Skip to main content

lean_ctx/server/
mod.rs

1pub mod bounded_lock;
2pub mod bypass_hint;
3pub mod compaction_sync;
4pub mod context_gate;
5mod dispatch;
6pub mod dynamic_tools;
7pub mod elicitation;
8pub(crate) mod execute;
9pub mod helpers;
10pub mod multi_path;
11pub mod notifications;
12pub mod progress;
13pub mod prompts;
14pub mod reference_store;
15pub mod registry;
16pub mod resources;
17pub mod role_guard;
18pub mod roots;
19pub mod tool_trait;
20
21use futures::FutureExt;
22use rmcp::handler::server::ServerHandler;
23use rmcp::model::{
24    CallToolRequestParams, CallToolResult, Content, Implementation, InitializeRequestParams,
25    InitializeResult, ListToolsResult, PaginatedRequestParams, ServerCapabilities, ServerInfo,
26};
27use rmcp::service::{RequestContext, RoleServer};
28use rmcp::ErrorData;
29
30use crate::tools::{CrpMode, LeanCtxServer};
31
32impl ServerHandler for LeanCtxServer {
33    fn get_info(&self) -> ServerInfo {
34        let capabilities = ServerCapabilities::builder()
35            .enable_tools()
36            .enable_resources()
37            .enable_resources_subscribe()
38            .enable_prompts()
39            .build();
40
41        let config = crate::core::config::Config::load();
42        let level = crate::core::config::CompressionLevel::effective(&config);
43        let _ = crate::core::terse::rules_inject::inject(&level);
44
45        let instructions = crate::instructions::build_instructions(CrpMode::effective());
46
47        InitializeResult::new(capabilities)
48            .with_server_info(Implementation::new("lean-ctx", env!("CARGO_PKG_VERSION")))
49            .with_instructions(instructions)
50    }
51
52    async fn initialize(
53        &self,
54        request: InitializeRequestParams,
55        context: RequestContext<RoleServer>,
56    ) -> Result<InitializeResult, ErrorData> {
57        let name = request.client_info.name.clone();
58        tracing::info!("MCP client connected: {:?}", name);
59        *self.client_name.write().await = name.clone();
60        *self.peer.write().await = Some(context.peer.clone());
61
62        if self.session_mode != crate::tools::SessionMode::Shared {
63            crate::core::budget_tracker::BudgetTracker::global().reset();
64            if let Ok(data_dir) = crate::core::data_dir::lean_ctx_data_dir() {
65                let radar = data_dir.join("context_radar.jsonl");
66                if radar.exists() {
67                    let prev = data_dir.join("context_radar.prev.jsonl");
68                    let _ = std::fs::rename(&radar, &prev);
69                }
70            }
71        }
72
73        let has_roots = request.capabilities.roots.is_some();
74        self.has_client_roots
75            .store(has_roots, std::sync::atomic::Ordering::Relaxed);
76        if has_roots {
77            tracing::info!("Client supports MCP roots/list — will resolve on first tool call");
78        }
79
80        let env_root = roots::root_from_env();
81        let derived_root = derive_project_root_from_cwd();
82        let effective_root = env_root.or(derived_root);
83
84        let cwd_str = std::env::current_dir()
85            .ok()
86            .map(|p| p.to_string_lossy().to_string())
87            .unwrap_or_default();
88        {
89            let mut session = self.session.write().await;
90            if !cwd_str.is_empty() {
91                session.shell_cwd = Some(cwd_str.clone());
92            }
93            if let Some(ref root) = effective_root {
94                session.project_root = Some(root.clone());
95                tracing::info!("Project root set to: {root}");
96            } else if let Some(ref root) = session.project_root {
97                let root_path = std::path::Path::new(root);
98                let root_has_marker = has_project_marker(root_path);
99                let root_str = root_path.to_string_lossy();
100                let root_suspicious = root_str.contains("/.claude")
101                    || root_str.contains("/.codex")
102                    || root_str.contains("/var/folders/")
103                    || root_str.contains("/tmp/")
104                    || root_str.contains("\\.claude")
105                    || root_str.contains("\\.codex")
106                    || root_str.contains("\\AppData\\Local\\Temp")
107                    || root_str.contains("\\Temp\\");
108                if root_suspicious && !root_has_marker {
109                    session.project_root = None;
110                }
111            }
112            let cfg_extra = crate::core::config::Config::load().extra_roots;
113            if !cfg_extra.is_empty() {
114                let existing: std::collections::HashSet<_> =
115                    session.extra_roots.iter().cloned().collect();
116                for r in cfg_extra {
117                    if !existing.contains(&r) {
118                        session.extra_roots.push(r);
119                    }
120                }
121            }
122            if self.session_mode == crate::tools::SessionMode::Shared {
123                if let Some(ref root) = session.project_root {
124                    if let Some(ref rt) = self.context_os {
125                        rt.shared_sessions.persist_best_effort(
126                            root,
127                            &self.workspace_id,
128                            &self.channel_id,
129                            &session,
130                        );
131                        rt.metrics.record_session_persisted();
132                    }
133                }
134            } else {
135                let _ = session.save();
136            }
137        }
138
139        if let Some(ref root) = effective_root {
140            crate::core::index_orchestrator::ensure_all_background(root);
141        }
142
143        let agent_name = name.clone();
144        let agent_root = effective_root.clone().unwrap_or_default();
145        let agent_id_handle = self.agent_id.clone();
146        tokio::task::spawn_blocking(move || {
147            if std::env::var("LEAN_CTX_HEADLESS").is_ok() {
148                return;
149            }
150
151            // Avoid startup stampedes when multiple agent sessions initialize at once.
152            // These are best-effort maintenance tasks; it's fine to skip if another
153            // lean-ctx instance is already doing them.
154            let maintenance = crate::core::startup_guard::try_acquire_lock(
155                "startup-maintenance",
156                std::time::Duration::from_secs(2),
157                std::time::Duration::from_mins(2),
158            );
159            if maintenance.is_some() {
160                if let Some(home) = dirs::home_dir() {
161                    let _ = crate::rules_inject::inject_all_rules(&home);
162                }
163                crate::hooks::refresh_installed_hooks();
164                crate::core::version_check::check_background();
165            }
166            drop(maintenance);
167
168            if !agent_root.is_empty() {
169                let heuristic_role = match agent_name.to_lowercase().as_str() {
170                    n if n.contains("cursor") => Some("coder"),
171                    n if n.contains("claude") => Some("coder"),
172                    n if n.contains("codex") => Some("coder"),
173                    n if n.contains("antigravity") || n.contains("gemini") => Some("coder"),
174                    n if n.contains("review") => Some("reviewer"),
175                    n if n.contains("test") => Some("debugger"),
176                    _ => None,
177                };
178                let env_role = std::env::var("LEAN_CTX_ROLE")
179                    .or_else(|_| std::env::var("LEAN_CTX_AGENT_ROLE"))
180                    .ok();
181                let effective_role = env_role.as_deref().or(heuristic_role).unwrap_or("coder");
182
183                let _ = crate::core::roles::set_active_role_with_source(effective_role, true);
184
185                let mut registry = crate::core::agents::AgentRegistry::load_or_create();
186                registry.cleanup_stale(24);
187                let id = registry.register("mcp", Some(effective_role), &agent_root);
188                let _ = registry.save();
189                if let Ok(mut guard) = agent_id_handle.try_write() {
190                    *guard = Some(id);
191                }
192            }
193        });
194
195        let client_caps = crate::core::client_capabilities::ClientMcpCapabilities::detect(&name);
196        tracing::info!("Client capabilities: {}", client_caps.format_summary());
197
198        {
199            let cfg = crate::core::config::Config::load();
200            let cats = cfg.default_tool_categories_effective();
201            dynamic_tools::init_from_config(&cats);
202        }
203
204        if client_caps.dynamic_tools {
205            if let Ok(mut dt) = dynamic_tools::global().lock() {
206                dt.set_supports_list_changed(true);
207            }
208        }
209        if let Some(max) = client_caps.max_tools {
210            if let Ok(mut dt) = dynamic_tools::global().lock() {
211                dt.set_supports_list_changed(true);
212                if max < 100 {
213                    dt.unload_category(dynamic_tools::ToolCategory::Debug);
214                    dt.unload_category(dynamic_tools::ToolCategory::Memory);
215                }
216            }
217        }
218
219        crate::core::client_capabilities::set_detected(&client_caps);
220
221        let instructions =
222            crate::instructions::build_instructions_with_client(CrpMode::effective(), &name);
223
224        let capabilities = match (client_caps.resources, client_caps.prompts) {
225            (true, true) => ServerCapabilities::builder()
226                .enable_tools()
227                .enable_resources()
228                .enable_resources_subscribe()
