Skip to main content

lean_ctx/server/
mod.rs

1pub mod bounded_lock;
2pub mod bypass_hint;
3pub mod compaction_sync;
4pub mod context_gate;
5mod dispatch;
6pub mod dynamic_tools;
7pub mod elicitation;
8pub(crate) mod execute;
9pub mod helpers;
10pub mod multi_path;
11pub mod notifications;
12pub mod progress;
13pub mod prompts;
14pub mod reference_store;
15pub mod registry;
16pub mod resources;
17pub mod role_guard;
18pub mod roots;
19use roots::has_project_marker;
20pub mod tool_trait;
21
22use futures::FutureExt;
23use rmcp::handler::server::ServerHandler;
24use rmcp::model::{
25    CallToolRequestParams, CallToolResult, Content, Implementation, InitializeRequestParams,
26    InitializeResult, ListToolsResult, PaginatedRequestParams, ServerCapabilities, ServerInfo,
27};
28use rmcp::service::{RequestContext, RoleServer};
29use rmcp::ErrorData;
30
31use crate::tools::{CrpMode, LeanCtxServer};
32
33impl ServerHandler for LeanCtxServer {
34    fn get_info(&self) -> ServerInfo {
35        let capabilities = ServerCapabilities::builder()
36            .enable_tools()
37            .enable_resources()
38            .enable_resources_subscribe()
39            .enable_prompts()
40            .build();
41
42        let config = crate::core::config::Config::load();
43        let level = crate::core::config::CompressionLevel::effective(&config);
44        let _ = crate::core::terse::rules_inject::inject(&level);
45
46        let instructions = crate::instructions::build_instructions(CrpMode::effective());
47
48        InitializeResult::new(capabilities)
49            .with_server_info(Implementation::new("lean-ctx", env!("CARGO_PKG_VERSION")))
50            .with_instructions(instructions)
51    }
52
53    async fn initialize(
54        &self,
55        request: InitializeRequestParams,
56        context: RequestContext<RoleServer>,
57    ) -> Result<InitializeResult, ErrorData> {
58        let name = request.client_info.name.clone();
59        tracing::info!("MCP client connected: {:?}", name);
60        *self.client_name.write().await = name.clone();
61        *self.peer.write().await = Some(context.peer.clone());
62
63        if self.session_mode != crate::tools::SessionMode::Shared {
64            crate::core::budget_tracker::BudgetTracker::global().reset();
65            if let Ok(data_dir) = crate::core::data_dir::lean_ctx_data_dir() {
66                let radar = data_dir.join("context_radar.jsonl");
67                if radar.exists() {
68                    let prev = data_dir.join("context_radar.prev.jsonl");
69                    let _ = std::fs::rename(&radar, &prev);
70                }
71            }
72        }
73
74        let has_roots = request.capabilities.roots.is_some();
75        self.has_client_roots
76            .store(has_roots, std::sync::atomic::Ordering::Relaxed);
77        if has_roots {
78            tracing::info!("Client supports MCP roots/list — will resolve on first tool call");
79        }
80
81        let env_root = roots::root_from_env();
82        let derived_root = derive_project_root_from_cwd();
83        let effective_root = env_root.or(derived_root);
84
85        let cwd_str = std::env::current_dir()
86            .ok()
87            .map(|p| p.to_string_lossy().to_string())
88            .unwrap_or_default();
89        {
90            let mut session = self.session.write().await;
91            if !cwd_str.is_empty() {
92                session.shell_cwd = Some(cwd_str.clone());
93            }
94            if let Some(ref root) = effective_root {
95                session.project_root = Some(root.clone());
96                tracing::info!("Project root set to: {root}");
97            } else if let Some(ref root) = session.project_root {
98                // A previously persisted session may carry a contaminated root
99                // (e.g. HOME from an older build or a client that reported HOME
100                // as its workspace). Drop it unless it is a real, safe project
101                // dir — otherwise PROJECT MEMORY leaks across projects.
102                let root_path = std::path::Path::new(root);
103                let root_has_marker = has_project_marker(root_path);
104                let root_str = root_path.to_string_lossy();
105                let root_suspicious = crate::core::pathutil::is_broad_or_unsafe_root(root_path)
106                    || root_str.contains("/var/folders/")
107                    || root_str.contains("/tmp/")
108                    || root_str.contains("\\AppData\\Local\\Temp")
109                    || root_str.contains("\\Temp\\");
110                if root_suspicious && !root_has_marker {
111                    tracing::info!("Dropping suspicious persisted project root: {root}");
112                    session.project_root = None;
113                }
114            }
115            let cfg_extra = crate::core::config::Config::load().extra_roots;
116            if !cfg_extra.is_empty() {
117                let existing: std::collections::HashSet<_> =
118                    session.extra_roots.iter().cloned().collect();
119                for r in cfg_extra {
120                    if !existing.contains(&r) {
121                        session.extra_roots.push(r);
122                    }
123                }
124            }
125            if self.session_mode == crate::tools::SessionMode::Shared {
126                if let Some(ref root) = session.project_root {
127                    if let Some(ref rt) = self.context_os {
128                        rt.shared_sessions.persist_best_effort(
129                            root,
130                            &self.workspace_id,
131                            &self.channel_id,
132                            &session,
133                        );
134                        rt.metrics.record_session_persisted();
135                    }
136                }
137            } else if let Err(e) = session.save() {
138                tracing::warn!("lean-ctx: failed to persist session state: {e}");
139            }
140        }
141
142        if let Some(ref root) = effective_root {
143            crate::core::index_orchestrator::ensure_all_background(root);
144        }
145
146        let agent_name = name.clone();
147        let agent_root = effective_root.clone().unwrap_or_default();
148        let agent_id_handle = self.agent_id.clone();
149        tokio::task::spawn_blocking(move || {
150            if std::env::var("LEAN_CTX_HEADLESS").is_ok() {
151                return;
152            }
153
154            // Avoid startup stampedes when multiple agent sessions initialize at once.
155            // These are best-effort maintenance tasks; it's fine to skip if another
156            // lean-ctx instance is already doing them.
157            let maintenance = crate::core::startup_guard::try_acquire_lock(
158                "startup-maintenance",
159                std::time::Duration::from_secs(2),
160                std::time::Duration::from_mins(2),
161            );
162            if maintenance.is_some() {
163                if let Some(home) = dirs::home_dir() {
164                    let _ = crate::rules_inject::inject_all_rules(&home);
165                }
166                crate::hooks::refresh_installed_hooks();
167                crate::core::version_check::check_background();
168                // Enforce the on-disk budget: prune accumulated quarantined BM25
169                // indexes and cap the archive FTS DB (#2364). Silent (tracing
170                // only) so it never corrupts the MCP stdio protocol.
