Skip to main content

lean_ctx/server/
mod.rs

1pub mod bounded_lock;
2pub mod bypass_hint;
3pub mod compaction_sync;
4pub mod context_gate;
5mod dispatch;
6pub mod dynamic_tools;
7pub mod elicitation;
8pub(crate) mod execute;
9pub mod helpers;
10pub mod multi_path;
11pub mod notifications;
12pub mod progress;
13pub mod prompts;
14pub mod reference_store;
15pub mod registry;
16pub mod resources;
17pub mod role_guard;
18pub mod roots;
19pub mod tool_trait;
20
21use futures::FutureExt;
22use rmcp::handler::server::ServerHandler;
23use rmcp::model::{
24    CallToolRequestParams, CallToolResult, Content, Implementation, InitializeRequestParams,
25    InitializeResult, ListToolsResult, PaginatedRequestParams, ServerCapabilities, ServerInfo,
26};
27use rmcp::service::{RequestContext, RoleServer};
28use rmcp::ErrorData;
29
30use crate::tools::{CrpMode, LeanCtxServer};
31
32impl ServerHandler for LeanCtxServer {
33    fn get_info(&self) -> ServerInfo {
34        let capabilities = ServerCapabilities::builder()
35            .enable_tools()
36            .enable_resources()
37            .enable_resources_subscribe()
38            .enable_prompts()
39            .build();
40
41        let config = crate::core::config::Config::load();
42        let level = crate::core::config::CompressionLevel::effective(&config);
43        let _ = crate::core::terse::rules_inject::inject(&level);
44
45        let instructions = crate::instructions::build_instructions(CrpMode::effective());
46
47        InitializeResult::new(capabilities)
48            .with_server_info(Implementation::new("lean-ctx", env!("CARGO_PKG_VERSION")))
49            .with_instructions(instructions)
50    }
51
52    async fn initialize(
53        &self,
54        request: InitializeRequestParams,
55        context: RequestContext<RoleServer>,
56    ) -> Result<InitializeResult, ErrorData> {
57        let name = request.client_info.name.clone();
58        tracing::info!("MCP client connected: {:?}", name);
59        *self.client_name.write().await = name.clone();
60        *self.peer.write().await = Some(context.peer.clone());
61
62        if self.session_mode != crate::tools::SessionMode::Shared {
63            crate::core::budget_tracker::BudgetTracker::global().reset();
64            if let Ok(data_dir) = crate::core::data_dir::lean_ctx_data_dir() {
65                let radar = data_dir.join("context_radar.jsonl");
66                if radar.exists() {
67                    let prev = data_dir.join("context_radar.prev.jsonl");
68                    let _ = std::fs::rename(&radar, &prev);
69                }
70            }
71        }
72
73        let has_roots = request.capabilities.roots.is_some();
74        self.has_client_roots
75            .store(has_roots, std::sync::atomic::Ordering::Relaxed);
76        if has_roots {
77            tracing::info!("Client supports MCP roots/list — will resolve on first tool call");
78        }
79
80        let env_root = roots::root_from_env();
81        let derived_root = derive_project_root_from_cwd();
82        let effective_root = env_root.or(derived_root);
83
84        let cwd_str = std::env::current_dir()
85            .ok()
86            .map(|p| p.to_string_lossy().to_string())
87            .unwrap_or_default();
88        {
89            let mut session = self.session.write().await;
90            if !cwd_str.is_empty() {
91                session.shell_cwd = Some(cwd_str.clone());
92            }
93            if let Some(ref root) = effective_root {
94                session.project_root = Some(root.clone());
95                tracing::info!("Project root set to: {root}");
96            } else if let Some(ref root) = session.project_root {
97                let root_path = std::path::Path::new(root);
98                let root_has_marker = has_project_marker(root_path);
99                let root_str = root_path.to_string_lossy();
100                let root_suspicious = root_str.contains("/.claude")
101                    || root_str.contains("/.codex")
102                    || root_str.contains("/var/folders/")
103                    || root_str.contains("/tmp/")
104                    || root_str.contains("\\.claude")
105                    || root_str.contains("\\.codex")
106                    || root_str.contains("\\AppData\\Local\\Temp")
107                    || root_str.contains("\\Temp\\");
108                if root_suspicious && !root_has_marker {
109                    session.project_root = None;
110                }
111            }
112            let cfg_extra = crate::core::config::Config::load().extra_roots;
113            if !cfg_extra.is_empty() {
114                let existing: std::collections::HashSet<_> =
115                    session.extra_roots.iter().cloned().collect();
116                for r in cfg_extra {
117                    if !existing.contains(&r) {
118                        session.extra_roots.push(r);
119                    }
120                }
121            }
122            if self.session_mode == crate::tools::SessionMode::Shared {
123                if let Some(ref root) = session.project_root {
124                    if let Some(ref rt) = self.context_os {
125                        rt.shared_sessions.persist_best_effort(
126                            root,
127                            &self.workspace_id,
128                            &self.channel_id,
129                            &session,
130                        );
131                        rt.metrics.record_session_persisted();
132                    }
133                }
134            } else {
135                let _ = session.save();
136            }
137        }
138
139        if let Some(ref root) = effective_root {
140            crate::core::index_orchestrator::ensure_all_background(root);
141        }
142
143        let agent_name = name.clone();
144        let agent_root = effective_root.clone().unwrap_or_default();
145        let agent_id_handle = self.agent_id.clone();
146        tokio::task::spawn_blocking(move || {
147            if std::env::var("LEAN_CTX_HEADLESS").is_ok() {
148                return;
149            }
150
151            // Avoid startup stampedes when multiple agent sessions initialize at once.
152            // These are best-effort maintenance tasks; it's fine to skip if another
153            // lean-ctx instance is already doing them.
154            let maintenance = crate::core::startup_guard::try_acquire_lock(
155                "startup-maintenance",
156                std::time::Duration::from_secs(2),
157                std::time::Duration::from_mins(2),
158            );
159            if maintenance.is_some() {
160                if let Some(home) = dirs::home_dir() {
161                    let _ = crate::rules_inject::inject_all_rules(&home);
162                }
163                crate::hooks::refresh_installed_hooks();
164                crate::core::version_check::check_background();
165            }
166            drop(maintenance);
167
168            if !agent_root.is_empty() {
169                let heuristic_role = match agent_name.to_lowercase().as_str() {
170                    n if n.contains("cursor") => Some("coder"),
171                    n if n.contains("claude") => Some("coder"),
172                    n if n.contains("codex") => Some("coder"),
173                    n if n.contains("antigravity") || n.contains("gemini") => Some("coder"),
174                    n if n.contains("review") => Some("reviewer"),
175                    n if n.contains("test") => Some("debugger"),
176                    _ => None,
177                };
178                let env_role = std::env::var("LEAN_CTX_ROLE")
179                    .or_else(|_| std::env::var("LEAN_CTX_AGENT_ROLE"))
180                    .ok();
181                let effective_role = env_role.as_deref().or(heuristic_role).unwrap_or("coder");
182
183                let _ = crate::core::roles::set_active_role(effective_role);
184
185                let mut registry = crate::core::agents::AgentRegistry::load_or_create();
186                registry.cleanup_stale(24);
187                let id = registry.register("mcp", Some(effective_role), &agent_root);
188                let _ = registry.save();
189                if let Ok(mut guard) = agent_id_handle.try_write() {
190                    *guard = Some(id);
191                }
192            }
193        });
194
195        let client_caps = crate::core::client_capabilities::ClientMcpCapabilities::detect(&name);
196        tracing::info!("Client capabilities: {}", client_caps.format_summary());
197
198        {
199            let cfg = crate::core::config::Config::load();
200            let cats = cfg.default_tool_categories_effective();
201            dynamic_tools::init_from_config(&cats);
202        }
203
204        if client_caps.dynamic_tools {
205            if let Ok(mut dt) = dynamic_tools::global().lock() {
206                dt.set_supports_list_changed(true);
207            }
208        }
209        if let Some(max) = client_caps.max_tools {
210            if let Ok(mut dt) = dynamic_tools::global().lock() {
211                dt.set_supports_list_changed(true);
212                if max < 100 {
213                    dt.unload_category(dynamic_tools::ToolCategory::Debug);
214                    dt.unload_category(dynamic_tools::ToolCategory::Memory);
215                }
216            }
217        }
218
219        crate::core::client_capabilities::set_detected(&client_caps);
220
221        let instructions =
222            crate::instructions::build_instructions_with_client(CrpMode::effective(), &name);
223
224        let capabilities = match (client_caps.resources, client_caps.prompts) {
225            (true, true) => ServerCapabilities::builder()
226                .enable_tools()