229                .enable_prompts()
230                .build(),
231            (true, false) => ServerCapabilities::builder()
232                .enable_tools()
233                .enable_resources()
234                .enable_resources_subscribe()
235                .build(),
236            (false, true) => ServerCapabilities::builder()
237                .enable_tools()
238                .enable_prompts()
239                .build(),
240            (false, false) => ServerCapabilities::builder().enable_tools().build(),
241        };
242
243        Ok(InitializeResult::new(capabilities)
244            .with_server_info(Implementation::new("lean-ctx", env!("CARGO_PKG_VERSION")))
245            .with_instructions(instructions))
246    }
247
248    async fn list_tools(
249        &self,
250        _request: Option<PaginatedRequestParams>,
251        _context: RequestContext<RoleServer>,
252    ) -> Result<ListToolsResult, ErrorData> {
253        let all_tools = if crate::tool_defs::is_full_mode() {
254            if let Some(ref reg) = self.registry {
255                reg.tool_defs()
256            } else {
257                crate::tool_defs::granular_tool_defs()
258            }
259        } else if std::env::var("LEAN_CTX_UNIFIED").is_ok() {
260            crate::tool_defs::unified_tool_defs()
261        } else if let Some(ref reg) = self.registry {
262            let core_names = crate::tool_defs::core_tool_names();
263            reg.tool_defs()
264                .into_iter()
265                .filter(|t| core_names.contains(&t.name.as_ref()))
266                .collect()
267        } else {
268            crate::tool_defs::lazy_tool_defs()
269        };
270
271        let disabled = crate::core::config::Config::load().disabled_tools_effective();
272        let client = self.client_name.read().await.clone();
273        let is_zed = !client.is_empty() && client.to_lowercase().contains("zed");
274
275        let active_role = crate::core::roles::active_role();
276        let tools: Vec<_> = all_tools
277            .into_iter()
278            .filter(|t| {
279                let name = t.name.as_ref();
280                if !disabled.is_empty() && disabled.iter().any(|d| d.as_str() == name) {
281                    return false;
282                }
283                if is_zed && name == "ctx_edit" {
284                    return false;
285                }
286                if !active_role.is_tool_allowed(name) {
287                    return false;
288                }
289                true
290            })
291            .collect();
292
293        let tools = {
294            let Ok(dyn_state) = dynamic_tools::global().lock() else {
295                tracing::warn!("dynamic_tools mutex poisoned in list_tools; returning unfiltered");
296                return Ok(ListToolsResult {
297                    tools,
298                    ..Default::default()
299                });
300            };
301            if dyn_state.supports_list_changed() {
302                tools
303                    .into_iter()
304                    .filter(|t| dyn_state.is_tool_active(t.name.as_ref()))
305                    .collect()
306            } else {
307                tools
308            }
309        };
310
311        let tools = {
312            let active = self.workflow.read().await.clone();
313            if let Some(run) = active {
314                if run.current == "done" || is_workflow_stale(&run) {
315                    let mut wf = self.workflow.write().await;
316                    *wf = None;
317                    let _ = crate::core::workflow::clear_active();
318                } else if let Some(state) = run.spec.state(&run.current) {
319                    if let Some(allowed) = &state.allowed_tools {
320                        let mut allow: std::collections::HashSet<&str> =
321                            allowed.iter().map(std::string::String::as_str).collect();
322                        for passthrough in WORKFLOW_PASSTHROUGH_TOOLS {
323                            allow.insert(passthrough);
324                        }
325                        return Ok(ListToolsResult {
326                            tools: tools
327                                .into_iter()
328                                .filter(|t| allow.contains(t.name.as_ref()))
329                                .collect(),
330                            ..Default::default()
331                        });
332                    }
333                }
334            }
335            tools
336        };
337
338        let tools = {
339            let cfg = crate::core::config::Config::load();
340            let level = crate::core::config::CompressionLevel::effective(&cfg);
341            let mode =
342                crate::core::terse::mcp_compress::DescriptionMode::from_compression_level(&level);
343            if mode == crate::core::terse::mcp_compress::DescriptionMode::Full {
344                tools
345            } else {
346                tools
347                    .into_iter()
348                    .map(|mut t| {
349                        let compressed = crate::core::terse::mcp_compress::compress_description(
350                            t.name.as_ref(),
351                            t.description.as_deref().unwrap_or(""),
352                            mode,
353                        );
354                        t.description = Some(compressed.into());
355                        t
356                    })
357                    .collect()
358            }
359        };
360
361        Ok(ListToolsResult {
362            tools,
363            ..Default::default()
364        })
365    }
366
367    async fn list_prompts(
368        &self,
369        _request: Option<PaginatedRequestParams>,
370        _context: RequestContext<RoleServer>,
371    ) -> Result<rmcp::model::ListPromptsResult, ErrorData> {
372        Ok(rmcp::model::ListPromptsResult::with_all_items(
373            prompts::list_prompts(),
374        ))
375    }
376
377    async fn get_prompt(
378        &self,
379        request: rmcp::model::GetPromptRequestParams,
380        _context: RequestContext<RoleServer>,
381    ) -> Result<rmcp::model::GetPromptResult, ErrorData> {
382        let ledger = self.ledger.read().await;
383        match prompts::get_prompt(&request, &ledger) {
384            Some(result) => Ok(result),
385            None => Err(ErrorData::invalid_params(
386                format!("Unknown prompt: {}", request.name),
387                None,
388            )),
389        }
390    }
391
392    async fn list_resources(
393        &self,
394        _request: Option<PaginatedRequestParams>,
395        _context: RequestContext<RoleServer>,
396    ) -> Result<rmcp::model::ListResourcesResult, rmcp::ErrorData> {
397        Ok(rmcp::model::ListResourcesResult::with_all_items(
398            resources::list_resources(),
399        ))
400    }
401
402    async fn read_resource(
403        &self,
404        request: rmcp::model::ReadResourceRequestParams,
405        _context: RequestContext<RoleServer>,
406    ) -> Result<rmcp::model::ReadResourceResult, rmcp::ErrorData> {
407        let ledger = self.ledger.read().await;
408        match resources::read_resource(&request.uri, &ledger) {
409            Some(contents) => Ok(rmcp::model::ReadResourceResult::new(contents)),
410            None => Err(rmcp::ErrorData::resource_not_found(
411                format!("Unknown resource: {}", request.uri),
412                None,
413            )),
414        }
415    }
416
417    async fn call_tool(
418        &self,
419        request: CallToolRequestParams,
420        context: RequestContext<RoleServer>,
421    ) -> Result<CallToolResult, ErrorData> {
422        use std::panic::AssertUnwindSafe;
423
424        let progress_token = request
425            .meta
426            .as_ref()
427            .and_then(rmcp::model::Meta::get_progress_token);
428        if let Some(ref token) = progress_token {
429            let sender =
430                crate::server::progress::ProgressSender::new(context.peer.clone(), token.clone());
431            *self
432                .progress_sender
433                .lock()
434                .unwrap_or_else(std::sync::PoisonError::into_inner) = Some(sender);
435        }
436
437        let tool_name_for_panic = request.name.as_ref().to_string();
438        let args_fp_for_panic = request
439            .arguments
440            .as_ref()
441            .map(|a| {
442                crate::core::loop_detection::LoopDetector::fingerprint(&serde_json::Value::Object(
443                    a.clone(),
444                ))
445            })
446            .unwrap_or_default();
447
448        let loop_detector = self.loop_detector.clone();
449
450        match AssertUnwindSafe(self.call_tool_guarded(request))
451            .catch_unwind()
452            .await
453        {
454            Ok(result) => result,
455            Err(panic_payload) => {
456                let detail = if let Some(s) = panic_payload.downcast_ref::<&str>() {
457                    (*s).to_string()
458                } else if let Some(s) = panic_payload.downcast_ref::<String>() {
459                    s.clone()
460                } else {
461                    "unknown".to_string()
462                };
463                tracing::error!("call_tool panicked: {detail}");
464
465                if let Ok(mut detector) =
466                    tokio::time::timeout(std::time::Duration::from_secs(1), loop_detector.write())
467                        .await
468                {
469                    detector.record_error_outcome(&tool_name_for_panic, &args_fp_for_panic);
470                }
471
472                Ok(CallToolResult::error(vec![Content::text(
473                    "ERROR: lean-ctx internal error. The MCP server is still running. \
