Skip to main content

lean_ctx/server/
mod.rs

1pub mod bounded_lock;
2pub mod bypass_hint;
3pub mod compaction_sync;
4pub mod context_gate;
5mod dispatch;
6pub mod dynamic_tools;
7pub mod elicitation;
8pub(crate) mod execute;
9pub mod helpers;
10pub mod notifications;
11pub mod prompts;
12pub mod reference_store;
13pub mod registry;
14pub mod resources;
15pub mod role_guard;
16pub mod tool_trait;
17
18use futures::FutureExt;
19use rmcp::handler::server::ServerHandler;
20use rmcp::model::{
21    CallToolRequestParams, CallToolResult, Content, Implementation, InitializeRequestParams,
22    InitializeResult, ListToolsResult, PaginatedRequestParams, ServerCapabilities, ServerInfo,
23};
24use rmcp::service::{RequestContext, RoleServer};
25use rmcp::ErrorData;
26
27use crate::tools::{CrpMode, LeanCtxServer};
28
29impl ServerHandler for LeanCtxServer {
30    fn get_info(&self) -> ServerInfo {
31        let capabilities = ServerCapabilities::builder()
32            .enable_tools()
33            .enable_resources()
34            .enable_resources_subscribe()
35            .enable_prompts()
36            .build();
37
38        let config = crate::core::config::Config::load();
39        let level = crate::core::config::CompressionLevel::effective(&config);
40        let _ = crate::core::terse::rules_inject::inject(&level);
41
42        let instructions = crate::instructions::build_instructions(CrpMode::effective());
43
44        InitializeResult::new(capabilities)
45            .with_server_info(Implementation::new("lean-ctx", env!("CARGO_PKG_VERSION")))
46            .with_instructions(instructions)
47    }
48
49    async fn initialize(
50        &self,
51        request: InitializeRequestParams,
52        context: RequestContext<RoleServer>,
53    ) -> Result<InitializeResult, ErrorData> {
54        let name = request.client_info.name.clone();
55        tracing::info!("MCP client connected: {:?}", name);
56        *self.client_name.write().await = name.clone();
57        *self.peer.write().await = Some(context.peer.clone());
58
59        if self.session_mode != crate::tools::SessionMode::Shared {
60            crate::core::budget_tracker::BudgetTracker::global().reset();
61            if let Ok(data_dir) = crate::core::data_dir::lean_ctx_data_dir() {
62                let radar = data_dir.join("context_radar.jsonl");
63                if radar.exists() {
64                    let prev = data_dir.join("context_radar.prev.jsonl");
65                    let _ = std::fs::rename(&radar, &prev);
66                }
67            }
68        }
69
70        let derived_root = derive_project_root_from_cwd();
71        let cwd_str = std::env::current_dir()
72            .ok()
73            .map(|p| p.to_string_lossy().to_string())
74            .unwrap_or_default();
75        {
76            let mut session = self.session.write().await;
77            if !cwd_str.is_empty() {
78                session.shell_cwd = Some(cwd_str.clone());
79            }
80            if let Some(ref root) = derived_root {
81                session.project_root = Some(root.clone());
82                tracing::info!("Project root set to: {root}");
83            } else if let Some(ref root) = session.project_root {
84                let root_path = std::path::Path::new(root);
85                let root_has_marker = has_project_marker(root_path);
86                let root_str = root_path.to_string_lossy();
87                let root_suspicious = root_str.contains("/.claude")
88                    || root_str.contains("/.codex")
89                    || root_str.contains("/var/folders/")
90                    || root_str.contains("/tmp/")
91                    || root_str.contains("\\.claude")
92                    || root_str.contains("\\.codex")
93                    || root_str.contains("\\AppData\\Local\\Temp")
94                    || root_str.contains("\\Temp\\");
95                if root_suspicious && !root_has_marker {
96                    session.project_root = None;
97                }
98            }
99            if self.session_mode == crate::tools::SessionMode::Shared {
100                if let Some(ref root) = session.project_root {
101                    if let Some(ref rt) = self.context_os {
102                        rt.shared_sessions.persist_best_effort(
103                            root,
104                            &self.workspace_id,
105                            &self.channel_id,
106                            &session,
107                        );
108                        rt.metrics.record_session_persisted();
109                    }
110                }
111            } else {
112                let _ = session.save();
113            }
114        }
115
116        let agent_name = name.clone();
117        let agent_root = derived_root.clone().unwrap_or_default();
118        let agent_id_handle = self.agent_id.clone();
119        tokio::task::spawn_blocking(move || {
120            if std::env::var("LEAN_CTX_HEADLESS").is_ok() {
121                return;
122            }
123
124            // Avoid startup stampedes when multiple agent sessions initialize at once.
125            // These are best-effort maintenance tasks; it's fine to skip if another
126            // lean-ctx instance is already doing them.
127            let maintenance = crate::core::startup_guard::try_acquire_lock(
128                "startup-maintenance",
129                std::time::Duration::from_secs(2),
130                std::time::Duration::from_mins(2),
131            );
132            if maintenance.is_some() {
133                if let Some(home) = dirs::home_dir() {
134                    let _ = crate::rules_inject::inject_all_rules(&home);
135                }
136                crate::hooks::refresh_installed_hooks();
137                crate::core::version_check::check_background();
138            }
139            drop(maintenance);
140
141            if !agent_root.is_empty() {
142                let heuristic_role = match agent_name.to_lowercase().as_str() {
143                    n if n.contains("cursor") => Some("coder"),
144                    n if n.contains("claude") => Some("coder"),
145                    n if n.contains("codex") => Some("coder"),
146                    n if n.contains("antigravity") || n.contains("gemini") => Some("coder"),
147                    n if n.contains("review") => Some("reviewer"),
148                    n if n.contains("test") => Some("debugger"),
149                    _ => None,
150                };
151                let env_role = std::env::var("LEAN_CTX_ROLE")
152                    .or_else(|_| std::env::var("LEAN_CTX_AGENT_ROLE"))
153                    .ok();
154                let effective_role = env_role.as_deref().or(heuristic_role).unwrap_or("coder");
155
156                let _ = crate::core::roles::set_active_role(effective_role);
157
158                let mut registry = crate::core::agents::AgentRegistry::load_or_create();
159                registry.cleanup_stale(24);
160                let id = registry.register("mcp", Some(effective_role), &agent_root);
161                let _ = registry.save();
162                if let Ok(mut guard) = agent_id_handle.try_write() {
163                    *guard = Some(id);
164                }
165            }
166        });
167
168        let client_caps = crate::core::client_capabilities::ClientMcpCapabilities::detect(&name);
169        tracing::info!("Client capabilities: {}", client_caps.format_summary());
170
171        {
172            let cfg = crate::core::config::Config::load();
173            let cats = cfg.default_tool_categories_effective();
174            dynamic_tools::init_from_config(&cats);
175        }
176
177        if client_caps.dynamic_tools {
178            if let Ok(mut dt) = dynamic_tools::global().lock() {
179                dt.set_supports_list_changed(true);
180            }
181        }
182        if let Some(max) = client_caps.max_tools {
183            if let Ok(mut dt) = dynamic_tools::global().lock() {
184                dt.set_supports_list_changed(true);
185                if max < 100 {
186                    dt.unload_category(dynamic_tools::ToolCategory::Debug);
187                    dt.unload_category(dynamic_tools::ToolCategory::Memory);
188                }
189            }
190        }
191
192        crate::core::client_capabilities::set_detected(&client_caps);
193
194        let instructions =
195            crate::instructions::build_instructions_with_client(CrpMode::effective(), &name);
196
197        let capabilities = match (client_caps.resources, client_caps.prompts) {
198            (true, true) => ServerCapabilities::builder()
199                .enable_tools()
200                .enable_resources()
201                .enable_resources_subscribe()
202                .enable_prompts()
203                .build(),
204            (true, false) => ServerCapabilities::builder()
205                .enable_tools()
206                .enable_resources()
