fix: restrict tool callback tolerance to read-only effects

This commit is contained in:
m4
2026-09-03 22:40:36 +08:00
parent 812e05d29d
commit 324011ab3f
2 changed files with 50 additions and 1 deletions
+5 -1
View File
@@ -21,6 +21,7 @@ if TYPE_CHECKING:
_READ_ONLY_PREFIXES = ("read_", "get_", "list_", "search_", "find_", "check_")
_READ_ONLY_NAMES = {
"tavily_search",
"web_search",
"glob",
"grep",
@@ -136,6 +137,7 @@ class RecoverableToolEffectMiddleware(AgentMiddleware):
tool_call_id = str(tool_call.get("id") or "")
arguments = tool_call.get("args") or {}
request_hash = _hash(arguments)
effect_class = _effect_class(tool_name)
checkpoint_ns = str(metadata.get("checkpoint_ns") or metadata.get("langgraph_checkpoint_ns") or "")
task_path = ":".join(
str(metadata.get(name) or "")
@@ -160,7 +162,7 @@ class RecoverableToolEffectMiddleware(AgentMiddleware):
"task_path": task_path,
"tool_call_id": tool_call_id,
"tool_name": tool_name,
"effect_class": _effect_class(tool_name),
"effect_class": effect_class,
"request_hash": request_hash,
},
)
@@ -233,6 +235,8 @@ class RecoverableToolEffectMiddleware(AgentMiddleware):
tool_name,
effect_id,
)
if effect_class != "read_only":
raise EvoRuntimeError("TOOL_EFFECT_TERMINAL_UNAVAILABLE") from None
return ToolMessage(
content="TOOL_EFFECT_TERMINAL_UNAVAILABLE",
tool_call_id=tool_call_id,