171                let _ = crate::core::storage_maintenance::run_quiet();
172            }
173            drop(maintenance);
174
175            if !agent_root.is_empty() {
176                let heuristic_role = match agent_name.to_lowercase().as_str() {
177                    n if n.contains("cursor") => Some("coder"),
178                    n if n.contains("claude") => Some("coder"),
179                    n if n.contains("codex") => Some("coder"),
180                    n if n.contains("antigravity") || n.contains("gemini") => Some("coder"),
181                    n if n.contains("review") => Some("reviewer"),
182                    n if n.contains("test") => Some("debugger"),
183                    _ => None,
184                };
185                let env_role = std::env::var("LEAN_CTX_ROLE")
186                    .or_else(|_| std::env::var("LEAN_CTX_AGENT_ROLE"))
187                    .ok();
188                let effective_role = env_role.as_deref().or(heuristic_role).unwrap_or("coder");
189
190                let _ = crate::core::roles::set_active_role_with_source(effective_role, true);
191
192                let mut registry = crate::core::agents::AgentRegistry::load_or_create();
193                registry.cleanup_stale(24);
194                let id = registry.register("mcp", Some(effective_role), &agent_root);
195                let _ = registry.save();
196                if let Ok(mut guard) = agent_id_handle.try_write() {
197                    *guard = Some(id);
198                }
199            }
200        });
201
202        let client_caps = crate::core::client_capabilities::ClientMcpCapabilities::detect(&name);
203        tracing::info!("Client capabilities: {}", client_caps.format_summary());
204
205        {
206            let cfg = crate::core::config::Config::load();
207            let cats = cfg.default_tool_categories_effective();
208            dynamic_tools::init_from_config(&cats);
209        }
210
211        if client_caps.dynamic_tools {
212            if let Ok(mut dt) = dynamic_tools::global().lock() {
213                dt.set_supports_list_changed(true);
214            }
215        }
216        if let Some(max) = client_caps.max_tools {
217            if let Ok(mut dt) = dynamic_tools::global().lock() {
218                dt.set_supports_list_changed(true);
219                if max < 100 {
220                    dt.unload_category(dynamic_tools::ToolCategory::Debug);
221                    dt.unload_category(dynamic_tools::ToolCategory::Memory);
222                }
223            }
224        }
225
226        crate::core::client_capabilities::set_detected(&client_caps);
227
228        let instructions =
229            crate::instructions::build_instructions_with_client(CrpMode::effective(), &name);
230
231        let capabilities = match (client_caps.resources, client_caps.prompts) {
232            (true, true) => ServerCapabilities::builder()
233                .enable_tools()
234                .enable_resources()
235                .enable_resources_subscribe()
236                .enable_prompts()
237                .build(),
238            (true, false) => ServerCapabilities::builder()
239                .enable_tools()
240                .enable_resources()
241                .enable_resources_subscribe()
242                .build(),
243            (false, true) => ServerCapabilities::builder()
244                .enable_tools()
245                .enable_prompts()
246                .build(),
247            (false, false) => ServerCapabilities::builder().enable_tools().build(),
248        };
249
250        Ok(InitializeResult::new(capabilities)
251            .with_server_info(Implementation::new("lean-ctx", env!("CARGO_PKG_VERSION")))
252            .with_instructions(instructions))
253    }
254
255    async fn list_tools(
256        &self,
257        _request: Option<PaginatedRequestParams>,
258        _context: RequestContext<RoleServer>,
259    ) -> Result<ListToolsResult, ErrorData> {
260        let all_tools = if crate::tool_defs::is_full_mode() {
261            if let Some(ref reg) = self.registry {
262                reg.tool_defs()
263            } else {
264                crate::tool_defs::granular_tool_defs()
265            }
266        } else if std::env::var("LEAN_CTX_UNIFIED").is_ok() {
267            crate::tool_defs::unified_tool_defs()
268        } else if let Some(ref reg) = self.registry {
269            let core_names = crate::tool_defs::core_tool_names();
270            reg.tool_defs()
271                .into_iter()
272                .filter(|t| core_names.contains(&t.name.as_ref()))
273                .collect()
274        } else {
275            crate::tool_defs::lazy_tool_defs()
276        };
277
278        let disabled = crate::core::config::Config::load().disabled_tools_effective();
279        let client = self.client_name.read().await.clone();
280        let is_zed = !client.is_empty() && client.to_lowercase().contains("zed");
281
282        let active_role = crate::core::roles::active_role();
283        let tools: Vec<_> = all_tools
284            .into_iter()
285            .filter(|t| {
286                let name = t.name.as_ref();
287                if !disabled.is_empty() && disabled.iter().any(|d| d.as_str() == name) {
288                    return false;
289                }
290                if is_zed && name == "ctx_edit" {
291                    return false;
292                }
293                if !active_role.is_tool_allowed(name) {
294                    return false;
295                }
296                true
297            })
298            .collect();
299
300        let tools = {
301            let Ok(dyn_state) = dynamic_tools::global().lock() else {
302                tracing::warn!("dynamic_tools mutex poisoned in list_tools; returning unfiltered");
303                return Ok(ListToolsResult {
304                    tools,
305                    ..Default::default()
306                });
307            };
308            if dyn_state.supports_list_changed() {
309                tools
310                    .into_iter()
311                    .filter(|t| dyn_state.is_tool_active(t.name.as_ref()))
312                    .collect()
313            } else {
314                tools
315            }
316        };
317
318        let tools = {
319            let active = self.workflow.read().await.clone();
320            if let Some(run) = active {
321                if run.current == "done" || is_workflow_stale(&run) {
322                    let mut wf = self.workflow.write().await;
323                    *wf = None;
324                    let _ = crate::core::workflow::clear_active();
325                } else if let Some(state) = run.spec.state(&run.current) {
326                    if let Some(allowed) = &state.allowed_tools {
327                        let mut allow: std::collections::HashSet<&str> =
328                            allowed.iter().map(std::string::String::as_str).collect();
329                        for passthrough in WORKFLOW_PASSTHROUGH_TOOLS {
330                            allow.insert(passthrough);
331                        }
332                        return Ok(ListToolsResult {
333                            tools: tools
334                                .into_iter()
335                                .filter(|t| allow.contains(t.name.as_ref()))
336                                .collect(),
337                            ..Default::default()
338                        });
339                    }
340                }
341            }
342            tools
343        };
344
345        let tools = {
346            let cfg = crate::core::config::Config::load();
347            let level = crate::core::config::CompressionLevel::effective(&cfg);
348            let mode =
349                crate::core::terse::mcp_compress::DescriptionMode::from_compression_level(&level);
350            if mode == crate::core::terse::mcp_compress::DescriptionMode::Full {
351                tools
352            } else {
353                tools
354                    .into_iter()
355                    .map(|mut t| {
356                        let compressed = crate::core::terse::mcp_compress::compress_description(
357                            t.name.as_ref(),
358                            t.description.as_deref().unwrap_or(""),
359                            mode,
360                        );
361                        t.description = Some(compressed.into());
362                        t
363                    })
364                    .collect()
365            }
366        };
367
368        Ok(ListToolsResult {
369            tools,
370            ..Default::default()
371        })
372    }
373
374    async fn list_prompts(
375        &self,
376        _request: Option<PaginatedRequestParams>,
377        _context: RequestContext<RoleServer>,
378    ) -> Result<rmcp::model::ListPromptsResult, ErrorData> {
379        Ok(rmcp::model::ListPromptsResult::with_all_items(
380            prompts::list_prompts(),
381        ))
382    }
383
384    async fn get_prompt(
385        &self,
386        request: rmcp::model::GetPromptRequestParams,
387        _context: RequestContext<RoleServer>,
388    ) -> Result<rmcp::model::GetPromptResult, ErrorData> {
389        let ledger = self.ledger.read().await;
390        match prompts::get_prompt(&request, &ledger) {
391            Some(result) => Ok(result),
392            None => Err(ErrorData::invalid_params(
393                format!("Unknown prompt: {}", request.name),
394                None,
395            )),
396        }
397    }
398
399    async fn list_resources(
400        &self,
401        _request: Option<PaginatedRequestParams>,
402        _context: RequestContext<RoleServer>,
403    ) -> Result<rmcp::model::ListResourcesResult, rmcp::ErrorData> {
404        Ok(rmcp::model::ListResourcesResult::with_all_items(
405            resources::list_resources(),
406        ))
407    }
408
409    async fn read_resource(
410        &self,
411        request: rmcp::model::ReadResourceRequestParams,
412        _context: RequestContext<RoleServer>,
413    ) -> Result<rmcp::model::ReadResourceResult, rmcp::ErrorData> {
414        let ledger = self.ledger.read().await;
415        match resources::read_resource(&request.uri, &ledger) {
416            Some(contents) => Ok(rmcp::model::ReadResourceResult::new(contents)),
417            None => Err(rmcp::ErrorData::resource_not_found(
418                format!("Unknown resource: {}", request.uri),
419                None,
420            )),
421        }
422    }
423
424    async fn call_tool(
425        &self,
426        request: CallToolRequestParams,
427        context: RequestContext<RoleServer>,
428    ) -> Result<CallToolResult, ErrorData> {
429        use std::panic::AssertUnwindSafe;
430
431        let progress_token = request
432            .meta
433            .as_ref()
434            .and_then(rmcp::model::Meta::get_progress_token);
435        if let Some(ref token) = progress_token {
436            let sender =
437                crate::server::progress::ProgressSender::new(context.peer.clone(), token.clone());
438            *self
439                .progress_sender
440                .lock()
441                .unwrap_or_else(std::sync::PoisonError::into_inner) = Some(sender);
442        }
443
444        let tool_name_for_panic = request.name.as_ref().to_string();
445        let args_fp_for_panic = request
446            .arguments
447            .as_ref()
448            .map(|a| {
449                crate::core::loop_detection::LoopDetector::fingerprint(&serde_json::Value::Object(
450                    a.clone(),
451                ))
452            })
453            .unwrap_or_default();
454
455        let loop_detector = self.loop_detector.clone();
456
457        match AssertUnwindSafe(self.call_tool_guarded(request))
458            .catch_unwind()
459            .await
460        {
461            Ok(result) => result,
462            Err(panic_payload) => {
463                let detail = if let Some(s) = panic_payload.downcast_ref::<&str>() {
464                    (*s).to_string()
465                } else if let Some(s) = panic_payload.downcast_ref::<String>() {
466                    s.clone()
467                } else {
468                    "unknown".to_string()
469                };
470                tracing::error!("call_tool panicked: {detail}");
471
472                if let Ok(mut detector) =
473                    tokio::time::timeout(std::time::Duration::from_secs(1), loop_detector.write())
474                        .await
475                {
476                    detector.record_error_outcome(&tool_name_for_panic, &args_fp_for_panic);
477                }
478
479                Ok(CallToolResult::error(vec![Content::text(
480                    "ERROR: lean-ctx internal error. The MCP server is still running. \