207                .enable_resources_subscribe()
208                .build(),
209            (false, true) => ServerCapabilities::builder()
210                .enable_tools()
211                .enable_prompts()
212                .build(),
213            (false, false) => ServerCapabilities::builder().enable_tools().build(),
214        };
215
216        Ok(InitializeResult::new(capabilities)
217            .with_server_info(Implementation::new("lean-ctx", env!("CARGO_PKG_VERSION")))
218            .with_instructions(instructions))
219    }
220
221    async fn list_tools(
222        &self,
223        _request: Option<PaginatedRequestParams>,
224        _context: RequestContext<RoleServer>,
225    ) -> Result<ListToolsResult, ErrorData> {
226        let all_tools = if crate::tool_defs::is_full_mode() {
227            if let Some(ref reg) = self.registry {
228                reg.tool_defs()
229            } else {
230                crate::tool_defs::granular_tool_defs()
231            }
232        } else if std::env::var("LEAN_CTX_UNIFIED").is_ok() {
233            crate::tool_defs::unified_tool_defs()
234        } else if let Some(ref reg) = self.registry {
235            let core_names = crate::tool_defs::core_tool_names();
236            reg.tool_defs()
237                .into_iter()
238                .filter(|t| core_names.contains(&t.name.as_ref()))
239                .collect()
240        } else {
241            crate::tool_defs::lazy_tool_defs()
242        };
243
244        let disabled = crate::core::config::Config::load().disabled_tools_effective();
245        let client = self.client_name.read().await.clone();
246        let is_zed = !client.is_empty() && client.to_lowercase().contains("zed");
247
248        let tools: Vec<_> = all_tools
249            .into_iter()
250            .filter(|t| {
251                let name = t.name.as_ref();
252                if !disabled.is_empty() && disabled.iter().any(|d| d.as_str() == name) {
253                    return false;
254                }
255                if is_zed && name == "ctx_edit" {
256                    return false;
257                }
258                true
259            })
260            .collect();
261
262        let tools = {
263            let Ok(dyn_state) = dynamic_tools::global().lock() else {
264                tracing::warn!("dynamic_tools mutex poisoned in list_tools; returning unfiltered");
265                return Ok(ListToolsResult {
266                    tools,
267                    ..Default::default()
268                });
269            };
270            if dyn_state.supports_list_changed() {
271                tools
272                    .into_iter()
273                    .filter(|t| dyn_state.is_tool_active(t.name.as_ref()))
274                    .collect()
275            } else {
276                tools
277            }
278        };
279
280        let tools = {
281            let active = self.workflow.read().await.clone();
282            if let Some(run) = active {
283                if run.current == "done" || is_workflow_stale(&run) {
284                    let mut wf = self.workflow.write().await;
285                    *wf = None;
286                    let _ = crate::core::workflow::clear_active();
287                } else if let Some(state) = run.spec.state(&run.current) {
288                    if let Some(allowed) = &state.allowed_tools {
289                        let mut allow: std::collections::HashSet<&str> =
290                            allowed.iter().map(std::string::String::as_str).collect();
291                        for passthrough in WORKFLOW_PASSTHROUGH_TOOLS {
292                            allow.insert(passthrough);
293                        }
294                        return Ok(ListToolsResult {
295                            tools: tools
296                                .into_iter()
297                                .filter(|t| allow.contains(t.name.as_ref()))
298                                .collect(),
299                            ..Default::default()
300                        });
301                    }
302                }
303            }
304            tools
305        };
306
307        let tools = {
308            let cfg = crate::core::config::Config::load();
309            let level = crate::core::config::CompressionLevel::effective(&cfg);
310            let mode =
311                crate::core::terse::mcp_compress::DescriptionMode::from_compression_level(&level);
312            if mode == crate::core::terse::mcp_compress::DescriptionMode::Full {
313                tools
314            } else {
315                tools
316                    .into_iter()
317                    .map(|mut t| {
318                        let compressed = crate::core::terse::mcp_compress::compress_description(
319                            t.name.as_ref(),
320                            t.description.as_deref().unwrap_or(""),
321                            mode,
322                        );
323                        t.description = Some(compressed.into());
324                        t
325                    })
326                    .collect()
327            }
328        };
329
330        Ok(ListToolsResult {
331            tools,
332            ..Default::default()
333        })
334    }
335
336    async fn list_prompts(
337        &self,
338        _request: Option<PaginatedRequestParams>,
339        _context: RequestContext<RoleServer>,
340    ) -> Result<rmcp::model::ListPromptsResult, ErrorData> {
341        Ok(rmcp::model::ListPromptsResult::with_all_items(
342            prompts::list_prompts(),
343        ))
344    }
345
346    async fn get_prompt(
347        &self,
348        request: rmcp::model::GetPromptRequestParams,
349        _context: RequestContext<RoleServer>,
350    ) -> Result<rmcp::model::GetPromptResult, ErrorData> {
351        let ledger = self.ledger.read().await;
352        match prompts::get_prompt(&request, &ledger) {
353            Some(result) => Ok(result),
354            None => Err(ErrorData::invalid_params(
355                format!("Unknown prompt: {}", request.name),
356                None,
357            )),
358        }
359    }
360
361    async fn list_resources(
362        &self,
363        _request: Option<PaginatedRequestParams>,
364        _context: RequestContext<RoleServer>,
365    ) -> Result<rmcp::model::ListResourcesResult, rmcp::ErrorData> {
366        Ok(rmcp::model::ListResourcesResult::with_all_items(
367            resources::list_resources(),
368        ))
369    }
370
371    async fn read_resource(
372        &self,
373        request: rmcp::model::ReadResourceRequestParams,
374        _context: RequestContext<RoleServer>,
375    ) -> Result<rmcp::model::ReadResourceResult, rmcp::ErrorData> {
376        let ledger = self.ledger.read().await;
377        match resources::read_resource(&request.uri, &ledger) {
378            Some(contents) => Ok(rmcp::model::ReadResourceResult::new(contents)),
379            None => Err(rmcp::ErrorData::resource_not_found(
380                format!("Unknown resource: {}", request.uri),
381                None,
382            )),
383        }
384    }
385
386    async fn call_tool(
387        &self,
388        request: CallToolRequestParams,
389        _context: RequestContext<RoleServer>,
390    ) -> Result<CallToolResult, ErrorData> {
391        use std::panic::AssertUnwindSafe;
392
393        let tool_name_for_panic = request.name.as_ref().to_string();
394        let args_fp_for_panic = request
395            .arguments
396            .as_ref()
397            .map(|a| {
398                crate::core::loop_detection::LoopDetector::fingerprint(&serde_json::Value::Object(
399                    a.clone(),
400                ))
401            })
402            .unwrap_or_default();
403
404        let loop_detector = self.loop_detector.clone();
405
406        match AssertUnwindSafe(self.call_tool_guarded(request))
407            .catch_unwind()
408            .await
409        {
410            Ok(result) => result,
411            Err(panic_payload) => {
412                let detail = if let Some(s) = panic_payload.downcast_ref::<&str>() {
413                    (*s).to_string()
414                } else if let Some(s) = panic_payload.downcast_ref::<String>() {
415                    s.clone()
416                } else {
417                    "unknown".to_string()
418                };
419                tracing::error!("call_tool panicked: {detail}");
420
421                if let Ok(mut detector) =
422                    tokio::time::timeout(std::time::Duration::from_secs(1), loop_detector.write())
423                        .await
424                {
425                    detector.record_error_outcome(&tool_name_for_panic, &args_fp_for_panic);
426                }
427
428                Ok(CallToolResult::error(vec![Content::text(
429                    "ERROR: lean-ctx internal error. The MCP server is still running. \
