tool, mavend: Hexis owns the tier of a Hexis capability (V-523)
read_only was the whole decision on the Hexis act path, which flattened three answers into two. A capability that wipes the thing it names got the same single spoken "да" as one that restarts a service, and requires_confirmation — which the Hexis contract calls server-derived and never settable by a caller — was read by nobody. docs/ecosystem.md §17.3 says confirmation follows risk. RiskOfCapability reads Hexis's risk, read_only and requires_confirmation and returns one of the three tiers internal/tool already had. It takes plain values rather than a Capability, so internal/tool keeps no dependency on the Hexis client. RiskOf keeps deriving, because a shell row the owner ticked on /tools has no upstream to ask. Every disagreement between the three fields goes up, never down: safe and mutating is a contradiction and takes the confirm, an unrecognised tier takes the confirm, and requires_confirmation may only raise. Same default as an unrecognised dispatch shape — argue your way down, never up. The irreversible refusal was a Go literal in two places and is now one deck entry, act_needs_authed_surface. It lost four words to the persona ceiling.
This commit is contained in:
@@ -57,7 +57,7 @@ func (h *reactiveHandler) actionAct(ctx context.Context, dec router.Decision) st
|
||||
// help: everything that proposed this act — the STT, the router,
|
||||
// the fuzzy allowlist match — is a guess, and a spoken "да" checks
|
||||
// none of it. She names the gap instead.
|
||||
return "это я из голоса не выполню — после него ничего не вернуть. запусти сам, если правда надо."
|
||||
return phraser.A(phraser.ActNeedsAuthedSurface, nil)
|
||||
case errors.Is(err, tool.ErrNotEnabled):
|
||||
return h.proposeGap(ctx, dec)
|
||||
case errors.Is(err, tool.ErrNotConnected), errors.Is(err, mcp.ErrNotConnected), errors.Is(err, mcp.ErrNoServer):
|
||||
|
||||
@@ -12,6 +12,7 @@ import (
|
||||
"github.com/kami/maven/internal/phraser"
|
||||
"github.com/kami/maven/internal/router"
|
||||
"github.com/kami/maven/internal/store"
|
||||
"github.com/kami/maven/internal/tool"
|
||||
)
|
||||
|
||||
// The three services, spelled the way she says them out loud. A service that is
|
||||
@@ -625,7 +626,24 @@ func (h *reactiveHandler) handleHexisAct(ctx context.Context, dec router.Decisio
|
||||
|
||||
// Read-only capabilities run immediately; mutating ones are parked for an
|
||||
// explicit spoken confirm bound to this capability + target.
|
||||
if !matched.ReadOnly {
|
||||
// The tier decides, and Hexis owns the tier (Vikunja #523). read_only alone
|
||||
// used to decide it here, which flattened three answers into two: a
|
||||
// capability that wipes the thing it names got the same single spoken "да"
|
||||
// as one that restarts a service, and requires_confirmation — which the
|
||||
// Hexis contract calls server-derived and not settable by a caller — was
|
||||
// read by nobody. docs/ecosystem.md §17.3 says confirmation follows risk.
|
||||
tier := tool.RiskOfCapability(matched.Risk, matched.ReadOnly, matched.RequiresConfirmation)
|
||||
policy := tool.PolicyFor(tier)
|
||||
if !policy.VoiceMayRun {
|
||||
// Irreversible. A confirm turn would not help, for the same reason it
|
||||
// does not help a local row: the STT heard it, the model routed it and
|
||||
// a substring matched the capability, and a spoken "да" checks none of
|
||||
// those. She names the gap and he runs it himself.