481                     Please retry or use a different approach."
482                        .to_string(),
483                )]))
484            }
485        }
486    }
487
488    async fn on_roots_list_changed(
489        &self,
490        _context: rmcp::service::NotificationContext<RoleServer>,
491    ) {
492        tracing::info!("Received roots/list_changed — will re-resolve on next tool call");
493        self.roots_resolved
494            .store(false, std::sync::atomic::Ordering::Relaxed);
495    }
496}
497
498impl LeanCtxServer {
499    async fn call_tool_guarded(
500        &self,
501        request: CallToolRequestParams,
502    ) -> Result<CallToolResult, ErrorData> {
503        self.check_idle_expiry().await;
504        self.resolve_roots_once().await;
505        elicitation::increment_call();
506
507        let original_name = request.name.as_ref().to_string();
508        let (resolved_name, resolved_args) = if original_name == "ctx" {
509            let sub = request
510                .arguments
511                .as_ref()
512                .and_then(|a| a.get("tool"))
513                .and_then(|v| v.as_str())
514                .map(std::string::ToString::to_string)
515                .ok_or_else(|| {
516                    ErrorData::invalid_params("'tool' is required for ctx meta-tool", None)
517                })?;
518            let tool_name = if sub.starts_with("ctx_") {
519                sub
520            } else {
521                format!("ctx_{sub}")
522            };
523            let mut args = request.arguments.unwrap_or_default();
524            args.remove("tool");
525            (tool_name, Some(args))
526        } else {
527            (original_name, request.arguments)
528        };
529        let name = resolved_name.as_str();
530        let args = resolved_args.as_ref();
531
532        let role_check = role_guard::check_tool_access(name);
533        if let Some(denied) = role_guard::into_call_tool_result(&role_check) {
534            tracing::warn!(
535                tool = name,
536                role = %role_check.role_name,
537                "Tool blocked by role policy"
538            );
539            return Ok(denied);
540        }
541
542        if name != "ctx_workflow" {
543            let active = self.workflow.read().await.clone();
544            if let Some(run) = active {
545                if run.current == "done" || is_workflow_stale(&run) {
546                    let mut wf = self.workflow.write().await;
547                    *wf = None;
548                    let _ = crate::core::workflow::clear_active();
549                } else if !WORKFLOW_PASSTHROUGH_TOOLS.contains(&name) {
550                    if let Some(state) = run.spec.state(&run.current) {
551                        if let Some(allowed) = &state.allowed_tools {
552                            let allowed_ok = allowed.iter().any(|t| t == name);
553                            if !allowed_ok {
554                                let mut shown = allowed.clone();
555                                shown.sort();
556                                shown.truncate(30);
557                                return Ok(CallToolResult::success(vec![Content::text(format!(
558                                    "Tool '{name}' blocked by workflow '{}' (state: {}). Allowed: {}. Use ctx_workflow(action=\"stop\") to exit.",
559                                    run.spec.name,
560                                    run.current,
561                                    shown.join(", ")
562                                ))]));
563                            }
564                        }
565                    }
566                }
567            }
568        }
569
570        let auto_context = {
571            let task = {
572                let session = self.session.read().await;
573                session.task.as_ref().map(|t| t.description.clone())
574            };
575            let project_root = {
576                let session = self.session.read().await;
577                session.project_root.clone()
578            };
579            let cache_timeout =
580                tokio::time::timeout(std::time::Duration::from_secs(5), self.cache.write()).await;
581            if let Ok(mut cache) = cache_timeout {
582                crate::tools::autonomy::session_lifecycle_pre_hook(
583                    &self.autonomy,
584                    name,
585                    &mut cache,
586                    task.as_deref(),
587                    project_root.as_deref(),
588                    CrpMode::effective(),
589                )
590            } else {
591                tracing::warn!("pre-dispatch: cache write-lock timeout (5s), skipping autonomy");
592                None
593            }
594        };
595
596        let args_fp = args
597            .map(|a| {
598                crate::core::loop_detection::LoopDetector::fingerprint(&serde_json::Value::Object(
599                    a.clone(),
600                ))
601            })
602            .unwrap_or_default();
603        let throttle_result = {
604            let fp = &args_fp;
605            let detector_timeout = tokio::time::timeout(
606                std::time::Duration::from_secs(3),
607                self.loop_detector.write(),
608            )
609            .await;
610            if let Ok(mut detector) = detector_timeout {
611                let is_search = crate::core::loop_detection::LoopDetector::is_search_tool(name);
612                let is_search_shell = name == "ctx_shell" && {
613                    let cmd = args
614                        .as_ref()
615                        .and_then(|a| a.get("command"))
616                        .and_then(|v| v.as_str())
617                        .unwrap_or("");
618                    crate::core::loop_detection::LoopDetector::is_search_shell_command(cmd)
619                };
620
621                if is_search || is_search_shell {
622                    let search_pattern = args.and_then(|a| {
623                        a.get("pattern")
624                            .or_else(|| a.get("query"))
625                            .and_then(|v| v.as_str())
626                    });
627                    let shell_pattern = if is_search_shell {
628                        args.and_then(|a| a.get("command"))
629                            .and_then(|v| v.as_str())
630                            .and_then(helpers::extract_search_pattern_from_command)
631                    } else {
632                        None
633                    };
634                    let pat = search_pattern.or(shell_pattern.as_deref());
635                    detector.record_search(name, fp, pat)
636                } else {
637                    detector.record_call(name, fp)
638                }
639            } else {
640                tracing::warn!("pre-dispatch: loop_detector write-lock timeout (3s), skipping");
641                crate::core::loop_detection::ThrottleResult::default()
642            }
643        };
644
645        if throttle_result.level == crate::core::loop_detection::ThrottleLevel::Blocked {
646            let msg = throttle_result.message.unwrap_or_default();
647            return Ok(CallToolResult::success(vec![Content::text(msg)]));
648        }
649
650        let throttle_warning =
651            if throttle_result.level == crate::core::loop_detection::ThrottleLevel::Reduced {
652                throttle_result.message.clone()
653            } else {
654                None
655            };
656
657        let config = crate::core::config::Config::load();
658        let minimal = config.minimal_overhead_effective();
659
660        {
661            use crate::core::budget_tracker::{BudgetLevel, BudgetTracker};
662            let snap = BudgetTracker::global().check();
663            if *snap.worst_level() == BudgetLevel::Exhausted
664                && name != "ctx_session"
665                && name != "ctx_cost"
666                && name != "ctx_metrics"
667            {
668                for (dim, lvl, used, limit) in [
669                    (
670                        "tokens",
671                        &snap.tokens.level,
672                        format!("{}", snap.tokens.used),
673                        format!("{}", snap.tokens.limit),
674                    ),
675                    (
676                        "shell",
677                        &snap.shell.level,
678                        format!("{}", snap.shell.used),
679                        format!("{}", snap.shell.limit),
680                    ),
681                    (
682                        "cost",
683                        &snap.cost.level,
684                        format!("${:.2}", snap.cost.used_usd),
685                        format!("${:.2}", snap.cost.limit_usd),
686                    ),
687                ] {
688                    if *lvl == BudgetLevel::Exhausted {
689                        crate::core::events::emit_budget_exhausted(&snap.role, dim, &used, &limit);
690                    }
691                }
692                let msg = format!(
693                    "[BUDGET EXHAUSTED] {}\n\
694                     Use `ctx_session action=role` to check/switch roles, \
695                     or `ctx_session action=reset` to start fresh.",
696                    snap.format_compact()
697                );
698                tracing::warn!(tool = name, "{msg}");
699                return Ok(CallToolResult::success(vec![Content::text(msg)]));
700            }
701        }
702
703        if is_shell_tool_name(name) {
704            crate::core::budget_tracker::BudgetTracker::global().record_shell();
705        }
706
707        let tool_start = std::time::Instant::now();
708        let (mut result_text, tool_saved_tokens) =
709            match self.dispatch_tool(name, args, minimal).await {
710                Ok(pair) => pair,
711                Err(e) => {
712                    if let Ok(mut detector) = tokio::time::timeout(
713                        std::time::Duration::from_secs(1),
714                        self.loop_detector.write(),
715                    )
716                    .await
717                    {
718                        detector.record_error_outcome(name, &args_fp);
719                    }
720                    return Err(e);
721                }
722            };
723
724        let is_raw_shell = name == "ctx_shell" && {
725            let arg_raw = helpers::get_bool(args, "raw").unwrap_or(false);
726            let arg_bypass = helpers::get_bool(args, "bypass").unwrap_or(false);
727            arg_raw
728                || arg_bypass
729                || std::env::var("LEAN_CTX_DISABLED").is_ok()
730                || std::env::var("LEAN_CTX_RAW").is_ok()
731        };
732
733        let pre_terse_len = result_text.len();
734        let output_tokens = {
735            let tokens = crate::core::tokens::count_tokens(&result_text) as u64;
736            crate::core::budget_tracker::BudgetTracker::global().record_tokens(tokens);
737            tokens
738        };
739
740        crate::core::anomaly::record_metric("tokens_per_call", output_tokens as f64);
741
742        // Context IR: record lineage for every tool call.