430                     Please retry or use a different approach."
431                        .to_string(),
432                )]))
433            }
434        }
435    }
436}
437
438impl LeanCtxServer {
439    async fn call_tool_guarded(
440        &self,
441        request: CallToolRequestParams,
442    ) -> Result<CallToolResult, ErrorData> {
443        self.check_idle_expiry().await;
444        elicitation::increment_call();
445
446        let original_name = request.name.as_ref().to_string();
447        let (resolved_name, resolved_args) = if original_name == "ctx" {
448            let sub = request
449                .arguments
450                .as_ref()
451                .and_then(|a| a.get("tool"))
452                .and_then(|v| v.as_str())
453                .map(std::string::ToString::to_string)
454                .ok_or_else(|| {
455                    ErrorData::invalid_params("'tool' is required for ctx meta-tool", None)
456                })?;
457            let tool_name = if sub.starts_with("ctx_") {
458                sub
459            } else {
460                format!("ctx_{sub}")
461            };
462            let mut args = request.arguments.unwrap_or_default();
463            args.remove("tool");
464            (tool_name, Some(args))
465        } else {
466            (original_name, request.arguments)
467        };
468        let name = resolved_name.as_str();
469        let args = resolved_args.as_ref();
470
471        let role_check = role_guard::check_tool_access(name);
472        if let Some(denied) = role_guard::into_call_tool_result(&role_check) {
473            tracing::warn!(
474                tool = name,
475                role = %role_check.role_name,
476                "Tool blocked by role policy"
477            );
478            return Ok(denied);
479        }
480
481        if name != "ctx_workflow" {
482            let active = self.workflow.read().await.clone();
483            if let Some(run) = active {
484                if run.current == "done" || is_workflow_stale(&run) {
485                    let mut wf = self.workflow.write().await;
486                    *wf = None;
487                    let _ = crate::core::workflow::clear_active();
488                } else if !WORKFLOW_PASSTHROUGH_TOOLS.contains(&name) {
489                    if let Some(state) = run.spec.state(&run.current) {
490                        if let Some(allowed) = &state.allowed_tools {
491                            let allowed_ok = allowed.iter().any(|t| t == name);
492                            if !allowed_ok {
493                                let mut shown = allowed.clone();
494                                shown.sort();
495                                shown.truncate(30);
496                                return Ok(CallToolResult::success(vec![Content::text(format!(
497                                    "Tool '{name}' blocked by workflow '{}' (state: {}). Allowed: {}. Use ctx_workflow(action=\"stop\") to exit.",
498                                    run.spec.name,
499                                    run.current,
500                                    shown.join(", ")
501                                ))]));
502                            }
503                        }
504                    }
505                }
506            }
507        }
508
509        let auto_context = {
510            let task = {
511                let session = self.session.read().await;
512                session.task.as_ref().map(|t| t.description.clone())
513            };
514            let project_root = {
515                let session = self.session.read().await;
516                session.project_root.clone()
517            };
518            let cache_timeout =
519                tokio::time::timeout(std::time::Duration::from_secs(5), self.cache.write()).await;
520            if let Ok(mut cache) = cache_timeout {
521                crate::tools::autonomy::session_lifecycle_pre_hook(
522                    &self.autonomy,
523                    name,
524                    &mut cache,
525                    task.as_deref(),
526                    project_root.as_deref(),
527                    CrpMode::effective(),
528                )
529            } else {
530                tracing::warn!("pre-dispatch: cache write-lock timeout (5s), skipping autonomy");
531                None
532            }
533        };
534
535        let args_fp = args
536            .map(|a| {
537                crate::core::loop_detection::LoopDetector::fingerprint(&serde_json::Value::Object(
538                    a.clone(),
539                ))
540            })
541            .unwrap_or_default();
542        let throttle_result = {
543            let fp = &args_fp;
544            let detector_timeout = tokio::time::timeout(
545                std::time::Duration::from_secs(3),
546                self.loop_detector.write(),
547            )
548            .await;
549            if let Ok(mut detector) = detector_timeout {
550                let is_search = crate::core::loop_detection::LoopDetector::is_search_tool(name);
551                let is_search_shell = name == "ctx_shell" && {
552                    let cmd = args
553                        .as_ref()
554                        .and_then(|a| a.get("command"))
555                        .and_then(|v| v.as_str())
556                        .unwrap_or("");
557                    crate::core::loop_detection::LoopDetector::is_search_shell_command(cmd)
558                };
559
560                if is_search || is_search_shell {
561                    let search_pattern = args.and_then(|a| {
562                        a.get("pattern")
563                            .or_else(|| a.get("query"))
564                            .and_then(|v| v.as_str())
565                    });
566                    let shell_pattern = if is_search_shell {
567                        args.and_then(|a| a.get("command"))
568                            .and_then(|v| v.as_str())
569                            .and_then(helpers::extract_search_pattern_from_command)
570                    } else {
571                        None
572                    };
573                    let pat = search_pattern.or(shell_pattern.as_deref());
574                    detector.record_search(name, fp, pat)
575                } else {
576                    detector.record_call(name, fp)
577                }
578            } else {
579                tracing::warn!("pre-dispatch: loop_detector write-lock timeout (3s), skipping");
580                crate::core::loop_detection::ThrottleResult::default()
581            }
582        };
583
584        if throttle_result.level == crate::core::loop_detection::ThrottleLevel::Blocked {
585            let msg = throttle_result.message.unwrap_or_default();
586            return Ok(CallToolResult::success(vec![Content::text(msg)]));
587        }
588
589        let throttle_warning =
590            if throttle_result.level == crate::core::loop_detection::ThrottleLevel::Reduced {
591                throttle_result.message.clone()
592            } else {
593                None
594            };
595
596        let config = crate::core::config::Config::load();
597        let minimal = config.minimal_overhead_effective();
598
599        {
600            use crate::core::budget_tracker::{BudgetLevel, BudgetTracker};
601            let snap = BudgetTracker::global().check();
602            if *snap.worst_level() == BudgetLevel::Exhausted
603                && name != "ctx_session"
604                && name != "ctx_cost"
605                && name != "ctx_metrics"
606            {
607                for (dim, lvl, used, limit) in [
608                    (
609                        "tokens",
610                        &snap.tokens.level,
611                        format!("{}", snap.tokens.used),
612                        format!("{}", snap.tokens.limit),
613                    ),
614                    (
615                        "shell",
616                        &snap.shell.level,
617                        format!("{}", snap.shell.used),
618                        format!("{}", snap.shell.limit),
619                    ),
620                    (
621                        "cost",
622                        &snap.cost.level,
623                        format!("${:.2}", snap.cost.used_usd),
624                        format!("${:.2}", snap.cost.limit_usd),
625                    ),
626                ] {
627                    if *lvl == BudgetLevel::Exhausted {
628                        crate::core::events::emit_budget_exhausted(&snap.role, dim, &used, &limit);
629                    }
630                }
631                let msg = format!(
632                    "[BUDGET EXHAUSTED] {}\n\
633                     Use `ctx_session action=role` to check/switch roles, \
634                     or `ctx_session action=reset` to start fresh.",
635                    snap.format_compact()
636                );
637                tracing::warn!(tool = name, "{msg}");
638                return Ok(CallToolResult::success(vec![Content::text(msg)]));
639            }
640        }
641
642        if is_shell_tool_name(name) {
643            crate::core::budget_tracker::BudgetTracker::global().record_shell();
644        }
645
646        let tool_start = std::time::Instant::now();
647        let (mut result_text, tool_saved_tokens) =
648            match self.dispatch_tool(name, args, minimal).await {
649                Ok(pair) => pair,
650                Err(e) => {
651                    if let Ok(mut detector) = tokio::time::timeout(
652                        std::time::Duration::from_secs(1),
653                        self.loop_detector.write(),
654                    )
655                    .await
656                    {
657                        detector.record_error_outcome(name, &args_fp);
658                    }
659                    return Err(e);
660                }
661            };
662
663        let is_raw_shell = name == "ctx_shell" && {
664            let arg_raw = helpers::get_bool(args, "raw").unwrap_or(false);
665            let arg_bypass = helpers::get_bool(args, "bypass").unwrap_or(false);
666            arg_raw
667                || arg_bypass
668                || std::env::var("LEAN_CTX_DISABLED").is_ok()
669                || std::env::var("LEAN_CTX_RAW").is_ok()
670        };
671
672        let pre_terse_len = result_text.len();
673        let output_tokens = {
674            let tokens = crate::core::tokens::count_tokens(&result_text) as u64;
675            crate::core::budget_tracker::BudgetTracker::global().record_tokens(tokens);
676            tokens
677        };
678
679        crate::core::anomaly::record_metric("tokens_per_call", output_tokens as f64);
680
681        // Context IR: record lineage for every tool call.