|
||||
h.recordEcosystemTrace(ctx, "hexis", "confirmation", traceRefused, started,
|
||||
map[string]any{"entity_id": entityID, "capability": matched.Name, "risk": string(tier)})
|
||||
return phraser.A(phraser.ActNeedsAuthedSurface, nil)
|
||||
}
|
||||
if policy.Confirm {
|
||||
h.mu.Lock()
|
||||
h.pendingHexis = &pendingHexisExec{
|
||||
capabilityID: matched.ID,
|
||||
|
||||
@@ -253,3 +253,62 @@ func actRan(reply string) bool {
|
||||
|
||||
// muzickIndexer — the display name every ecosystem fixture resolves to.
|
||||
const muzickIndexer = "Muzick indexer"
|
||||
|
||||
// read_only used to be the whole decision on this path, which meant a
|
||||
// capability that destroys what it names got the same single spoken "да" as one
|
||||
// that restarts a service. Hexis declares the tier and the voice path is not an
|
||||
// authorised surface for the top one (Vikunja #523).
|
||||
func TestHexisIrreversibleCapabilityIsNotRunFromVoice(t *testing.T) {
|
||||
ctx := context.Background()
|
||||
resolved := `{"status":"resolved","entity":{"id":"ent_muzick","display_name":"Muzick indexer","type":"service"}}`
|
||||
caps := `[{"id":"cap_wipe","name":"restart","read_only":false,"risk":"irreversible","requires_confirmation":true}]`
|
||||
h, executed := newHexisTestHandler(t, resolved, caps)
|
||||
|
||||
reply := h.handleHexisAct(ctx, actDec("muzick indexer"))
|
||||
if *executed {
|
||||
t.Fatal("an irreversible capability ran from the voice path")
|
||||
}
|
||||
if h.pendingHexis != nil {
|
||||
t.Fatal("an irreversible capability parked a confirm; a spoken да is not enough authority")
|
||||
}
|
||||
if !strings.Contains(reply, "не вернуть") {
|
||||
t.Errorf("reply = %q; want it to name why she will not run it", reply)
|
||||
}
|
||||
}
|
||||
|
||||
// The other half: Hexis calling a capability safe is enough to run it, even
|
||||
// though read_only is the field that used to decide. Nothing here re-derives.
|
||||
func TestHexisSafeCapabilityRunsOnItsDeclaredTier(t *testing.T) {
|
||||
ctx := context.Background()
|
||||
resolved := `{"status":"resolved","entity":{"id":"ent_muzick","display_name":"Muzick indexer","type":"service"}}`
|
||||
caps := `[{"id":"cap_status","name":"restart","read_only":true,"risk":"safe"}]`
|
||||
h, executed := newHexisTestHandler(t, resolved, caps)
|
||||
|
||||
reply := h.handleHexisAct(ctx, actDec("muzick indexer"))
|
||||
if !*executed {
|
||||
t.Fatal("a capability Hexis calls safe should run")
|
||||
}
|
||||
if !actRan(reply) {
|
||||
t.Fatalf("unexpected reply %q", reply)
|
||||
}
|
||||
}
|
||||
|
||||
// A mutating capability with no declared tier keeps the confirm turn it has
|
||||
// always had, so the split does not quietly loosen an existing box.
|
||||
func TestHexisUndeclaredTierStillConfirms(t *testing.T) {
|
||||
ctx := context.Background()
|
||||
resolved := `{"status":"resolved","entity":{"id":"ent_muzick","display_name":"Muzick indexer","type":"service"}}`
|
||||
caps := `[{"id":"cap_restart","name":"restart","read_only":false}]`
|
||||
h, executed := newHexisTestHandler(t, resolved, caps)
|
||||
|
||||
reply := h.handleHexisAct(ctx, actDec("muzick indexer"))
|
||||
if *executed {
|
||||
t.Fatal("a mutating capability ran without a confirm")
|
||||
}
|
||||
if h.pendingHexis == nil {
|
||||
t.Fatal("a mutating capability did not park a confirm")
|
||||
}
|
||||
if !strings.Contains(reply, "да или нет") {
|
||||
t.Errorf("reply = %q; want the confirm question", reply)
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user