743        if let Some(ref ir) = self.context_ir {
744            let tool_duration = tool_start.elapsed();
745            let source_kind = match name {
746                n if n.contains("read") || n.contains("multi_read") || n.contains("smart_read") => {
747                    crate::core::context_ir::ContextIrSourceKindV1::Read
748                }
749                "ctx_shell" => crate::core::context_ir::ContextIrSourceKindV1::Shell,
750                "ctx_search" | "ctx_semantic_search" => {
751                    crate::core::context_ir::ContextIrSourceKindV1::Search
752                }
753                "ctx_provider" => crate::core::context_ir::ContextIrSourceKindV1::Provider,
754                _ => crate::core::context_ir::ContextIrSourceKindV1::Other,
755            };
756            let ir_path = helpers::get_str(args, "path");
757            let ir_command = helpers::get_str(args, "command");
758            let ir_mode = helpers::get_str(args, "mode");
759            let excerpt = if result_text.len() > 200 {
760                let mut end = 200;
761                while !result_text.is_char_boundary(end) && end > 0 {
762                    end -= 1;
763                }
764                &result_text[..end]
765            } else {
766                &result_text
767            };
768            let input = crate::core::context_ir::RecordIrInput {
769                kind: source_kind,
770                tool: name,
771                client_name: None,
772                agent_id: None,
773                path: ir_path.as_deref(),
774                command: ir_command.as_deref(),
775                pattern: ir_mode.as_deref(),
776                input_tokens: pre_terse_len / 4,
777                output_tokens: output_tokens as usize,
778                duration: tool_duration,
779                content_excerpt: excerpt,
780            };
781            ir.write().await.record(input);
782        }
783
784        // Correction-loop detection: track re-reads and re-runs as quality signals.
785        {
786            let mut detector = self.loop_detector.write().await;
787            if name == "ctx_read" {
788                let path = helpers::get_str(args, "path").unwrap_or_default();
789                let mode = helpers::get_str(args, "mode").unwrap_or_else(|| "auto".into());
790                let fresh = helpers::get_bool(args, "fresh").unwrap_or(false);
791                detector.record_read_for_correction(&path, &mode, fresh);
792            } else if name == "ctx_shell" {
793                let cmd = helpers::get_str(args, "command").unwrap_or_default();
794                detector.record_shell_for_correction(&cmd);
795            }
796            let correction_count = detector.correction_count();
797            if correction_count > 0 {
798                crate::core::anomaly::record_metric(
799                    "correction_loop_rate",
800                    f64::from(correction_count),
801                );
802            }
803            // Auto-degrade: reduce compression when correction rate is high
804            use crate::core::config::CompressionLevel;
805            if correction_count >= 5 {
806                CompressionLevel::set_session_degrade(&CompressionLevel::Off);
807            } else if correction_count >= 3 {
808                CompressionLevel::set_session_degrade(&CompressionLevel::Lite);
809            } else if correction_count == 0 {
810                CompressionLevel::clear_session_degrade();
811            }
812            detector.prune_corrections();
813        }
814
815        // Persist anomaly detector — debounced to reduce I/O in burst sequences.
816        crate::core::anomaly::save_debounced();
817
818        let budget_warning = {
819            use crate::core::budget_tracker::{BudgetLevel, BudgetTracker};
820            let snap = BudgetTracker::global().check();
821            if *snap.worst_level() == BudgetLevel::Warning {
822                for (dim, lvl, used, limit, pct) in [
823                    (
824                        "tokens",
825                        &snap.tokens.level,
826                        format!("{}", snap.tokens.used),
827                        format!("{}", snap.tokens.limit),
828                        snap.tokens.percent,
829                    ),
830                    (
831                        "shell",
832                        &snap.shell.level,
833                        format!("{}", snap.shell.used),
834                        format!("{}", snap.shell.limit),
835                        snap.shell.percent,
836                    ),
837                    (
838                        "cost",
839                        &snap.cost.level,
840                        format!("${:.2}", snap.cost.used_usd),
841                        format!("${:.2}", snap.cost.limit_usd),
842                        snap.cost.percent,
843                    ),
844                ] {
845                    if *lvl == BudgetLevel::Warning {
846                        crate::core::events::emit_budget_warning(
847                            &snap.role, dim, &used, &limit, pct,
848                        );
849                    }
850                }
851                if crate::core::protocol::meta_visible() {
852                    Some(format!("[BUDGET WARNING] {}", snap.format_compact()))
853                } else {
854                    None
855                }
856            } else {
857                None
858            }
859        };
860
861        let archive_hint = if minimal || is_raw_shell {
862            None
863        } else {
864            use crate::core::archive;
865            let archivable = matches!(
866                name,
867                "ctx_shell"
868                    | "ctx_read"
869                    | "ctx_multi_read"
870                    | "ctx_smart_read"
871                    | "ctx_execute"
872                    | "ctx_search"
873                    | "ctx_tree"
874            );
875            if archivable && archive::should_archive(&result_text) {
876                let cmd = helpers::get_str(args, "command")
877                    .or_else(|| helpers::get_str(args, "path"))
878                    .unwrap_or_default();
879                let session_id = self.session.read().await.id.clone();
880                let to_store = crate::core::redaction::redact_text_if_enabled(&result_text);
881                let tokens = crate::core::tokens::count_tokens(&to_store);
882                archive::store(name, &cmd, &to_store, Some(&session_id))
883                    .map(|id| archive::format_hint(&id, to_store.len(), tokens))
884            } else {
885                None
886            }
887        };
888
889        let pre_compression = result_text.clone();
890        let deeply_compressed = matches!(
891            name,
892            "ctx_read" | "ctx_multi_read" | "ctx_smart_read" | "ctx_compress" | "ctx_overview"
893        );
894        let skip_terse = is_raw_shell
895            || (tool_saved_tokens > 0 && deeply_compressed)
896            || (name == "ctx_shell"
897                && helpers::get_str(args, "command")
898                    .is_some_and(|c| crate::shell::compress::has_structural_output(&c)));
899        let compression = crate::core::config::CompressionLevel::effective(&config);
900        if compression.is_active() && !skip_terse {
901            let terse_result =
902                crate::core::terse::pipeline::compress(&result_text, &compression, None);
903            if terse_result.quality_passed && terse_result.savings_pct >= 3.0 {
904                result_text = terse_result.output;
905            }
906        }
907
908        let profile_hints = crate::core::profiles::active_profile().output_hints;
909
910        if !is_raw_shell && profile_hints.verify_footer() {
911            let verify_cfg = crate::core::profiles::active_profile().verification;
912            let vr = crate::core::output_verification::verify_output(
913                &pre_compression,
914                &result_text,
915                &verify_cfg,
916            );
917            if !vr.warnings.is_empty() {
918                let msg = format!("[VERIFY] {}", vr.format_compact());
919                result_text = format!("{result_text}\n\n{msg}");
920            }
921        }
922
923        if profile_hints.archive_hint() {
924            if let Some(hint) = archive_hint {
925                result_text = format!("{result_text}\n{hint}");
926            }
927        }
928
929        if !is_raw_shell {
930            if let Some(ctx) = auto_context {
931                let ctx_tokens = crate::core::tokens::count_tokens(&ctx);
932                if ctx_tokens <= 400 {
933                    result_text = format!("{ctx}\n\n{result_text}");
934                }
935            }
936        }
937
938        if let Some(warning) = throttle_warning {
939            result_text = format!("{result_text}\n\n{warning}");
940        }
941
942        if let Some(bw) = budget_warning {
943            result_text = format!("{result_text}\n\n{bw}");
944        }
945
946        if !self
947            .rules_stale_checked
948            .swap(true, std::sync::atomic::Ordering::Relaxed)
949        {
950            let client = self.client_name.read().await.clone();
951            if !client.is_empty() && crate::rules_inject::check_rules_freshness(&client).is_some() {
952                // Self-heal: auto-refresh the rules on disk instead of asking
953                // the user to run setup manually (#2365). The rewrite is
954                // idempotent and cheap; run it off the async runtime.
955                let _ = tokio::task::spawn_blocking(|| {
956                    if let Some(home) = dirs::home_dir() {
957                        let _ = crate::rules_inject::inject_all_rules(&home);
958                    }
959                })
960                .await;
961                result_text = format!(
962                    "{result_text}\n\n[RULES AUTO-UPDATED] Your lean-ctx rules were written by \
963                     an older version and have been refreshed on disk. Start a new session to \
964                     load them for full compatibility."
965                );
966            }
967        }
968
969        {
970            // Evaluate SLOs for observability (watch/dashboard), but keep tool outputs clean.