474                     Please retry or use a different approach."
475                        .to_string(),
476                )]))
477            }
478        }
479    }
480
481    async fn on_roots_list_changed(
482        &self,
483        _context: rmcp::service::NotificationContext<RoleServer>,
484    ) {
485        tracing::info!("Received roots/list_changed — will re-resolve on next tool call");
486        self.roots_resolved
487            .store(false, std::sync::atomic::Ordering::Relaxed);
488    }
489}
490
491impl LeanCtxServer {
492    async fn call_tool_guarded(
493        &self,
494        request: CallToolRequestParams,
495    ) -> Result<CallToolResult, ErrorData> {
496        self.check_idle_expiry().await;
497        self.resolve_roots_once().await;
498        elicitation::increment_call();
499
500        let original_name = request.name.as_ref().to_string();
501        let (resolved_name, resolved_args) = if original_name == "ctx" {
502            let sub = request
503                .arguments
504                .as_ref()
505                .and_then(|a| a.get("tool"))
506                .and_then(|v| v.as_str())
507                .map(std::string::ToString::to_string)
508                .ok_or_else(|| {
509                    ErrorData::invalid_params("'tool' is required for ctx meta-tool", None)
510                })?;
511            let tool_name = if sub.starts_with("ctx_") {
512                sub
513            } else {
514                format!("ctx_{sub}")
515            };
516            let mut args = request.arguments.unwrap_or_default();
517            args.remove("tool");
518            (tool_name, Some(args))
519        } else {
520            (original_name, request.arguments)
521        };
522        let name = resolved_name.as_str();
523        let args = resolved_args.as_ref();
524
525        let role_check = role_guard::check_tool_access(name);
526        if let Some(denied) = role_guard::into_call_tool_result(&role_check) {
527            tracing::warn!(
528                tool = name,
529                role = %role_check.role_name,
530                "Tool blocked by role policy"
531            );
532            return Ok(denied);
533        }
534
535        if name != "ctx_workflow" {
536            let active = self.workflow.read().await.clone();
537            if let Some(run) = active {
538                if run.current == "done" || is_workflow_stale(&run) {
539                    let mut wf = self.workflow.write().await;
540                    *wf = None;
541                    let _ = crate::core::workflow::clear_active();
542                } else if !WORKFLOW_PASSTHROUGH_TOOLS.contains(&name) {
543                    if let Some(state) = run.spec.state(&run.current) {
544                        if let Some(allowed) = &state.allowed_tools {
545                            let allowed_ok = allowed.iter().any(|t| t == name);
546                            if !allowed_ok {
547                                let mut shown = allowed.clone();
548                                shown.sort();
549                                shown.truncate(30);
550                                return Ok(CallToolResult::success(vec![Content::text(format!(
551                                    "Tool '{name}' blocked by workflow '{}' (state: {}). Allowed: {}. Use ctx_workflow(action=\"stop\") to exit.",
552                                    run.spec.name,
553                                    run.current,
554                                    shown.join(", ")
555                                ))]));
556                            }
557                        }
558                    }
559                }
560            }
561        }
562
563        let auto_context = {
564            let task = {
565                let session = self.session.read().await;
566                session.task.as_ref().map(|t| t.description.clone())
567            };
568            let project_root = {
569                let session = self.session.read().await;
570                session.project_root.clone()
571            };
572            let cache_timeout =
573                tokio::time::timeout(std::time::Duration::from_secs(5), self.cache.write()).await;
574            if let Ok(mut cache) = cache_timeout {
575                crate::tools::autonomy::session_lifecycle_pre_hook(
576                    &self.autonomy,
577                    name,
578                    &mut cache,
579                    task.as_deref(),
580                    project_root.as_deref(),
581                    CrpMode::effective(),
582                )
583            } else {
584                tracing::warn!("pre-dispatch: cache write-lock timeout (5s), skipping autonomy");
585                None
586            }
587        };
588
589        let args_fp = args
590            .map(|a| {
591                crate::core::loop_detection::LoopDetector::fingerprint(&serde_json::Value::Object(
592                    a.clone(),
593                ))
594            })
595            .unwrap_or_default();
596        let throttle_result = {
597            let fp = &args_fp;
598            let detector_timeout = tokio::time::timeout(
599                std::time::Duration::from_secs(3),
600                self.loop_detector.write(),
601            )
602            .await;
603            if let Ok(mut detector) = detector_timeout {
604                let is_search = crate::core::loop_detection::LoopDetector::is_search_tool(name);
605                let is_search_shell = name == "ctx_shell" && {
606                    let cmd = args
607                        .as_ref()
608                        .and_then(|a| a.get("command"))
609                        .and_then(|v| v.as_str())
610                        .unwrap_or("");
611                    crate::core::loop_detection::LoopDetector::is_search_shell_command(cmd)
612                };
613
614                if is_search || is_search_shell {
615                    let search_pattern = args.and_then(|a| {
616                        a.get("pattern")
617                            .or_else(|| a.get("query"))
618                            .and_then(|v| v.as_str())
619                    });
620                    let shell_pattern = if is_search_shell {
621                        args.and_then(|a| a.get("command"))
622                            .and_then(|v| v.as_str())
623                            .and_then(helpers::extract_search_pattern_from_command)
624                    } else {
625                        None
626                    };
627                    let pat = search_pattern.or(shell_pattern.as_deref());
628                    detector.record_search(name, fp, pat)
629                } else {
630                    detector.record_call(name, fp)
631                }
632            } else {
633                tracing::warn!("pre-dispatch: loop_detector write-lock timeout (3s), skipping");
634                crate::core::loop_detection::ThrottleResult::default()
635            }
636        };
637
638        if throttle_result.level == crate::core::loop_detection::ThrottleLevel::Blocked {
639            let msg = throttle_result.message.unwrap_or_default();
640            return Ok(CallToolResult::success(vec![Content::text(msg)]));
641        }
642
643        let throttle_warning =
644            if throttle_result.level == crate::core::loop_detection::ThrottleLevel::Reduced {
645                throttle_result.message.clone()
646            } else {
647                None
648            };
649
650        let config = crate::core::config::Config::load();
651        let minimal = config.minimal_overhead_effective();
652
653        {
654            use crate::core::budget_tracker::{BudgetLevel, BudgetTracker};
655            let snap = BudgetTracker::global().check();
656            if *snap.worst_level() == BudgetLevel::Exhausted
657                && name != "ctx_session"
658                && name != "ctx_cost"
659                && name != "ctx_metrics"
660            {
661                for (dim, lvl, used, limit) in [
662                    (
663                        "tokens",
664                        &snap.tokens.level,
665                        format!("{}", snap.tokens.used),
666                        format!("{}", snap.tokens.limit),
667                    ),
668                    (
669                        "shell",
670                        &snap.shell.level,
671                        format!("{}", snap.shell.used),
672                        format!("{}", snap.shell.limit),
673                    ),
674                    (
675                        "cost",
676                        &snap.cost.level,
677                        format!("${:.2}", snap.cost.used_usd),
678                        format!("${:.2}", snap.cost.limit_usd),
679                    ),
680                ] {
681                    if *lvl == BudgetLevel::Exhausted {
682                        crate::core::events::emit_budget_exhausted(&snap.role, dim, &used, &limit);
683                    }
684                }
685                let msg = format!(
686                    "[BUDGET EXHAUSTED] {}\n\
687                     Use `ctx_session action=role` to check/switch roles, \
688                     or `ctx_session action=reset` to start fresh.",
689                    snap.format_compact()
690                );
691                tracing::warn!(tool = name, "{msg}");
692                return Ok(CallToolResult::success(vec![Content::text(msg)]));
693            }
694        }
695
696        if is_shell_tool_name(name) {
697            crate::core::budget_tracker::BudgetTracker::global().record_shell();
698        }
699
700        let tool_start = std::time::Instant::now();
701        let (mut result_text, tool_saved_tokens) =
702            match self.dispatch_tool(name, args, minimal).await {
703                Ok(pair) => pair,
704                Err(e) => {
705                    if let Ok(mut detector) = tokio::time::timeout(
706                        std::time::Duration::from_secs(1),
707                        self.loop_detector.write(),
708                    )
709                    .await
710                    {
711                        detector.record_error_outcome(name, &args_fp);
712                    }
713                    return Err(e);
714                }
715            };
716
717        let is_raw_shell = name == "ctx_shell" && {
718            let arg_raw = helpers::get_bool(args, "raw").unwrap_or(false);
719            let arg_bypass = helpers::get_bool(args, "bypass").unwrap_or(false);
720            arg_raw
721                || arg_bypass
722                || std::env::var("LEAN_CTX_DISABLED").is_ok()
723                || std::env::var("LEAN_CTX_RAW").is_ok()
724        };
725
726        let pre_terse_len = result_text.len();
727        let output_tokens = {
728            let tokens = crate::core::tokens::count_tokens(&result_text) as u64;
729            crate::core::budget_tracker::BudgetTracker::global().record_tokens(tokens);
730            tokens
731        };
732
733        crate::core::anomaly::record_metric("tokens_per_call", output_tokens as f64);
734
735        // Context IR: record lineage for every tool call.