682        if let Some(ref ir) = self.context_ir {
683            let tool_duration = tool_start.elapsed();
684            let source_kind = match name {
685                n if n.contains("read") || n.contains("multi_read") || n.contains("smart_read") => {
686                    crate::core::context_ir::ContextIrSourceKindV1::Read
687                }
688                "ctx_shell" => crate::core::context_ir::ContextIrSourceKindV1::Shell,
689                "ctx_search" | "ctx_semantic_search" => {
690                    crate::core::context_ir::ContextIrSourceKindV1::Search
691                }
692                "ctx_provider" => crate::core::context_ir::ContextIrSourceKindV1::Provider,
693                _ => crate::core::context_ir::ContextIrSourceKindV1::Other,
694            };
695            let ir_path = helpers::get_str(args, "path");
696            let ir_command = helpers::get_str(args, "command");
697            let ir_mode = helpers::get_str(args, "mode");
698            let excerpt = if result_text.len() > 200 {
699                let mut end = 200;
700                while !result_text.is_char_boundary(end) && end > 0 {
701                    end -= 1;
702                }
703                &result_text[..end]
704            } else {
705                &result_text
706            };
707            let input = crate::core::context_ir::RecordIrInput {
708                kind: source_kind,
709                tool: name,
710                client_name: None,
711                agent_id: None,
712                path: ir_path.as_deref(),
713                command: ir_command.as_deref(),
714                pattern: ir_mode.as_deref(),
715                input_tokens: pre_terse_len / 4,
716                output_tokens: output_tokens as usize,
717                duration: tool_duration,
718                content_excerpt: excerpt,
719            };
720            ir.write().await.record(input);
721        }
722
723        // Correction-loop detection: track re-reads and re-runs as quality signals.
724        {
725            let mut detector = self.loop_detector.write().await;
726            if name == "ctx_read" {
727                let path = helpers::get_str(args, "path").unwrap_or_default();
728                let mode = helpers::get_str(args, "mode").unwrap_or_else(|| "auto".into());
729                let fresh = helpers::get_bool(args, "fresh").unwrap_or(false);
730                detector.record_read_for_correction(&path, &mode, fresh);
731            } else if name == "ctx_shell" {
732                let cmd = helpers::get_str(args, "command").unwrap_or_default();
733                detector.record_shell_for_correction(&cmd);
734            }
735            let correction_count = detector.correction_count();
736            if correction_count > 0 {
737                crate::core::anomaly::record_metric(
738                    "correction_loop_rate",
739                    f64::from(correction_count),
740                );
741            }
742            // Auto-degrade: reduce compression when correction rate is high
743            use crate::core::config::CompressionLevel;
744            if correction_count >= 5 {
745                CompressionLevel::set_session_degrade(&CompressionLevel::Off);
746            } else if correction_count >= 3 {
747                CompressionLevel::set_session_degrade(&CompressionLevel::Lite);
748            } else if correction_count == 0 {
749                CompressionLevel::clear_session_degrade();
750            }
751            detector.prune_corrections();
752        }
753
754        // Persist anomaly detector — debounced to reduce I/O in burst sequences.
755        crate::core::anomaly::save_debounced();
756
757        let budget_warning = {
758            use crate::core::budget_tracker::{BudgetLevel, BudgetTracker};
759            let snap = BudgetTracker::global().check();
760            if *snap.worst_level() == BudgetLevel::Warning {
761                for (dim, lvl, used, limit, pct) in [
762                    (
763                        "tokens",
764                        &snap.tokens.level,
765                        format!("{}", snap.tokens.used),
766                        format!("{}", snap.tokens.limit),
767                        snap.tokens.percent,
768                    ),
769                    (
770                        "shell",
771                        &snap.shell.level,
772                        format!("{}", snap.shell.used),
773                        format!("{}", snap.shell.limit),
774                        snap.shell.percent,
775                    ),
776                    (
777                        "cost",
778                        &snap.cost.level,
779                        format!("${:.2}", snap.cost.used_usd),
780                        format!("${:.2}", snap.cost.limit_usd),
781                        snap.cost.percent,
782                    ),
783                ] {
784                    if *lvl == BudgetLevel::Warning {
785                        crate::core::events::emit_budget_warning(
786                            &snap.role, dim, &used, &limit, pct,
787                        );
788                    }
789                }
790                if crate::core::protocol::meta_visible() {
791                    Some(format!("[BUDGET WARNING] {}", snap.format_compact()))
792                } else {
793                    None
794                }
795            } else {
796                None
797            }
798        };
799
800        let archive_hint = if minimal || is_raw_shell {
801            None
802        } else {
803            use crate::core::archive;
804            let archivable = matches!(
805                name,
806                "ctx_shell"
807                    | "ctx_read"
808                    | "ctx_multi_read"
809                    | "ctx_smart_read"
810                    | "ctx_execute"
811                    | "ctx_search"
812                    | "ctx_tree"
813            );
814            if archivable && archive::should_archive(&result_text) {
815                let cmd = helpers::get_str(args, "command")
816                    .or_else(|| helpers::get_str(args, "path"))
817                    .unwrap_or_default();
818                let session_id = self.session.read().await.id.clone();
819                let to_store = crate::core::redaction::redact_text_if_enabled(&result_text);
820                let tokens = crate::core::tokens::count_tokens(&to_store);
821                archive::store(name, &cmd, &to_store, Some(&session_id))
822                    .map(|id| archive::format_hint(&id, to_store.len(), tokens))
823            } else {
824                None
825            }
826        };
827
828        let pre_compression = result_text.clone();
829        let skip_terse = is_raw_shell
830            || tool_saved_tokens > 0
831            || (name == "ctx_shell"
832                && helpers::get_str(args, "command")
833                    .is_some_and(|c| crate::shell::compress::has_structural_output(&c)));
834        let compression = crate::core::config::CompressionLevel::effective(&config);
835        if compression.is_active() && !skip_terse {
836            let terse_result =
837                crate::core::terse::pipeline::compress(&result_text, &compression, None);
838            if terse_result.quality_passed && terse_result.savings_pct >= 3.0 {
839                result_text = terse_result.output;
840            }
841        }
842
843        let profile_hints = crate::core::profiles::active_profile().output_hints;
844
845        if !is_raw_shell && profile_hints.verify_footer() {
846            let verify_cfg = crate::core::profiles::active_profile().verification;
847            let vr = crate::core::output_verification::verify_output(
848                &pre_compression,
849                &result_text,
850                &verify_cfg,
851            );
852            if !vr.warnings.is_empty() {
853                let msg = format!("[VERIFY] {}", vr.format_compact());
854                result_text = format!("{result_text}\n\n{msg}");
855            }
856        }
857
858        if profile_hints.archive_hint() {
859            if let Some(hint) = archive_hint {
860                result_text = format!("{result_text}\n{hint}");
861            }
862        }
863
864        if !is_raw_shell {
865            if let Some(ctx) = auto_context {
866                let ctx_tokens = crate::core::tokens::count_tokens(&ctx);
867                if ctx_tokens <= 400 {
868                    result_text = format!("{ctx}\n\n{result_text}");
869                }
870            }
871        }
872
873        if let Some(warning) = throttle_warning {
874            result_text = format!("{result_text}\n\n{warning}");
875        }
876
877        if let Some(bw) = budget_warning {
878            result_text = format!("{result_text}\n\n{bw}");
879        }
880
881        if !self
882            .rules_stale_checked
883            .swap(true, std::sync::atomic::Ordering::Relaxed)
884        {
885            let client = self.client_name.read().await.clone();
886            if !client.is_empty() {
887                if let Some(stale_msg) = crate::rules_inject::check_rules_freshness(&client) {
888                    result_text = format!("{result_text}\n\n{stale_msg}");
889                }
890            }
891        }
892
893        {
894            // Evaluate SLOs for observability (watch/dashboard), but keep tool outputs clean.
