aptu-coder 0.28.0

MCP server for multi-language code structure analysis
Documentation
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
// SPDX-FileCopyrightText: 2026 aptu-coder contributors
// SPDX-License-Identifier: Apache-2.0

mod common;

use common::call_tool_raw;

/// edit_overwrite with working_dir writes the file inside working_dir, not server CWD.
#[tokio::test]
async fn edit_overwrite_working_dir_writes_inside_working_dir() {
    // Arrange: create a temp dir inside CWD to act as working_dir.
    let cwd = std::env::current_dir().expect("should get cwd");
    let temp_dir = tempfile::TempDir::new_in(&cwd).expect("should create temp dir in cwd");
    let working_dir = temp_dir
        .path()
        .to_str()
        .expect("temp dir path is valid UTF-8");
    let file_name = "output.txt";
    let expected_path = temp_dir.path().join(file_name);

    // Act: call edit_overwrite with a relative path and working_dir
    let resp = call_tool_raw(
        "edit_overwrite",
        serde_json::json!({
            "path": file_name,
            "content": "hello from working_dir",
            "working_dir": working_dir
        }),
    )
    .await;

    // Assert: tool must succeed and file must exist inside working_dir
    assert!(
        !resp["result"]["isError"].as_bool().unwrap_or(false),
        "expected success but got error: {resp}"
    );
    assert!(
        expected_path.exists(),
        "file should exist inside working_dir at {:?}",
        expected_path
    );
    let written = std::fs::read_to_string(&expected_path).expect("should read written file");
    assert_eq!(written, "hello from working_dir");
}

/// edit_overwrite without working_dir creates a new file relative to server CWD.
#[tokio::test]
async fn edit_overwrite_new_file_no_working_dir() {
    // Arrange: create a temp dir inside CWD for the target file.
    let cwd = std::env::current_dir().expect("should get cwd");
    let temp_dir = tempfile::TempDir::new_in(&cwd).expect("should create temp dir in cwd");
    let file_name = "new_output.txt";
    let expected_path = temp_dir.path().join(file_name);
    // Build the relative path from CWD to the temp dir file.
    let temp_stem = temp_dir
        .path()
        .file_name()
        .expect("temp dir has file name")
        .to_str()
        .expect("temp dir name is valid UTF-8");
    let relative_path = format!("{temp_stem}/{file_name}");

    // Act: call edit_overwrite without working_dir
    let resp = call_tool_raw(
        "edit_overwrite",
        serde_json::json!({
            "path": relative_path,
            "content": "hello no working_dir"
        }),
    )
    .await;

    // Assert: tool must succeed and file must exist and contain correct content
    assert!(
        !resp["result"]["isError"].as_bool().unwrap_or(false),
        "expected success but got error: {resp}"
    );
    assert!(
        expected_path.exists(),
        "file should exist at {:?}",
        expected_path
    );
    let written = std::fs::read_to_string(&expected_path).expect("should read written file");
    assert_eq!(written, "hello no working_dir");
}

/// edit_replace with working_dir modifies the correct file inside working_dir, not server CWD.
#[tokio::test]
async fn edit_replace_working_dir_modifies_inside_working_dir() {
    // Arrange: create a temp dir inside CWD with a pre-existing file.
    let cwd = std::env::current_dir().expect("should get cwd");
    let temp_dir = tempfile::TempDir::new_in(&cwd).expect("should create temp dir in cwd");
    let working_dir = temp_dir
        .path()
        .to_str()
        .expect("temp dir path is valid UTF-8");
    let file_name = "source.txt";
    let file_path = temp_dir.path().join(file_name);
    std::fs::write(&file_path, "old text here").expect("should write initial file");

    // Act: call edit_replace with a relative path and working_dir
    let resp = call_tool_raw(
        "edit_replace",
        serde_json::json!({
            "path": file_name,
            "old_text": "old text here",
            "new_text": "new text here",
            "working_dir": working_dir
        }),
    )
    .await;

    // Assert: tool must succeed and file inside working_dir must be updated
    assert!(
        !resp["result"]["isError"].as_bool().unwrap_or(false),
        "expected success but got error: {resp}"
    );
    let updated = std::fs::read_to_string(&file_path).expect("should read updated file");
    assert_eq!(updated, "new text here");
}