227                .enable_resources()
228                .enable_resources_subscribe()
229                .enable_prompts()
230                .build(),
231            (true, false) => ServerCapabilities::builder()
232                .enable_tools()
233                .enable_resources()
234                .enable_resources_subscribe()
235                .build(),
236            (false, true) => ServerCapabilities::builder()
237                .enable_tools()
238                .enable_prompts()
239                .build(),
240            (false, false) => ServerCapabilities::builder().enable_tools().build(),
241        };
242
243        Ok(InitializeResult::new(capabilities)
244            .with_server_info(Implementation::new("lean-ctx", env!("CARGO_PKG_VERSION")))
245            .with_instructions(instructions))
246    }
247
248    async fn list_tools(
249        &self,
250        _request: Option<PaginatedRequestParams>,
251        _context: RequestContext<RoleServer>,
252    ) -> Result<ListToolsResult, ErrorData> {
253        let all_tools = if crate::tool_defs::is_full_mode() {
254            if let Some(ref reg) = self.registry {
255                reg.tool_defs()
256            } else {
257                crate::tool_defs::granular_tool_defs()
258            }
259        } else if std::env::var("LEAN_CTX_UNIFIED").is_ok() {
260            crate::tool_defs::unified_tool_defs()
261        } else if let Some(ref reg) = self.registry {
262            let core_names = crate::tool_defs::core_tool_names();
263            reg.tool_defs()
264                .into_iter()
265                .filter(|t| core_names.contains(&t.name.as_ref()))
266                .collect()
267        } else {
268            crate::tool_defs::lazy_tool_defs()
269        };
270
271        let disabled = crate::core::config::Config::load().disabled_tools_effective();
272        let client = self.client_name.read().await.clone();
273        let is_zed = !client.is_empty() && client.to_lowercase().contains("zed");
274
275        let tools: Vec<_> = all_tools
276            .into_iter()
277            .filter(|t| {
278                let name = t.name.as_ref();
279                if !disabled.is_empty() && disabled.iter().any(|d| d.as_str() == name) {
280                    return false;
281                }
282                if is_zed && name == "ctx_edit" {
283                    return false;
284                }
285                true
286            })
287            .collect();
288
289        let tools = {
290            let Ok(dyn_state) = dynamic_tools::global().lock() else {
291                tracing::warn!("dynamic_tools mutex poisoned in list_tools; returning unfiltered");
292                return Ok(ListToolsResult {
293                    tools,
294                    ..Default::default()
295                });
296            };
297            if dyn_state.supports_list_changed() {
298                tools
299                    .into_iter()
300                    .filter(|t| dyn_state.is_tool_active(t.name.as_ref()))
301                    .collect()
302            } else {
303                tools
304            }
305        };
306
307        let tools = {
308            let active = self.workflow.read().await.clone();
309            if let Some(run) = active {
310                if run.current == "done" || is_workflow_stale(&run) {
311                    let mut wf = self.workflow.write().await;
312                    *wf = None;
313                    let _ = crate::core::workflow::clear_active();
314                } else if let Some(state) = run.spec.state(&run.current) {
315                    if let Some(allowed) = &state.allowed_tools {
316                        let mut allow: std::collections::HashSet<&str> =
317                            allowed.iter().map(std::string::String::as_str).collect();
318                        for passthrough in WORKFLOW_PASSTHROUGH_TOOLS {
319                            allow.insert(passthrough);
320                        }
321                        return Ok(ListToolsResult {
322                            tools: tools
323                                .into_iter()
324                                .filter(|t| allow.contains(t.name.as_ref()))
325                                .collect(),
326                            ..Default::default()
327                        });
328                    }
329                }
330            }
331            tools
332        };
333
334        let tools = {
335            let cfg = crate::core::config::Config::load();
336            let level = crate::core::config::CompressionLevel::effective(&cfg);
337            let mode =
338                crate::core::terse::mcp_compress::DescriptionMode::from_compression_level(&level);
339            if mode == crate::core::terse::mcp_compress::DescriptionMode::Full {
340                tools
341            } else {
342                tools
343                    .into_iter()
344                    .map(|mut t| {
345                        let compressed = crate::core::terse::mcp_compress::compress_description(
346                            t.name.as_ref(),
347                            t.description.as_deref().unwrap_or(""),
348                            mode,
349                        );
350                        t.description = Some(compressed.into());
351                        t
352                    })
353                    .collect()
354            }
355        };
356
357        Ok(ListToolsResult {
358            tools,
359            ..Default::default()
360        })
361    }
362
363    async fn list_prompts(
364        &self,
365        _request: Option<PaginatedRequestParams>,
366        _context: RequestContext<RoleServer>,
367    ) -> Result<rmcp::model::ListPromptsResult, ErrorData> {
368        Ok(rmcp::model::ListPromptsResult::with_all_items(
369            prompts::list_prompts(),
370        ))
371    }
372
373    async fn get_prompt(
374        &self,
375        request: rmcp::model::GetPromptRequestParams,
376        _context: RequestContext<RoleServer>,
377    ) -> Result<rmcp::model::GetPromptResult, ErrorData> {
378        let ledger = self.ledger.read().await;
379        match prompts::get_prompt(&request, &ledger) {
380            Some(result) => Ok(result),
381            None => Err(ErrorData::invalid_params(
382                format!("Unknown prompt: {}", request.name),
383                None,
384            )),
385        }
386    }
387
388    async fn list_resources(
389        &self,
390        _request: Option<PaginatedRequestParams>,
391        _context: RequestContext<RoleServer>,
392    ) -> Result<rmcp::model::ListResourcesResult, rmcp::ErrorData> {
393        Ok(rmcp::model::ListResourcesResult::with_all_items(
394            resources::list_resources(),
395        ))
396    }
397
398    async fn read_resource(
399        &self,
400        request: rmcp::model::ReadResourceRequestParams,
401        _context: RequestContext<RoleServer>,
402    ) -> Result<rmcp::model::ReadResourceResult, rmcp::ErrorData> {
403        let ledger = self.ledger.read().await;
404        match resources::read_resource(&request.uri, &ledger) {
405            Some(contents) => Ok(rmcp::model::ReadResourceResult::new(contents)),
406            None => Err(rmcp::ErrorData::resource_not_found(
407                format!("Unknown resource: {}", request.uri),
408                None,
409            )),
410        }
411    }
412
413    async fn call_tool(
414        &self,
415        request: CallToolRequestParams,
416        context: RequestContext<RoleServer>,
417    ) -> Result<CallToolResult, ErrorData> {
418        use std::panic::AssertUnwindSafe;
419
420        let progress_token = request
421            .meta
422            .as_ref()
423            .and_then(rmcp::model::Meta::get_progress_token);
424        if let Some(ref token) = progress_token {
425            let sender =
426                crate::server::progress::ProgressSender::new(context.peer.clone(), token.clone());
427            *self
428                .progress_sender
429                .lock()
430                .unwrap_or_else(std::sync::PoisonError::into_inner) = Some(sender);
431        }
432
433        let tool_name_for_panic = request.name.as_ref().to_string();
434        let args_fp_for_panic = request
435            .arguments
436            .as_ref()
437            .map(|a| {
438                crate::core::loop_detection::LoopDetector::fingerprint(&serde_json::Value::Object(
439                    a.clone(),
440                ))
441            })
442            .unwrap_or_default();
443
444        let loop_detector = self.loop_detector.clone();
445
446        match AssertUnwindSafe(self.call_tool_guarded(request))
447            .catch_unwind()
448            .await
449        {
450            Ok(result) => result,
451            Err(panic_payload) => {
452                let detail = if let Some(s) = panic_payload.downcast_ref::<&str>() {
453                    (*s).to_string()
454                } else if let Some(s) = panic_payload.downcast_ref::<String>() {
455                    s.clone()
456                } else {
457                    "unknown".to_string()
458                };
459                tracing::error!("call_tool panicked: {detail}");
460
461                if let Ok(mut detector) =
462                    tokio::time::timeout(std::time::Duration::from_secs(1), loop_detector.write())
463                        .await
464                {
465                    detector.record_error_outcome(&tool_name_for_panic, &args_fp_for_panic);
466                }
467
468                Ok(CallToolResult::error(vec![Content::text(
469                    "ERROR: lean-ctx internal error. The MCP server is still running. \