736        if let Some(ref ir) = self.context_ir {
737            let tool_duration = tool_start.elapsed();
738            let source_kind = match name {
739                n if n.contains("read") || n.contains("multi_read") || n.contains("smart_read") => {
740                    crate::core::context_ir::ContextIrSourceKindV1::Read
741                }
742                "ctx_shell" => crate::core::context_ir::ContextIrSourceKindV1::Shell,
743                "ctx_search" | "ctx_semantic_search" => {
744                    crate::core::context_ir::ContextIrSourceKindV1::Search
745                }
746                "ctx_provider" => crate::core::context_ir::ContextIrSourceKindV1::Provider,
747                _ => crate::core::context_ir::ContextIrSourceKindV1::Other,
748            };
749            let ir_path = helpers::get_str(args, "path");
750            let ir_command = helpers::get_str(args, "command");
751            let ir_mode = helpers::get_str(args, "mode");
752            let excerpt = if result_text.len() > 200 {
753                let mut end = 200;
754                while !result_text.is_char_boundary(end) && end > 0 {
755                    end -= 1;
756                }
757                &result_text[..end]
758            } else {
759                &result_text
760            };
761            let input = crate::core::context_ir::RecordIrInput {
762                kind: source_kind,
763                tool: name,
764                client_name: None,
765                agent_id: None,
766                path: ir_path.as_deref(),
767                command: ir_command.as_deref(),
768                pattern: ir_mode.as_deref(),
769                input_tokens: pre_terse_len / 4,
770                output_tokens: output_tokens as usize,
771                duration: tool_duration,
772                content_excerpt: excerpt,
773            };
774            ir.write().await.record(input);
775        }
776
777        // Correction-loop detection: track re-reads and re-runs as quality signals.
778        {
779            let mut detector = self.loop_detector.write().await;
780            if name == "ctx_read" {
781                let path = helpers::get_str(args, "path").unwrap_or_default();
782                let mode = helpers::get_str(args, "mode").unwrap_or_else(|| "auto".into());
783                let fresh = helpers::get_bool(args, "fresh").unwrap_or(false);
784                detector.record_read_for_correction(&path, &mode, fresh);
785            } else if name == "ctx_shell" {
786                let cmd = helpers::get_str(args, "command").unwrap_or_default();
787                detector.record_shell_for_correction(&cmd);
788            }
789            let correction_count = detector.correction_count();
790            if correction_count > 0 {
791                crate::core::anomaly::record_metric(
792                    "correction_loop_rate",
793                    f64::from(correction_count),
794                );
795            }
796            // Auto-degrade: reduce compression when correction rate is high
797            use crate::core::config::CompressionLevel;
798            if correction_count >= 5 {
799                CompressionLevel::set_session_degrade(&CompressionLevel::Off);
800            } else if correction_count >= 3 {
801                CompressionLevel::set_session_degrade(&CompressionLevel::Lite);
802            } else if correction_count == 0 {
803                CompressionLevel::clear_session_degrade();
804            }
805            detector.prune_corrections();
806        }
807
808        // Persist anomaly detector — debounced to reduce I/O in burst sequences.
809        crate::core::anomaly::save_debounced();
810
811        let budget_warning = {
812            use crate::core::budget_tracker::{BudgetLevel, BudgetTracker};
813            let snap = BudgetTracker::global().check();
814            if *snap.worst_level() == BudgetLevel::Warning {
815                for (dim, lvl, used, limit, pct) in [
816                    (
817                        "tokens",
818                        &snap.tokens.level,
819                        format!("{}", snap.tokens.used),
820                        format!("{}", snap.tokens.limit),
821                        snap.tokens.percent,
822                    ),
823                    (
824                        "shell",
825                        &snap.shell.level,
826                        format!("{}", snap.shell.used),
827                        format!("{}", snap.shell.limit),
828                        snap.shell.percent,
829                    ),
830                    (
831                        "cost",
832                        &snap.cost.level,
833                        format!("${:.2}", snap.cost.used_usd),
834                        format!("${:.2}", snap.cost.limit_usd),
835                        snap.cost.percent,
836                    ),
837                ] {
838                    if *lvl == BudgetLevel::Warning {
839                        crate::core::events::emit_budget_warning(
840                            &snap.role, dim, &used, &limit, pct,
841                        );
842                    }
843                }
844                if crate::core::protocol::meta_visible() {
845                    Some(format!("[BUDGET WARNING] {}", snap.format_compact()))
846                } else {
847                    None
848                }
849            } else {
850                None
851            }
852        };
853
854        let archive_hint = if minimal || is_raw_shell {
855            None
856        } else {
857            use crate::core::archive;
858            let archivable = matches!(
859                name,
860                "ctx_shell"
861                    | "ctx_read"
862                    | "ctx_multi_read"
863                    | "ctx_smart_read"
864                    | "ctx_execute"
865                    | "ctx_search"
866                    | "ctx_tree"
867            );
868            if archivable && archive::should_archive(&result_text) {
869                let cmd = helpers::get_str(args, "command")
870                    .or_else(|| helpers::get_str(args, "path"))
871                    .unwrap_or_default();
872                let session_id = self.session.read().await.id.clone();
873                let to_store = crate::core::redaction::redact_text_if_enabled(&result_text);
874                let tokens = crate::core::tokens::count_tokens(&to_store);
875                archive::store(name, &cmd, &to_store, Some(&session_id))
876                    .map(|id| archive::format_hint(&id, to_store.len(), tokens))
877            } else {
878                None
879            }
880        };
881
882        let pre_compression = result_text.clone();
883        let skip_terse = is_raw_shell
884            || tool_saved_tokens > 0
885            || (name == "ctx_shell"
886                && helpers::get_str(args, "command")
887                    .is_some_and(|c| crate::shell::compress::has_structural_output(&c)));
888        let compression = crate::core::config::CompressionLevel::effective(&config);
889        if compression.is_active() && !skip_terse {
890            let terse_result =
891                crate::core::terse::pipeline::compress(&result_text, &compression, None);
892            if terse_result.quality_passed && terse_result.savings_pct >= 3.0 {
893                result_text = terse_result.output;
894            }
895        }
896
897        let profile_hints = crate::core::profiles::active_profile().output_hints;
898
899        if !is_raw_shell && profile_hints.verify_footer() {
900            let verify_cfg = crate::core::profiles::active_profile().verification;
901            let vr = crate::core::output_verification::verify_output(
902                &pre_compression,
903                &result_text,
904                &verify_cfg,
905            );
906            if !vr.warnings.is_empty() {
907                let msg = format!("[VERIFY] {}", vr.format_compact());
908                result_text = format!("{result_text}\n\n{msg}");
909            }
910        }
911
912        if profile_hints.archive_hint() {
913            if let Some(hint) = archive_hint {
914                result_text = format!("{result_text}\n{hint}");
915            }
916        }
917
918        if !is_raw_shell {
919            if let Some(ctx) = auto_context {
920                let ctx_tokens = crate::core::tokens::count_tokens(&ctx);
921                if ctx_tokens <= 400 {
922                    result_text = format!("{ctx}\n\n{result_text}");
923                }
924            }
925        }
926
927        if let Some(warning) = throttle_warning {
928            result_text = format!("{result_text}\n\n{warning}");
929        }
930
931        if let Some(bw) = budget_warning {
932            result_text = format!("{result_text}\n\n{bw}");
933        }
934
935        if !self
936            .rules_stale_checked
937            .swap(true, std::sync::atomic::Ordering::Relaxed)
938        {
939            let client = self.client_name.read().await.clone();
940            if !client.is_empty() {
941                if let Some(stale_msg) = crate::rules_inject::check_rules_freshness(&client) {
942                    result_text = format!("{result_text}\n\n{stale_msg}");
943                }
944            }
945        }
946
947        {
948            // Evaluate SLOs for observability (watch/dashboard), but keep tool outputs clean.
