mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-09-30 11:33:14 +00:00
* fix(webhooks): fall back to vision model for Slack/Linear image threads Re-land upstream #1626 onto the modular webhook structure. When a Slack mention or Linear issue carries images but the resolved model is text-only, fall back to a vision-capable model instead of dropping the images. Re-points default_vision_model_pair at the fork's image-capable models (Opus 4.8 default, else any supports_images model) rather than upstream's openai:/anthropic: provider filter. Refs #80, upstream #1626 * fix(slack): persist trace_message_ts so web-handoff updates the trace reply Re-land upstream #1630 onto the modular structure. The first-mention store_slack_run_mapping call did not pass trace_message_ts, so it was never persisted (nothing to preserve from on first mention) and _notify_slack_web_handoff always skipped the trace-reply update on web handoff. Pass it through and cover it with a test. Refs #80, upstream #1630 * feat(slack): include channel context in Slack prompts Re-land upstream #1633 onto the modular structure. Fetch cached Slack channel metadata once per event (_get_slack_channel_context) and thread it through the docs-plz gate, repo resolution, and process_slack_mention so prompts carry the channel name and a clearly-marked untrusted channel description. Avoids duplicate conversations.info calls. Refs #80, upstream #1633 * feat(tools): add slack_start_new_thread breakout tool Re-land upstream #1638 onto the modular structure. Adds the slack_start_new_thread tool (posts a top-level Slack message and dispatches a fresh agent run for a broken-out task via the durable dispatch_agent_run contract), wires it into the agent tool list and tools/__init__, adds prompt guidance, and excludes it from plan mode so it can't bypass the approval flow. Tool imports only live modules. Refs #80, upstream #1638 * feat(plan): notify Slack on plan approval Re-land upstream #1632 onto the modular structure. When a plan is approved via the dashboard approve endpoint, post a thread reply to the originating Slack thread noting the comment count and approver, after the follow-up run is dispatched. Slack post failures never break approval. Adapted to the fork's approve_plan (no plan_markdown read). Refs #80, upstream #1632 * feat(plan): publish plans from sandbox files Re-land upstream #1635 onto the modular structure, completing the partially-ported change so dev is internally consistent. save_plan now takes a plan_file_path, reads the agent-authored Markdown file from /workspace/plans/ (validating extension/location/UTF-8/size) and publishes it, instead of taking a plan_markdown string. Removes write_file/edit_file from PLAN_MODE_EXCLUDED_TOOLS so the agent can author the plan file, updates enter_plan_mode/reject_plan guidance and the e2e fake LLM. Skips the #1610-only update_plan hunk (not on dev). Refs #80, upstream #1635 * fix(security): SSRF-harden server-side image fetch + stop logging raw image URLs INJ-01 (high): fetch_image_block used follow_redirects=True with no per-hop revalidation and discarded the resolved-IP pin, so an attacker-authored Slack/ Linear image URL could 302-redirect the fetch to an internal host / cloud metadata endpoint (blind SSRF), and DNS-rebinding could bypass the one-shot is_url_safe check. Route image fetches through the same per-hop resolve+pin+ revalidate loop the http_request tool uses, lifted into url_safety as the shared request_with_safe_redirects. Also strip the per-host Slack/Linear bearer token on redirect so it can't be replayed to a redirect target. SC-1 (low): linear.py logged full image URLs (which can carry signed tokens) at DEBUG; multimodal logged them at INFO on every fetch. Log host-only. Sink lived in multimodal.py (unchanged by the feature work) but PR #128 widened its reach by no longer dropping images for text-only models. Fixing on the base branch so #130/#129 inherit it on rebase. Adds fetch_image_block SSRF regression tests (redirect-to-internal blocked; auth stripped on redirect).
63 lines
2.5 KiB
Python
63 lines
2.5 KiB
Python
"""Tool: ``enter_plan_mode``. Switch the run into read-only planning."""
|
|
|
|
from __future__ import annotations
|
|
|
|
import logging
|
|
from typing import Annotated
|
|
|
|
from langchain_core.messages import ToolMessage
|
|
from langchain_core.tools import InjectedToolCallId
|
|
from langgraph.config import get_config
|
|
from langgraph.types import Command
|
|
|
|
from ..dashboard.plan_store import PLAN_STATUS_PLANNING, set_plan_status
|
|
|
|
logger = logging.getLogger(__name__)
|
|
|
|
_ENTERED_MESSAGE = (
|
|
"Plan mode is active. Stay read-only for the target repo: research the codebase, "
|
|
"create or edit a dated, concise plan file under `/workspace/plans/`, then publish "
|
|
"it with the `save_plan` tool and share the plan-review link in the source channel. "
|
|
"Do not edit repo files, commit, push, or open a PR — wait for the user to approve "
|
|
"the plan."
|
|
)
|
|
|
|
|
|
async def enter_plan_mode(tool_call_id: Annotated[str, InjectedToolCallId]) -> Command:
|
|
"""Activate plan mode mid-run.
|
|
|
|
Call this when you believe the task would benefit from a structured
|
|
implementation plan before writing any code — e.g. when the request is
|
|
complex, touches many files, or has multiple valid approaches. This is
|
|
NOT triggered by the word "plan" appearing in the request; use your
|
|
judgment about whether planning is genuinely warranted.
|
|
|
|
Once activated, stay read-only for the target repo: research the codebase,
|
|
create or edit a dated, concise Markdown plan outside any repo (for example,
|
|
``/workspace/plans/YYYY-MM-DD-short-task-slug.md``), then publish it with
|
|
the ``save_plan`` tool and share the plan-review link with the user. Do not
|
|
edit repo files, commit, push, or open a PR — the user reviews the plan and
|
|
approves it before you implement.
|
|
"""
|
|
thread_id = _thread_id_from_config()
|
|
if thread_id:
|
|
try:
|
|
await set_plan_status(thread_id, PLAN_STATUS_PLANNING, plan_mode=True)
|
|
except Exception:
|
|
logger.warning("Failed to persist plan-mode entry for %s", thread_id, exc_info=True)
|
|
return Command(
|
|
update={
|
|
"plan_mode": True,
|
|
"messages": [ToolMessage(content=_ENTERED_MESSAGE, tool_call_id=tool_call_id)],
|
|
}
|
|
)
|
|
|
|
|
|
def _thread_id_from_config() -> str | None:
|
|
try:
|
|
config = get_config()
|
|
except Exception:
|
|
return None
|
|
configurable = config.get("configurable", {}) if isinstance(config, dict) else {}
|
|
thread_id = configurable.get("thread_id") if isinstance(configurable, dict) else None
|
|
return str(thread_id) if thread_id else None
|