470                     Please retry or use a different approach."
471                        .to_string(),
472                )]))
473            }
474        }
475    }
476
477    async fn on_roots_list_changed(
478        &self,
479        _context: rmcp::service::NotificationContext<RoleServer>,
480    ) {
481        tracing::info!("Received roots/list_changed — will re-resolve on next tool call");
482        self.roots_resolved
483            .store(false, std::sync::atomic::Ordering::Relaxed);
484    }
485}
486
487impl LeanCtxServer {
488    async fn call_tool_guarded(
489        &self,
490        request: CallToolRequestParams,
491    ) -> Result<CallToolResult, ErrorData> {
492        self.check_idle_expiry().await;
493        self.resolve_roots_once().await;
494        elicitation::increment_call();
495
496        let original_name = request.name.as_ref().to_string();
497        let (resolved_name, resolved_args) = if original_name == "ctx" {
498            let sub = request
499                .arguments
500                .as_ref()
501                .and_then(|a| a.get("tool"))
502                .and_then(|v| v.as_str())
503                .map(std::string::ToString::to_string)
504                .ok_or_else(|| {
505                    ErrorData::invalid_params("'tool' is required for ctx meta-tool", None)
506                })?;
507            let tool_name = if sub.starts_with("ctx_") {
508                sub
509            } else {
510                format!("ctx_{sub}")
511            };
512            let mut args = request.arguments.unwrap_or_default();
513            args.remove("tool");
514            (tool_name, Some(args))
515        } else {
516            (original_name, request.arguments)
517        };
518        let name = resolved_name.as_str();
519        let args = resolved_args.as_ref();
520
521        let role_check = role_guard::check_tool_access(name);
522        if let Some(denied) = role_guard::into_call_tool_result(&role_check) {
523            tracing::warn!(
524                tool = name,
525                role = %role_check.role_name,
526                "Tool blocked by role policy"
527            );
528            return Ok(denied);
529        }
530
531        if name != "ctx_workflow" {
532            let active = self.workflow.read().await.clone();
533            if let Some(run) = active {
534                if run.current == "done" || is_workflow_stale(&run) {
535                    let mut wf = self.workflow.write().await;
536                    *wf = None;
537                    let _ = crate::core::workflow::clear_active();
538                } else if !WORKFLOW_PASSTHROUGH_TOOLS.contains(&name) {
539                    if let Some(state) = run.spec.state(&run.current) {
540                        if let Some(allowed) = &state.allowed_tools {
541                            let allowed_ok = allowed.iter().any(|t| t == name);
542                            if !allowed_ok {
543                                let mut shown = allowed.clone();
544                                shown.sort();
545                                shown.truncate(30);
546                                return Ok(CallToolResult::success(vec![Content::text(format!(
547                                    "Tool '{name}' blocked by workflow '{}' (state: {}). Allowed: {}. Use ctx_workflow(action=\"stop\") to exit.",
548                                    run.spec.name,
549                                    run.current,
550                                    shown.join(", ")
551                                ))]));
552                            }
553                        }
554                    }
555                }
556            }
557        }
558
559        let auto_context = {
560            let task = {
561                let session = self.session.read().await;
562                session.task.as_ref().map(|t| t.description.clone())
563            };
564            let project_root = {
565                let session = self.session.read().await;
566                session.project_root.clone()
567            };
568            let cache_timeout =
569                tokio::time::timeout(std::time::Duration::from_secs(5), self.cache.write()).await;
570            if let Ok(mut cache) = cache_timeout {
571                crate::tools::autonomy::session_lifecycle_pre_hook(
572                    &self.autonomy,
573                    name,
574                    &mut cache,
575                    task.as_deref(),
576                    project_root.as_deref(),
577                    CrpMode::effective(),
578                )
579            } else {
580                tracing::warn!("pre-dispatch: cache write-lock timeout (5s), skipping autonomy");
581                None
582            }
583        };
584
585        let args_fp = args
586            .map(|a| {
587                crate::core::loop_detection::LoopDetector::fingerprint(&serde_json::Value::Object(
588                    a.clone(),
589                ))
590            })
591            .unwrap_or_default();
592        let throttle_result = {
593            let fp = &args_fp;
594            let detector_timeout = tokio::time::timeout(
595                std::time::Duration::from_secs(3),
596                self.loop_detector.write(),
597            )
598            .await;
599            if let Ok(mut detector) = detector_timeout {
600                let is_search = crate::core::loop_detection::LoopDetector::is_search_tool(name);
601                let is_search_shell = name == "ctx_shell" && {
602                    let cmd = args
603                        .as_ref()
604                        .and_then(|a| a.get("command"))
605                        .and_then(|v| v.as_str())
606                        .unwrap_or("");
607                    crate::core::loop_detection::LoopDetector::is_search_shell_command(cmd)
608                };
609
610                if is_search || is_search_shell {
611                    let search_pattern = args.and_then(|a| {
612                        a.get("pattern")
613                            .or_else(|| a.get("query"))
614                            .and_then(|v| v.as_str())
615                    });
616                    let shell_pattern = if is_search_shell {
617                        args.and_then(|a| a.get("command"))
618                            .and_then(|v| v.as_str())
619                            .and_then(helpers::extract_search_pattern_from_command)
620                    } else {
621                        None
622                    };
623                    let pat = search_pattern.or(shell_pattern.as_deref());
624                    detector.record_search(name, fp, pat)
625                } else {
626                    detector.record_call(name, fp)
627                }
628            } else {
629                tracing::warn!("pre-dispatch: loop_detector write-lock timeout (3s), skipping");
630                crate::core::loop_detection::ThrottleResult::default()
631            }
632        };
633
634        if throttle_result.level == crate::core::loop_detection::ThrottleLevel::Blocked {
635            let msg = throttle_result.message.unwrap_or_default();
636            return Ok(CallToolResult::success(vec![Content::text(msg)]));
637        }
638
639        let throttle_warning =
640            if throttle_result.level == crate::core::loop_detection::ThrottleLevel::Reduced {
641                throttle_result.message.clone()
642            } else {
643                None
644            };
645
646        let config = crate::core::config::Config::load();
647        let minimal = config.minimal_overhead_effective();
648
649        {
650            use crate::core::budget_tracker::{BudgetLevel, BudgetTracker};
651            let snap = BudgetTracker::global().check();
652            if *snap.worst_level() == BudgetLevel::Exhausted
653                && name != "ctx_session"
654                && name != "ctx_cost"
655                && name != "ctx_metrics"
656            {
657                for (dim, lvl, used, limit) in [
658                    (
659                        "tokens",
660                        &snap.tokens.level,
661                        format!("{}", snap.tokens.used),
662                        format!("{}", snap.tokens.limit),
663                    ),
664                    (
665                        "shell",
666                        &snap.shell.level,
667                        format!("{}", snap.shell.used),
668                        format!("{}", snap.shell.limit),
669                    ),
670                    (
671                        "cost",
672                        &snap.cost.level,
673                        format!("${:.2}", snap.cost.used_usd),
674                        format!("${:.2}", snap.cost.limit_usd),
675                    ),
676                ] {
677                    if *lvl == BudgetLevel::Exhausted {
678                        crate::core::events::emit_budget_exhausted(&snap.role, dim, &used, &limit);
679                    }
680                }
681                let msg = format!(
682                    "[BUDGET EXHAUSTED] {}\n\
683                     Use `ctx_session action=role` to check/switch roles, \
684                     or `ctx_session action=reset` to start fresh.",
685                    snap.format_compact()
686                );
687                tracing::warn!(tool = name, "{msg}");
688                return Ok(CallToolResult::success(vec![Content::text(msg)]));
689            }
690        }
691
692        if is_shell_tool_name(name) {
693            crate::core::budget_tracker::BudgetTracker::global().record_shell();
694        }
695
696        let tool_start = std::time::Instant::now();
697        let (mut result_text, tool_saved_tokens) =
698            match self.dispatch_tool(name, args, minimal).await {
699                Ok(pair) => pair,
700                Err(e) => {
701                    if let Ok(mut detector) = tokio::time::timeout(
702                        std::time::Duration::from_secs(1),
703                        self.loop_detector.write(),
704                    )
705                    .await
706                    {
707                        detector.record_error_outcome(name, &args_fp);
708                    }
709                    return Err(e);
710                }
711            };
712
713        let is_raw_shell = name == "ctx_shell" && {
714            let arg_raw = helpers::get_bool(args, "raw").unwrap_or(false);
715            let arg_bypass = helpers::get_bool(args, "bypass").unwrap_or(false);
716            arg_raw
717                || arg_bypass
718                || std::env::var("LEAN_CTX_DISABLED").is_ok()
719                || std::env::var("LEAN_CTX_RAW").is_ok()
720        };
721
722        let pre_terse_len = result_text.len();
723        let output_tokens = {
724            let tokens = crate::core::tokens::count_tokens(&result_text) as u64;
725            crate::core::budget_tracker::BudgetTracker::global().record_tokens(tokens);
726            tokens
727        };
728
729        crate::core::anomaly::record_metric("tokens_per_call", output_tokens as f64);
730
731        // Context IR: record lineage for every tool call.
