_url_with_dns_check` returns a `ValidatedUrl` whose vetted `addrs` the caller must pin its HTTP client to (e.g. `reqwest`'s `resolve_to_addrs`); re-resolving the hostname reopens DNS rebinding. | | ||
| | `filesystem` | The file and repository tools: `file_read`, `file_write`, `edit_file`, `apply_patch`, `grep`, `glob`, `list_files`, `csv_export`, `read_diff`, `git_operations`, `run_linter`, `run_tests`, `update_memory_md`, `image_info`, `read_workspace_state`. Every tool that can touch a path takes an `Arc<dyn FsGate>`: the tool does the I/O, the host's gate (autonomy, workspace boundary, approvals, action budget) decides whether it may. | | ||
| | `network` | The network tools: `http_request`, `web_fetch`, `curl`, `pushover`. Every tool takes an `Arc<dyn NetGate>`: the tool does the I/O, the host's gate (autonomy, action budget, approval, privacy mode, proxy) decides whether it may and how. Two smaller seams keep host behavior out: `PaymentHook` answers a `402 Payment Required` for `http_request`, and `HtmlExtractor` converts pages to Markdown for `web_fetch`. Names, descriptions and schemas are pinned by `src/network/fixtures/`. | | ||
| | `network` | The network tools: `http_request`, `web_fetch`, `curl`, `pushover`. Every tool takes an `Arc<dyn NetGate>`: the tool does the I/O, the host's gate (autonomy, action budget, approval, privacy mode, proxy) decides whether it may and how. Two smaller seams keep host behavior out: `PaymentHook` answers a `402 Payment Required` for `http_request`, and `HtmlExtractor` converts pages to Markdown for `web_fetch`. `WebFetchTool::new_async` accepts a fallible `AsyncHtmlExtractor` for transforms supplied by a remote service or loadable module; detection and extraction are awaited with the configured request timeout applied to each operation, and failures propagate without a local retry. Both constructors extract before applying the output cap, and skip extraction for raw or explicitly non-HTML responses. Names, descriptions and schemas are pinned by `src/network/fixtures/`. | | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Document the extractor input ceiling This documentation now explicitly says extraction happens before the output cap, so [RULE] unbounded-extractor-input · |
||
| | `sanitize` | Lexical sanitization helpers for untrusted tool, skill and capability metadata, including control and instruction-fence removal plus UTF-8-safe byte truncation. | | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Integrate sanitization into metadata production paths The sanitizer is still only defined and tested; the repository search shows no production caller of [RULE] missing-sanitization-integration · |
||
| | `detect_tools` | `find_on_path` and the read-only `detect_tools` tool. | | ||
|
|
||
| No enforcement of host policy lives here; the crate only supplies mechanisms. The `filesystem` tools' name, description and JSON Schema are pinned by the fixtures in `src/filesystem/fixtures/`. | ||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -13,6 +13,7 @@ | |
| //! - [`url_guard`] — URL validation with SSRF checks, plus DNS resolution | ||
| //! that returns the vetted addresses for the caller to pin its connection to. | ||
| //! - [`detect_tools`] — `PATH` probing and the read-only `detect_tools` tool. | ||
| //! - [`sanitize`] — lexical sanitization and truncation for untrusted metadata. | ||
| //! | ||
| //! # Example | ||
| //! | ||
|
|
@@ -35,4 +36,5 @@ pub mod detect_tools; | |
| pub mod file_state; | ||
| pub mod filesystem; | ||
| pub mod network; | ||
| pub mod sanitize; | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Integrate sanitization into metadata production paths Exporting the sanitizer does not apply it anywhere: the repository has no call sites for Additional
|
||
| pub mod url_guard; | ||
Uh oh!
There was an error while loading. Please reload this page.