/// edit_overwrite on a read-only directory returns an Io error without leaking path in message.
///
/// edit_overwrite uses an atomic write (NamedTempFile + rename). rename(2) succeeds on a
/// read-only *file* as long as the parent directory is writable, so the test locks the
/// directory (0o555) rather than the file. A non-writable directory blocks both the temp-file
/// creation and the rename, producing the expected Io error on any privilege level.
#[cfg(unix)]
#[tokio::test]
async fn edit_overwrite_io_error_no_path_leak() {
    use std::fs::Permissions;
    use std::os::unix::fs::PermissionsExt;

    // Arrange: create a temp dir inside CWD with a file inside it.
    let cwd = std::env::current_dir().expect("should get cwd");
    let temp_dir = tempfile::TempDir::new_in(&cwd).expect("should create temp dir in cwd");
    let file_name = "readonly.txt";
    let file_path = temp_dir.path().join(file_name);
    std::fs::write(&file_path, "original content").expect("should write file");
    let working_dir = temp_dir
        .path()
        .to_str()
        .expect("temp dir path is valid UTF-8");

    // Lock the parent directory (0o555). This blocks NamedTempFile::new_in and rename(2),
    // which is what edit_overwrite uses internally (atomic write via tempfile + persist).
    std::fs::set_permissions(temp_dir.path(), Permissions::from_mode(0o555))
        .expect("should set directory permissions");

    // Root-skip: root can create files even in a non-writable directory on some kernels.
    // Probe by attempting to create a new file in the locked directory.
    let probe_path = temp_dir.path().join("probe");
    if std::fs::write(&probe_path, "probe").is_ok() {
        std::fs::set_permissions(temp_dir.path(), Permissions::from_mode(0o755)).ok();
        return;
    }

    // Act
    let resp = call_tool_raw(
        "edit_overwrite",
        serde_json::json!({
            "path": file_name,
            "content": "new content",
            "working_dir": working_dir
        }),
    )
    .await;

    // Restore directory permissions before TempDir drops (drop needs write access to rmdir).
    std::fs::set_permissions(temp_dir.path(), Permissions::from_mode(0o755)).ok();

    // Assert: error without path in message
    assert!(
        resp["result"]["isError"].as_bool().unwrap_or(false),
        "expected error but got success: {resp}"
    );
    let msg = resp["result"]["content"][0]["text"]
        .as_str()
        .expect("should have error text");
    assert!(
        !msg.contains(file_name),
        "error message must not contain file name: {msg}"
    );
    assert!(
        !msg.contains(working_dir),
        "error message must not contain working_dir path: {msg}"
    );
}

/// edit_overwrite reports invalid working_dir without exposing path in error message.
#[tokio::test]
async fn edit_overwrite_invalid_working_dir_no_path_leak() {
    // Arrange: use a non-existent path as working_dir
    let bad_wd = "/nonexistent-working-dir-for-edit-overwrite-test";
    let resp = call_tool_raw(
        "edit_overwrite",
        serde_json::json!({
            "path": "test.txt",
            "content": "hello",
            "working_dir": bad_wd
        }),
    )
    .await;

    // Assert: error without raw path in message
    assert!(
        resp["result"]["isError"].as_bool().unwrap_or(false),
        "expected error but got success: {resp}"
    );
    let msg = resp["result"]["content"][0]["text"]
        .as_str()
        .expect("should have error text");
    assert!(
        !msg.contains(bad_wd),
        "error message must not contain working_dir path: {msg}"
    );
}

/// edit_replace reports invalid working_dir without exposing path in error message.
#[tokio::test]
async fn edit_replace_invalid_working_dir_no_path_leak() {
    // Arrange: use a non-existent path as working_dir
    let bad_wd = "/nonexistent-working-dir-for-edit-replace-test";
    let resp = call_tool_raw(
        "edit_replace",
        serde_json::json!({
            "path": "test.txt",
            "old_text": "old",
            "new_text": "new",
            "working_dir": bad_wd
        }),
    )
    .await;