971            let _ = crate::core::slo::evaluate();
972        }
973
974        if name == "ctx_read" {
975            if minimal {
976                let cache_clone = self.cache.clone();
977                let autonomy_clone = self.autonomy.clone();
978                let name_owned = name.to_string();
979                tokio::spawn(async move {
980                    let result = std::panic::AssertUnwindSafe(async {
981                        let mut cache = cache_clone.write().await;
982                        crate::tools::autonomy::maybe_auto_dedup(
983                            &autonomy_clone,
984                            &mut cache,
985                            &name_owned,
986                        );
987                    })
988                    .catch_unwind()
989                    .await;
990                    if let Err(e) = result {
991                        let msg = e
992                            .downcast_ref::<String>()
993                            .map(String::as_str)
994                            .or_else(|| e.downcast_ref::<&str>().copied())
995                            .unwrap_or("unknown");
996                        tracing::error!("background auto_dedup panicked: {msg}");
997                    }
998                });
999            } else {
1000                let read_path = self
1001                    .resolve_path_or_passthrough(
1002                        &helpers::get_str(args, "path").unwrap_or_default(),
1003                    )
1004                    .await;
1005                let project_root = {
1006                    let session = self.session.read().await;
1007                    session.project_root.clone()
1008                };
1009
1010                // Bounded cache lock for enrichment — degrade gracefully under contention
1011                let enrich_timeout =
1012                    tokio::time::timeout(std::time::Duration::from_secs(3), self.cache.write())
1013                        .await;
1014                if let Ok(mut cache) = enrich_timeout {
1015                    let enrich = crate::tools::autonomy::enrich_after_read(
1016                        &self.autonomy,
1017                        &mut cache,
1018                        &read_path,
1019                        project_root.as_deref(),
1020                        None,
1021                        crate::tools::CrpMode::effective(),
1022                        false,
1023                    );
1024                    if profile_hints.related_hint() {
1025                        if let Some(hint) = enrich.related_hint {
1026                            result_text = format!("{result_text}\n{hint}");
1027                        }
1028                    }
1029                    crate::tools::autonomy::maybe_auto_dedup(&self.autonomy, &mut cache, name);
1030                } else {
1031                    tracing::warn!(
1032                        "post-dispatch cache lock timeout (3s) for {read_path}, skipping enrichment"
1033                    );
1034                }
1035
1036                // Ledger update — fire-and-forget to avoid blocking concurrent reads
1037                let ledger_clone = self.ledger.clone();
1038                let session_clone = self.session.clone();
1039                let peer_clone = self.peer.clone();
1040                let read_path_owned = read_path.clone();
1041                let project_root_owned = project_root.clone();
1042                let mode_used =
1043                    helpers::get_str(args, "mode").unwrap_or_else(|| "auto".to_string());
1044                let out_tok = output_tokens as usize;
1045                let sent_tok = crate::core::tokens::count_tokens(&result_text);
1046                let wants_eviction = true;
1047                let wants_elicitation = profile_hints.elicitation_hint();
1048                tokio::spawn(async move {
1049                    let result = std::panic::AssertUnwindSafe(async {
1050                        let active_task = {
1051                            let session = session_clone.read().await;
1052                            session.task.as_ref().map(|t| t.description.clone())
1053                        };
1054                        let mut ledger = ledger_clone.write().await;
1055                        let overlay = crate::core::context_overlay::OverlayStore::load_project(
1056                            &std::path::PathBuf::from(project_root_owned.as_deref().unwrap_or(".")),
1057                        );
1058                        let gate_result = context_gate::post_dispatch_record_with_task(
1059                            &read_path_owned,
1060                            &mode_used,
1061                            out_tok,
1062                            sent_tok,
1063                            &mut ledger,
1064                            &overlay,
1065                            active_task.as_deref(),
1066                        );
1067                        drop(ledger);
1068                        if wants_eviction {
1069                            if let Some(hint) = &gate_result.eviction_hint {
1070                                tracing::debug!("deferred eviction hint: {hint}");
1071                            }
1072                        }
1073                        if wants_elicitation {
1074                            if let Some(hint) = &gate_result.elicitation_hint {
1075                                tracing::debug!("deferred elicitation hint: {hint}");
1076                            }
1077                        }
1078                        if gate_result.resource_changed {
1079                            if let Some(peer) = peer_clone.read().await.as_ref() {
1080                                notifications::send_resource_updated(
1081                                    peer,
1082                                    notifications::RESOURCE_URI_SUMMARY,
1083                                )
1084                                .await;
1085                            }
1086                        }
1087                    })
1088                    .catch_unwind()
1089                    .await;
1090                    if let Err(e) = result {
1091                        let msg = e
1092                            .downcast_ref::<String>()
1093                            .map(String::as_str)
1094                            .or_else(|| e.downcast_ref::<&str>().copied())
1095                            .unwrap_or("unknown");
1096                        tracing::error!("background post_dispatch panicked: {msg}");
1097                    }
1098                });
1099            }
1100        }
1101
1102        if !minimal && !is_raw_shell && name == "ctx_shell" {
1103            let cmd = helpers::get_str(args, "command").unwrap_or_default();
1104
1105            if let Some(file_path) = extract_file_read_from_shell(&cmd) {
1106                if let Ok(mut bt) = crate::core::bounce_tracker::global().lock() {
1107                    bt.next_seq();
1108                    bt.record_shell_file_access(&file_path);
1109                }
1110            }
1111
1112            if profile_hints.efficiency_hint() {
1113                let calls = self.tool_calls.read().await;
1114                let last_original = calls.last().map_or(0, |c| c.original_tokens);
1115                drop(calls);
1116                let pre_hint_tokens = crate::core::tokens::count_tokens(&result_text);
1117                if let Some(hint) = crate::tools::autonomy::shell_efficiency_hint(
1118                    &self.autonomy,
1119                    &cmd,
1120                    last_original,
1121                    pre_hint_tokens,
1122                ) {
1123                    result_text = format!("{result_text}\n{hint}");
1124                }
1125            }
1126        }
1127
1128        if !minimal && !is_raw_shell {
1129            if let Ok(data_dir) = crate::core::data_dir::lean_ctx_data_dir() {
1130                let session = self.session.read().await;
1131                bypass_hint::set_session_id(&session.id);
1132                drop(session);
1133                if let Some(hint) = bypass_hint::check(&data_dir) {
1134                    result_text = format!("{result_text}\n{hint}");
1135                }
1136            }
1137            bypass_hint::record_lctx_call();
1138        }
1139
1140        if let Some(finding) = crate::core::auto_findings::extract(name, &result_text) {
1141            let mut session = self.session.write().await;
1142            session.add_finding(finding.file.as_deref(), None, &finding.summary);
1143            let project_root = session.project_root.clone();
1144            drop(session);
1145            if let Some(ref root) = project_root {
1146                let f = finding.clone();
1147                let r = root.clone();
1148                std::thread::spawn(move || {
1149                    crate::core::auto_capture::capture_finding(&r, &f);
1150                });
1151            }
1152        }
1153        if let Some(extra) = crate::core::auto_capture::extract_extra(name, &result_text) {
1154            let session = self.session.read().await;
1155            let project_root = session.project_root.clone();
1156            drop(session);
1157            if let Some(ref root) = project_root {
1158                let e = extra.clone();
1159                let r = root.clone();
1160                std::thread::spawn(move || {
1161                    crate::core::auto_capture::capture_finding(&r, &e);
1162                });
1163            }
1164        }
1165
1166        {
1167            let tool_name = name.to_string();
1168            let summary = result_text.lines().next().unwrap_or("").to_string();
1169            std::thread::spawn(move || {
1170                crate::core::journal::maybe_day_separator();
1171                crate::core::journal::log_tool_call(&tool_name, &summary);
1172            });
1173        }
1174
1175        #[allow(clippy::cast_possible_truncation)]
1176        let output_token_count = if result_text.len() == pre_terse_len {
1177            output_tokens as usize
1178        } else {
1179            crate::core::tokens::count_tokens(&result_text)
1180        };
1181
1182        // OPT-4: Correct stats with post-processing token counts.
1183        // dispatch/mod.rs records savings before terse/hints; adjust here
1184        // so persistent stats reflect what the model actually receives.
1185        if result_text.len() != pre_terse_len && tool_saved_tokens > 0 {
1186            let pre_savings = tool_saved_tokens;
1187            let actual_sent = output_token_count;
1188            let original = actual_sent + pre_savings;
1189            let actual_savings = original.saturating_sub(actual_sent);
1190            if actual_savings != pre_savings {
1191                let delta = pre_savings as i64 - actual_savings as i64;
1192                if delta != 0 {
1193                    crate::core::stats::adjust_savings(name, delta);
1194                }
1195            }
1196        }
1197
1198        let action = helpers::get_str(args, "action");
1199
1200        // K-bounded staleness guard: warn if shared context has diverged.
