放开 Game Agent 读取工具的绝对路径和项目外路径
Project CI / AI game creator shell Rust crates (pull_request) Successful in 1m32s
Project CI / Backend tests (pull_request) Failing after 20s
Project CI / AI game creator shell Rust smoke (pull_request) Successful in 1m56s
Project CI / Frontend tests (pull_request) Successful in 2m26s
Project CI / Repository checks (pull_request) Failing after 15s
Project CI / AI game creator shell web tests (pull_request) Successful in 1m42s
Project CI / AI game creator shell Rust lane 2/2 (pull_request) Has been cancelled
Project CI / AI game creator shell Rust lane 1/2 (pull_request) Has been cancelled
Project CI / Native shell tests (pull_request) Has been cancelled

- agc_read_project_context 与 agc_list_project_files 改走 resolve_game_agent_read_path,绝对路径和离开项目的 .. 可以读
- 落在项目内的路径仍按项目相对路径处理,继续拒绝 .agent、凭据文件名、符号链接和硬链接
- 项目外读取同样拒绝这些受保护名字和链接,目录列表标记为未登记且不可导入
- agc_write_file、agc_apply_patch、素材导入和共享 normalize_relative_path 仍限定在当前项目
- Codex 进程沙箱仍是 read-only,提示词未改
- 决策记录、实施计划和 pitfalls 同步该口径
This commit is contained in:
2026-09-29 12:18:11 +01:00
parent 30a190d183
commit 59966b55c0
6 changed files with 392 additions and 54 deletions
@@ -1,5 +1,11 @@
# 决策记录
## 2026-09-29 Game Agent 读取工具接受绝对路径和项目外路径
- 决策:`agc_read_project_context` 与 `agc_list_project_files` 可以读取绝对路径,以及用 `..` 离开当前项目的路径。项目内相对路径仍拒绝 `.agent`、凭据文件名、符号链接和硬链接。项目外读取同样拒绝这些受保护名字和链接,但不因路径落在项目外而失败。
- 范围:`agc_write_file`、`agc_apply_patch`、素材导入和原生补丁仍限定在当前项目。共享 `normalize_relative_path` 不放宽。Codex 进程沙箱仍是 `read-only`。提示词本轮未改。
- 关联:`apps/ai-game-creator-shell/src-tauri/src/agent/direct_project_context.rs`、`direct_tools_mcp.rs`、`direct_tool_bridge.rs`。
## 2026-09-29 安装钩子的可执行逻辑只允许待在 !macro 里
- 背景:dev 渠道改名迁移钩子的第一版把迁移写成顶层 `Function`,并在函数体里调 `nsis_tauri_utils::KillProcess`;Jenkins 打 Windows 包时 makensis 在 `installer-hooks.nsh` 第 68 行报 `Plugin not found` 并中断(模板第 28 行 include 钩子,早于模板常量与 `!addplugindir`)。
@@ -1,5 +1,12 @@
# 踩坑与排障记录
## 2026-09-29 Game Agent 读工具被项目相对路径规则拦住
- 现象:`agc_read_project_context` 或 `agc_list_project_files` 对绝对路径返回「项目文件路径不能是绝对路径」,对 `..` 返回「项目文件路径非法」。
- 原因:这两条读取入口以前直接调用共享 `normalize_relative_path`。该函数同时服务项目浏览、快照和写入,不能放宽。
- 处理:读取入口改走 `resolve_game_agent_read_path`。绝对路径和离开项目的 `..` 可以读;项目内的 `.agent`、凭据文件名、符号链接和硬链接仍然拒绝。写入、补丁、素材导入和 `read-only` 沙箱不变。
- 关联:`apps/ai-game-creator-shell/src-tauri/src/agent/direct_project_context.rs`。
## 2026-09-29 NSIS 安装钩子被 include 在模板常量与插件目录之前(Jenkins 打包在 makensis 处中断)
- **现象**:`Genarrative-Agc-Windows-Build` 打 dev 渠道 Windows 包时,Rust 编译过了,makensis 却报 `Plugin not found, cannot call nsis_tauri_utils::KillProcess`、`!include: error in script: "...\installer-hooks.nsh" on line 68`、`Error in script "...\installer.nsi" on line 28 -- aborting creation process`,Tauri 最后只补一句 `failed to bundle project 'The system cannot find the file specified. (os error 2)'`,退出码 1。
@@ -205,6 +205,7 @@ UI 编辑器的“分析参考图”步骤、Rust 命令 `suggest_ui_design_sema
- OAuth 在目录捕获与模型进程内产生的轮换结果仅在宿主私有 runtime 中延续,按原始认证来源指纹、路由、项目及稳定账户/用户身份绑定后复制到下一回合的新私有 HOME;不回写用户原始认证文件,不缓存 API Key。来源、路由或身份改变时不继承,迟到的旧实例不得覆盖新回合结果;轮换结果未确认时禁止重用旧 token。
- 实例退役与验收完成使用不同判据:Windows 仍要求完整 Job 退出;Unix 已确认主进程退出且所控进程组为空时可退役并允许下一显式用户回合,但 group-only 证明不能使原会话从 Interrupted 升为 Completed,不能自动重放旧操作。主进程、所属组或退出状态仍未知时继续阻断新实例。
- 补丁完整复用固定版本官方语法解析与执行语义。宿主枚举每个源和目标(包括所有 Move 和重复操作),检查项目边界、受保护路径和链接,在本地短写事务中复核后执行;取消、预算、退出证明和未知结果仍走统一宿主控制。失败可能已有部分修改,不能声称全批回滚或自动原样重放。
- 2026-09-29:`agc_read_project_context` 与 `agc_list_project_files` 可以读取绝对路径,以及用 `..` 离开当前项目的路径。项目内相对路径仍拒绝 `.agent`、凭据文件名、符号链接和硬链接;项目外读取同样拒绝这些受保护名字和链接。`agc_write_file`、`agc_apply_patch`、素材导入和原生补丁仍限定在当前项目。Codex 进程沙箱仍是 `read-only`。提示词未改。
- 模型计划进度保存到同一回合的宿主状态,仅作展示,不等于验收通过;计划更新和长资源调用可以同时推进。真正共享资源的修改仍保持必要顺序。
### 验收