Files
goclaw/internal/tools/delegation_artifact_result_policy.go
T
Duc Nguyenandntduc bb7712a9ff fix(collaboration): harden delegated task isolation (#1486)
* feat(collaboration): isolate delegated artifacts and child runs

Isolate delegated inputs and outputs behind secure artifact exchange lifecycles. Scope Agent Link tasks by tenant and root agent, and enforce delegation spawn-tree boundaries. Add process-wide child-run admission and preserve logical media paths across native, MCP, and sandbox execution.

* fix(collaboration): harden delegated task isolation

Enforce tenant and root-agent task scope across migrations and stores. Add exactly-once async completion delivery, delegated sandbox boundaries, and confined artifact and media recovery across runtime surfaces.

* fix(collaboration): recover interrupted async tasks

* fix(collaboration): normalize persisted child-run status

---------

Co-authored-by: ntduc <ntduc@cpp.ai.vn>
2026-07-30 14:17:40 +07:00

37 lines
1.0 KiB
Go

package tools
import (
"context"
"strings"
)
// ApplyDelegationArtifactResultPolicy keeps unvalidated delegate outputs inside
// the exchange. Publication is owned by DelegateTool after the child run
// succeeds and the manifest has been validated.
func ApplyDelegationArtifactResultPolicy(ctx context.Context, result *Result) {
if result == nil || !IsDelegationArtifactRun(ctx) {
return
}
result.Media = nil
result.ForLLM = stripArtifactMediaLines(result.ForLLM)
}
func stripArtifactMediaLines(content string) string {
if !strings.Contains(content, "MEDIA:") {
return content
}
lines := strings.Split(content, "\n")
kept := make([]string, 0, len(lines))
for _, line := range lines {
trimmed := strings.TrimSpace(line)
if strings.HasPrefix(trimmed, "[[audio_as_voice]]") {
continue
}
cleaned := strings.TrimRight(embeddedMediaPattern.ReplaceAllString(line, ""), " \t")
if strings.TrimSpace(cleaned) != "" {
kept = append(kept, cleaned)
}
}
return strings.TrimSpace(strings.Join(kept, "\n"))
}