1201        const K_STALENESS_BOUND: i64 = 10;
1202        if self.session_mode == crate::tools::SessionMode::Shared {
1203            if let Some(ref rt) = self.context_os {
1204                let latest = rt.bus.latest_id(&self.workspace_id, &self.channel_id);
1205                let cursor = self
1206                    .last_seen_event_id
1207                    .load(std::sync::atomic::Ordering::Relaxed);
1208                if cursor > 0 && latest - cursor > K_STALENESS_BOUND {
1209                    let gap = latest - cursor;
1210                    result_text = format!(
1211                        "[CONTEXT STALE] {gap} events happened since your last read. \
1212                         Use ctx_session(action=\"status\") to sync.\n\n{result_text}"
1213                    );
1214                }
1215                self.last_seen_event_id
1216                    .store(latest, std::sync::atomic::Ordering::Relaxed);
1217            }
1218        }
1219
1220        {
1221            let input = helpers::canonical_args_string(args);
1222            let input_md5 = helpers::hash_fast(&input);
1223            let output_md5 = helpers::hash_fast(&result_text);
1224            let agent_id = self.agent_id.read().await.clone();
1225            let client_name = self.client_name.read().await.clone();
1226            let mut explicit_intent: Option<(
1227                crate::core::intent_protocol::IntentRecord,
1228                Option<String>,
1229                String,
1230            )> = None;
1231
1232            let pending_session_save = {
1233                let empty_args = serde_json::Map::new();
1234                let args_map = args.unwrap_or(&empty_args);
1235                let mut session = self.session.write().await;
1236                session.record_tool_receipt(
1237                    name,
1238                    action.as_deref(),
1239                    &input_md5,
1240                    &output_md5,
1241                    agent_id.as_deref(),
1242                    Some(&client_name),
1243                );
1244
1245                if let Some(intent) = crate::core::intent_protocol::infer_from_tool_call(
1246                    name,
1247                    action.as_deref(),
1248                    args_map,
1249                    session.project_root.as_deref(),
1250                ) {
1251                    let is_explicit =
1252                        intent.source == crate::core::intent_protocol::IntentSource::Explicit;
1253                    let root = session.project_root.clone();
1254                    let sid = session.id.clone();
1255                    session.record_intent(intent.clone());
1256                    if is_explicit {
1257                        explicit_intent = Some((intent, root, sid));
1258                    }
1259                }
1260                if session.should_save() {
1261                    session.prepare_save().ok()
1262                } else {
1263                    None
1264                }
1265            };
1266
1267            if let Some(prepared) = pending_session_save {
1268                let ir_clone = self.context_ir.clone();
1269                tokio::task::spawn_blocking(move || {
1270                    let _ = prepared.write_to_disk();
1271                    if let Some(ir) = ir_clone {
1272                        if let Ok(ir_guard) = ir.try_read() {
1273                            ir_guard.save();
1274                        }
1275                    }
1276                });
1277            }
1278
1279            if let Some((intent, root, session_id)) = explicit_intent {
1280                let _ = crate::core::intent_protocol::apply_side_effects(
1281                    &intent,
1282                    root.as_deref(),
1283                    &session_id,
1284                );
1285            }
1286
1287            if self.autonomy.is_enabled() {
1288                let (calls, project_root) = {
1289                    let session = self.session.read().await;
1290                    (session.stats.total_tool_calls, session.project_root.clone())
1291                };
1292
1293                if let Some(root) = project_root {
1294                    if crate::tools::autonomy::should_auto_consolidate(&self.autonomy, calls) {
1295                        let root_clone = root.clone();
1296                        tokio::task::spawn_blocking(move || {
1297                            let _ = crate::core::consolidation_engine::consolidate_latest(
1298                                &root_clone,
1299                                crate::core::consolidation_engine::ConsolidationBudgets::default(),
1300                            );
1301                        });
1302                    }
1303                }
1304            }
1305
1306            let agent_key = agent_id.unwrap_or_else(|| "unknown".to_string());
1307            let input_token_count = crate::core::tokens::count_tokens(&input) as u64;
1308            let output_token_count_u64 = output_token_count as u64;
1309            let name_owned = name.to_string();
1310            tokio::task::spawn_blocking(move || {
1311                let pricing = crate::core::gain::model_pricing::ModelPricing::load();
1312                let quote = pricing.quote_from_env_or_agent_type(&client_name);
1313                let cost_usd =
1314                    quote
1315                        .cost
1316                        .estimate_usd(input_token_count, output_token_count_u64, 0, 0);
1317                crate::core::budget_tracker::BudgetTracker::global().record_cost_usd(cost_usd);
1318
1319                let mut store = crate::core::a2a::cost_attribution::CostStore::load();
1320                store.record_tool_call(
1321                    &agent_key,
1322                    &client_name,
1323                    &name_owned,
1324                    input_token_count,
1325                    output_token_count_u64,
1326                    0,
1327                );
1328                if let Err(e) = store.save() {
1329                    tracing::warn!("lean-ctx: failed to persist cost attribution: {e}");
1330                }
1331            });
1332        }
1333
1334        // Context Bus: conflict detection for knowledge writes in shared mode.
1335        if self.session_mode == crate::tools::SessionMode::Shared
1336            && name == "ctx_knowledge"
1337            && action.as_deref() == Some("remember")
1338        {
1339            if let Some(ref rt) = self.context_os {
1340                let my_agent = self.agent_id.read().await.clone();
1341                let category = helpers::get_str(args, "category");
1342                let key = helpers::get_str(args, "key");
1343                if let (Some(ref cat), Some(ref k)) = (&category, &key) {
1344                    let recent = rt.bus.recent_by_kind(
1345                        &self.workspace_id,
1346                        &self.channel_id,
1347                        "knowledge_remembered",
1348                        20,
1349                    );
1350                    for ev in &recent {
1351                        let p = &ev.payload;
1352                        let ev_cat = p.get("category").and_then(|v| v.as_str());
1353                        let ev_key = p.get("key").and_then(|v| v.as_str());
1354                        let ev_actor = ev.actor.as_deref();
1355                        if ev_cat == Some(cat.as_str())
1356                            && ev_key == Some(k.as_str())
1357                            && ev_actor != my_agent.as_deref()
1358                        {
1359                            let other = ev_actor.unwrap_or("unknown");
1360                            result_text = format!(
1361                                "[CONFLICT] Agent '{other}' recently wrote to the same knowledge key \
1362                                 '{cat}/{k}'. Review before proceeding.\n\n{result_text}"
1363                            );
1364                            break;
1365                        }
1366                    }
1367                }
1368            }
1369        }
1370
1371        // Context OS: persist shared session + publish events.
1372        if self.session_mode == crate::tools::SessionMode::Shared {
1373            let ws = self.workspace_id.clone();
1374            let ch = self.channel_id.clone();
1375            let rt = self.context_os.clone();
1376            let agent = self.agent_id.read().await.clone();
1377            let tool = name.to_string();
1378            let tool_action = action.clone();
1379            let tool_path = helpers::get_str(args, "path");
1380            let tool_category = helpers::get_str(args, "category");
1381            let tool_key = helpers::get_str(args, "key");
1382            let session_snapshot = self.session.read().await.clone();
1383            let session_task = session_snapshot.task.clone();
1384            tokio::task::spawn_blocking(move || {
1385                let Some(rt) = rt else {
1386                    return;
1387                };
1388                let Some(root) = session_snapshot.project_root.as_deref() else {
1389                    return;
1390                };
1391                rt.shared_sessions
1392                    .persist_best_effort(root, &ws, &ch, &session_snapshot);
1393                rt.metrics.record_session_persisted();
1394
1395                let mut base_payload = serde_json::json!({
1396                    "tool": tool,
1397                    "action": tool_action,
1398                });
1399                if let Some(ref p) = tool_path {
1400                    base_payload["path"] = serde_json::Value::String(p.clone());
1401                }
1402                if let Some(ref c) = tool_category {
1403                    base_payload["category"] = serde_json::Value::String(c.clone());
1404                }
1405                if let Some(ref k) = tool_key {
1406                    base_payload["key"] = serde_json::Value::String(k.clone());
1407                }
1408                if let Some(ref t) = session_task {
1409                    base_payload["reasoning"] = serde_json::Value::String(t.description.clone());
1410                }
1411
1412                if rt
1413                    .bus
1414                    .append(
1415                        &ws,
1416                        &ch,
1417                        &crate::core::context_os::ContextEventKindV1::ToolCallRecorded,
1418                        agent.as_deref(),
1419                        base_payload.clone(),
1420                    )
1421                    .is_some()
1422                {
1423                    rt.metrics.record_event_appended();
1424                    rt.metrics.record_event_broadcast();
1425                }
1426
1427                if let Some(secondary) =
1428                    crate::core::context_os::secondary_event_kind(&tool, tool_action.as_deref())
1429                {
1430                    if rt
1431                        .bus
1432                        .append(&ws, &ch, &secondary, agent.as_deref(), base_payload)
1433                        .is_some()
1434                    {
1435                        rt.metrics.record_event_appended();
1436                        rt.metrics.record_event_broadcast();
1437                    }
1438                }
1439            });
1440        }
1441
1442        let skip_checkpoint = minimal
1443            || matches!(
1444                name,
1445                "ctx_compress"
1446                    | "ctx_metrics"
1447                    | "ctx_benchmark"
1448                    | "ctx_analyze"
1449                    | "ctx_cache"
1450                    | "ctx_discover"
1451                    | "ctx_dedup"
1452                    | "ctx_session"
1453                    | "ctx_knowledge"
1454                    | "ctx_agent"
1455                    | "ctx_share"
1456                    | "ctx_gain"
1457                    | "ctx_overview"
1458                    | "ctx_preload"
1459                    | "ctx_cost"
1460                    | "ctx_heatmap"
1461                    | "ctx_task"
1462                    | "ctx_impact"
1463                    | "ctx_architecture"
1464                    | "ctx_smells"
1465                    | "ctx_workflow"
1466            );
1467
1468        if !skip_checkpoint && self.increment_and_check() {
1469            if let Some(checkpoint) = self.auto_checkpoint().await {
1470                let interval = LeanCtxServer::checkpoint_interval_effective();
1471                let hints = crate::core::profiles::active_profile().output_hints;
1472                if hints.checkpoint_in_output() && crate::core::protocol::meta_visible() {
1473                    let combined = format!(
1474                        "{result_text}\n\n--- AUTO CHECKPOINT (every {interval} calls) ---\n{checkpoint}"
1475                    );
1476                    return Ok(CallToolResult::success(vec![Content::text(combined)]));
1477                }
1478            }
1479        }
1480
1481        let tool_duration_ms = tool_start.elapsed().as_millis() as u64;
1482        if tool_duration_ms > 100 {
1483            LeanCtxServer::append_tool_call_log(
1484                name,
1485                tool_duration_ms,
1486                0,
1487                0,
1488                None,
1489                &chrono::Local::now().format("%Y-%m-%d %H:%M:%S").to_string(),
1490            );
1491        }
1492
1493        let current_count = self.call_count.load(std::sync::atomic::Ordering::Relaxed);
1494        if current_count > 0 && current_count.is_multiple_of(100) {
1495            std::thread::spawn(crate::cloud_sync::cloud_background_tasks);
1496        }
1497
1498        Ok(CallToolResult::success(vec![Content::text(result_text)]))
1499    }
1500
1501    /// Resolve project root from MCP client roots (once per session).