    // Assert: error without raw path in message
    assert!(
        resp["result"]["isError"].as_bool().unwrap_or(false),
        "expected error but got success: {resp}"
    );
    let msg = resp["result"]["content"][0]["text"]
        .as_str()
        .expect("should have error text");
    assert!(
        !msg.contains(bad_wd),
        "error message must not contain working_dir path: {msg}"
    );
}

#[tokio::test]
async fn test_edit_replace_empty_new_text_deletes_block() {
    let cwd = std::env::current_dir().expect("should get cwd");
    let temp_dir = tempfile::TempDir::new_in(&cwd).expect("should create temp dir in cwd");
    let working_dir = temp_dir
        .path()
        .to_str()
        .expect("temp dir path is valid UTF-8");
    let file_name = "delete_block.txt";
    let file_path = temp_dir.path().join(file_name);
    std::fs::write(&file_path, "line one\nDELETE ME\nline three\n").expect("should write file");

    let resp = call_tool_raw(
        "edit_replace",
        serde_json::json!({
            "path": file_name,
            "old_text": "DELETE ME\n",
            "new_text": "",
            "working_dir": working_dir
        }),
    )
    .await;

    assert!(
        !resp["result"]["isError"].as_bool().unwrap_or(false),
        "expected success, got: {resp}"
    );
    let content = std::fs::read_to_string(&file_path).expect("should read updated file");
    assert_eq!(content, "line one\nline three\n");
}

#[tokio::test]
async fn test_edit_replace_empty_new_text_entire_file() {
    let cwd = std::env::current_dir().expect("should get cwd");
    let temp_dir = tempfile::TempDir::new_in(&cwd).expect("should create temp dir in cwd");
    let working_dir = temp_dir
        .path()
        .to_str()
        .expect("temp dir path is valid UTF-8");
    let file_name = "whole_file.txt";
    let file_path = temp_dir.path().join(file_name);
    std::fs::write(&file_path, "entire content").expect("should write file");

    let resp = call_tool_raw(
        "edit_replace",
        serde_json::json!({
            "path": file_name,
            "old_text": "entire content",
            "new_text": "",
            "working_dir": working_dir
        }),
    )
    .await;

    assert!(
        !resp["result"]["isError"].as_bool().unwrap_or(false),
        "expected success, got: {resp}"
    );
    let content = std::fs::read_to_string(&file_path).expect("should read updated file");
    assert_eq!(
        content, "",
        "file should be empty after full-content deletion"
    );
}

/// edit_overwrite with a path whose parent directory does not exist returns INVALID_PARAMS.
#[tokio::test]
async fn test_edit_overwrite_new_file_missing_parent_dir() {
    // Arrange: create temp working_dir and try to write into a non-existent subdirectory
    let cwd = std::env::current_dir().expect("should get cwd");
    let temp_dir = tempfile::TempDir::new_in(&cwd).expect("should create temp dir in cwd");
    let working_dir = temp_dir
        .path()
        .to_str()
        .expect("temp dir path is valid UTF-8");
    // The parent "nonexistent" does not exist inside working_dir
    let file_name = "nonexistent/new_file.txt";

    // Act
    let resp = call_tool_raw(
        "edit_overwrite",
        serde_json::json!({
            "path": file_name,
            "content": "should not be written",
            "working_dir": working_dir
        }),
    )
    .await;

    // Assert
    assert!(
        resp["result"]["isError"].as_bool().unwrap_or(false),
        "expected error but got success: {resp}"
    );
}

/// edit_overwrite with a deeply nested path where only the top-level parent exists returns INVALID_PARAMS.
#[tokio::test]
async fn test_edit_overwrite_new_file_deeply_nested() {
    // Arrange: create temp working_dir with only a/ directory
    let cwd = std::env::current_dir().expect("should get cwd");
    let temp_dir = tempfile::TempDir::new_in(&cwd).expect("should create temp dir in cwd");
    let working_dir = temp_dir
        .path()
        .to_str()
        .expect("temp dir path is valid UTF-8");
    // Create only the top-level a/ directory
    std::fs::create_dir(temp_dir.path().join("a")).expect("should create dir a");
    // a/b/c/new.txt -- b/c does not exist
    let file_name = "a/b/c/new.txt";