949            let _ = crate::core::slo::evaluate();
950        }
951
952        if name == "ctx_read" {
953            if minimal {
954                let cache_clone = self.cache.clone();
955                let autonomy_clone = self.autonomy.clone();
956                let name_owned = name.to_string();
957                tokio::spawn(async move {
958                    let result = std::panic::AssertUnwindSafe(async {
959                        let mut cache = cache_clone.write().await;
960                        crate::tools::autonomy::maybe_auto_dedup(
961                            &autonomy_clone,
962                            &mut cache,
963                            &name_owned,
964                        );
965                    })
966                    .catch_unwind()
967                    .await;
968                    if let Err(e) = result {
969                        let msg = e
970                            .downcast_ref::<String>()
971                            .map(String::as_str)
972                            .or_else(|| e.downcast_ref::<&str>().copied())
973                            .unwrap_or("unknown");
974                        tracing::error!("background auto_dedup panicked: {msg}");
975                    }
976                });
977            } else {
978                let read_path = self
979                    .resolve_path_or_passthrough(
980                        &helpers::get_str(args, "path").unwrap_or_default(),
981                    )
982                    .await;
983                let project_root = {
984                    let session = self.session.read().await;
985                    session.project_root.clone()
986                };
987
988                // Bounded cache lock for enrichment — degrade gracefully under contention
989                let enrich_timeout =
990                    tokio::time::timeout(std::time::Duration::from_secs(3), self.cache.write())
991                        .await;
992                if let Ok(mut cache) = enrich_timeout {
993                    let enrich = crate::tools::autonomy::enrich_after_read(
994                        &self.autonomy,
995                        &mut cache,
996                        &read_path,
997                        project_root.as_deref(),
998                        None,
999                        crate::tools::CrpMode::effective(),
1000                        false,
1001                    );
1002                    if profile_hints.related_hint() {
1003                        if let Some(hint) = enrich.related_hint {
1004                            result_text = format!("{result_text}\n{hint}");
1005                        }
1006                    }
1007                    crate::tools::autonomy::maybe_auto_dedup(&self.autonomy, &mut cache, name);
1008                } else {
1009                    tracing::warn!(
1010                        "post-dispatch cache lock timeout (3s) for {read_path}, skipping enrichment"
1011                    );
1012                }
1013
1014                // Ledger update — fire-and-forget to avoid blocking concurrent reads
1015                let ledger_clone = self.ledger.clone();
1016                let session_clone = self.session.clone();
1017                let peer_clone = self.peer.clone();
1018                let read_path_owned = read_path.clone();
1019                let project_root_owned = project_root.clone();
1020                let mode_used =
1021                    helpers::get_str(args, "mode").unwrap_or_else(|| "auto".to_string());
1022                let out_tok = output_tokens as usize;
1023                let sent_tok = crate::core::tokens::count_tokens(&result_text);
1024                let wants_eviction = true;
1025                let wants_elicitation = profile_hints.elicitation_hint();
1026                tokio::spawn(async move {
1027                    let result = std::panic::AssertUnwindSafe(async {
1028                        let active_task = {
1029                            let session = session_clone.read().await;
1030                            session.task.as_ref().map(|t| t.description.clone())
1031                        };
1032                        let mut ledger = ledger_clone.write().await;
1033                        let overlay = crate::core::context_overlay::OverlayStore::load_project(
1034                            &std::path::PathBuf::from(project_root_owned.as_deref().unwrap_or(".")),
1035                        );
1036                        let gate_result = context_gate::post_dispatch_record_with_task(
1037                            &read_path_owned,
1038                            &mode_used,
1039                            out_tok,
1040                            sent_tok,
1041                            &mut ledger,
1042                            &overlay,
1043                            active_task.as_deref(),
1044                        );
1045                        drop(ledger);
1046                        if wants_eviction {
1047                            if let Some(hint) = &gate_result.eviction_hint {
1048                                tracing::debug!("deferred eviction hint: {hint}");
1049                            }
1050                        }
1051                        if wants_elicitation {
1052                            if let Some(hint) = &gate_result.elicitation_hint {
1053                                tracing::debug!("deferred elicitation hint: {hint}");
1054                            }
1055                        }
1056                        if gate_result.resource_changed {
1057                            if let Some(peer) = peer_clone.read().await.as_ref() {
1058                                notifications::send_resource_updated(
1059                                    peer,
1060                                    notifications::RESOURCE_URI_SUMMARY,
1061                                )
1062                                .await;
1063                            }
1064                        }
1065                    })
1066                    .catch_unwind()
1067                    .await;
1068                    if let Err(e) = result {
1069                        let msg = e
1070                            .downcast_ref::<String>()
1071                            .map(String::as_str)
1072                            .or_else(|| e.downcast_ref::<&str>().copied())
1073                            .unwrap_or("unknown");
1074                        tracing::error!("background post_dispatch panicked: {msg}");
1075                    }
1076                });
1077            }
1078        }
1079
1080        if !minimal && !is_raw_shell && name == "ctx_shell" {
1081            let cmd = helpers::get_str(args, "command").unwrap_or_default();
1082
1083            if let Some(file_path) = extract_file_read_from_shell(&cmd) {
1084                if let Ok(mut bt) = crate::core::bounce_tracker::global().lock() {
1085                    bt.next_seq();
1086                    bt.record_shell_file_access(&file_path);
1087                }
1088            }
1089
1090            if profile_hints.efficiency_hint() {
1091                let calls = self.tool_calls.read().await;
1092                let last_original = calls.last().map_or(0, |c| c.original_tokens);
1093                drop(calls);
1094                let pre_hint_tokens = crate::core::tokens::count_tokens(&result_text);
1095                if let Some(hint) = crate::tools::autonomy::shell_efficiency_hint(
1096                    &self.autonomy,
1097                    &cmd,
1098                    last_original,
1099                    pre_hint_tokens,
1100                ) {
1101                    result_text = format!("{result_text}\n{hint}");
1102                }
1103            }
1104        }
1105
1106        if !minimal && !is_raw_shell {
1107            if let Ok(data_dir) = crate::core::data_dir::lean_ctx_data_dir() {
1108                let session = self.session.read().await;
1109                bypass_hint::set_session_id(&session.id);
1110                drop(session);
1111                if let Some(hint) = bypass_hint::check(&data_dir) {
1112                    result_text = format!("{result_text}\n{hint}");
1113                }
1114            }
1115            bypass_hint::record_lctx_call();
1116        }
1117
1118        if let Some(finding) = crate::core::auto_findings::extract(name, &result_text) {
1119            let mut session = self.session.write().await;
1120            session.add_finding(finding.file.as_deref(), None, &finding.summary);
1121            drop(session);
1122        }
1123
1124        #[allow(clippy::cast_possible_truncation)]
1125        let output_token_count = if result_text.len() == pre_terse_len {
1126            output_tokens as usize
1127        } else {
1128            crate::core::tokens::count_tokens(&result_text)
1129        };
1130
1131        // OPT-4: Correct stats with post-processing token counts.
1132        // dispatch/mod.rs records savings before terse/hints; adjust here
1133        // so persistent stats reflect what the model actually receives.
1134        if result_text.len() != pre_terse_len && tool_saved_tokens > 0 {
1135            let pre_savings = tool_saved_tokens;
1136            let actual_sent = output_token_count;
1137            let original = actual_sent + pre_savings;
1138            let actual_savings = original.saturating_sub(actual_sent);
1139            if actual_savings != pre_savings {
1140                let delta = pre_savings as i64 - actual_savings as i64;
1141                if delta != 0 {
1142                    crate::core::stats::adjust_savings(name, delta);
1143                }
1144            }
1145        }
1146
1147        let action = helpers::get_str(args, "action");
1148
1149        // K-bounded staleness guard: warn if shared context has diverged.