1502    /// Called on the first tool call. If the client supports `roots/list`,
1503    /// we query it and pick the best root with project markers.
1504    async fn resolve_roots_once(&self) {
1505        use std::sync::atomic::Ordering;
1506        if !self.has_client_roots.load(Ordering::Relaxed) {
1507            return;
1508        }
1509        if self.roots_resolved.swap(true, Ordering::Relaxed) {
1510            return;
1511        }
1512        let peer_guard = self.peer.read().await;
1513        let Some(peer) = peer_guard.as_ref() else {
1514            return;
1515        };
1516        let list_result = match peer.list_roots().await {
1517            Ok(r) => r,
1518            Err(e) => {
1519                tracing::warn!("roots/list failed: {e}");
1520                return;
1521            }
1522        };
1523        drop(peer_guard);
1524
1525        let uris: Vec<String> = list_result.roots.iter().map(|r| r.uri.clone()).collect();
1526        let validated_paths = roots::valid_dir_paths_from_uris(&uris);
1527        let Some(new_root) = roots::best_root_from_uris(&uris) else {
1528            return;
1529        };
1530        // Defense-in-depth: never adopt a broad/unsafe root (HOME, `/`, agent
1531        // sandbox dirs) even if the client reports it — it would pollute the
1532        // session and resolve relative paths against the wrong tree.
1533        if crate::core::pathutil::is_broad_or_unsafe_root(std::path::Path::new(&new_root)) {
1534            tracing::warn!("MCP roots: ignoring unsafe project root {new_root}");
1535            return;
1536        }
1537
1538        let mut session = self.session.write().await;
1539        let old_root = session.project_root.clone();
1540
1541        let other_roots: Vec<String> = validated_paths
1542            .iter()
1543            .filter(|p| p.as_str() != new_root)
1544            .cloned()
1545            .collect();
1546        if !other_roots.is_empty() {
1547            session.extra_roots = other_roots;
1548            tracing::info!(
1549                "MCP roots: {} extra root(s) registered",
1550                session.extra_roots.len()
1551            );
1552        }
1553
1554        if old_root.as_deref() == Some(&new_root) {
1555            let _ = session.save();
1556            return;
1557        }
1558        tracing::info!(
1559            "MCP roots: switching project root from {:?} to {new_root}",
1560            old_root
1561        );
1562        if let Some(existing) =
1563            crate::core::session::SessionState::load_latest_for_project_root(&new_root)
1564        {
1565            *session = existing;
1566            session.extra_roots = validated_paths
1567                .iter()
1568                .filter(|p| p.as_str() != new_root)
1569                .cloned()
1570                .collect();
1571        }
1572        session.project_root = Some(new_root);
1573        let _ = session.save();
1574    }
1575}
1576
1577pub fn build_instructions_for_test(crp_mode: CrpMode) -> String {
1578    crate::instructions::build_instructions_for_test(crp_mode)
1579}
1580
1581pub fn build_claude_code_instructions_for_test() -> String {
1582    crate::instructions::claude_code_instructions()
1583}
1584
1585fn is_home_or_agent_dir(dir: &std::path::Path) -> bool {
1586    if let Some(home) = dirs::home_dir() {
1587        if dir == home {
1588            return true;
1589        }
1590    }
1591    let dir_str = dir.to_string_lossy();
1592    dir_str.ends_with("/.claude")
1593        || dir_str.ends_with("/.codex")
1594        || dir_str.contains("/.claude/")
1595        || dir_str.contains("/.codex/")
1596}
1597
1598fn git_toplevel_from(dir: &std::path::Path) -> Option<String> {
1599    std::process::Command::new("git")
1600        .args(["rev-parse", "--show-toplevel"])
1601        .current_dir(dir)
1602        .stdout(std::process::Stdio::piped())
1603        .stderr(std::process::Stdio::null())
1604        .output()
1605        .ok()
1606        .and_then(|o| {
1607            if o.status.success() {
1608                String::from_utf8(o.stdout)
1609                    .ok()
1610                    .map(|s| s.trim().to_string())
1611            } else {
1612                None
1613            }
1614        })
1615}
1616
1617pub fn derive_project_root_from_cwd() -> Option<String> {
1618    let cwd = std::env::current_dir().ok()?;
1619    let canonical = crate::core::pathutil::safe_canonicalize_or_self(&cwd);
1620
1621    if is_home_or_agent_dir(&canonical) {
1622        return git_toplevel_from(&canonical);
1623    }
1624
1625    if has_project_marker(&canonical) {
1626        return Some(canonical.to_string_lossy().to_string());
1627    }
1628
1629    if let Some(git_root) = git_toplevel_from(&canonical) {
1630        return Some(git_root);
1631    }
1632
1633    if let Some(root) = detect_multi_root_workspace(&canonical) {
1634        return Some(root);
1635    }
1636
1637    // Fallback: use CWD as project root if it's a specific, safe directory.
1638    // This ensures bare directories (no .git, no markers) still work.
1639    // Guard: reject home dir, filesystem root, and agent sandbox dirs.
1640    if !crate::core::pathutil::is_broad_or_unsafe_root(&canonical) {
1641        tracing::info!(
1642            "No project markers found — using CWD as project root: {}",
1643            canonical.display()
1644        );
1645        return Some(canonical.to_string_lossy().to_string());
1646    }
1647
1648    None
1649}
1650
1651// Delegated to crate::core::pathutil::is_broad_or_unsafe_root
1652#[cfg(test)]
1653use crate::core::pathutil::is_broad_or_unsafe_root;
1654
1655/// Detect a multi-root workspace: a directory that has no project markers
1656/// itself, but contains child directories that do. In this case, use the
1657/// parent as jail root and auto-allow all child projects via LEAN_CTX_ALLOW_PATH.
1658fn detect_multi_root_workspace(dir: &std::path::Path) -> Option<String> {
1659    let entries = std::fs::read_dir(dir).ok()?;
1660    let mut child_projects: Vec<String> = Vec::new();
1661
1662    for entry in entries.flatten() {
1663        let path = entry.path();
1664        if path.is_dir() && has_project_marker(&path) {
1665            let canonical = crate::core::pathutil::safe_canonicalize_or_self(&path);
1666            child_projects.push(canonical.to_string_lossy().to_string());
1667        }
1668    }
1669
1670    if child_projects.len() >= 2 {
1671        let existing = std::env::var("LEAN_CTX_ALLOW_PATH").unwrap_or_default();
1672        let sep = if cfg!(windows) { ";" } else { ":" };
1673        let merged = if existing.is_empty() {
1674            child_projects.join(sep)
1675        } else {
1676            format!("{existing}{sep}{}", child_projects.join(sep))
1677        };
1678        std::env::set_var("LEAN_CTX_ALLOW_PATH", &merged);
1679        tracing::info!(
1680            "Multi-root workspace detected at {}: auto-allowing {} child projects",
1681            dir.display(),
1682            child_projects.len()
1683        );
1684        return Some(dir.to_string_lossy().to_string());
1685    }
1686
1687    None
1688}
1689
1690pub fn tool_descriptions_for_test() -> Vec<(&'static str, &'static str)> {
1691    crate::tool_defs::list_all_tool_defs()
1692        .into_iter()
1693        .map(|(name, desc, _)| (name, desc))
1694        .collect()
1695}
1696
1697pub fn tool_schemas_json_for_test() -> String {
1698    crate::tool_defs::list_all_tool_defs()
1699        .iter()
1700        .map(|(name, _, schema)| format!("{name}: {schema}"))
1701        .collect::<Vec<_>>()
1702        .join("\n")
1703}
1704
1705/// Tools that always pass through the workflow gate regardless of state.
1706/// Read-only tools should never be blocked — agents need them for context
1707/// recovery after crashes or session transitions.
