feat: disable agent observation writes in web deploy

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
This commit is contained in:
m4
2026-08-19 21:59:38 +08:00
parent 4445379f0a
commit b68fdf6d57
2 changed files with 20 additions and 0 deletions
+3
View File
@@ -952,6 +952,9 @@ def _get_default_agent():
cfg = _ensure_config()
web_full = os.environ.get("EVOSCIENTIST_DEPLOY_MODE", "").lower() == "full"
if web_full:
from .config.settings import MemoryObservationWriter
cfg.memory_observation_writer = MemoryObservationWriter.OFF
# Refuse to expose a Web graph whose command isolation is missing or
# ineffective. CLI/stripped runtimes do not enter this path.
from .native_sandbox import ensure_native_sandbox_ready
+17
View File
@@ -645,3 +645,20 @@ def test_read_profile_memory_honors_memory_dir_override(tmp_path, monkeypatch):
content = middleware._read_profile_memory(memory_dir=user_mem)
assert "per-user marker" in content
def test_web_full_agent_does_not_expose_record_observation(monkeypatch):
import EvoScientist.EvoScientist as mod
from EvoScientist.config.settings import MemoryObservationWriter
cfg = mod._ensure_config()
cfg.memory_observation_writer = MemoryObservationWriter.OFF
mw = mod._get_default_middleware(
workspace_dir="/workspace",
cfg=cfg,
enable_memory_workers=False,
)
memory_mw = next(m for m in mw if isinstance(m, memory_module.EvoMemoryMiddleware))
assert "record_observation" not in {t.name for t in memory_mw.tools}
assert {"search_observations", "read_memory"} <= {t.name for t in memory_mw.tools}