mirror of
https://github.com/usestrix/strix.git
synced 2026-09-14 14:19:09 +08:00
e4548cb28c
* fix(proxy,tooling): serialize+reconnect Caido client, actionable HTTPQL errors, sandbox tool guidance
Addresses the top recurring agent tool-call failures observed in telemetry:
- proxy: the shared Caido client had no locking or reconnect, so concurrent
agent calls raced ("Transport is already connected") and a dead transport
poisoned the rest of the run ("Connector is closed"/"Server disconnected").
Add an asyncio lock + bounded reconnect in caido_api.call_with_client (sandbox
path) and a scan-wide caido_lock in the run context that host-side proxy tools
hold around every call. Deterministic errors are not retried.
- proxy: list_requests now returns Caido's exact parser message, echoes the
offending query, and includes a corrected-syntax hint so agents self-correct
instead of retrying a broken HTTPQL filter.
- shell/prompt: document that write_stdin requires a process started with
tty=true; nudge toward writing Python to a file over deeply-nested one-liners;
note the venv pre-installs common libs.
- agent-browser: distinguish daemon/connection failures (run doctor, don't loop)
from malformed commands; invoke directly (no sh -c wrapper).
- containers: use POSIX '.' instead of the bashism 'source' in generated rc
files (fixes 'sh: source: not found'); add file + xxd and pre-install
requests/httpx/beautifulsoup4/lxml/pyjwt/cryptography in the sandbox venv.
- tests: cover proxy serialization/reconnect/no-retry and HTTPQL errors.
* fix(proxy): host-side reconnect, close stale clients, don't retry mutations
Addresses Greptile review on the reconnect logic:
- Host path had no reconnect: a dead shared context client (Caido restart /
network blip) previously disabled proxy tools for the rest of the scan. Add
SharedCaidoClient, a serialized reconnect-safe holder stored once per scan in
the run context and shared across agents. On a dead transport it rebuilds via
reconnect_caido, which re-selects the SAME Caido project (preserving captured
traffic) instead of creating a new empty one.
- Don't repeat completed mutations: call_with_client / SharedCaidoClient.call
take idempotent=. Reads retry once on reconnect; replay + scope
create/update/delete heal the client but re-raise instead of risking a
double-apply.
- Don't leak replaced clients: the stale client is aclose()d (best-effort) on
every reconnect.
- Extend tests to cover close-on-reconnect, non-idempotent re-raise, and the
SharedCaidoClient holder.
* fix(proxy): close replacement Caido client when project.select fails
Addresses Greptile P1: in reconnect_caido (and bootstrap_caido) a successful
connect() followed by a failing project.select()/create() discarded the
connected client without closing it, so a missing/unavailable project could
leak a transport on every retry. Close the client before re-raising.
---------
Co-authored-by: Alex Schapiro <bearsyankees@gmail.com>
33 lines
1.5 KiB
Markdown
33 lines
1.5 KiB
Markdown
# shell — `exec_command` + `write_stdin`
|
|
|
|
SDK-provided shell tools wired per-run from the sandbox session. Every CLI
|
|
invocation the agent makes (nmap, ffuf, agent-browser, python3, …) goes
|
|
through `exec_command`. `write_stdin` streams input to a still-running
|
|
process started by an earlier `exec_command` (for interactive prompts).
|
|
|
|
## `write_stdin` requires a TTY-backed process
|
|
|
|
`exec_command` runs each command in a fresh **non-interactive** shell (plain
|
|
pipes, no TTY) by default. `write_stdin` only works against a process that is
|
|
still running **and** was started with a PTY. The canonical sequence is:
|
|
|
|
```text
|
|
exec_command(cmd="python3", tty=true) # start a PTY-backed process
|
|
write_stdin(session_id=<id>, chars="print(1)\n")
|
|
```
|
|
|
|
Calling `write_stdin` on a command started with the default `tty=false`, or on
|
|
a process that has already exited, fails with
|
|
`stdin is not available for this process. Start the command with 'tty=true' in
|
|
'exec_command' before using 'write_stdin'.` Use `tty=true` for REPLs,
|
|
`ssh`/`nc`/`ftp`, `msfconsole`, or to deliver a Ctrl-C to a long-running job.
|
|
|
|
- **Implementation:** `agents.sandbox.capabilities.tools.shell_tool.ShellTool`
|
|
(in the upstream `agents` SDK)
|
|
- **Wired in:** `strix/agents/factory.py` — added per-run via the SDK
|
|
`Shell` capability; `write_stdin` is wrapped to drop the SDK's `pid`
|
|
arg from the function schema.
|
|
- **Sandbox env:** `http_proxy` / `https_proxy` route every shell child
|
|
through Caido; `AGENT_BROWSER_*`, `REQUESTS_CA_BUNDLE` etc. come from
|
|
`containers/Dockerfile`.
|