732        if let Some(ref ir) = self.context_ir {
733            let tool_duration = tool_start.elapsed();
734            let source_kind = match name {
735                n if n.contains("read") || n.contains("multi_read") || n.contains("smart_read") => {
736                    crate::core::context_ir::ContextIrSourceKindV1::Read
737                }
738                "ctx_shell" => crate::core::context_ir::ContextIrSourceKindV1::Shell,
739                "ctx_search" | "ctx_semantic_search" => {
740                    crate::core::context_ir::ContextIrSourceKindV1::Search
741                }
742                "ctx_provider" => crate::core::context_ir::ContextIrSourceKindV1::Provider,
743                _ => crate::core::context_ir::ContextIrSourceKindV1::Other,
744            };
745            let ir_path = helpers::get_str(args, "path");
746            let ir_command = helpers::get_str(args, "command");
747            let ir_mode = helpers::get_str(args, "mode");
748            let excerpt = if result_text.len() > 200 {
749                let mut end = 200;
750                while !result_text.is_char_boundary(end) && end > 0 {
751                    end -= 1;
752                }
753                &result_text[..end]
754            } else {
755                &result_text
756            };
757            let input = crate::core::context_ir::RecordIrInput {
758                kind: source_kind,
759                tool: name,
760                client_name: None,
761                agent_id: None,
762                path: ir_path.as_deref(),
763                command: ir_command.as_deref(),
764                pattern: ir_mode.as_deref(),
765                input_tokens: pre_terse_len / 4,
766                output_tokens: output_tokens as usize,
767                duration: tool_duration,
768                content_excerpt: excerpt,
769            };
770            ir.write().await.record(input);
771        }
772
773        // Correction-loop detection: track re-reads and re-runs as quality signals.
774        {
775            let mut detector = self.loop_detector.write().await;
776            if name == "ctx_read" {
777                let path = helpers::get_str(args, "path").unwrap_or_default();
778                let mode = helpers::get_str(args, "mode").unwrap_or_else(|| "auto".into());
779                let fresh = helpers::get_bool(args, "fresh").unwrap_or(false);
780                detector.record_read_for_correction(&path, &mode, fresh);
781            } else if name == "ctx_shell" {
782                let cmd = helpers::get_str(args, "command").unwrap_or_default();
783                detector.record_shell_for_correction(&cmd);
784            }
785            let correction_count = detector.correction_count();
786            if correction_count > 0 {
787                crate::core::anomaly::record_metric(
788                    "correction_loop_rate",
789                    f64::from(correction_count),
790                );
791            }
792            // Auto-degrade: reduce compression when correction rate is high
793            use crate::core::config::CompressionLevel;
794            if correction_count >= 5 {
795                CompressionLevel::set_session_degrade(&CompressionLevel::Off);
796            } else if correction_count >= 3 {
797                CompressionLevel::set_session_degrade(&CompressionLevel::Lite);
798            } else if correction_count == 0 {
799                CompressionLevel::clear_session_degrade();
800            }
801            detector.prune_corrections();
802        }
803
804        // Persist anomaly detector — debounced to reduce I/O in burst sequences.
805        crate::core::anomaly::save_debounced();
806
807        let budget_warning = {
808            use crate::core::budget_tracker::{BudgetLevel, BudgetTracker};
809            let snap = BudgetTracker::global().check();
810            if *snap.worst_level() == BudgetLevel::Warning {
811                for (dim, lvl, used, limit, pct) in [
812                    (
813                        "tokens",
814                        &snap.tokens.level,
815                        format!("{}", snap.tokens.used),
816                        format!("{}", snap.tokens.limit),
817                        snap.tokens.percent,
818                    ),
819                    (
820                        "shell",
821                        &snap.shell.level,
822                        format!("{}", snap.shell.used),
823                        format!("{}", snap.shell.limit),
824                        snap.shell.percent,
825                    ),
826                    (
827                        "cost",
828                        &snap.cost.level,
829                        format!("${:.2}", snap.cost.used_usd),
830                        format!("${:.2}", snap.cost.limit_usd),
831                        snap.cost.percent,
832                    ),
833                ] {
834                    if *lvl == BudgetLevel::Warning {
835                        crate::core::events::emit_budget_warning(
836                            &snap.role, dim, &used, &limit, pct,
837                        );
838                    }
839                }
840                if crate::core::protocol::meta_visible() {
841                    Some(format!("[BUDGET WARNING] {}", snap.format_compact()))
842                } else {
843                    None
844                }
845            } else {
846                None
847            }
848        };
849
850        let archive_hint = if minimal || is_raw_shell {
851            None
852        } else {
853            use crate::core::archive;
854            let archivable = matches!(
855                name,
856                "ctx_shell"
857                    | "ctx_read"
858                    | "ctx_multi_read"
859                    | "ctx_smart_read"
860                    | "ctx_execute"
861                    | "ctx_search"
862                    | "ctx_tree"
863            );
864            if archivable && archive::should_archive(&result_text) {
865                let cmd = helpers::get_str(args, "command")
866                    .or_else(|| helpers::get_str(args, "path"))
867                    .unwrap_or_default();
868                let session_id = self.session.read().await.id.clone();
869                let to_store = crate::core::redaction::redact_text_if_enabled(&result_text);
870                let tokens = crate::core::tokens::count_tokens(&to_store);
871                archive::store(name, &cmd, &to_store, Some(&session_id))
872                    .map(|id| archive::format_hint(&id, to_store.len(), tokens))
873            } else {
874                None
875            }
876        };
877
878        let pre_compression = result_text.clone();
879        let skip_terse = is_raw_shell
880            || tool_saved_tokens > 0
881            || (name == "ctx_shell"
882                && helpers::get_str(args, "command")
883                    .is_some_and(|c| crate::shell::compress::has_structural_output(&c)));
884        let compression = crate::core::config::CompressionLevel::effective(&config);
885        if compression.is_active() && !skip_terse {
886            let terse_result =
887                crate::core::terse::pipeline::compress(&result_text, &compression, None);
888            if terse_result.quality_passed && terse_result.savings_pct >= 3.0 {
889                result_text = terse_result.output;
890            }
891        }
892
893        let profile_hints = crate::core::profiles::active_profile().output_hints;
894
895        if !is_raw_shell && profile_hints.verify_footer() {
896            let verify_cfg = crate::core::profiles::active_profile().verification;
897            let vr = crate::core::output_verification::verify_output(
898                &pre_compression,
899                &result_text,
900                &verify_cfg,
901            );
902            if !vr.warnings.is_empty() {
903                let msg = format!("[VERIFY] {}", vr.format_compact());
904                result_text = format!("{result_text}\n\n{msg}");
905            }
906        }
907
908        if profile_hints.archive_hint() {
909            if let Some(hint) = archive_hint {
910                result_text = format!("{result_text}\n{hint}");
911            }
912        }
913
914        if !is_raw_shell {
915            if let Some(ctx) = auto_context {
916                let ctx_tokens = crate::core::tokens::count_tokens(&ctx);
917                if ctx_tokens <= 400 {
918                    result_text = format!("{ctx}\n\n{result_text}");
919                }
920            }
921        }
922
923        if let Some(warning) = throttle_warning {
924            result_text = format!("{result_text}\n\n{warning}");
925        }
926
927        if let Some(bw) = budget_warning {
928            result_text = format!("{result_text}\n\n{bw}");
929        }
930
931        if !self
932            .rules_stale_checked
933            .swap(true, std::sync::atomic::Ordering::Relaxed)
934        {
935            let client = self.client_name.read().await.clone();
936            if !client.is_empty() {
937                if let Some(stale_msg) = crate::rules_inject::check_rules_freshness(&client) {
938                    result_text = format!("{result_text}\n\n{stale_msg}");
939                }
940            }
941        }
942
943        {
944            // Evaluate SLOs for observability (watch/dashboard), but keep tool outputs clean.
