picoclaw/pkg
admin-mf 9a0b281734 forward-port: multi-tenancy hint plumbing on agent processOptions (phase 1)
Re-applies the tenant-isolation extension from the deleted pkg/agent/loop.go
to upstream's split agent_*.go layout. Phase 1 plumbs the protocol; Phase 2
(future PR) wires effective sessions / provider / context per turn.

What's added:
- New file pkg/agent/agent_tenant.go (kept isolated for sync friendliness):
  - extractTenantOverrides reads workspace_override, config_dir,
    allowed_tools, allowed_skills from msg.Context.Raw
  - Validates workspace_override and config_dir resolve within the
    workspace_root boundary set in agents.defaults; rejects path escape
  - Fails closed when any override is present but workspace_root is unset,
    so tenants cannot bypass the security boundary
  - applyTo copies the overrides onto processOptions
  - logIfPresent logs a single line summarising tenant routing per turn
- processOptions in agent.go gains four override fields (WorkspaceOverride,
  ConfigDir, AllowedTools, AllowedSkills)
- agent_message.go processMessage extracts and applies the overrides right
  after building processOptions
- agent_tenant_test.go covers the happy path, escape rejection, missing
  boundary rejection, and CSV parsing

Phase 2 will introduce effSessions, effContextBuilder, effProvider, effModel
on processOptions and thread them through pipeline_llm/turn_state/context_*
so each tenant turn runs against an isolated session store, context builder,
and provider credential set. Phase 2 is deferred because:
- MagicForm doesn't currently send webhook traffic (verified), so phase 1's
  protocol-level plumbing has no live consumer that requires the swap yet.
- Phase 2 needs design discussion (per-tenant credential storage, session
  backend selection) that warrants its own focused PR.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-07 12:20:23 -05:00
..
agent forward-port: multi-tenancy hint plumbing on agent processOptions (phase 1) 2026-05-07 12:20:23 -05:00
audio feat(provider,web,asr): enhance model management with explicit provider metadata (#2701) 2026-05-06 16:06:49 +08:00
auth Merge upstream/main into sync/upstream-2026-05-07 2026-05-07 12:12:44 -05:00
bus Merge upstream/main into sync/upstream-2026-05-07 2026-05-07 12:12:44 -05:00
channels Merge upstream/main into sync/upstream-2026-05-07 2026-05-07 12:12:44 -05:00
commands feat(agent): stop command 2026-05-04 08:41:29 +02:00
config Merge upstream/main into sync/upstream-2026-05-07 2026-05-07 12:12:44 -05:00
constants refactor: replace bool map with set-style map for internal channels (#472) 2026-02-19 11:48:17 +01:00
credential refactor config and security to simplified the structure (#2068) 2026-03-28 00:03:34 +08:00
cron refactor(cron): remove deliver and type params, unify agent execution path (#2147) 2026-03-29 22:52:34 +08:00
devices refactor(runtime): drop non-session legacy context compatibility 2026-04-01 20:56:48 +08:00
events fix(events): keep runtime observers non-blocking 2026-04-27 13:09:03 +08:00
fileutil Merge pull request #1829 from perhapzz/test/add-fileutil-health-tests 2026-03-26 10:42:13 +01:00
gateway forward-port: register magicform channel in gateway init 2026-05-07 12:13:10 -05:00
health fix(host): modernize default host selection order 2026-04-14 14:03:23 +08:00
heartbeat refactor(runtime): drop non-session legacy context compatibility 2026-04-01 20:56:48 +08:00
identity fix(identity): support negative integers in isNumeric for Telegram group IDs 2026-03-21 17:09:02 +07:00
isolation fix: treat PID=1 as stale in PID file singleton check, fix govet shadow, add .gitattributes (#2642) 2026-04-24 15:26:34 +08:00
logger unify all panic event to panic log file (#2250) 2026-04-01 23:26:49 +08:00
mcp fix(events): keep runtime observers non-blocking 2026-04-27 13:09:03 +08:00
media Fix 1886 media cleanup policy (#1887) 2026-03-23 12:13:59 +08:00
memory fix(message): ignore transient assistant thoughts in message count and history truncation 2026-04-25 12:26:28 +08:00
migrate refactor(config): make config.Channel to multiple instance support 2026-04-13 22:21:21 +08:00
netbind fix(web): address latest Copilot review points 2026-04-14 23:39:59 +08:00
pathutil feat(security): unify workspace_root boundary enforcement across CLI and gateway 2026-03-06 13:14:15 -06:00
pid fix: treat PID=1 as stale in PID file singleton check, fix govet shadow, add .gitattributes (#2642) 2026-04-24 15:26:34 +08:00
providers feat(provider,web,asr): enhance model management with explicit provider metadata (#2701) 2026-05-06 16:06:49 +08:00
routing feat(routing): add ordered dispatch rules 2026-04-01 22:13:04 +08:00
seahorse fix(seahorse): enforce target token thresholds for leaf summaries 2026-05-04 14:10:42 +02:00
session fix(reasoning): persist canonical history for DeepSeek and web chat 2026-04-24 21:45:41 +08:00
skills Merge upstream/main into sync/upstream-2026-05-07 2026-05-07 12:12:44 -05:00
state refactor Config to add Version and migratable 2026-03-12 13:52:55 +08:00
tokenizer feat(seahorse): implement short-term memory engine (LCM) (#2285) 2026-04-05 09:05:16 +08:00
tools forward-port: write size cap + crypto/rand temp suffixes in fs sandbox 2026-05-07 12:16:13 -05:00
updater fix(updater): retry release fetches (#2511) 2026-04-14 10:44:21 +08:00
utils Merge pull request #2670 from david1gp/fix/tool-feedback-pretty-print 2026-05-04 21:47:32 +02:00
env.go Merge branch 'main' into version 2026-03-19 18:04:58 +08:00