895            let _ = crate::core::slo::evaluate();
896        }
897
898        if name == "ctx_read" {
899            if minimal {
900                let cache_clone = self.cache.clone();
901                let autonomy_clone = self.autonomy.clone();
902                let name_owned = name.to_string();
903                tokio::spawn(async move {
904                    let result = std::panic::AssertUnwindSafe(async {
905                        let mut cache = cache_clone.write().await;
906                        crate::tools::autonomy::maybe_auto_dedup(
907                            &autonomy_clone,
908                            &mut cache,
909                            &name_owned,
910                        );
911                    })
912                    .catch_unwind()
913                    .await;
914                    if let Err(e) = result {
915                        let msg = e
916                            .downcast_ref::<String>()
917                            .map(String::as_str)
918                            .or_else(|| e.downcast_ref::<&str>().copied())
919                            .unwrap_or("unknown");
920                        tracing::error!("background auto_dedup panicked: {msg}");
921                    }
922                });
923            } else {
924                let read_path = self
925                    .resolve_path_or_passthrough(
926                        &helpers::get_str(args, "path").unwrap_or_default(),
927                    )
928                    .await;
929                let project_root = {
930                    let session = self.session.read().await;
931                    session.project_root.clone()
932                };
933
934                // Bounded cache lock for enrichment — degrade gracefully under contention
935                let enrich_timeout =
936                    tokio::time::timeout(std::time::Duration::from_secs(3), self.cache.write())
937                        .await;
938                if let Ok(mut cache) = enrich_timeout {
939                    let enrich = crate::tools::autonomy::enrich_after_read(
940                        &self.autonomy,
941                        &mut cache,
942                        &read_path,
943                        project_root.as_deref(),
944                        None,
945                        crate::tools::CrpMode::effective(),
946                        false,
947                    );
948                    if profile_hints.related_hint() {
949                        if let Some(hint) = enrich.related_hint {
950                            result_text = format!("{result_text}\n{hint}");
951                        }
952                    }
953                    crate::tools::autonomy::maybe_auto_dedup(&self.autonomy, &mut cache, name);
954                } else {
955                    tracing::warn!(
956                        "post-dispatch cache lock timeout (3s) for {read_path}, skipping enrichment"
957                    );
958                }
959
960                // Ledger update — fire-and-forget to avoid blocking concurrent reads
961                let ledger_clone = self.ledger.clone();
962                let session_clone = self.session.clone();
963                let peer_clone = self.peer.clone();
964                let read_path_owned = read_path.clone();
965                let project_root_owned = project_root.clone();
966                let mode_used =
967                    helpers::get_str(args, "mode").unwrap_or_else(|| "auto".to_string());
968                let out_tok = output_tokens as usize;
969                let sent_tok = crate::core::tokens::count_tokens(&result_text);
970                let wants_eviction = true;
971                let wants_elicitation = profile_hints.elicitation_hint();
972                tokio::spawn(async move {
973                    let result = std::panic::AssertUnwindSafe(async {
974                        let active_task = {
975                            let session = session_clone.read().await;
976                            session.task.as_ref().map(|t| t.description.clone())
977                        };
978                        let mut ledger = ledger_clone.write().await;
979                        let overlay = crate::core::context_overlay::OverlayStore::load_project(
980                            &std::path::PathBuf::from(project_root_owned.as_deref().unwrap_or(".")),
981                        );
982                        let gate_result = context_gate::post_dispatch_record_with_task(
983                            &read_path_owned,
984                            &mode_used,
985                            out_tok,
986                            sent_tok,
987                            &mut ledger,
988                            &overlay,
989                            active_task.as_deref(),
990                        );
991                        drop(ledger);
992                        if wants_eviction {
993                            if let Some(hint) = &gate_result.eviction_hint {
994                                tracing::debug!("deferred eviction hint: {hint}");
995                            }
996                        }
997                        if wants_elicitation {
998                            if let Some(hint) = &gate_result.elicitation_hint {
999                                tracing::debug!("deferred elicitation hint: {hint}");
1000                            }
1001                        }
1002                        if gate_result.resource_changed {
1003                            if let Some(peer) = peer_clone.read().await.as_ref() {
1004                                notifications::send_resource_updated(
1005                                    peer,
1006                                    notifications::RESOURCE_URI_SUMMARY,
1007                                )
1008                                .await;
1009                            }
1010                        }
1011                    })
1012                    .catch_unwind()
1013                    .await;
1014                    if let Err(e) = result {
1015                        let msg = e
1016                            .downcast_ref::<String>()
1017                            .map(String::as_str)
1018                            .or_else(|| e.downcast_ref::<&str>().copied())
1019                            .unwrap_or("unknown");
1020                        tracing::error!("background post_dispatch panicked: {msg}");
1021                    }
1022                });
1023            }
1024        }
1025
1026        if !minimal && !is_raw_shell && name == "ctx_shell" {
1027            let cmd = helpers::get_str(args, "command").unwrap_or_default();
1028
1029            if let Some(file_path) = extract_file_read_from_shell(&cmd) {
1030                if let Ok(mut bt) = crate::core::bounce_tracker::global().lock() {
1031                    bt.next_seq();
1032                    bt.record_shell_file_access(&file_path);
1033                }
1034            }
1035
1036            if profile_hints.efficiency_hint() {
1037                let calls = self.tool_calls.read().await;
1038                let last_original = calls.last().map_or(0, |c| c.original_tokens);
1039                drop(calls);
1040                let pre_hint_tokens = crate::core::tokens::count_tokens(&result_text);
1041                if let Some(hint) = crate::tools::autonomy::shell_efficiency_hint(
1042                    &self.autonomy,
1043                    &cmd,
1044                    last_original,
1045                    pre_hint_tokens,
1046                ) {
1047                    result_text = format!("{result_text}\n{hint}");
1048                }
1049            }
1050        }
1051
1052        if !minimal && !is_raw_shell {
1053            bypass_hint::record_lctx_call();
1054            if let Ok(data_dir) = crate::core::data_dir::lean_ctx_data_dir() {
1055                if let Some(hint) = bypass_hint::check(&data_dir) {
1056                    result_text = format!("{result_text}\n{hint}");
1057                }
1058            }
1059        }
1060
1061        #[allow(clippy::cast_possible_truncation)]
1062        let output_token_count = if result_text.len() == pre_terse_len {
1063            output_tokens as usize
1064        } else {
1065            crate::core::tokens::count_tokens(&result_text)
1066        };
1067        let action = helpers::get_str(args, "action");
1068
1069        // K-bounded staleness guard: warn if shared context has diverged.