945            let _ = crate::core::slo::evaluate();
946        }
947
948        if name == "ctx_read" {
949            if minimal {
950                let cache_clone = self.cache.clone();
951                let autonomy_clone = self.autonomy.clone();
952                let name_owned = name.to_string();
953                tokio::spawn(async move {
954                    let result = std::panic::AssertUnwindSafe(async {
955                        let mut cache = cache_clone.write().await;
956                        crate::tools::autonomy::maybe_auto_dedup(
957                            &autonomy_clone,
958                            &mut cache,
959                            &name_owned,
960                        );
961                    })
962                    .catch_unwind()
963                    .await;
964                    if let Err(e) = result {
965                        let msg = e
966                            .downcast_ref::<String>()
967                            .map(String::as_str)
968                            .or_else(|| e.downcast_ref::<&str>().copied())
969                            .unwrap_or("unknown");
970                        tracing::error!("background auto_dedup panicked: {msg}");
971                    }
972                });
973            } else {
974                let read_path = self
975                    .resolve_path_or_passthrough(
976                        &helpers::get_str(args, "path").unwrap_or_default(),
977                    )
978                    .await;
979                let project_root = {
980                    let session = self.session.read().await;
981                    session.project_root.clone()
982                };
983
984                // Bounded cache lock for enrichment — degrade gracefully under contention
985                let enrich_timeout =
986                    tokio::time::timeout(std::time::Duration::from_secs(3), self.cache.write())
987                        .await;
988                if let Ok(mut cache) = enrich_timeout {
989                    let enrich = crate::tools::autonomy::enrich_after_read(
990                        &self.autonomy,
991                        &mut cache,
992                        &read_path,
993                        project_root.as_deref(),
994                        None,
995                        crate::tools::CrpMode::effective(),
996                        false,
997                    );
998                    if profile_hints.related_hint() {
999                        if let Some(hint) = enrich.related_hint {
1000                            result_text = format!("{result_text}\n{hint}");
1001                        }
1002                    }
1003                    crate::tools::autonomy::maybe_auto_dedup(&self.autonomy, &mut cache, name);
1004                } else {
1005                    tracing::warn!(
1006                        "post-dispatch cache lock timeout (3s) for {read_path}, skipping enrichment"
1007                    );
1008                }
1009
1010                // Ledger update — fire-and-forget to avoid blocking concurrent reads
1011                let ledger_clone = self.ledger.clone();
1012                let session_clone = self.session.clone();
1013                let peer_clone = self.peer.clone();
1014                let read_path_owned = read_path.clone();
1015                let project_root_owned = project_root.clone();
1016                let mode_used =
1017                    helpers::get_str(args, "mode").unwrap_or_else(|| "auto".to_string());
1018                let out_tok = output_tokens as usize;
1019                let sent_tok = crate::core::tokens::count_tokens(&result_text);
1020                let wants_eviction = true;
1021                let wants_elicitation = profile_hints.elicitation_hint();
1022                tokio::spawn(async move {
1023                    let result = std::panic::AssertUnwindSafe(async {
1024                        let active_task = {
1025                            let session = session_clone.read().await;
1026                            session.task.as_ref().map(|t| t.description.clone())
1027                        };
1028                        let mut ledger = ledger_clone.write().await;
1029                        let overlay = crate::core::context_overlay::OverlayStore::load_project(
1030                            &std::path::PathBuf::from(project_root_owned.as_deref().unwrap_or(".")),
1031                        );
1032                        let gate_result = context_gate::post_dispatch_record_with_task(
1033                            &read_path_owned,
1034                            &mode_used,
1035                            out_tok,
1036                            sent_tok,
1037                            &mut ledger,
1038                            &overlay,
1039                            active_task.as_deref(),
1040                        );
1041                        drop(ledger);
1042                        if wants_eviction {
1043                            if let Some(hint) = &gate_result.eviction_hint {
1044                                tracing::debug!("deferred eviction hint: {hint}");
1045                            }
1046                        }
1047                        if wants_elicitation {
1048                            if let Some(hint) = &gate_result.elicitation_hint {
1049                                tracing::debug!("deferred elicitation hint: {hint}");
1050                            }
1051                        }
1052                        if gate_result.resource_changed {
1053                            if let Some(peer) = peer_clone.read().await.as_ref() {
1054                                notifications::send_resource_updated(
1055                                    peer,
1056                                    notifications::RESOURCE_URI_SUMMARY,
1057                                )
1058                                .await;
1059                            }
1060                        }
1061                    })
1062                    .catch_unwind()
1063                    .await;
1064                    if let Err(e) = result {
1065                        let msg = e
1066                            .downcast_ref::<String>()
1067                            .map(String::as_str)
1068                            .or_else(|| e.downcast_ref::<&str>().copied())
1069                            .unwrap_or("unknown");
1070                        tracing::error!("background post_dispatch panicked: {msg}");
1071                    }
1072                });
1073            }
1074        }
1075
1076        if !minimal && !is_raw_shell && name == "ctx_shell" {
1077            let cmd = helpers::get_str(args, "command").unwrap_or_default();
1078
1079            if let Some(file_path) = extract_file_read_from_shell(&cmd) {
1080                if let Ok(mut bt) = crate::core::bounce_tracker::global().lock() {
1081                    bt.next_seq();
1082                    bt.record_shell_file_access(&file_path);
1083                }
1084            }
1085
1086            if profile_hints.efficiency_hint() {
1087                let calls = self.tool_calls.read().await;
1088                let last_original = calls.last().map_or(0, |c| c.original_tokens);
1089                drop(calls);
1090                let pre_hint_tokens = crate::core::tokens::count_tokens(&result_text);
1091                if let Some(hint) = crate::tools::autonomy::shell_efficiency_hint(
1092                    &self.autonomy,
1093                    &cmd,
1094                    last_original,
1095                    pre_hint_tokens,
1096                ) {
1097                    result_text = format!("{result_text}\n{hint}");
1098                }
1099            }
1100        }
1101
1102        if !minimal && !is_raw_shell {
1103            if let Ok(data_dir) = crate::core::data_dir::lean_ctx_data_dir() {
1104                let session = self.session.read().await;
1105                bypass_hint::set_session_id(&session.id);
1106                drop(session);
1107                if let Some(hint) = bypass_hint::check(&data_dir) {
1108                    result_text = format!("{result_text}\n{hint}");
1109                }
1110            }
1111            bypass_hint::record_lctx_call();
1112        }
1113
1114        if let Some(finding) = crate::core::auto_findings::extract(name, &result_text) {
1115            let mut session = self.session.write().await;
1116            session.add_finding(finding.file.as_deref(), None, &finding.summary);
1117            drop(session);
1118        }
1119
1120        #[allow(clippy::cast_possible_truncation)]
1121        let output_token_count = if result_text.len() == pre_terse_len {
1122            output_tokens as usize
1123        } else {
1124            crate::core::tokens::count_tokens(&result_text)
1125        };
1126
1127        // OPT-4: Correct stats with post-processing token counts.
1128        // dispatch/mod.rs records savings before terse/hints; adjust here
1129        // so persistent stats reflect what the model actually receives.
1130        if result_text.len() != pre_terse_len && tool_saved_tokens > 0 {
1131            let pre_savings = tool_saved_tokens;
1132            let actual_sent = output_token_count;
1133            let original = actual_sent + pre_savings;
1134            let actual_savings = original.saturating_sub(actual_sent);
1135            if actual_savings != pre_savings {
1136                let delta = pre_savings as i64 - actual_savings as i64;
1137                if delta != 0 {
1138                    crate::core::stats::adjust_savings(name, delta);
1139                }
1140            }
1141        }
1142
1143        let action = helpers::get_str(args, "action");
1144
1145        // K-bounded staleness guard: warn if shared context has diverged.
