文件和行号
- internal/agent/constraint_violation.go:123-146 (recordReasoning)
- internal/agent/constraint_violation.go:150-191 (checkToolCall)
- internal/agent/constraint_violation.go:220-225 (cvCheckViolation case "scope")
问题描述
scope 类型约束只增不减、互相不感知:recordReasoning 仅按 pattern+type 去重,无淘汰/取代机制;checkToolCall 对每个 scope 约束独立判定"路径不匹配即违规",多个 scope 约束隐式构成全局 AND。
触发场景(复核 subagent 已实测复现)
iter 1: "I'll only modify files in the auth/ directory." → 约束 A (scope: auth/)
iter 5: "I'll limit changes to the docs/ folder." → 约束 B (scope: docs/)
iter 6: edit_file auth/handler.go → 完全符合约束 A
实际输出:"edit_file targets 'auth/handler.go', which is outside the 'docs/' scope you declared"——误报。第二次合法 auth 编辑再次报警,烧光 cvMaxWarnings=2 全部配额;之后真正的越界编辑(如 cmd/main.go)反而静默。
预期行为 vs 实际行为
- 预期:scope 声明是任务局部承诺,后声明应取代先声明(avoid 约束天然可叠加、应维持不变)
- 实际:两个不同 scope 声明后,任何编辑必然违反其中之一(除非路径同时匹配两个目录),detector 退化为纯噪音源:误导性 guidance 指向错误方向("narrow the tool target")+ 配额耗尽使真违规失去检测
修复建议
新 scope 声明取代同类型旧约束(保留最新 1~2 个 scope);avoid 约束保持叠加。wiring 参考:agent.go:2407 (recordReasoning)、:3831 (checkToolCall)、:1750 (仅用户输入时 reset)、guidance_compact_reset.go:397(compaction 只清 warnings 不清约束)。
严重程度
medium(advisory 非阻塞、每轮 reset、提取需 path-like token 门槛较高;但一旦触发系统性烧光配额并误导 agent,检测价值被完全抵消)
(初审 + 独立复核 subagent 双重确认,复核以临时测试实测复现两次误报 + 配额烧尽)
文件和行号
问题描述
scope 类型约束只增不减、互相不感知:recordReasoning 仅按 pattern+type 去重,无淘汰/取代机制;checkToolCall 对每个 scope 约束独立判定"路径不匹配即违规",多个 scope 约束隐式构成全局 AND。
触发场景(复核 subagent 已实测复现)
实际输出:"edit_file targets 'auth/handler.go', which is outside the 'docs/' scope you declared"——误报。第二次合法 auth 编辑再次报警,烧光 cvMaxWarnings=2 全部配额;之后真正的越界编辑(如 cmd/main.go)反而静默。
预期行为 vs 实际行为
修复建议
新 scope 声明取代同类型旧约束(保留最新 1~2 个 scope);avoid 约束保持叠加。wiring 参考:agent.go:2407 (recordReasoning)、:3831 (checkToolCall)、:1750 (仅用户输入时 reset)、guidance_compact_reset.go:397(compaction 只清 warnings 不清约束)。
严重程度
medium(advisory 非阻塞、每轮 reset、提取需 path-like token 门槛较高;但一旦触发系统性烧光配额并误导 agent,检测价值被完全抵消)
(初审 + 独立复核 subagent 双重确认,复核以临时测试实测复现两次误报 + 配额烧尽)