1070        const K_STALENESS_BOUND: i64 = 10;
1071        if self.session_mode == crate::tools::SessionMode::Shared {
1072            if let Some(ref rt) = self.context_os {
1073                let latest = rt.bus.latest_id(&self.workspace_id, &self.channel_id);
1074                let cursor = self
1075                    .last_seen_event_id
1076                    .load(std::sync::atomic::Ordering::Relaxed);
1077                if cursor > 0 && latest - cursor > K_STALENESS_BOUND {
1078                    let gap = latest - cursor;
1079                    result_text = format!(
1080                        "[CONTEXT STALE] {gap} events happened since your last read. \
1081                         Use ctx_session(action=\"status\") to sync.\n\n{result_text}"
1082                    );
1083                }
1084                self.last_seen_event_id
1085                    .store(latest, std::sync::atomic::Ordering::Relaxed);
1086            }
1087        }
1088
1089        {
1090            let input = helpers::canonical_args_string(args);
1091            let input_md5 = helpers::hash_fast(&input);
1092            let output_md5 = helpers::hash_fast(&result_text);
1093            let agent_id = self.agent_id.read().await.clone();
1094            let client_name = self.client_name.read().await.clone();
1095            let mut explicit_intent: Option<(
1096                crate::core::intent_protocol::IntentRecord,
1097                Option<String>,
1098                String,
1099            )> = None;
1100
1101            let pending_session_save = {
1102                let empty_args = serde_json::Map::new();
1103                let args_map = args.unwrap_or(&empty_args);
1104                let mut session = self.session.write().await;
1105                session.record_tool_receipt(
1106                    name,
1107                    action.as_deref(),
1108                    &input_md5,
1109                    &output_md5,
1110                    agent_id.as_deref(),
1111                    Some(&client_name),
1112                );
1113
1114                if let Some(intent) = crate::core::intent_protocol::infer_from_tool_call(
1115                    name,
1116                    action.as_deref(),
1117                    args_map,
1118                    session.project_root.as_deref(),
1119                ) {
1120                    let is_explicit =
1121                        intent.source == crate::core::intent_protocol::IntentSource::Explicit;
1122                    let root = session.project_root.clone();
1123                    let sid = session.id.clone();
1124                    session.record_intent(intent.clone());
1125                    if is_explicit {
1126                        explicit_intent = Some((intent, root, sid));
1127                    }
1128                }
1129                if session.should_save() {
1130                    session.prepare_save().ok()
1131                } else {
1132                    None
1133                }
1134            };
1135
1136            if let Some(prepared) = pending_session_save {
1137                let ir_clone = self.context_ir.clone();
1138                tokio::task::spawn_blocking(move || {
1139                    let _ = prepared.write_to_disk();
1140                    if let Some(ir) = ir_clone {
1141                        if let Ok(ir_guard) = ir.try_read() {
1142                            ir_guard.save();
1143                        }
1144                    }
1145                });
1146            }
1147
1148            if let Some((intent, root, session_id)) = explicit_intent {
1149                let _ = crate::core::intent_protocol::apply_side_effects(
1150                    &intent,
1151                    root.as_deref(),
1152                    &session_id,
1153                );
1154            }
1155
1156            if self.autonomy.is_enabled() {
1157                let (calls, project_root) = {
1158                    let session = self.session.read().await;
1159                    (session.stats.total_tool_calls, session.project_root.clone())
1160                };
1161
1162                if let Some(root) = project_root {
1163                    if crate::tools::autonomy::should_auto_consolidate(&self.autonomy, calls) {
1164                        let root_clone = root.clone();
1165                        tokio::task::spawn_blocking(move || {
1166                            let _ = crate::core::consolidation_engine::consolidate_latest(
1167                                &root_clone,
1168                                crate::core::consolidation_engine::ConsolidationBudgets::default(),
1169                            );
1170                        });
1171                    }
1172                }
1173            }
1174
1175            let agent_key = agent_id.unwrap_or_else(|| "unknown".to_string());
1176            let input_token_count = crate::core::tokens::count_tokens(&input) as u64;
1177            let output_token_count_u64 = output_token_count as u64;
1178            let name_owned = name.to_string();
1179            tokio::task::spawn_blocking(move || {
1180                let pricing = crate::core::gain::model_pricing::ModelPricing::load();
1181                let quote = pricing.quote_from_env_or_agent_type(&client_name);
1182                let cost_usd =
1183                    quote
1184                        .cost
1185                        .estimate_usd(input_token_count, output_token_count_u64, 0, 0);
1186                crate::core::budget_tracker::BudgetTracker::global().record_cost_usd(cost_usd);
1187
1188                let mut store = crate::core::a2a::cost_attribution::CostStore::load();
1189                store.record_tool_call(
1190                    &agent_key,
1191                    &client_name,
1192                    &name_owned,
1193                    input_token_count,
1194                    output_token_count_u64,
1195                    0,
1196                );
1197                let _ = store.save();
1198            });
1199        }
1200
1201        // Context Bus: conflict detection for knowledge writes in shared mode.
1202        if self.session_mode == crate::tools::SessionMode::Shared
1203            && name == "ctx_knowledge"
1204            && action.as_deref() == Some("remember")
1205        {
1206            if let Some(ref rt) = self.context_os {
1207                let my_agent = self.agent_id.read().await.clone();
1208                let category = helpers::get_str(args, "category");
1209                let key = helpers::get_str(args, "key");
1210                if let (Some(ref cat), Some(ref k)) = (&category, &key) {
1211                    let recent = rt.bus.recent_by_kind(
1212                        &self.workspace_id,
1213                        &self.channel_id,
1214                        "knowledge_remembered",
1215                        20,
1216                    );
1217                    for ev in &recent {
1218                        let p = &ev.payload;
1219                        let ev_cat = p.get("category").and_then(|v| v.as_str());
1220                        let ev_key = p.get("key").and_then(|v| v.as_str());
1221                        let ev_actor = ev.actor.as_deref();
1222                        if ev_cat == Some(cat.as_str())
1223                            && ev_key == Some(k.as_str())
1224                            && ev_actor != my_agent.as_deref()
1225                        {
1226                            let other = ev_actor.unwrap_or("unknown");
1227                            result_text = format!(
1228                                "[CONFLICT] Agent '{other}' recently wrote to the same knowledge key \
1229                                 '{cat}/{k}'. Review before proceeding.\n\n{result_text}"
1230                            );
1231                            break;
1232                        }
1233                    }
1234                }
1235            }
1236        }
1237
1238        // Context OS: persist shared session + publish events.
1239        if self.session_mode == crate::tools::SessionMode::Shared {
1240            let ws = self.workspace_id.clone();
1241            let ch = self.channel_id.clone();
1242            let rt = self.context_os.clone();
1243            let agent = self.agent_id.read().await.clone();
1244            let tool = name.to_string();
1245            let tool_action = action.clone();
1246            let tool_path = helpers::get_str(args, "path");
1247            let tool_category = helpers::get_str(args, "category");
1248            let tool_key = helpers::get_str(args, "key");
1249            let session_snapshot = self.session.read().await.clone();
1250            let session_task = session_snapshot.task.clone();
1251            tokio::task::spawn_blocking(move || {
1252                let Some(rt) = rt else {
1253                    return;
1254                };
1255                let Some(root) = session_snapshot.project_root.as_deref() else {
1256                    return;
1257                };
1258                rt.shared_sessions
1259                    .persist_best_effort(root, &ws, &ch, &session_snapshot);
1260                rt.metrics.record_session_persisted();
1261
1262                let mut base_payload = serde_json::json!({
1263                    "tool": tool,
1264                    "action": tool_action,
1265                });
1266                if let Some(ref p) = tool_path {
1267                    base_payload["path"] = serde_json::Value::String(p.clone());
1268                }
1269                if let Some(ref c) = tool_category {
1270                    base_payload["category"] = serde_json::Value::String(c.clone());