1146        const K_STALENESS_BOUND: i64 = 10;
1147        if self.session_mode == crate::tools::SessionMode::Shared {
1148            if let Some(ref rt) = self.context_os {
1149                let latest = rt.bus.latest_id(&self.workspace_id, &self.channel_id);
1150                let cursor = self
1151                    .last_seen_event_id
1152                    .load(std::sync::atomic::Ordering::Relaxed);
1153                if cursor > 0 && latest - cursor > K_STALENESS_BOUND {
1154                    let gap = latest - cursor;
1155                    result_text = format!(
1156                        "[CONTEXT STALE] {gap} events happened since your last read. \
1157                         Use ctx_session(action=\"status\") to sync.\n\n{result_text}"
1158                    );
1159                }
1160                self.last_seen_event_id
1161                    .store(latest, std::sync::atomic::Ordering::Relaxed);
1162            }
1163        }
1164
1165        {
1166            let input = helpers::canonical_args_string(args);
1167            let input_md5 = helpers::hash_fast(&input);
1168            let output_md5 = helpers::hash_fast(&result_text);
1169            let agent_id = self.agent_id.read().await.clone();
1170            let client_name = self.client_name.read().await.clone();
1171            let mut explicit_intent: Option<(
1172                crate::core::intent_protocol::IntentRecord,
1173                Option<String>,
1174                String,
1175            )> = None;
1176
1177            let pending_session_save = {
1178                let empty_args = serde_json::Map::new();
1179                let args_map = args.unwrap_or(&empty_args);
1180                let mut session = self.session.write().await;
1181                session.record_tool_receipt(
1182                    name,
1183                    action.as_deref(),
1184                    &input_md5,
1185                    &output_md5,
1186                    agent_id.as_deref(),
1187                    Some(&client_name),
1188                );
1189
1190                if let Some(intent) = crate::core::intent_protocol::infer_from_tool_call(
1191                    name,
1192                    action.as_deref(),
1193                    args_map,
1194                    session.project_root.as_deref(),
1195                ) {
1196                    let is_explicit =
1197                        intent.source == crate::core::intent_protocol::IntentSource::Explicit;
1198                    let root = session.project_root.clone();
1199                    let sid = session.id.clone();
1200                    session.record_intent(intent.clone());
1201                    if is_explicit {
1202                        explicit_intent = Some((intent, root, sid));
1203                    }
1204                }
1205                if session.should_save() {
1206                    session.prepare_save().ok()
1207                } else {
1208                    None
1209                }
1210            };
1211
1212            if let Some(prepared) = pending_session_save {
1213                let ir_clone = self.context_ir.clone();
1214                tokio::task::spawn_blocking(move || {
1215                    let _ = prepared.write_to_disk();
1216                    if let Some(ir) = ir_clone {
1217                        if let Ok(ir_guard) = ir.try_read() {
1218                            ir_guard.save();
1219                        }
1220                    }
1221                });
1222            }
1223
1224            if let Some((intent, root, session_id)) = explicit_intent {
1225                let _ = crate::core::intent_protocol::apply_side_effects(
1226                    &intent,
1227                    root.as_deref(),
1228                    &session_id,
1229                );
1230            }
1231
1232            if self.autonomy.is_enabled() {
1233                let (calls, project_root) = {
1234                    let session = self.session.read().await;
1235                    (session.stats.total_tool_calls, session.project_root.clone())
1236                };
1237
1238                if let Some(root) = project_root {
1239                    if crate::tools::autonomy::should_auto_consolidate(&self.autonomy, calls) {
1240                        let root_clone = root.clone();
1241                        tokio::task::spawn_blocking(move || {
1242                            let _ = crate::core::consolidation_engine::consolidate_latest(
1243                                &root_clone,
1244                                crate::core::consolidation_engine::ConsolidationBudgets::default(),
1245                            );
1246                        });
1247                    }
1248                }
1249            }
1250
1251            let agent_key = agent_id.unwrap_or_else(|| "unknown".to_string());
1252            let input_token_count = crate::core::tokens::count_tokens(&input) as u64;
1253            let output_token_count_u64 = output_token_count as u64;
1254            let name_owned = name.to_string();
1255            tokio::task::spawn_blocking(move || {
1256                let pricing = crate::core::gain::model_pricing::ModelPricing::load();
1257                let quote = pricing.quote_from_env_or_agent_type(&client_name);
1258                let cost_usd =
1259                    quote
1260                        .cost
1261                        .estimate_usd(input_token_count, output_token_count_u64, 0, 0);
1262                crate::core::budget_tracker::BudgetTracker::global().record_cost_usd(cost_usd);
1263
1264                let mut store = crate::core::a2a::cost_attribution::CostStore::load();
1265                store.record_tool_call(
1266                    &agent_key,
1267                    &client_name,
1268                    &name_owned,
1269                    input_token_count,
1270                    output_token_count_u64,
1271                    0,
1272                );
1273                let _ = store.save();
1274            });
1275        }
1276
1277        // Context Bus: conflict detection for knowledge writes in shared mode.
1278        if self.session_mode == crate::tools::SessionMode::Shared
1279            && name == "ctx_knowledge"
1280            && action.as_deref() == Some("remember")
1281        {
1282            if let Some(ref rt) = self.context_os {
1283                let my_agent = self.agent_id.read().await.clone();
1284                let category = helpers::get_str(args, "category");
1285                let key = helpers::get_str(args, "key");
1286                if let (Some(ref cat), Some(ref k)) = (&category, &key) {
1287                    let recent = rt.bus.recent_by_kind(
1288                        &self.workspace_id,
1289                        &self.channel_id,
1290                        "knowledge_remembered",
1291                        20,
1292                    );
1293                    for ev in &recent {
1294                        let p = &ev.payload;
1295                        let ev_cat = p.get("category").and_then(|v| v.as_str());
1296                        let ev_key = p.get("key").and_then(|v| v.as_str());
1297                        let ev_actor = ev.actor.as_deref();
1298                        if ev_cat == Some(cat.as_str())
1299                            && ev_key == Some(k.as_str())
1300                            && ev_actor != my_agent.as_deref()
1301                        {
1302                            let other = ev_actor.unwrap_or("unknown");
1303                            result_text = format!(
1304                                "[CONFLICT] Agent '{other}' recently wrote to the same knowledge key \
1305                                 '{cat}/{k}'. Review before proceeding.\n\n{result_text}"
1306                            );
1307                            break;
1308                        }
1309                    }
1310                }
1311            }
1312        }
1313
1314        // Context OS: persist shared session + publish events.
1315        if self.session_mode == crate::tools::SessionMode::Shared {
1316            let ws = self.workspace_id.clone();
1317            let ch = self.channel_id.clone();
1318            let rt = self.context_os.clone();
1319            let agent = self.agent_id.read().await.clone();
1320            let tool = name.to_string();
1321            let tool_action = action.clone();
1322            let tool_path = helpers::get_str(args, "path");
1323            let tool_category = helpers::get_str(args, "category");
1324            let tool_key = helpers::get_str(args, "key");
1325            let session_snapshot = self.session.read().await.clone();
1326            let session_task = session_snapshot.task.clone();
1327            tokio::task::spawn_blocking(move || {
1328                let Some(rt) = rt else {
1329                    return;
1330                };
1331                let Some(root) = session_snapshot.project_root.as_deref() else {
1332                    return;
1333                };
1334                rt.shared_sessions
1335                    .persist_best_effort(root, &ws, &ch, &session_snapshot);
1336                rt.metrics.record_session_persisted();
1337
1338                let mut base_payload = serde_json::json!({
1339                    "tool": tool,
1340                    "action": tool_action,
1341                });
1342                if let Some(ref p) = tool_path {
1343                    base_payload["path"] = serde_json::Value::String(p.clone());
1344                }
1345                if let Some(ref c) = tool_category {
1346                    base_payload["category"] = serde_json::Value::String(c.clone());
1347                }
1348                if let Some(ref k) = tool_key {
1349                    base_payload["key"] = serde_json::Value::String(k.clone());
1350                }
1351                if let Some(ref t) = session_task {
1352                    base_payload["reasoning"] = serde_json::Value::String(t.description.clone());
1353                }
1354
1355                if rt
1356                    .bus
1357                    .append(
1358                        &ws,
1359                        &ch,
1360                        &crate::core::context_os::ContextEventKindV1::ToolCallRecorded,
1361                        agent.as_deref(),
1362                        base_payload.clone(),
1363                    )
1364                    .is_some()
1365                {
1366                    rt.metrics.record_event_appended();
1367                    rt.metrics.record_event_broadcast();
1368                }
1369
1370                if let Some(secondary) =
1371                    crate::core::context_os::secondary_event_kind(&tool, tool_action.as_deref())
1372                {
1373                    if rt
1374                        .bus
1375                        .append(&ws, &ch, &secondary, agent.as_deref(), base_payload)
1376                        .is_some()
1377                    {
1378                        rt.metrics.record_event_appended();
1379                        rt.metrics.record_event_broadcast();
1380                    }
1381                }
1382            });
1383        }
1384
1385        let skip_checkpoint = minimal
1386            || matches!(
1387                name,
1388                "ctx_compress"
1389                    | "ctx_metrics"
1390                    | "ctx_benchmark"
1391                    | "ctx_analyze"
1392                    | "ctx_cache"
1393                    | "ctx_discover"
1394                    | "ctx_dedup"
1395                    | "ctx_session"
1396                    | "ctx_knowledge"
1397                    | "ctx_agent"
1398                    | "ctx_share"
1399                    | "ctx_gain"
1400                    | "ctx_overview"
1401                    | "ctx_preload"
1402                    | "ctx_cost"
1403                    | "ctx_heatmap"
1404                    | "ctx_task"
1405                    | "ctx_impact"
1406                    | "ctx_architecture"
1407                    | "ctx_smells"
1408                    | "ctx_workflow"
1409            );
1410
1411        if !skip_checkpoint && self.increment_and_check() {
1412            if let Some(checkpoint) = self.auto_checkpoint().await {
1413                let interval = LeanCtxServer::checkpoint_interval_effective();
1414                let hints = crate::core::profiles::active_profile().output_hints;
1415                if hints.checkpoint_in_output() && crate::core::protocol::meta_visible() {
1416                    let combined = format!(
1417                        "{result_text}\n\n--- AUTO CHECKPOINT (every {interval} calls) ---\n{checkpoint}"
1418                    );
1419                    return Ok(CallToolResult::success(vec![Content::text(combined)]));
1420                }
1421            }
1422        }
1423
1424        let tool_duration_ms = tool_start.elapsed().as_millis() as u64;
1425        if tool_duration_ms > 100 {
1426            LeanCtxServer::append_tool_call_log(
1427                name,
1428                tool_duration_ms,
1429                0,
1430                0,
1431                None,
1432                &chrono::Local::now().format("%Y-%m-%d %H:%M:%S").to_string(),
1433            );
1434        }
1435
1436        let current_count = self.call_count.load(std::sync::atomic::Ordering::Relaxed);
1437        if current_count > 0 && current_count.is_multiple_of(100) {
1438            std::thread::spawn(crate::cloud_sync::cloud_background_tasks);
1439        }
1440
1441        Ok(CallToolResult::success(vec![Content::text(result_text)]))
1442    }
1443
1444    /// Resolve project root from MCP client roots (once per session).