1150        const K_STALENESS_BOUND: i64 = 10;
1151        if self.session_mode == crate::tools::SessionMode::Shared {
1152            if let Some(ref rt) = self.context_os {
1153                let latest = rt.bus.latest_id(&self.workspace_id, &self.channel_id);
1154                let cursor = self
1155                    .last_seen_event_id
1156                    .load(std::sync::atomic::Ordering::Relaxed);
1157                if cursor > 0 && latest - cursor > K_STALENESS_BOUND {
1158                    let gap = latest - cursor;
1159                    result_text = format!(
1160                        "[CONTEXT STALE] {gap} events happened since your last read. \
1161                         Use ctx_session(action=\"status\") to sync.\n\n{result_text}"
1162                    );
1163                }
1164                self.last_seen_event_id
1165                    .store(latest, std::sync::atomic::Ordering::Relaxed);
1166            }
1167        }
1168
1169        {
1170            let input = helpers::canonical_args_string(args);
1171            let input_md5 = helpers::hash_fast(&input);
1172            let output_md5 = helpers::hash_fast(&result_text);
1173            let agent_id = self.agent_id.read().await.clone();
1174            let client_name = self.client_name.read().await.clone();
1175            let mut explicit_intent: Option<(
1176                crate::core::intent_protocol::IntentRecord,
1177                Option<String>,
1178                String,
1179            )> = None;
1180
1181            let pending_session_save = {
1182                let empty_args = serde_json::Map::new();
1183                let args_map = args.unwrap_or(&empty_args);
1184                let mut session = self.session.write().await;
1185                session.record_tool_receipt(
1186                    name,
1187                    action.as_deref(),
1188                    &input_md5,
1189                    &output_md5,
1190                    agent_id.as_deref(),
1191                    Some(&client_name),
1192                );
1193
1194                if let Some(intent) = crate::core::intent_protocol::infer_from_tool_call(
1195                    name,
1196                    action.as_deref(),
1197                    args_map,
1198                    session.project_root.as_deref(),
1199                ) {
1200                    let is_explicit =
1201                        intent.source == crate::core::intent_protocol::IntentSource::Explicit;
1202                    let root = session.project_root.clone();
1203                    let sid = session.id.clone();
1204                    session.record_intent(intent.clone());
1205                    if is_explicit {
1206                        explicit_intent = Some((intent, root, sid));
1207                    }
1208                }
1209                if session.should_save() {
1210                    session.prepare_save().ok()
1211                } else {
1212                    None
1213                }
1214            };
1215
1216            if let Some(prepared) = pending_session_save {
1217                let ir_clone = self.context_ir.clone();
1218                tokio::task::spawn_blocking(move || {
1219                    let _ = prepared.write_to_disk();
1220                    if let Some(ir) = ir_clone {
1221                        if let Ok(ir_guard) = ir.try_read() {
1222                            ir_guard.save();
1223                        }
1224                    }
1225                });
1226            }
1227
1228            if let Some((intent, root, session_id)) = explicit_intent {
1229                let _ = crate::core::intent_protocol::apply_side_effects(
1230                    &intent,
1231                    root.as_deref(),
1232                    &session_id,
1233                );
1234            }
1235
1236            if self.autonomy.is_enabled() {
1237                let (calls, project_root) = {
1238                    let session = self.session.read().await;
1239                    (session.stats.total_tool_calls, session.project_root.clone())
1240                };
1241
1242                if let Some(root) = project_root {
1243                    if crate::tools::autonomy::should_auto_consolidate(&self.autonomy, calls) {
1244                        let root_clone = root.clone();
1245                        tokio::task::spawn_blocking(move || {
1246                            let _ = crate::core::consolidation_engine::consolidate_latest(
1247                                &root_clone,
1248                                crate::core::consolidation_engine::ConsolidationBudgets::default(),
1249                            );
1250                        });
1251                    }
1252                }
1253            }
1254
1255            let agent_key = agent_id.unwrap_or_else(|| "unknown".to_string());
1256            let input_token_count = crate::core::tokens::count_tokens(&input) as u64;
1257            let output_token_count_u64 = output_token_count as u64;
1258            let name_owned = name.to_string();
1259            tokio::task::spawn_blocking(move || {
1260                let pricing = crate::core::gain::model_pricing::ModelPricing::load();
1261                let quote = pricing.quote_from_env_or_agent_type(&client_name);
1262                let cost_usd =
1263                    quote
1264                        .cost
1265                        .estimate_usd(input_token_count, output_token_count_u64, 0, 0);
1266                crate::core::budget_tracker::BudgetTracker::global().record_cost_usd(cost_usd);
1267
1268                let mut store = crate::core::a2a::cost_attribution::CostStore::load();
1269                store.record_tool_call(
1270                    &agent_key,
1271                    &client_name,
1272                    &name_owned,
1273                    input_token_count,
1274                    output_token_count_u64,
1275                    0,
1276                );
1277                let _ = store.save();
1278            });
1279        }
1280
1281        // Context Bus: conflict detection for knowledge writes in shared mode.
1282        if self.session_mode == crate::tools::SessionMode::Shared
1283            && name == "ctx_knowledge"
1284            && action.as_deref() == Some("remember")
1285        {
1286            if let Some(ref rt) = self.context_os {
1287                let my_agent = self.agent_id.read().await.clone();
1288                let category = helpers::get_str(args, "category");
1289                let key = helpers::get_str(args, "key");
1290                if let (Some(ref cat), Some(ref k)) = (&category, &key) {
1291                    let recent = rt.bus.recent_by_kind(
1292                        &self.workspace_id,
1293                        &self.channel_id,
1294                        "knowledge_remembered",
1295                        20,
1296                    );
1297                    for ev in &recent {
1298                        let p = &ev.payload;
1299                        let ev_cat = p.get("category").and_then(|v| v.as_str());
1300                        let ev_key = p.get("key").and_then(|v| v.as_str());
1301                        let ev_actor = ev.actor.as_deref();
1302                        if ev_cat == Some(cat.as_str())
1303                            && ev_key == Some(k.as_str())
1304                            && ev_actor != my_agent.as_deref()
1305                        {
1306                            let other = ev_actor.unwrap_or("unknown");
1307                            result_text = format!(
1308                                "[CONFLICT] Agent '{other}' recently wrote to the same knowledge key \
1309                                 '{cat}/{k}'. Review before proceeding.\n\n{result_text}"
1310                            );
1311                            break;
1312                        }
1313                    }
1314                }
1315            }
1316        }
1317
1318        // Context OS: persist shared session + publish events.
1319        if self.session_mode == crate::tools::SessionMode::Shared {
1320            let ws = self.workspace_id.clone();
1321            let ch = self.channel_id.clone();
1322            let rt = self.context_os.clone();
1323            let agent = self.agent_id.read().await.clone();
1324            let tool = name.to_string();
1325            let tool_action = action.clone();
1326            let tool_path = helpers::get_str(args, "path");
1327            let tool_category = helpers::get_str(args, "category");
1328            let tool_key = helpers::get_str(args, "key");
1329            let session_snapshot = self.session.read().await.clone();
1330            let session_task = session_snapshot.task.clone();
1331            tokio::task::spawn_blocking(move || {
1332                let Some(rt) = rt else {
1333                    return;
1334                };
1335                let Some(root) = session_snapshot.project_root.as_deref() else {
1336                    return;
1337                };
1338                rt.shared_sessions
1339                    .persist_best_effort(root, &ws, &ch, &session_snapshot);
1340                rt.metrics.record_session_persisted();
1341
1342                let mut base_payload = serde_json::json!({
1343                    "tool": tool,
1344                    "action": tool_action,
1345                });
1346                if let Some(ref p) = tool_path {
1347                    base_payload["path"] = serde_json::Value::String(p.clone());
1348                }
1349                if let Some(ref c) = tool_category {
1350                    base_payload["category"] = serde_json::Value::String(c.clone());
1351                }
1352                if let Some(ref k) = tool_key {
1353                    base_payload["key"] = serde_json::Value::String(k.clone());
1354                }
1355                if let Some(ref t) = session_task {
1356                    base_payload["reasoning"] = serde_json::Value::String(t.description.clone());
1357                }
1358
1359                if rt
1360                    .bus
1361                    .append(
1362                        &ws,
1363                        &ch,
1364                        &crate::core::context_os::ContextEventKindV1::ToolCallRecorded,
1365                        agent.as_deref(),
1366                        base_payload.clone(),
1367                    )
1368                    .is_some()
1369                {
1370                    rt.metrics.record_event_appended();
1371                    rt.metrics.record_event_broadcast();
1372                }
1373
1374                if let Some(secondary) =
1375                    crate::core::context_os::secondary_event_kind(&tool, tool_action.as_deref())
1376                {
1377                    if rt
1378                        .bus
1379                        .append(&ws, &ch, &secondary, agent.as_deref(), base_payload)
1380                        .is_some()
1381                    {
1382                        rt.metrics.record_event_appended();
1383                        rt.metrics.record_event_broadcast();
1384                    }
1385                }
1386            });
1387        }
1388
1389        let skip_checkpoint = minimal
1390            || matches!(
1391                name,
1392                "ctx_compress"
1393                    | "ctx_metrics"
1394                    | "ctx_benchmark"
1395                    | "ctx_analyze"
1396                    | "ctx_cache"
1397                    | "ctx_discover"
1398                    | "ctx_dedup"
1399                    | "ctx_session"
1400                    | "ctx_knowledge"
1401                    | "ctx_agent"
1402                    | "ctx_share"
1403                    | "ctx_gain"
1404                    | "ctx_overview"
1405                    | "ctx_preload"
1406                    | "ctx_cost"
1407                    | "ctx_heatmap"
1408                    | "ctx_task"
1409                    | "ctx_impact"
1410                    | "ctx_architecture"
1411                    | "ctx_smells"
1412                    | "ctx_workflow"
1413            );
1414
1415        if !skip_checkpoint && self.increment_and_check() {
1416            if let Some(checkpoint) = self.auto_checkpoint().await {
1417                let interval = LeanCtxServer::checkpoint_interval_effective();
1418                let hints = crate::core::profiles::active_profile().output_hints;
1419                if hints.checkpoint_in_output() && crate::core::protocol::meta_visible() {
1420                    let combined = format!(
1421                        "{result_text}\n\n--- AUTO CHECKPOINT (every {interval} calls) ---\n{checkpoint}"
1422                    );
1423                    return Ok(CallToolResult::success(vec![Content::text(combined)]));
1424                }
1425            }
1426        }
1427
1428        let tool_duration_ms = tool_start.elapsed().as_millis() as u64;
1429        if tool_duration_ms > 100 {
1430            LeanCtxServer::append_tool_call_log(
1431                name,
1432                tool_duration_ms,
1433                0,
1434                0,
1435                None,
1436                &chrono::Local::now().format("%Y-%m-%d %H:%M:%S").to_string(),
1437            );
1438        }
1439
1440        let current_count = self.call_count.load(std::sync::atomic::Ordering::Relaxed);
1441        if current_count > 0 && current_count.is_multiple_of(100) {
1442            std::thread::spawn(crate::cloud_sync::cloud_background_tasks);
1443        }
1444
1445        Ok(CallToolResult::success(vec![Content::text(result_text)]))
1446    }
1447
1448    /// Resolve project root from MCP client roots (once per session).