    // Act
    let resp = call_tool_raw(
        "edit_overwrite",
        serde_json::json!({
            "path": file_name,
            "content": "should not be written",
            "working_dir": working_dir
        }),
    )
    .await;

    // Assert
    assert!(
        resp["result"]["isError"].as_bool().unwrap_or(false),
        "expected error but got success: {resp}"
    );
}

/// edit_overwrite where the parent is a symlink to a valid directory succeeds.
#[tokio::test]
async fn test_edit_overwrite_new_file_symlink_parent() {
    // Arrange: create a temp working_dir, a subdirectory, and a symlink pointing to it
    let cwd = std::env::current_dir().expect("should get cwd");
    let temp_dir = tempfile::TempDir::new_in(&cwd).expect("should create temp dir in cwd");
    let working_dir = temp_dir.path();
    // Create a real subdirectory
    let real_sub = working_dir.join("real_dir");
    std::fs::create_dir(&real_sub).expect("should create real_dir");
    // Create a symlink pointing to the real subdirectory
    let symlink_path = working_dir.join("link_to_real");
    std::os::unix::fs::symlink(&real_sub, &symlink_path)
        .expect("should create symlink to real_dir");
    let working_dir_str = working_dir.to_str().expect("temp dir path is valid UTF-8");
    let file_name = "link_to_real/through_symlink.txt";

    // Act
    let resp = call_tool_raw(
        "edit_overwrite",
        serde_json::json!({
            "path": file_name,
            "content": "written via symlink parent",
            "working_dir": working_dir_str
        }),
    )
    .await;

    // Assert: success, file exists in the canonical real_dir
    assert!(
        !resp["result"]["isError"].as_bool().unwrap_or(false),
        "expected success but got error: {resp}"
    );
    let expected_path = real_sub.join("through_symlink.txt");
    assert!(
        expected_path.exists(),
        "file should exist inside real_dir at {:?}",
        expected_path
    );
    let written =
        std::fs::read_to_string(&expected_path).expect("should read written file via symlink");
    assert_eq!(written, "written via symlink parent");
}

/// edit_overwrite where the parent component is a regular file returns INVALID_PARAMS.
#[tokio::test]
async fn test_edit_overwrite_parent_is_file() {
    // Arrange: create temp working_dir with a file that will be used as a "parent"
    let cwd = std::env::current_dir().expect("should get cwd");
    let temp_dir = tempfile::TempDir::new_in(&cwd).expect("should create temp dir in cwd");
    let working_dir = temp_dir
        .path()
        .to_str()
        .expect("temp dir path is valid UTF-8");
    // Create a regular file
    let file_path = temp_dir.path().join("not_a_dir.txt");
    std::fs::write(&file_path, "i am a file, not a directory").expect("should write test file");
    // Try to write "inside" that file as if it were a directory
    let file_name = "not_a_dir.txt/child.txt";

    // Act
    let resp = call_tool_raw(
        "edit_overwrite",
        serde_json::json!({
            "path": file_name,
            "content": "should not be written",
            "working_dir": working_dir
        }),
    )
    .await;

    // Assert
    assert!(
        resp["result"]["isError"].as_bool().unwrap_or(false),
        "expected error but got success: {resp}"
    );
}

/// edit_overwrite with absolute path outside CWD and no working_dir succeeds.
#[tokio::test]
async fn edit_overwrite_absolute_path_outside_cwd_no_working_dir() {
    // Arrange: create a temp dir outside CWD (TempDir::new() uses system temp dir).
    let temp_dir = tempfile::TempDir::new().expect("should create temp dir outside cwd");
    let file_path = temp_dir.path().join("outside_cwd.txt");
    let path_str = file_path.to_str().expect("path is valid UTF-8").to_string();

    // Act: call edit_overwrite with absolute path and no working_dir
    let resp = call_tool_raw(
        "edit_overwrite",
        serde_json::json!({
            "path": path_str,
            "content": "written outside CWD"
        }),
    )
    .await;

