fix(session): restore sandbox-fs after agent-run quiesce

Agent runs quiesced stdio MCP extensions including sandbox-fs, but reconcile
skipped re-adding missing stdio extensions and treated absent listings as OK.
Preserve sandbox-fs across quiesce and re-add other required stdio extensions
on the next reconcile so generate_image and write_file stay available.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
john
2026-08-07 15:49:04 +08:00
parent 49ff7c9bad
commit d523b9595d
4 changed files with 96 additions and 20 deletions
+1 -4
View File
@@ -86,9 +86,6 @@ export function extensionsNeedingRefresh(currentExtensions, desiredExtensions) {
if (!name) continue; if (!name) continue;
const exists = current.some((ext) => extensionName(ext) === name); const exists = current.some((ext) => extensionName(ext) === name);
if (!exists) { if (!exists) {
// goosed may omit active stdio MCP extensions from the session listing
// even though /agent/start already loaded them; do not hot-add stdio.
if (String(config?.type ?? '') === 'stdio') continue;
toAdd.push(config); toAdd.push(config);
} }
} }
@@ -98,7 +95,7 @@ export function extensionsNeedingRefresh(currentExtensions, desiredExtensions) {
function stdioListingOmissionAllowed(currentExt, desiredConfig) { function stdioListingOmissionAllowed(currentExt, desiredConfig) {
if (String(desiredConfig?.type ?? '') !== 'stdio') return false; if (String(desiredConfig?.type ?? '') !== 'stdio') return false;
if (!currentExt) return true; if (!currentExt) return false;
const currentExec = extensionExecutionConfig(currentExt); const currentExec = extensionExecutionConfig(currentExt);
const desiredExec = extensionExecutionConfig(desiredConfig); const desiredExec = extensionExecutionConfig(desiredConfig);
return currentExec.type === 'stdio' return currentExec.type === 'stdio'
+79 -11
View File
@@ -122,22 +122,24 @@ test('extensionsNeedingRefresh adds missing extensions', () => {
assert.equal(toAdd[0].name, 'summon'); assert.equal(toAdd[0].name, 'summon');
}); });
test('extensionsNeedingRefresh does not hot-add missing stdio extensions', () => { test('extensionsNeedingRefresh re-adds missing stdio extensions after quiesce', () => {
const desiredSandbox = {
type: 'stdio',
name: 'sandbox-fs',
cmd: '/usr/local/bin/node',
args: ['/opt/portal/mindspace-sandbox-mcp.mjs', '/tmp/user-1'],
available_tools: ['read_file', 'generate_image'],
};
const { toRemove, toAdd } = extensionsNeedingRefresh( const { toRemove, toAdd } = extensionsNeedingRefresh(
[{ name: 'developer', available_tools: ['read_image'] }], [{ name: 'developer', available_tools: ['read_image'] }],
[ [
{ name: 'developer', available_tools: ['read_image'] }, { name: 'developer', available_tools: ['read_image'] },
{ desiredSandbox,
type: 'stdio',
name: 'sandbox-fs',
cmd: '/usr/local/bin/node',
args: ['/opt/portal/mindspace-sandbox-mcp.mjs', '/tmp/user-1'],
available_tools: ['read_file'],
},
], ],
); );
assert.deepEqual(toRemove, []); assert.deepEqual(toRemove, []);
assert.deepEqual(toAdd, []); assert.equal(toAdd.length, 1);
assert.equal(toAdd[0].name, 'sandbox-fs');
}); });
test('extensionPolicyViolations reports unexpected, duplicate, and mismatched extensions', () => { test('extensionPolicyViolations reports unexpected, duplicate, and mismatched extensions', () => {
@@ -161,7 +163,7 @@ test('extensionPolicyViolations reports unexpected, duplicate, and mismatched ex
); );
}); });
test('extensionPolicyViolations ignores stdio extensions omitted from goosed listing', () => { test('extensionPolicyViolations flags stdio extensions missing from goosed listing', () => {
assert.deepEqual( assert.deepEqual(
extensionPolicyViolations( extensionPolicyViolations(
[{ name: 'developer', available_tools: ['read_image'] }], [{ name: 'developer', available_tools: ['read_image'] }],
@@ -186,7 +188,7 @@ test('extensionPolicyViolations ignores stdio extensions omitted from goosed lis
{ {
unexpected: [], unexpected: [],
duplicate: [], duplicate: [],
missingOrMismatched: [], missingOrMismatched: ['sandbox-fs', 'tkmind-search'],
}, },
); );
}); });
@@ -334,6 +336,72 @@ test('reconcileAgentSession restarts after adding missing extensions', async ()
]); ]);
}); });
test('reconcileAgentSession restarts after re-adding quiesced stdio extensions', async () => {
const calls = [];
let extensionReads = 0;
const desiredSandbox = {
type: 'stdio',
name: 'sandbox-fs',
cmd: '/usr/local/bin/node',
args: ['/opt/portal/mindspace-sandbox-mcp.mjs', '/tmp/user-1'],
available_tools: ['write_file', 'generate_image'],
};
const apiFetch = async (pathname) => {
calls.push(pathname);
if (pathname === '/sessions/session-1') {
return {
ok: true,
text: async () => JSON.stringify({ working_dir: '/valid/workspace' }),
};
}
if (pathname === '/sessions/session-1/extensions') {
extensionReads += 1;
return {
ok: true,
text: async () =>
JSON.stringify({
extensions:
extensionReads === 1
? [{ name: 'developer', available_tools: ['read_image'] }]
: [desiredSandbox, { name: 'developer', available_tools: ['read_image'] }],
}),
};
}
if (
pathname === '/agent/add_extension'
|| pathname === '/agent/restart'
) {
return {
ok: true,
text: async () => JSON.stringify({ ok: true }),
};
}
const harness = harnessMemoryResponse(pathname);
