feat(research): wire tools + research workflow graph (research-workflow §2/§3)

Makes the research feature runnable end-to-end, off by default.

- config: [tools.research] (enabled, searxng_url, max_results, max_fetch_bytes).
- registration: web_search/web_fetch are built into BOTH the default and per-workspace
  tool registries when research.enabled, sharing one HTTP client threaded from Main
  (none built on the static path). Egress stays harness-enforced: web_fetch is T2
  (operator-approved) and the existing NetworkHostRule still applies.
- workflow: examples/workflows/research.toml — decompose → gather → report, with the
  three artifact schemas and prompts. Fan-out (search per sub-question, fetch per source)
  runs as repeated tool calls inside the gather stage (Correx has no parallel agents);
  per-source synthesis into the dossier is the compression step, so the report stage
  consumes summaries, never raw pages. ResearchWorkflowTest validates the graph contract.

To run: set [tools.research].enabled, register the 3 [[artifacts]], copy research.toml +
prompts + schemas into the workflows dir, start SearXNG. Launch like any workflow (the
T2 fetch approval surfaces as an approval card; the report opens in the artifact viewer).

Follow-ups (noted, not blocking): batch fetch-approval at the source-list level (§3),
a dedicated SourceFetched/LowQualityExtraction event (quality + content hash are already
in tool-result metadata), dynamic per-session egress allowlist, and the web approval client (§6).
This commit is contained in:
2026-06-13 23:18:19 +04:00
parent ad2d38ce46
commit 7a0d4d0ee2
11 changed files with 321 additions and 1 deletions
@@ -125,6 +125,7 @@ data class ToolsConfig(
val networkAllowedHosts: List<String> = emptyList(),
val networkDeniedHosts: List<String> = emptyList(),
val allowedWorkspaceRoots: List<String> = emptyList(),
val research: ResearchConfig = ResearchConfig(),
) {
companion object {
val DEFAULT_PRIVILEGED_LOCATIONS: List<String> = listOf(
@@ -138,6 +139,19 @@ data class ToolsConfig(
}
}
/**
* Deep-research workflow (research-workflow-spec). Off by default: enabling it registers the
* network tools web_search (T1, hits only [searxngUrl]) and web_fetch (T2, operator-approved).
* [searxngUrl] is the self-hosted SearXNG endpoint; [maxFetchBytes] caps a single fetched page.
*/
@Serializable
data class ResearchConfig(
val enabled: Boolean = false,
val searxngUrl: String = "http://localhost:8888",
val maxResults: Int = 8,
val maxFetchBytes: Long = 10_000_000,
)
@Serializable
data class ProviderConfig(
val id: String,