1708pub const WORKFLOW_PASSTHROUGH_TOOLS: &[&str] = &[
1709    "ctx",
1710    "ctx_workflow",
1711    "ctx_read",
1712    "ctx_multi_read",
1713    "ctx_smart_read",
1714    "ctx_search",
1715    "ctx_tree",
1716    "ctx_session",
1717    "ctx_ledger",
1718];
1719
1720/// A workflow is stale if it hasn't been updated in 30 minutes.
1721/// This prevents dead workflows from blocking tools across sessions.
1722pub fn is_workflow_stale(run: &crate::core::workflow::types::WorkflowRun) -> bool {
1723    let elapsed = chrono::Utc::now()
1724        .signed_duration_since(run.updated_at)
1725        .num_minutes();
1726    elapsed > 30
1727}
1728
1729fn is_shell_tool_name(name: &str) -> bool {
1730    matches!(name, "ctx_shell" | "ctx_execute")
1731}
1732
1733fn extract_file_read_from_shell(cmd: &str) -> Option<String> {
1734    let trimmed = cmd.trim();
1735    let parts: Vec<&str> = trimmed.split_whitespace().collect();
1736    if parts.len() < 2 {
1737        return None;
1738    }
1739    let bin = parts[0].rsplit('/').next().unwrap_or(parts[0]);
1740    match bin {
1741        "cat" | "head" | "tail" | "less" | "more" | "bat" | "batcat" => {
1742            let file_arg = parts.iter().skip(1).find(|a| !a.starts_with('-'))?;
1743            Some(file_arg.to_string())
1744        }
1745        _ => None,
1746    }
1747}
1748
1749#[cfg(test)]
1750mod tests {
1751    use super::*;
1752
1753    #[test]
1754    fn project_markers_detected() {
1755        let tmp = tempfile::tempdir().unwrap();
1756        let root = tmp.path().join("myproject");
1757        std::fs::create_dir_all(&root).unwrap();
1758        assert!(!has_project_marker(&root));
1759
1760        std::fs::create_dir(root.join(".git")).unwrap();
1761        assert!(has_project_marker(&root));
1762    }
1763
1764    #[test]
1765    fn home_dir_detected_as_agent_dir() {
1766        if let Some(home) = dirs::home_dir() {
1767            assert!(is_home_or_agent_dir(&home));
1768        }
1769    }
1770
1771    #[test]
1772    fn agent_dirs_detected() {
1773        let claude = std::path::PathBuf::from("/home/user/.claude");
1774        assert!(is_home_or_agent_dir(&claude));
1775        let codex = std::path::PathBuf::from("/home/user/.codex");
1776        assert!(is_home_or_agent_dir(&codex));
1777        let project = std::path::PathBuf::from("/home/user/projects/myapp");
1778        assert!(!is_home_or_agent_dir(&project));
1779    }
1780
1781    #[test]
1782    fn test_unified_tool_count() {
1783        let tools = crate::tool_defs::unified_tool_defs();
1784        assert_eq!(tools.len(), 5, "Expected 5 unified tools");
1785    }
1786
1787    #[test]
1788    fn test_granular_tool_count() {
1789        let tools = crate::tool_defs::granular_tool_defs();
1790        assert!(tools.len() >= 25, "Expected at least 25 granular tools");
1791    }
1792
1793    #[test]
1794    fn test_registry_tool_count_ssot() {
1795        let registry = crate::server::registry::build_registry();
1796        assert_eq!(
1797            registry.len(),
1798            63,
1799            "Registry tool count drift! Update this test AND all docs when adding/removing tools."
1800        );
1801    }
1802
1803    #[test]
1804    fn disabled_tools_filters_list() {
1805        let all = crate::tool_defs::granular_tool_defs();
1806        let total = all.len();
1807        let disabled = ["ctx_graph".to_string(), "ctx_agent".to_string()];
1808        let filtered: Vec<_> = all
1809            .into_iter()
1810            .filter(|t| !disabled.iter().any(|d| t.name.as_ref() == d.as_str()))
1811            .collect();
1812        assert_eq!(filtered.len(), total - 2);
1813        assert!(!filtered.iter().any(|t| t.name.as_ref() == "ctx_graph"));
1814        assert!(!filtered.iter().any(|t| t.name.as_ref() == "ctx_agent"));
1815    }
1816
1817    #[test]
1818    fn empty_disabled_tools_returns_all() {
1819        let all = crate::tool_defs::granular_tool_defs();
1820        let total = all.len();
1821        let disabled: Vec<String> = vec![];
1822        let filtered: Vec<_> = all
1823            .into_iter()
1824            .filter(|t| !disabled.iter().any(|d| t.name.as_ref() == d.as_str()))
1825            .collect();
1826        assert_eq!(filtered.len(), total);
1827    }
1828
1829    #[test]
1830    fn misspelled_disabled_tool_is_silently_ignored() {
1831        let all = crate::tool_defs::granular_tool_defs();
1832        let total = all.len();
1833        let disabled = ["ctx_nonexistent_tool".to_string()];
1834        let filtered: Vec<_> = all
1835            .into_iter()
1836            .filter(|t| !disabled.iter().any(|d| t.name.as_ref() == d.as_str()))
1837            .collect();
1838        assert_eq!(filtered.len(), total);
1839    }
1840
1841    #[test]
1842    fn detect_multi_root_workspace_with_child_projects() {
1843        let tmp = tempfile::tempdir().unwrap();
1844        let workspace = tmp.path().join("workspace");
1845        std::fs::create_dir_all(&workspace).unwrap();
1846
1847        let proj_a = workspace.join("project-a");
1848        let proj_b = workspace.join("project-b");
1849        std::fs::create_dir_all(proj_a.join(".git")).unwrap();
1850        std::fs::create_dir_all(&proj_b).unwrap();
1851        std::fs::write(proj_b.join("package.json"), "{}").unwrap();
1852
1853        let result = detect_multi_root_workspace(&workspace);
1854        assert!(
1855            result.is_some(),
1856            "should detect workspace with 2 child projects"
1857        );
1858
1859        std::env::remove_var("LEAN_CTX_ALLOW_PATH");
1860    }
1861
1862    #[test]
1863    fn detect_multi_root_workspace_returns_none_for_single_project() {
1864        let tmp = tempfile::tempdir().unwrap();
1865        let workspace = tmp.path().join("workspace");
1866        std::fs::create_dir_all(&workspace).unwrap();
1867
1868        let proj_a = workspace.join("project-a");
1869        std::fs::create_dir_all(proj_a.join(".git")).unwrap();
1870
1871        let result = detect_multi_root_workspace(&workspace);
1872        assert!(
1873            result.is_none(),
1874            "should not detect workspace with only 1 child project"
1875        );
1876    }
1877
1878    #[test]
1879    fn is_broad_or_unsafe_root_rejects_home() {
1880        if let Some(home) = dirs::home_dir() {
1881            assert!(is_broad_or_unsafe_root(&home));
1882        }
1883    }
1884
1885    #[test]
1886    fn is_broad_or_unsafe_root_rejects_filesystem_root() {
1887        assert!(is_broad_or_unsafe_root(std::path::Path::new("/")));
1888    }
1889
1890    #[test]
1891    fn is_broad_or_unsafe_root_rejects_agent_dirs() {
1892        assert!(is_broad_or_unsafe_root(std::path::Path::new(
1893            "/home/user/.claude"
1894        )));
1895        assert!(is_broad_or_unsafe_root(std::path::Path::new(
1896            "/home/user/.codex"
1897        )));
1898    }
1899
1900    #[test]
1901    fn is_broad_or_unsafe_root_allows_project_subdir() {
1902        let tmp = tempfile::tempdir().unwrap();
1903        let subdir = tmp.path().join("my-project");
1904        std::fs::create_dir_all(&subdir).unwrap();
1905        assert!(!is_broad_or_unsafe_root(&subdir));
1906    }
1907
1908    #[test]
1909    fn is_broad_or_unsafe_root_allows_tmp_subdirs() {
1910        assert!(!is_broad_or_unsafe_root(std::path::Path::new(
1911            "/tmp/leanctx-test"
1912        )));
1913        assert!(!is_broad_or_unsafe_root(std::path::Path::new(
1914            "/tmp/my-project"
1915        )));
1916    }
1917
1918    #[test]
1919    fn is_broad_or_unsafe_root_allows_home_subdirs() {
1920        if let Some(home) = dirs::home_dir() {
1921            let subdir = home.join("projects").join("my-app");
1922            assert!(!is_broad_or_unsafe_root(&subdir));
1923        }
1924    }
1925
1926    #[test]
1927    fn derive_project_root_falls_back_to_bare_cwd() {
1928        let tmp = tempfile::tempdir().unwrap();
1929        let bare = tmp.path().join("bare-dir");
1930        std::fs::create_dir_all(&bare).unwrap();
1931
1932        let original = std::env::current_dir().unwrap();
1933        std::env::set_current_dir(&bare).unwrap();
1934        let result = derive_project_root_from_cwd();
1935        std::env::set_current_dir(original).unwrap();
1936
1937        assert!(result.is_some(), "bare dir should produce a project root");
1938        let root = result.unwrap();
1939        assert!(
1940            root.contains("bare-dir"),
1941            "fallback should use the bare dir path"
1942        );
1943    }
1944}