1449    /// Called on the first tool call. If the client supports `roots/list`,
1450    /// we query it and pick the best root with project markers.
1451    async fn resolve_roots_once(&self) {
1452        use std::sync::atomic::Ordering;
1453        if !self.has_client_roots.load(Ordering::Relaxed) {
1454            return;
1455        }
1456        if self.roots_resolved.swap(true, Ordering::Relaxed) {
1457            return;
1458        }
1459        let peer_guard = self.peer.read().await;
1460        let Some(peer) = peer_guard.as_ref() else {
1461            return;
1462        };
1463        let list_result = match peer.list_roots().await {
1464            Ok(r) => r,
1465            Err(e) => {
1466                tracing::warn!("roots/list failed: {e}");
1467                return;
1468            }
1469        };
1470        drop(peer_guard);
1471
1472        let uris: Vec<String> = list_result.roots.iter().map(|r| r.uri.clone()).collect();
1473        let validated_paths = roots::valid_dir_paths_from_uris(&uris);
1474        let Some(new_root) = roots::best_root_from_uris(&uris) else {
1475            return;
1476        };
1477
1478        let mut session = self.session.write().await;
1479        let old_root = session.project_root.clone();
1480
1481        let other_roots: Vec<String> = validated_paths
1482            .iter()
1483            .filter(|p| p.as_str() != new_root)
1484            .cloned()
1485            .collect();
1486        if !other_roots.is_empty() {
1487            session.extra_roots = other_roots;
1488            tracing::info!(
1489                "MCP roots: {} extra root(s) registered",
1490                session.extra_roots.len()
1491            );
1492        }
1493
1494        if old_root.as_deref() == Some(&new_root) {
1495            let _ = session.save();
1496            return;
1497        }
1498        tracing::info!(
1499            "MCP roots: switching project root from {:?} to {new_root}",
1500            old_root
1501        );
1502        if let Some(existing) =
1503            crate::core::session::SessionState::load_latest_for_project_root(&new_root)
1504        {
1505            *session = existing;
1506            session.extra_roots = validated_paths
1507                .iter()
1508                .filter(|p| p.as_str() != new_root)
1509                .cloned()
1510                .collect();
1511        }
1512        session.project_root = Some(new_root);
1513        let _ = session.save();
1514    }
1515}
1516
1517pub fn build_instructions_for_test(crp_mode: CrpMode) -> String {
1518    crate::instructions::build_instructions_for_test(crp_mode)
1519}
1520
1521pub fn build_claude_code_instructions_for_test() -> String {
1522    crate::instructions::claude_code_instructions()
1523}
1524
1525const PROJECT_MARKERS: &[&str] = &[
1526    ".git",
1527    "Cargo.toml",
1528    "package.json",
1529    "go.mod",
1530    "pyproject.toml",
1531    "setup.py",
1532    "pom.xml",
1533    "build.gradle",
1534    "Makefile",
1535    ".lean-ctx.toml",
1536];
1537
1538fn has_project_marker(dir: &std::path::Path) -> bool {
1539    PROJECT_MARKERS.iter().any(|m| dir.join(m).exists())
1540}
1541
1542fn is_home_or_agent_dir(dir: &std::path::Path) -> bool {
1543    if let Some(home) = dirs::home_dir() {
1544        if dir == home {
1545            return true;
1546        }
1547    }
1548    let dir_str = dir.to_string_lossy();
1549    dir_str.ends_with("/.claude")
1550        || dir_str.ends_with("/.codex")
1551        || dir_str.contains("/.claude/")
1552        || dir_str.contains("/.codex/")
1553}
1554
1555fn git_toplevel_from(dir: &std::path::Path) -> Option<String> {
1556    std::process::Command::new("git")
1557        .args(["rev-parse", "--show-toplevel"])
1558        .current_dir(dir)
1559        .stdout(std::process::Stdio::piped())
1560        .stderr(std::process::Stdio::null())
1561        .output()
1562        .ok()
1563        .and_then(|o| {
1564            if o.status.success() {
1565                String::from_utf8(o.stdout)
1566                    .ok()
1567                    .map(|s| s.trim().to_string())
1568            } else {
1569                None
1570            }
1571        })
1572}
1573
1574pub fn derive_project_root_from_cwd() -> Option<String> {
1575    let cwd = std::env::current_dir().ok()?;
1576    let canonical = crate::core::pathutil::safe_canonicalize_or_self(&cwd);
1577
1578    if is_home_or_agent_dir(&canonical) {
1579        return git_toplevel_from(&canonical);
1580    }
1581
1582    if has_project_marker(&canonical) {
1583        return Some(canonical.to_string_lossy().to_string());
1584    }
1585
1586    if let Some(git_root) = git_toplevel_from(&canonical) {
1587        return Some(git_root);
1588    }
1589
1590    if let Some(root) = detect_multi_root_workspace(&canonical) {
1591        return Some(root);
1592    }
1593
1594    // Fallback: use CWD as project root if it's a specific, safe directory.
1595    // This ensures bare directories (no .git, no markers) still work.
1596    // Guard: reject home dir, filesystem root, and agent sandbox dirs.
1597    if !crate::core::pathutil::is_broad_or_unsafe_root(&canonical) {
1598        tracing::info!(
1599            "No project markers found — using CWD as project root: {}",
1600            canonical.display()
1601        );
1602        return Some(canonical.to_string_lossy().to_string());
1603    }
1604
1605    None
1606}
1607
1608// Delegated to crate::core::pathutil::is_broad_or_unsafe_root
1609#[cfg(test)]
1610use crate::core::pathutil::is_broad_or_unsafe_root;
1611
1612/// Detect a multi-root workspace: a directory that has no project markers
1613/// itself, but contains child directories that do. In this case, use the
1614/// parent as jail root and auto-allow all child projects via LEAN_CTX_ALLOW_PATH.
1615fn detect_multi_root_workspace(dir: &std::path::Path) -> Option<String> {
1616    let entries = std::fs::read_dir(dir).ok()?;
1617    let mut child_projects: Vec<String> = Vec::new();
1618
1619    for entry in entries.flatten() {
1620        let path = entry.path();
1621        if path.is_dir() && has_project_marker(&path) {
1622            let canonical = crate::core::pathutil::safe_canonicalize_or_self(&path);
1623            child_projects.push(canonical.to_string_lossy().to_string());
1624        }
1625    }
1626
1627    if child_projects.len() >= 2 {
1628        let existing = std::env::var("LEAN_CTX_ALLOW_PATH").unwrap_or_default();
1629        let sep = if cfg!(windows) { ";" } else { ":" };
1630        let merged = if existing.is_empty() {
1631            child_projects.join(sep)
1632        } else {
1633            format!("{existing}{sep}{}", child_projects.join(sep))
1634        };
1635        std::env::set_var("LEAN_CTX_ALLOW_PATH", &merged);
1636        tracing::info!(
1637            "Multi-root workspace detected at {}: auto-allowing {} child projects",
1638            dir.display(),
1639            child_projects.len()
1640        );
1641        return Some(dir.to_string_lossy().to_string());
1642    }
1643
1644    None
1645}
1646
1647pub fn tool_descriptions_for_test() -> Vec<(&'static str, &'static str)> {
1648    crate::tool_defs::list_all_tool_defs()
1649        .into_iter()
1650        .map(|(name, desc, _)| (name, desc))
1651        .collect()
1652}
1653
1654pub fn tool_schemas_json_for_test() -> String {
1655    crate::tool_defs::list_all_tool_defs()
1656        .iter()
1657        .map(|(name, _, schema)| format!("{name}: {schema}"))
1658        .collect::<Vec<_>>()
1659        .join("\n")
1660}
1661
1662/// Tools that always pass through the workflow gate regardless of state.
1663/// Read-only tools should never be blocked — agents need them for context
1664/// recovery after crashes or session transitions.
1665pub const WORKFLOW_PASSTHROUGH_TOOLS: &[&str] = &[
1666    "ctx",
1667    "ctx_workflow",
1668    "ctx_read",
1669    "ctx_multi_read",
1670    "ctx_smart_read",
1671    "ctx_search",
1672    "ctx_tree",
1673    "ctx_session",
1674    "ctx_ledger",
1675];
1676
1677/// A workflow is stale if it hasn't been updated in 30 minutes.
1678/// This prevents dead workflows from blocking tools across sessions.