if (harness) return harness;
throw new Error(`unexpected path: ${pathname}`);
};
await reconcileAgentSession(apiFetch, 'session-1', {
workingDir: '/valid/workspace',
sessionPolicy: {
extensionOverrides: [
{ name: 'developer', available_tools: ['read_image'] },
desiredSandbox,
],
},
});
assert.deepEqual(calls, [
'/sessions/session-1',
'/sessions/session-1/extensions',
'/agent/add_extension',
'/agent/restart',
'/sessions/session-1/extensions',
'/agent/harness_remember',
'/agent/harness_bootstrap',
]);
});
test('reconcileAgentSession fails closed when restart does not apply the requested policy', async () => { test('reconcileAgentSession fails closed when restart does not apply the requested policy', async () => {
const apiFetch = async (pathname) => { const apiFetch = async (pathname) => {
if (pathname === '/sessions/session-1') { if (pathname === '/sessions/session-1') {
+7 -1
View File
@@ -2,6 +2,9 @@ function extensionName(config) {
return String(config?.name ?? '').trim(); return String(config?.name ?? '').trim();
} }
/** Stdio MCP extensions that must survive agent-run quiesce (page write + image gen). */
export const PRESERVED_STDIO_EXTENSIONS = new Set(['sandbox-fs']);
async function readJson(response) { async function readJson(response) {
const text = await response.text(); const text = await response.text();
if (!response.ok) { if (!response.ok) {
@@ -52,6 +55,7 @@ export async function cancelSessionActiveRequest(apiFetch, sessionId, requestId)
/** /**
* Stop per-session stdio MCP children while preserving the Goose conversation. * Stop per-session stdio MCP children while preserving the Goose conversation.
* Session reconciliation restores the required extensions before the next turn. * Session reconciliation restores the required extensions before the next turn.
* Critical page tools (sandbox-fs) stay attached so the next turn is not tool-less.
*/ */
export async function quiesceSessionStdioExtensions(apiFetch, sessionId) { export async function quiesceSessionStdioExtensions(apiFetch, sessionId) {
const normalizedSessionId = String(sessionId ?? '').trim(); const normalizedSessionId = String(sessionId ?? '').trim();
@@ -60,7 +64,9 @@ export async function quiesceSessionStdioExtensions(apiFetch, sessionId) {
const payload = await readJson( const payload = await readJson(
await apiFetch(`/sessions/${encodeURIComponent(normalizedSessionId)}/extensions`), await apiFetch(`/sessions/${encodeURIComponent(normalizedSessionId)}/extensions`),
); );
const names = sessionStdioExtensionNames(payload?.extensions); const names = sessionStdioExtensionNames(payload?.extensions).filter(
(name) => !PRESERVED_STDIO_EXTENSIONS.has(name),
);
const removed = []; const removed = [];
for (const name of names) { for (const name of names) {
await readJson( await readJson(
+9 -4
View File
@@ -2,6 +2,7 @@ import assert from 'node:assert/strict';
import test from 'node:test'; import test from 'node:test';
import { import {
cancelSessionActiveRequest, cancelSessionActiveRequest,
PRESERVED_STDIO_EXTENSIONS,
quiesceSessionStdioExtensions, quiesceSessionStdioExtensions,
sessionStdioExtensionNames, sessionStdioExtensionNames,
} from './session-runtime-lifecycle.mjs'; } from './session-runtime-lifecycle.mjs';
@@ -82,7 +83,7 @@ test('quiesceSessionStdioExtensions removes stdio children without deleting sess
const result = await quiesceSessionStdioExtensions(apiFetch, 'session-1'); const result = await quiesceSessionStdioExtensions(apiFetch, 'session-1');
assert.deepEqual(result, { assert.deepEqual(result, {
removed: ['sandbox-fs', 'tkmind-search'], removed: ['tkmind-search'],
skipped: false, skipped: false,
}); });
assert.deepEqual( assert.deepEqual(
@@ -90,23 +91,27 @@ test('quiesceSessionStdioExtensions removes stdio children without deleting sess
[ [
'/sessions/session-1/extensions', '/sessions/session-1/extensions',
'/agent/remove_extension', '/agent/remove_extension',
'/agent/remove_extension',
], ],
); );
assert.deepEqual( assert.deepEqual(
calls.slice(1).map(({ init }) => JSON.parse(init.body)), calls.slice(1).map(({ init }) => JSON.parse(init.body)),
[ [
{ session_id: 'session-1', name: 'sandbox-fs' },
{ session_id: 'session-1', name: 'tkmind-search' }, { session_id: 'session-1', name: 'tkmind-search' },
], ],
); );
assert.equal(PRESERVED_STDIO_EXTENSIONS.has('sandbox-fs'), true);
assert.equal(calls.some(({ pathname }) => pathname.includes('delete')), false); assert.equal(calls.some(({ pathname }) => pathname.includes('delete')), false);
}); });
test('quiesceSessionStdioExtensions fails when upstream removal is not acknowledged', async () => { test('quiesceSessionStdioExtensions fails when upstream removal is not acknowledged', async () => {
const apiFetch = async (pathname) => { const apiFetch = async (pathname) => {
if (pathname.endsWith('/extensions')) { if (pathname.endsWith('/extensions')) {
return jsonResponse({ extensions: [{ name: 'sandbox-fs', type: 'stdio' }] }); return jsonResponse({
extensions: [
{ name: 'sandbox-fs', type: 'stdio' },
{ name: 'tkmind-search', type: 'stdio' },
],
});
} }
return jsonResponse({ message: 'remove failed' }, { ok: false, status: 500 }); return jsonResponse({ message: 'remove failed' }, { ok: false, status: 500 });
}; };