    // Assert: tool must succeed and file must exist with correct content
    assert!(
        !resp["result"]["isError"].as_bool().unwrap_or(false),
        "expected success but got error: {resp}"
    );
    assert!(
        file_path.exists(),
        "file should exist outside CWD at {:?}",
        file_path
    );
    let written = std::fs::read_to_string(&file_path).expect("should read written file");
    assert_eq!(written, "written outside CWD");
}

/// edit_replace with absolute path outside CWD and no working_dir succeeds.
#[tokio::test]
async fn edit_replace_absolute_path_outside_cwd_no_working_dir() {
    // Arrange: create a temp dir outside CWD with a pre-existing file.
    let temp_dir = tempfile::TempDir::new().expect("should create temp dir outside cwd");
    let file_path = temp_dir.path().join("outside_cwd.txt");
    std::fs::write(&file_path, "old content").expect("should write initial file");
    let path_str = file_path.to_str().expect("path is valid UTF-8").to_string();

    // Act: call edit_replace with absolute path and no working_dir
    let resp = call_tool_raw(
        "edit_replace",
        serde_json::json!({
            "path": path_str,
            "old_text": "old content",
            "new_text": "new content"
        }),
    )
    .await;

    // Assert: tool must succeed and file must be updated
    assert!(
        !resp["result"]["isError"].as_bool().unwrap_or(false),
        "expected success but got error: {resp}"
    );
    let updated = std::fs::read_to_string(&file_path).expect("should read updated file");
    assert_eq!(updated, "new content");
}

/// edit_overwrite with nonexistent parent directory and no working_dir still fails.
#[tokio::test]
async fn edit_overwrite_nonexistent_parent_outside_cwd_no_working_dir() {
    // Arrange: create a temp dir outside CWD, use a path whose parent does not exist.
    let temp_dir = tempfile::TempDir::new().expect("should create temp dir outside cwd");
    let nonexistent_parent = temp_dir.path().join("nonexistent_subdir").join("child.txt");
    let path_str = nonexistent_parent
        .to_str()
        .expect("path is valid UTF-8")
        .to_string();

    // Act: call edit_overwrite with absolute path whose parent does not exist
    let resp = call_tool_raw(
        "edit_overwrite",
        serde_json::json!({
            "path": path_str,
            "content": "should not be written"
        }),
    )
    .await;

    // Assert: tool must fail because parent does not exist
    assert!(
        resp["result"]["isError"].as_bool().unwrap_or(false),
        "expected error but got success: {resp}"
    );
}

/// edit_overwrite with ../ traversal path resolving outside CWD and no working_dir succeeds.
#[tokio::test]
async fn edit_overwrite_traversal_path_outside_cwd_no_working_dir() {
    // Arrange: create a temp dir outside CWD, compute a relative traversal from CWD to it.
    let temp_dir = tempfile::TempDir::new().expect("should create temp dir outside cwd");
    let file_path = temp_dir.path().join("traversal.txt");
    let cwd = std::env::current_dir().expect("should get cwd");

    // Build a relative path from CWD to the target file using ../ traversal.
    // Go up from CWD to root, then descend to the target file.
    let up_count = cwd.components().count();
    let mut rel = std::path::PathBuf::new();
    for _ in 0..up_count {
        rel.push("..");
    }
    let file_str = file_path.to_str().expect("path is valid UTF-8");
    let file_without_root = file_str.trim_start_matches('/');
    rel.push(file_without_root);
    let relative_str = rel
        .to_str()
        .expect("relative path is valid UTF-8")
        .to_string();

    // Act: call edit_overwrite with the relative traversal path and no working_dir
    let resp = call_tool_raw(
        "edit_overwrite",
        serde_json::json!({
            "path": relative_str,
            "content": "written via traversal"
        }),
    )
    .await;

    // Assert: tool must succeed (traversal outside CWD now allowed without working_dir)
    assert!(
        !resp["result"]["isError"].as_bool().unwrap_or(false),
        "expected success but got error: {resp}"
    );
    assert!(file_path.exists(), "file should exist at {:?}", file_path);
    let written = std::fs::read_to_string(&file_path).expect("should read written file");
    assert_eq!(written, "written via traversal");
}