1679pub fn is_workflow_stale(run: &crate::core::workflow::types::WorkflowRun) -> bool {
1680    let elapsed = chrono::Utc::now()
1681        .signed_duration_since(run.updated_at)
1682        .num_minutes();
1683    elapsed > 30
1684}
1685
1686fn is_shell_tool_name(name: &str) -> bool {
1687    matches!(name, "ctx_shell" | "ctx_execute")
1688}
1689
1690fn extract_file_read_from_shell(cmd: &str) -> Option<String> {
1691    let trimmed = cmd.trim();
1692    let parts: Vec<&str> = trimmed.split_whitespace().collect();
1693    if parts.len() < 2 {
1694        return None;
1695    }
1696    let bin = parts[0].rsplit('/').next().unwrap_or(parts[0]);
1697    match bin {
1698        "cat" | "head" | "tail" | "less" | "more" | "bat" | "batcat" => {
1699            let file_arg = parts.iter().skip(1).find(|a| !a.starts_with('-'))?;
1700            Some(file_arg.to_string())
1701        }
1702        _ => None,
1703    }
1704}
1705
1706#[cfg(test)]
1707mod tests {
1708    use super::*;
1709
1710    #[test]
1711    fn project_markers_detected() {
1712        let tmp = tempfile::tempdir().unwrap();
1713        let root = tmp.path().join("myproject");
1714        std::fs::create_dir_all(&root).unwrap();
1715        assert!(!has_project_marker(&root));
1716
1717        std::fs::create_dir(root.join(".git")).unwrap();
1718        assert!(has_project_marker(&root));
1719    }
1720
1721    #[test]
1722    fn home_dir_detected_as_agent_dir() {
1723        if let Some(home) = dirs::home_dir() {
1724            assert!(is_home_or_agent_dir(&home));
1725        }
1726    }
1727
1728    #[test]
1729    fn agent_dirs_detected() {
1730        let claude = std::path::PathBuf::from("/home/user/.claude");
1731        assert!(is_home_or_agent_dir(&claude));
1732        let codex = std::path::PathBuf::from("/home/user/.codex");
1733        assert!(is_home_or_agent_dir(&codex));
1734        let project = std::path::PathBuf::from("/home/user/projects/myapp");
1735        assert!(!is_home_or_agent_dir(&project));
1736    }
1737
1738    #[test]
1739    fn test_unified_tool_count() {
1740        let tools = crate::tool_defs::unified_tool_defs();
1741        assert_eq!(tools.len(), 5, "Expected 5 unified tools");
1742    }
1743
1744    #[test]
1745    fn test_granular_tool_count() {
1746        let tools = crate::tool_defs::granular_tool_defs();
1747        assert!(tools.len() >= 25, "Expected at least 25 granular tools");
1748    }
1749
1750    #[test]
1751    fn test_registry_tool_count_ssot() {
1752        let registry = crate::server::registry::build_registry();
1753        assert_eq!(
1754            registry.len(),
1755            62,
1756            "Registry tool count drift! Update this test AND all docs when adding/removing tools."
1757        );
1758    }
1759
1760    #[test]
1761    fn disabled_tools_filters_list() {
1762        let all = crate::tool_defs::granular_tool_defs();
1763        let total = all.len();
1764        let disabled = ["ctx_graph".to_string(), "ctx_agent".to_string()];
1765        let filtered: Vec<_> = all
1766            .into_iter()
1767            .filter(|t| !disabled.iter().any(|d| t.name.as_ref() == d.as_str()))
1768            .collect();
1769        assert_eq!(filtered.len(), total - 2);
1770        assert!(!filtered.iter().any(|t| t.name.as_ref() == "ctx_graph"));
1771        assert!(!filtered.iter().any(|t| t.name.as_ref() == "ctx_agent"));
1772    }
1773
1774    #[test]
1775    fn empty_disabled_tools_returns_all() {
1776        let all = crate::tool_defs::granular_tool_defs();
1777        let total = all.len();
1778        let disabled: Vec<String> = vec![];
1779        let filtered: Vec<_> = all
1780            .into_iter()
1781            .filter(|t| !disabled.iter().any(|d| t.name.as_ref() == d.as_str()))
1782            .collect();
1783        assert_eq!(filtered.len(), total);
1784    }
1785
1786    #[test]
1787    fn misspelled_disabled_tool_is_silently_ignored() {
1788        let all = crate::tool_defs::granular_tool_defs();
1789        let total = all.len();
1790        let disabled = ["ctx_nonexistent_tool".to_string()];
1791        let filtered: Vec<_> = all
1792            .into_iter()
1793            .filter(|t| !disabled.iter().any(|d| t.name.as_ref() == d.as_str()))
1794            .collect();
1795        assert_eq!(filtered.len(), total);
1796    }
1797
1798    #[test]
1799    fn detect_multi_root_workspace_with_child_projects() {
1800        let tmp = tempfile::tempdir().unwrap();
1801        let workspace = tmp.path().join("workspace");
1802        std::fs::create_dir_all(&workspace).unwrap();
1803
1804        let proj_a = workspace.join("project-a");
1805        let proj_b = workspace.join("project-b");
1806        std::fs::create_dir_all(proj_a.join(".git")).unwrap();
1807        std::fs::create_dir_all(&proj_b).unwrap();
1808        std::fs::write(proj_b.join("package.json"), "{}").unwrap();
1809
1810        let result = detect_multi_root_workspace(&workspace);
1811        assert!(
1812            result.is_some(),
1813            "should detect workspace with 2 child projects"
1814        );
1815
1816        std::env::remove_var("LEAN_CTX_ALLOW_PATH");
1817    }
1818
1819    #[test]
1820    fn detect_multi_root_workspace_returns_none_for_single_project() {
1821        let tmp = tempfile::tempdir().unwrap();
1822        let workspace = tmp.path().join("workspace");
1823        std::fs::create_dir_all(&workspace).unwrap();
1824
1825        let proj_a = workspace.join("project-a");
1826        std::fs::create_dir_all(proj_a.join(".git")).unwrap();
1827
1828        let result = detect_multi_root_workspace(&workspace);
1829        assert!(
1830            result.is_none(),
1831            "should not detect workspace with only 1 child project"
1832        );
1833    }
1834
1835    #[test]
1836    fn is_broad_or_unsafe_root_rejects_home() {
1837        if let Some(home) = dirs::home_dir() {
1838            assert!(is_broad_or_unsafe_root(&home));
1839        }
1840    }
1841
1842    #[test]
1843    fn is_broad_or_unsafe_root_rejects_filesystem_root() {
1844        assert!(is_broad_or_unsafe_root(std::path::Path::new("/")));
1845    }
1846
1847    #[test]
1848    fn is_broad_or_unsafe_root_rejects_agent_dirs() {
1849        assert!(is_broad_or_unsafe_root(std::path::Path::new(
1850            "/home/user/.claude"
1851        )));
1852        assert!(is_broad_or_unsafe_root(std::path::Path::new(
1853            "/home/user/.codex"
1854        )));
1855    }
1856
1857    #[test]
1858    fn is_broad_or_unsafe_root_allows_project_subdir() {
1859        let tmp = tempfile::tempdir().unwrap();
1860        let subdir = tmp.path().join("my-project");
1861        std::fs::create_dir_all(&subdir).unwrap();
1862        assert!(!is_broad_or_unsafe_root(&subdir));
1863    }
1864
1865    #[test]
1866    fn is_broad_or_unsafe_root_allows_tmp_subdirs() {
1867        assert!(!is_broad_or_unsafe_root(std::path::Path::new(
1868            "/tmp/leanctx-test"
1869        )));
1870        assert!(!is_broad_or_unsafe_root(std::path::Path::new(
1871            "/tmp/my-project"
1872        )));
1873    }
1874
1875    #[test]
1876    fn is_broad_or_unsafe_root_allows_home_subdirs() {
1877        if let Some(home) = dirs::home_dir() {
1878            let subdir = home.join("projects").join("my-app");
1879            assert!(!is_broad_or_unsafe_root(&subdir));
1880        }
1881    }
1882
1883    #[test]
1884    fn derive_project_root_falls_back_to_bare_cwd() {
1885        let tmp = tempfile::tempdir().unwrap();
1886        let bare = tmp.path().join("bare-dir");
1887        std::fs::create_dir_all(&bare).unwrap();
1888
1889        let original = std::env::current_dir().unwrap();
1890        std::env::set_current_dir(&bare).unwrap();
1891        let result = derive_project_root_from_cwd();
1892        std::env::set_current_dir(original).unwrap();
1893
1894        assert!(result.is_some(), "bare dir should produce a project root");
1895        let root = result.unwrap();
1896        assert!(
1897            root.contains("bare-dir"),
1898            "fallback should use the bare dir path"
1899        );
1900    }
1901}