1445    /// Called on the first tool call. If the client supports `roots/list`,
1446    /// we query it and pick the best root with project markers.
1447    async fn resolve_roots_once(&self) {
1448        use std::sync::atomic::Ordering;
1449        if !self.has_client_roots.load(Ordering::Relaxed) {
1450            return;
1451        }
1452        if self.roots_resolved.swap(true, Ordering::Relaxed) {
1453            return;
1454        }
1455        let peer_guard = self.peer.read().await;
1456        let Some(peer) = peer_guard.as_ref() else {
1457            return;
1458        };
1459        let list_result = match peer.list_roots().await {
1460            Ok(r) => r,
1461            Err(e) => {
1462                tracing::warn!("roots/list failed: {e}");
1463                return;
1464            }
1465        };
1466        drop(peer_guard);
1467
1468        let uris: Vec<String> = list_result.roots.iter().map(|r| r.uri.clone()).collect();
1469        let validated_paths = roots::valid_dir_paths_from_uris(&uris);
1470        let Some(new_root) = roots::best_root_from_uris(&uris) else {
1471            return;
1472        };
1473
1474        let mut session = self.session.write().await;
1475        let old_root = session.project_root.clone();
1476
1477        let other_roots: Vec<String> = validated_paths
1478            .iter()
1479            .filter(|p| p.as_str() != new_root)
1480            .cloned()
1481            .collect();
1482        if !other_roots.is_empty() {
1483            session.extra_roots = other_roots;
1484            tracing::info!(
1485                "MCP roots: {} extra root(s) registered",
1486                session.extra_roots.len()
1487            );
1488        }
1489
1490        if old_root.as_deref() == Some(&new_root) {
1491            let _ = session.save();
1492            return;
1493        }
1494        tracing::info!(
1495            "MCP roots: switching project root from {:?} to {new_root}",
1496            old_root
1497        );
1498        if let Some(existing) =
1499            crate::core::session::SessionState::load_latest_for_project_root(&new_root)
1500        {
1501            *session = existing;
1502            session.extra_roots = validated_paths
1503                .iter()
1504                .filter(|p| p.as_str() != new_root)
1505                .cloned()
1506                .collect();
1507        }
1508        session.project_root = Some(new_root);
1509        let _ = session.save();
1510    }
1511}
1512
1513pub fn build_instructions_for_test(crp_mode: CrpMode) -> String {
1514    crate::instructions::build_instructions_for_test(crp_mode)
1515}
1516
1517pub fn build_claude_code_instructions_for_test() -> String {
1518    crate::instructions::claude_code_instructions()
1519}
1520
1521const PROJECT_MARKERS: &[&str] = &[
1522    ".git",
1523    "Cargo.toml",
1524    "package.json",
1525    "go.mod",
1526    "pyproject.toml",
1527    "setup.py",
1528    "pom.xml",
1529    "build.gradle",
1530    "Makefile",
1531    ".lean-ctx.toml",
1532];
1533
1534fn has_project_marker(dir: &std::path::Path) -> bool {
1535    PROJECT_MARKERS.iter().any(|m| dir.join(m).exists())
1536}
1537
1538fn is_home_or_agent_dir(dir: &std::path::Path) -> bool {
1539    if let Some(home) = dirs::home_dir() {
1540        if dir == home {
1541            return true;
1542        }
1543    }
1544    let dir_str = dir.to_string_lossy();
1545    dir_str.ends_with("/.claude")
1546        || dir_str.ends_with("/.codex")
1547        || dir_str.contains("/.claude/")
1548        || dir_str.contains("/.codex/")
1549}
1550
1551fn git_toplevel_from(dir: &std::path::Path) -> Option<String> {
1552    std::process::Command::new("git")
1553        .args(["rev-parse", "--show-toplevel"])
1554        .current_dir(dir)
1555        .stdout(std::process::Stdio::piped())
1556        .stderr(std::process::Stdio::null())
1557        .output()
1558        .ok()
1559        .and_then(|o| {
1560            if o.status.success() {
1561                String::from_utf8(o.stdout)
1562                    .ok()
1563                    .map(|s| s.trim().to_string())
1564            } else {
1565                None
1566            }
1567        })
1568}
1569
1570pub fn derive_project_root_from_cwd() -> Option<String> {
1571    let cwd = std::env::current_dir().ok()?;
1572    let canonical = crate::core::pathutil::safe_canonicalize_or_self(&cwd);
1573
1574    if is_home_or_agent_dir(&canonical) {
1575        return git_toplevel_from(&canonical);
1576    }
1577
1578    if has_project_marker(&canonical) {
1579        return Some(canonical.to_string_lossy().to_string());
1580    }
1581
1582    if let Some(git_root) = git_toplevel_from(&canonical) {
1583        return Some(git_root);
1584    }
1585
1586    if let Some(root) = detect_multi_root_workspace(&canonical) {
1587        return Some(root);
1588    }
1589
1590    // Fallback: use CWD as project root if it's a specific, safe directory.
1591    // This ensures bare directories (no .git, no markers) still work.
1592    // Guard: reject home dir, filesystem root, and agent sandbox dirs.
1593    if !crate::core::pathutil::is_broad_or_unsafe_root(&canonical) {
1594        tracing::info!(
1595            "No project markers found — using CWD as project root: {}",
1596            canonical.display()
1597        );
1598        return Some(canonical.to_string_lossy().to_string());
1599    }
1600
1601    None
1602}
1603
1604// Delegated to crate::core::pathutil::is_broad_or_unsafe_root
1605#[cfg(test)]
1606use crate::core::pathutil::is_broad_or_unsafe_root;
1607
1608/// Detect a multi-root workspace: a directory that has no project markers
1609/// itself, but contains child directories that do. In this case, use the
1610/// parent as jail root and auto-allow all child projects via LEAN_CTX_ALLOW_PATH.
1611fn detect_multi_root_workspace(dir: &std::path::Path) -> Option<String> {
1612    let entries = std::fs::read_dir(dir).ok()?;
1613    let mut child_projects: Vec<String> = Vec::new();
1614
1615    for entry in entries.flatten() {
1616        let path = entry.path();
1617        if path.is_dir() && has_project_marker(&path) {
1618            let canonical = crate::core::pathutil::safe_canonicalize_or_self(&path);
1619            child_projects.push(canonical.to_string_lossy().to_string());
1620        }
1621    }
1622
1623    if child_projects.len() >= 2 {
1624        let existing = std::env::var("LEAN_CTX_ALLOW_PATH").unwrap_or_default();
1625        let sep = if cfg!(windows) { ";" } else { ":" };
1626        let merged = if existing.is_empty() {
1627            child_projects.join(sep)
1628        } else {
1629            format!("{existing}{sep}{}", child_projects.join(sep))
1630        };
1631        std::env::set_var("LEAN_CTX_ALLOW_PATH", &merged);
1632        tracing::info!(
1633            "Multi-root workspace detected at {}: auto-allowing {} child projects",
1634            dir.display(),
1635            child_projects.len()
1636        );
1637        return Some(dir.to_string_lossy().to_string());
1638    }
1639
1640    None
1641}
1642
1643pub fn tool_descriptions_for_test() -> Vec<(&'static str, &'static str)> {
1644    crate::tool_defs::list_all_tool_defs()
1645        .into_iter()
1646        .map(|(name, desc, _)| (name, desc))
1647        .collect()
1648}
1649
1650pub fn tool_schemas_json_for_test() -> String {
1651    crate::tool_defs::list_all_tool_defs()
1652        .iter()
1653        .map(|(name, _, schema)| format!("{name}: {schema}"))
1654        .collect::<Vec<_>>()
1655        .join("\n")
1656}
1657
1658/// Tools that always pass through the workflow gate regardless of state.
1659/// Read-only tools should never be blocked — agents need them for context
1660/// recovery after crashes or session transitions.
1661pub const WORKFLOW_PASSTHROUGH_TOOLS: &[&str] = &[
1662    "ctx",
1663    "ctx_workflow",
1664    "ctx_read",
1665    "ctx_multi_read",
1666    "ctx_smart_read",
1667    "ctx_search",
1668    "ctx_tree",
1669    "ctx_session",
1670    "ctx_ledger",
1671];
1672
1673/// A workflow is stale if it hasn't been updated in 30 minutes.
1674/// This prevents dead workflows from blocking tools across sessions.