1271                }
1272                if let Some(ref k) = tool_key {
1273                    base_payload["key"] = serde_json::Value::String(k.clone());
1274                }
1275                if let Some(ref t) = session_task {
1276                    base_payload["reasoning"] = serde_json::Value::String(t.description.clone());
1277                }
1278
1279                if rt
1280                    .bus
1281                    .append(
1282                        &ws,
1283                        &ch,
1284                        &crate::core::context_os::ContextEventKindV1::ToolCallRecorded,
1285                        agent.as_deref(),
1286                        base_payload.clone(),
1287                    )
1288                    .is_some()
1289                {
1290                    rt.metrics.record_event_appended();
1291                    rt.metrics.record_event_broadcast();
1292                }
1293
1294                if let Some(secondary) =
1295                    crate::core::context_os::secondary_event_kind(&tool, tool_action.as_deref())
1296                {
1297                    if rt
1298                        .bus
1299                        .append(&ws, &ch, &secondary, agent.as_deref(), base_payload)
1300                        .is_some()
1301                    {
1302                        rt.metrics.record_event_appended();
1303                        rt.metrics.record_event_broadcast();
1304                    }
1305                }
1306            });
1307        }
1308
1309        let skip_checkpoint = minimal
1310            || matches!(
1311                name,
1312                "ctx_compress"
1313                    | "ctx_metrics"
1314                    | "ctx_benchmark"
1315                    | "ctx_analyze"
1316                    | "ctx_cache"
1317                    | "ctx_discover"
1318                    | "ctx_dedup"
1319                    | "ctx_session"
1320                    | "ctx_knowledge"
1321                    | "ctx_agent"
1322                    | "ctx_share"
1323                    | "ctx_gain"
1324                    | "ctx_overview"
1325                    | "ctx_preload"
1326                    | "ctx_cost"
1327                    | "ctx_heatmap"
1328                    | "ctx_task"
1329                    | "ctx_impact"
1330                    | "ctx_architecture"
1331                    | "ctx_smells"
1332                    | "ctx_workflow"
1333            );
1334
1335        if !skip_checkpoint && self.increment_and_check() {
1336            if let Some(checkpoint) = self.auto_checkpoint().await {
1337                let interval = LeanCtxServer::checkpoint_interval_effective();
1338                let hints = crate::core::profiles::active_profile().output_hints;
1339                if hints.checkpoint_in_output() && crate::core::protocol::meta_visible() {
1340                    let combined = format!(
1341                        "{result_text}\n\n--- AUTO CHECKPOINT (every {interval} calls) ---\n{checkpoint}"
1342                    );
1343                    return Ok(CallToolResult::success(vec![Content::text(combined)]));
1344                }
1345            }
1346        }
1347
1348        let tool_duration_ms = tool_start.elapsed().as_millis() as u64;
1349        if tool_duration_ms > 100 {
1350            LeanCtxServer::append_tool_call_log(
1351                name,
1352                tool_duration_ms,
1353                0,
1354                0,
1355                None,
1356                &chrono::Local::now().format("%Y-%m-%d %H:%M:%S").to_string(),
1357            );
1358        }
1359
1360        let current_count = self.call_count.load(std::sync::atomic::Ordering::Relaxed);
1361        if current_count > 0 && current_count.is_multiple_of(100) {
1362            std::thread::spawn(crate::cloud_sync::cloud_background_tasks);
1363        }
1364
1365        Ok(CallToolResult::success(vec![Content::text(result_text)]))
1366    }
1367}
1368
1369pub fn build_instructions_for_test(crp_mode: CrpMode) -> String {
1370    crate::instructions::build_instructions_for_test(crp_mode)
1371}
1372
1373pub fn build_claude_code_instructions_for_test() -> String {
1374    crate::instructions::claude_code_instructions()
1375}
1376
1377const PROJECT_MARKERS: &[&str] = &[
1378    ".git",
1379    "Cargo.toml",
1380    "package.json",
1381    "go.mod",
1382    "pyproject.toml",
1383    "setup.py",
1384    "pom.xml",
1385    "build.gradle",
1386    "Makefile",
1387    ".lean-ctx.toml",
1388];
1389
1390fn has_project_marker(dir: &std::path::Path) -> bool {
1391    PROJECT_MARKERS.iter().any(|m| dir.join(m).exists())
1392}
1393
1394fn is_home_or_agent_dir(dir: &std::path::Path) -> bool {
1395    if let Some(home) = dirs::home_dir() {
1396        if dir == home {
1397            return true;
1398        }
1399    }
1400    let dir_str = dir.to_string_lossy();
1401    dir_str.ends_with("/.claude")
1402        || dir_str.ends_with("/.codex")
1403        || dir_str.contains("/.claude/")
1404        || dir_str.contains("/.codex/")
1405}
1406
1407fn git_toplevel_from(dir: &std::path::Path) -> Option<String> {
1408    std::process::Command::new("git")
1409        .args(["rev-parse", "--show-toplevel"])
1410        .current_dir(dir)
1411        .stdout(std::process::Stdio::piped())
1412        .stderr(std::process::Stdio::null())
1413        .output()
1414        .ok()
1415        .and_then(|o| {
1416            if o.status.success() {
1417                String::from_utf8(o.stdout)
1418                    .ok()
1419                    .map(|s| s.trim().to_string())
1420            } else {
1421                None
1422            }
1423        })
1424}
1425
1426pub fn derive_project_root_from_cwd() -> Option<String> {
1427    let cwd = std::env::current_dir().ok()?;
1428    let canonical = crate::core::pathutil::safe_canonicalize_or_self(&cwd);
1429
1430    if is_home_or_agent_dir(&canonical) {
1431        return git_toplevel_from(&canonical);
1432    }
1433
1434    if has_project_marker(&canonical) {
1435        return Some(canonical.to_string_lossy().to_string());
1436    }
1437
1438    if let Some(git_root) = git_toplevel_from(&canonical) {
1439        return Some(git_root);
1440    }
1441
1442    if let Some(root) = detect_multi_root_workspace(&canonical) {
1443        return Some(root);
1444    }
1445
1446    // Fallback: use CWD as project root if it's a specific, safe directory.
1447    // This ensures bare directories (no .git, no markers) still work.
1448    // Guard: reject home dir, filesystem root, and agent sandbox dirs.
1449    if !crate::core::pathutil::is_broad_or_unsafe_root(&canonical) {
1450        tracing::info!(
1451            "No project markers found — using CWD as project root: {}",
1452            canonical.display()
1453        );
1454        return Some(canonical.to_string_lossy().to_string());
1455    }
1456
1457    None
1458}
1459
1460// Delegated to crate::core::pathutil::is_broad_or_unsafe_root
1461#[cfg(test)]
1462use crate::core::pathutil::is_broad_or_unsafe_root;
1463
1464/// Detect a multi-root workspace: a directory that has no project markers
1465/// itself, but contains child directories that do. In this case, use the
1466/// parent as jail root and auto-allow all child projects via LEAN_CTX_ALLOW_PATH.
1467fn detect_multi_root_workspace(dir: &std::path::Path) -> Option<String> {
1468    let entries = std::fs::read_dir(dir).ok()?;
1469    let mut child_projects: Vec<String> = Vec::new();
1470
1471    for entry in entries.flatten() {
1472        let path = entry.path();
1473        if path.is_dir() && has_project_marker(&path) {
1474            let canonical = crate::core::pathutil::safe_canonicalize_or_self(&path);
1475            child_projects.push(canonical.to_string_lossy().to_string());
1476        }
1477    }
1478
1479    if child_projects.len() >= 2 {
1480        let existing = std::env::var("LEAN_CTX_ALLOW_PATH").unwrap_or_default();
1481        let sep = if cfg!(windows) { ";" } else { ":" };
1482        let merged = if existing.is_empty() {
1483            child_projects.join(sep)
1484        } else {
1485            format!("{existing}{sep}{}", child_projects.join(sep))
1486        };
1487        std::env::set_var("LEAN_CTX_ALLOW_PATH", &merged);
1488        tracing::info!(
1489            "Multi-root workspace detected at {}: auto-allowing {} child projects",
1490            dir.display(),
1491            child_projects.len()
1492        );
1493        return Some(dir.to_string_lossy().to_string());
1494    }
1495
1496    None
1497}
1498
1499pub fn tool_descriptions_for_test() -> Vec<(&'static str, &'static str)> {
1500    crate::tool_defs::list_all_tool_defs()
1501        .into_iter()
1502        .map(|(name, desc, _)| (name, desc))
1503        .collect()
1504}
1505
1506pub fn tool_schemas_json_for_test() -> String {
1507    crate::tool_defs::list_all_tool_defs()
1508        .iter()
1509        .map(|(name, _, schema)| format!("{name}: {schema}"))
1510        .collect::<Vec<_>>()
1511        .join("\n")
1512}
1513
1514/// Tools that always pass through the workflow gate regardless of state.
1515/// Read-only tools should never be blocked — agents need them for context
1516/// recovery after crashes or session transitions.
1517pub const WORKFLOW_PASSTHROUGH_TOOLS: &[&str] = &[
1518    "ctx",
1519    "ctx_workflow",
1520    "ctx_read",
1521    "ctx_multi_read",
1522    "ctx_smart_read",
1523    "ctx_search",
1524    "ctx_tree",
1525    "ctx_session",
1526    "ctx_ledger",
1527];
1528
1529/// A workflow is stale if it hasn't been updated in 30 minutes.
1530/// This prevents dead workflows from blocking tools across sessions.
