open-swe/agent/middleware/__init__.py
Adam Moussa 0f0f616cd4
Some checks failed
CI / Lint (push) Has been cancelled
CI / Format check (push) Has been cancelled
CI / Typecheck (push) Has been cancelled
CI / Unit tests (push) Has been cancelled
CI / Playwright E2E (push) Has been cancelled
CI / Docker build smoke (push) Has been cancelled
CI / Triage ledger up to date (push) Has been cancelled
CI / ui bun.lock in sync (push) Has been cancelled
feat(open-swe): explicit-request reviewer verdicts + shell verdict guard (#214)
* feat(reviewer): explicit-request verdicts + shell verdict guard

Mention-triggered reviews that explicitly ask for a verdict now submit a
real APPROVE/REQUEST_CHANGES through publish_review; auto-reviews stay
advisory (COMMENT). Authorization is enforced in code: publish_review
honors a verdict only when the dispatching webhook set verdict_requested,
which only the explicit-mention path does.

- request_pr_review gains instructions (forwarded verbatim into an escaped
  requester_instructions data block) and request_verdict
- self-review guard downgrades verdicts on Open SWE-authored PRs; stale
  APPROVEs are best-effort dismissed when later findings land
- new PullRequestVerdictGuardMiddleware blocks gh pr review
  --approve/-a/--request-changes/-r, gh api, and curl verdict fallbacks on
  both the coding-agent and reviewer graphs
- shared escape helper moved to agent/utils/prompt_data.py

* fix(reviewer): harden verdict path against security-review findings

Adversarial security review (detector fan-out + proof-or-kill verifier)
of the verdict feature surfaced several verdict-integrity gaps; resolve
the confirmed ones:

- head-drift (high): a mid-run push moves the resolved head, so an APPROVE
  could anchor to an unreviewed commit. Downgrade any verdict to a comment
  when the resolved head differs from the reviewed head (verdict_ignored
  reason head_moved); the push's own re-review submits a fresh verdict.
- self-review fail-open: downgrade to comment when the PR author cannot be
  confirmed (author_unknown), and compare bot logins case-insensitively.
- verdict_submitted now reflects GitHub's returned review state, not just
  the event we asked for, so a coerced APPROVE isn't reported as submitted.
- an authorized verdict whose findings all anchor outside the diff now
  posts as a bodied review with zero inline comments instead of failing.
- add finding_reply to the shared data-block escape tag superset.
2026-07-20 15:28:00 -04:00

104 lines
4.4 KiB
Python

import sys
from types import ModuleType
from typing import TYPE_CHECKING, Any
_MIDDLEWARE_MODULES = {
"check_message_queue_before_model": ".check_message_queue",
"ensure_no_empty_msg": ".ensure_no_empty_msg",
"ExcludeToolsMiddleware": ".exclude_tools",
"ModelFallbackMiddleware": ".model_fallback",
"notify_step_limit_reached": ".notify_step_limit",
"PlanModeMiddleware": ".plan_mode",
"PullRequestCreationGuardMiddleware": ".pr_creation_guard",
"PullRequestVerdictGuardMiddleware": ".pr_verdict_guard",
"refresh_github_proxy_before_model": ".refresh_github_proxy",
"RepairOrphanedToolCallsMiddleware": ".repair_orphaned_tool_calls",
"SlackAssistantStatusMiddleware": ".refresh_slack_status",
"SandboxCircuitBreakerMiddleware": ".sandbox_circuit_breaker",
"SanitizeFireworksMessagesMiddleware": ".sanitize_fireworks_messages",
"SanitizeOpenAIResponsesMiddleware": ".sanitize_openai_responses",
"SanitizeThinkingBlocksMiddleware": ".sanitize_thinking_blocks",
"SanitizeToolInputsMiddleware": ".sanitize_tool_inputs",
"settle_review_check_on_exit": ".settle_review_check",
"SubdirAgentsReadMiddleware": ".subdir_agents",
"task_on_failure": ".task_retry",
"task_retry_on": ".task_retry",
"TimeoutWrapupMiddleware": ".timeout_wrapup",
"ToolArtifactMiddleware": ".tool_artifact",
"ToolErrorMiddleware": ".tool_error_handler",
"WorkflowPushGuardMiddleware": ".workflow_push_guard",
}
__all__ = [
"ExcludeToolsMiddleware",
"ModelFallbackMiddleware",
"PlanModeMiddleware",
"PullRequestCreationGuardMiddleware",
"PullRequestVerdictGuardMiddleware",
"RepairOrphanedToolCallsMiddleware",
"SanitizeFireworksMessagesMiddleware",
"SanitizeOpenAIResponsesMiddleware",
"SanitizeThinkingBlocksMiddleware",
"SanitizeToolInputsMiddleware",
"SubdirAgentsReadMiddleware",
"ToolArtifactMiddleware",
"ToolErrorMiddleware",
"TimeoutWrapupMiddleware",
"WorkflowPushGuardMiddleware",
"SandboxCircuitBreakerMiddleware",
"SlackAssistantStatusMiddleware",
"check_message_queue_before_model",
"ensure_no_empty_msg",
"notify_step_limit_reached",
"refresh_github_proxy_before_model",
"settle_review_check_on_exit",
"task_on_failure",
"task_retry_on",
]
if TYPE_CHECKING:
from .check_message_queue import check_message_queue_before_model
from .ensure_no_empty_msg import ensure_no_empty_msg
from .exclude_tools import ExcludeToolsMiddleware
from .model_fallback import ModelFallbackMiddleware
from .notify_step_limit import notify_step_limit_reached
from .plan_mode import PlanModeMiddleware
from .pr_creation_guard import PullRequestCreationGuardMiddleware
from .pr_verdict_guard import PullRequestVerdictGuardMiddleware
from .refresh_github_proxy import refresh_github_proxy_before_model
from .refresh_slack_status import SlackAssistantStatusMiddleware
from .repair_orphaned_tool_calls import RepairOrphanedToolCallsMiddleware
from .sandbox_circuit_breaker import SandboxCircuitBreakerMiddleware
from .sanitize_fireworks_messages import SanitizeFireworksMessagesMiddleware
from .sanitize_openai_responses import SanitizeOpenAIResponsesMiddleware
from .sanitize_thinking_blocks import SanitizeThinkingBlocksMiddleware
from .sanitize_tool_inputs import SanitizeToolInputsMiddleware
from .settle_review_check import settle_review_check_on_exit
from .subdir_agents import SubdirAgentsReadMiddleware
from .task_retry import task_on_failure, task_retry_on
from .timeout_wrapup import TimeoutWrapupMiddleware
from .tool_artifact import ToolArtifactMiddleware
from .tool_error_handler import ToolErrorMiddleware
from .workflow_push_guard import WorkflowPushGuardMiddleware
def _load_export(name: str) -> Any:
module_name = _MIDDLEWARE_MODULES.get(name)
if module_name is None:
raise AttributeError(f"module {__name__!r} has no attribute {name!r}")
from importlib import import_module
value = getattr(import_module(module_name, __name__), name)
globals()[name] = value
return value
class _LazyMiddlewareModule(ModuleType):
def __getattribute__(self, name: str) -> Any:
module_map = ModuleType.__getattribute__(self, "__dict__").get("_MIDDLEWARE_MODULES", {})
if name in module_map:
return _load_export(name)
return ModuleType.__getattribute__(self, name)
sys.modules[__name__].__class__ = _LazyMiddlewareModule