1675pub fn is_workflow_stale(run: &crate::core::workflow::types::WorkflowRun) -> bool {
1676    let elapsed = chrono::Utc::now()
1677        .signed_duration_since(run.updated_at)
1678        .num_minutes();
1679    elapsed > 30
1680}
1681
1682fn is_shell_tool_name(name: &str) -> bool {
1683    matches!(name, "ctx_shell" | "ctx_execute")
1684}
1685
1686fn extract_file_read_from_shell(cmd: &str) -> Option<String> {
1687    let trimmed = cmd.trim();
1688    let parts: Vec<&str> = trimmed.split_whitespace().collect();
1689    if parts.len() < 2 {
1690        return None;
1691    }
1692    let bin = parts[0].rsplit('/').next().unwrap_or(parts[0]);
1693    match bin {
1694        "cat" | "head" | "tail" | "less" | "more" | "bat" | "batcat" => {
1695            let file_arg = parts.iter().skip(1).find(|a| !a.starts_with('-'))?;
1696            Some(file_arg.to_string())
1697        }
1698        _ => None,
1699    }
1700}
1701
1702#[cfg(test)]
1703mod tests {
1704    use super::*;
1705
1706    #[test]
1707    fn project_markers_detected() {
1708        let tmp = tempfile::tempdir().unwrap();
1709        let root = tmp.path().join("myproject");
1710        std::fs::create_dir_all(&root).unwrap();
1711        assert!(!has_project_marker(&root));
1712
1713        std::fs::create_dir(root.join(".git")).unwrap();
1714        assert!(has_project_marker(&root));
1715    }
1716
1717    #[test]
1718    fn home_dir_detected_as_agent_dir() {
1719        if let Some(home) = dirs::home_dir() {
1720            assert!(is_home_or_agent_dir(&home));
1721        }
1722    }
1723
1724    #[test]
1725    fn agent_dirs_detected() {
1726        let claude = std::path::PathBuf::from("/home/user/.claude");
1727        assert!(is_home_or_agent_dir(&claude));
1728        let codex = std::path::PathBuf::from("/home/user/.codex");
1729        assert!(is_home_or_agent_dir(&codex));
1730        let project = std::path::PathBuf::from("/home/user/projects/myapp");
1731        assert!(!is_home_or_agent_dir(&project));
1732    }
1733
1734    #[test]
1735    fn test_unified_tool_count() {
1736        let tools = crate::tool_defs::unified_tool_defs();
1737        assert_eq!(tools.len(), 5, "Expected 5 unified tools");
1738    }
1739
1740    #[test]
1741    fn test_granular_tool_count() {
1742        let tools = crate::tool_defs::granular_tool_defs();
1743        assert!(tools.len() >= 25, "Expected at least 25 granular tools");
1744    }
1745
1746    #[test]
1747    fn test_registry_tool_count_ssot() {
1748        let registry = crate::server::registry::build_registry();
1749        assert_eq!(
1750            registry.len(),
1751            62,
1752            "Registry tool count drift! Update this test AND all docs when adding/removing tools."
1753        );
1754    }
1755
1756    #[test]
1757    fn disabled_tools_filters_list() {
1758        let all = crate::tool_defs::granular_tool_defs();
1759        let total = all.len();
1760        let disabled = ["ctx_graph".to_string(), "ctx_agent".to_string()];
1761        let filtered: Vec<_> = all
1762            .into_iter()
1763            .filter(|t| !disabled.iter().any(|d| t.name.as_ref() == d.as_str()))
1764            .collect();
1765        assert_eq!(filtered.len(), total - 2);
1766        assert!(!filtered.iter().any(|t| t.name.as_ref() == "ctx_graph"));
1767        assert!(!filtered.iter().any(|t| t.name.as_ref() == "ctx_agent"));
1768    }
1769
1770    #[test]
1771    fn empty_disabled_tools_returns_all() {
1772        let all = crate::tool_defs::granular_tool_defs();
1773        let total = all.len();
1774        let disabled: Vec<String> = vec![];
1775        let filtered: Vec<_> = all
1776            .into_iter()
1777            .filter(|t| !disabled.iter().any(|d| t.name.as_ref() == d.as_str()))
1778            .collect();
1779        assert_eq!(filtered.len(), total);
1780    }
1781
1782    #[test]
1783    fn misspelled_disabled_tool_is_silently_ignored() {
1784        let all = crate::tool_defs::granular_tool_defs();
1785        let total = all.len();
1786        let disabled = ["ctx_nonexistent_tool".to_string()];
1787        let filtered: Vec<_> = all
1788            .into_iter()
1789            .filter(|t| !disabled.iter().any(|d| t.name.as_ref() == d.as_str()))
1790            .collect();
1791        assert_eq!(filtered.len(), total);
1792    }
1793
1794    #[test]
1795    fn detect_multi_root_workspace_with_child_projects() {
1796        let tmp = tempfile::tempdir().unwrap();
1797        let workspace = tmp.path().join("workspace");
1798        std::fs::create_dir_all(&workspace).unwrap();
1799
1800        let proj_a = workspace.join("project-a");
1801        let proj_b = workspace.join("project-b");
1802        std::fs::create_dir_all(proj_a.join(".git")).unwrap();
1803        std::fs::create_dir_all(&proj_b).unwrap();
1804        std::fs::write(proj_b.join("package.json"), "{}").unwrap();
1805
1806        let result = detect_multi_root_workspace(&workspace);
1807        assert!(
1808            result.is_some(),
1809            "should detect workspace with 2 child projects"
1810        );
1811
1812        std::env::remove_var("LEAN_CTX_ALLOW_PATH");
1813    }
1814
1815    #[test]
1816    fn detect_multi_root_workspace_returns_none_for_single_project() {
1817        let tmp = tempfile::tempdir().unwrap();
1818        let workspace = tmp.path().join("workspace");
1819        std::fs::create_dir_all(&workspace).unwrap();
1820
1821        let proj_a = workspace.join("project-a");
1822        std::fs::create_dir_all(proj_a.join(".git")).unwrap();
1823
1824        let result = detect_multi_root_workspace(&workspace);
1825        assert!(
1826            result.is_none(),
1827            "should not detect workspace with only 1 child project"
1828        );
1829    }
1830
1831    #[test]
1832    fn is_broad_or_unsafe_root_rejects_home() {
1833        if let Some(home) = dirs::home_dir() {
1834            assert!(is_broad_or_unsafe_root(&home));
1835        }
1836    }
1837
1838    #[test]
1839    fn is_broad_or_unsafe_root_rejects_filesystem_root() {
1840        assert!(is_broad_or_unsafe_root(std::path::Path::new("/")));
1841    }
1842
1843    #[test]
1844    fn is_broad_or_unsafe_root_rejects_agent_dirs() {
1845        assert!(is_broad_or_unsafe_root(std::path::Path::new(
1846            "/home/user/.claude"
1847        )));
1848        assert!(is_broad_or_unsafe_root(std::path::Path::new(
1849            "/home/user/.codex"
1850        )));
1851    }
1852
1853    #[test]
1854    fn is_broad_or_unsafe_root_allows_project_subdir() {
1855        let tmp = tempfile::tempdir().unwrap();
1856        let subdir = tmp.path().join("my-project");
1857        std::fs::create_dir_all(&subdir).unwrap();
1858        assert!(!is_broad_or_unsafe_root(&subdir));
1859    }
1860
1861    #[test]
1862    fn is_broad_or_unsafe_root_allows_tmp_subdirs() {
1863        assert!(!is_broad_or_unsafe_root(std::path::Path::new(
1864            "/tmp/leanctx-test"
1865        )));
1866        assert!(!is_broad_or_unsafe_root(std::path::Path::new(
1867            "/tmp/my-project"
1868        )));
1869    }
1870
1871    #[test]
1872    fn is_broad_or_unsafe_root_allows_home_subdirs() {
1873        if let Some(home) = dirs::home_dir() {
1874            let subdir = home.join("projects").join("my-app");
1875            assert!(!is_broad_or_unsafe_root(&subdir));
1876        }
1877    }
1878
1879    #[test]
1880    fn derive_project_root_falls_back_to_bare_cwd() {
1881        let tmp = tempfile::tempdir().unwrap();
1882        let bare = tmp.path().join("bare-dir");
1883        std::fs::create_dir_all(&bare).unwrap();
1884
1885        let original = std::env::current_dir().unwrap();
1886        std::env::set_current_dir(&bare).unwrap();
1887        let result = derive_project_root_from_cwd();
1888        std::env::set_current_dir(original).unwrap();
1889
1890        assert!(result.is_some(), "bare dir should produce a project root");
1891        let root = result.unwrap();
1892        assert!(
1893            root.contains("bare-dir"),
1894            "fallback should use the bare dir path"
1895        );
1896    }
1897}