1531pub fn is_workflow_stale(run: &crate::core::workflow::types::WorkflowRun) -> bool {
1532    let elapsed = chrono::Utc::now()
1533        .signed_duration_since(run.updated_at)
1534        .num_minutes();
1535    elapsed > 30
1536}
1537
1538fn is_shell_tool_name(name: &str) -> bool {
1539    matches!(name, "ctx_shell" | "ctx_execute")
1540}
1541
1542fn extract_file_read_from_shell(cmd: &str) -> Option<String> {
1543    let trimmed = cmd.trim();
1544    let parts: Vec<&str> = trimmed.split_whitespace().collect();
1545    if parts.len() < 2 {
1546        return None;
1547    }
1548    let bin = parts[0].rsplit('/').next().unwrap_or(parts[0]);
1549    match bin {
1550        "cat" | "head" | "tail" | "less" | "more" | "bat" | "batcat" => {
1551            let file_arg = parts.iter().skip(1).find(|a| !a.starts_with('-'))?;
1552            Some(file_arg.to_string())
1553        }
1554        _ => None,
1555    }
1556}
1557
1558#[cfg(test)]
1559mod tests {
1560    use super::*;
1561
1562    #[test]
1563    fn project_markers_detected() {
1564        let tmp = tempfile::tempdir().unwrap();
1565        let root = tmp.path().join("myproject");
1566        std::fs::create_dir_all(&root).unwrap();
1567        assert!(!has_project_marker(&root));
1568
1569        std::fs::create_dir(root.join(".git")).unwrap();
1570        assert!(has_project_marker(&root));
1571    }
1572
1573    #[test]
1574    fn home_dir_detected_as_agent_dir() {
1575        if let Some(home) = dirs::home_dir() {
1576            assert!(is_home_or_agent_dir(&home));
1577        }
1578    }
1579
1580    #[test]
1581    fn agent_dirs_detected() {
1582        let claude = std::path::PathBuf::from("/home/user/.claude");
1583        assert!(is_home_or_agent_dir(&claude));
1584        let codex = std::path::PathBuf::from("/home/user/.codex");
1585        assert!(is_home_or_agent_dir(&codex));
1586        let project = std::path::PathBuf::from("/home/user/projects/myapp");
1587        assert!(!is_home_or_agent_dir(&project));
1588    }
1589
1590    #[test]
1591    fn test_unified_tool_count() {
1592        let tools = crate::tool_defs::unified_tool_defs();
1593        assert_eq!(tools.len(), 5, "Expected 5 unified tools");
1594    }
1595
1596    #[test]
1597    fn test_granular_tool_count() {
1598        let tools = crate::tool_defs::granular_tool_defs();
1599        assert!(tools.len() >= 25, "Expected at least 25 granular tools");
1600    }
1601
1602    #[test]
1603    fn test_registry_tool_count_ssot() {
1604        let registry = crate::server::registry::build_registry();
1605        assert_eq!(
1606            registry.len(),
1607            62,
1608            "Registry tool count drift! Update this test AND all docs when adding/removing tools."
1609        );
1610    }
1611
1612    #[test]
1613    fn disabled_tools_filters_list() {
1614        let all = crate::tool_defs::granular_tool_defs();
1615        let total = all.len();
1616        let disabled = ["ctx_graph".to_string(), "ctx_agent".to_string()];
1617        let filtered: Vec<_> = all
1618            .into_iter()
1619            .filter(|t| !disabled.iter().any(|d| t.name.as_ref() == d.as_str()))
1620            .collect();
1621        assert_eq!(filtered.len(), total - 2);
1622        assert!(!filtered.iter().any(|t| t.name.as_ref() == "ctx_graph"));
1623        assert!(!filtered.iter().any(|t| t.name.as_ref() == "ctx_agent"));
1624    }
1625
1626    #[test]
1627    fn empty_disabled_tools_returns_all() {
1628        let all = crate::tool_defs::granular_tool_defs();
1629        let total = all.len();
1630        let disabled: Vec<String> = vec![];
1631        let filtered: Vec<_> = all
1632            .into_iter()
1633            .filter(|t| !disabled.iter().any(|d| t.name.as_ref() == d.as_str()))
1634            .collect();
1635        assert_eq!(filtered.len(), total);
1636    }
1637
1638    #[test]
1639    fn misspelled_disabled_tool_is_silently_ignored() {
1640        let all = crate::tool_defs::granular_tool_defs();
1641        let total = all.len();
1642        let disabled = ["ctx_nonexistent_tool".to_string()];
1643        let filtered: Vec<_> = all
1644            .into_iter()
1645            .filter(|t| !disabled.iter().any(|d| t.name.as_ref() == d.as_str()))
1646            .collect();
1647        assert_eq!(filtered.len(), total);
1648    }
1649
1650    #[test]
1651    fn detect_multi_root_workspace_with_child_projects() {
1652        let tmp = tempfile::tempdir().unwrap();
1653        let workspace = tmp.path().join("workspace");
1654        std::fs::create_dir_all(&workspace).unwrap();
1655
1656        let proj_a = workspace.join("project-a");
1657        let proj_b = workspace.join("project-b");
1658        std::fs::create_dir_all(proj_a.join(".git")).unwrap();
1659        std::fs::create_dir_all(&proj_b).unwrap();
1660        std::fs::write(proj_b.join("package.json"), "{}").unwrap();
1661
1662        let result = detect_multi_root_workspace(&workspace);
1663        assert!(
1664            result.is_some(),
1665            "should detect workspace with 2 child projects"
1666        );
1667
1668        std::env::remove_var("LEAN_CTX_ALLOW_PATH");
1669    }
1670
1671    #[test]
1672    fn detect_multi_root_workspace_returns_none_for_single_project() {
1673        let tmp = tempfile::tempdir().unwrap();
1674        let workspace = tmp.path().join("workspace");
1675        std::fs::create_dir_all(&workspace).unwrap();
1676
1677        let proj_a = workspace.join("project-a");
1678        std::fs::create_dir_all(proj_a.join(".git")).unwrap();
1679
1680        let result = detect_multi_root_workspace(&workspace);
1681        assert!(
1682            result.is_none(),
1683            "should not detect workspace with only 1 child project"
1684        );
1685    }
1686
1687    #[test]
1688    fn is_broad_or_unsafe_root_rejects_home() {
1689        if let Some(home) = dirs::home_dir() {
1690            assert!(is_broad_or_unsafe_root(&home));
1691        }
1692    }
1693
1694    #[test]
1695    fn is_broad_or_unsafe_root_rejects_filesystem_root() {
1696        assert!(is_broad_or_unsafe_root(std::path::Path::new("/")));
1697    }
1698
1699    #[test]
1700    fn is_broad_or_unsafe_root_rejects_agent_dirs() {
1701        assert!(is_broad_or_unsafe_root(std::path::Path::new(
1702            "/home/user/.claude"
1703        )));
1704        assert!(is_broad_or_unsafe_root(std::path::Path::new(
1705            "/home/user/.codex"
1706        )));
1707    }
1708
1709    #[test]
1710    fn is_broad_or_unsafe_root_allows_project_subdir() {
1711        let tmp = tempfile::tempdir().unwrap();
1712        let subdir = tmp.path().join("my-project");
1713        std::fs::create_dir_all(&subdir).unwrap();
1714        assert!(!is_broad_or_unsafe_root(&subdir));
1715    }
1716
1717    #[test]
1718    fn is_broad_or_unsafe_root_allows_tmp_subdirs() {
1719        assert!(!is_broad_or_unsafe_root(std::path::Path::new(
1720            "/tmp/leanctx-test"
1721        )));
1722        assert!(!is_broad_or_unsafe_root(std::path::Path::new(
1723            "/tmp/my-project"
1724        )));
1725    }
1726
1727    #[test]
1728    fn is_broad_or_unsafe_root_allows_home_subdirs() {
1729        if let Some(home) = dirs::home_dir() {
1730            let subdir = home.join("projects").join("my-app");
1731            assert!(!is_broad_or_unsafe_root(&subdir));
1732        }
1733    }
1734
1735    #[test]
1736    fn derive_project_root_falls_back_to_bare_cwd() {
1737        let tmp = tempfile::tempdir().unwrap();
1738        let bare = tmp.path().join("bare-dir");
1739        std::fs::create_dir_all(&bare).unwrap();
1740
1741        let original = std::env::current_dir().unwrap();
1742        std::env::set_current_dir(&bare).unwrap();
1743        let result = derive_project_root_from_cwd();
1744        std::env::set_current_dir(original).unwrap();
1745
1746        assert!(result.is_some(), "bare dir should produce a project root");
1747        let root = result.unwrap();
1748        assert!(
1749            root.contains("bare-dir"),
1750            "fallback should use the bare dir path"
1751        );
1752    }
1753}