Commit 7757d87
* feat(core): register Workflow tool name (P1)
* feat(core): isWorkflowsEnabled config gate with env-var override (P1)
* feat(core): stripExportMeta helper for workflow sandbox (P1)
* feat(core): createWorkflowSandbox with determinism stubs (P1)
* test(core): cover workflow sandbox phase/log/agent primitives (P1)
* feat(core): WorkflowOrchestrator with injectable dispatch (P1)
* feat(core): WorkflowOrchestrator production dispatch via AgentHeadless (P1)
* feat(core): WorkflowTool wraps WorkflowOrchestrator (P1)
* feat(core): register WorkflowTool behind isWorkflowsEnabled gate (P1)
* feat(core): export WorkflowTool from package index (P1)
* fix(core): harden workflow sandbox + tighten agent() opts surface (P1)
SEC-C1: deep-null-proto + hardenClosure blocks args/closure realm-escape PoC.
SEC-C2: vm 30s timeout kills sync infinite loops.
UP-C1: agent() throws on unsupported opts (schema/isolation/model/agentType).
UP-I1: keep verbatim subagent system prompt comment.
ARCH-C1: thread AbortSignal into buildProductionDispatch → subagent.execute().
UP-C2: llmContent carries script result verbatim; metadata moves to returnDisplay.
SEC-I1: add WORKFLOW to EXCLUDED_TOOLS_FOR_SUBAGENTS to prevent recursive fan-out.
SEC-I2: cap logs[] at 10 000 lines with a truncation marker.
REUSE-I1: use ToolErrorType.EXECUTION_FAILED in workflow error returns.
TST: add security PoC tests, unique-runId, dispatch-rejection, llmContent-unwrap.
TST-I1: remove setter/getter tautology test from config.workflows.test.ts.
* refactor(core): decouple WorkflowOrchestrator from Config (P1)
- Extract WORKFLOW_SUBAGENT_SYSTEM_PROMPT into workflow-prompts.ts
- Lift buildProductionDispatch() into exported createProductionDispatch(config, signal?)
- WorkflowOrchestrator constructor now takes dispatch directly: (dispatch: WorkflowAgentDispatch)
- Remove WorkflowOrchestratorOptions interface
- WorkflowToolOptions.orchestratorOverrides replaced by WorkflowToolOptions.dispatch
- WorkflowToolInvocation.execute() calls createProductionDispatch() when no override is set
- Tests updated: orchestrator tests inject dispatch directly; production-dispatch tests moved to createProductionDispatch describe block
* fix(core): Math proxy hardening, subagent prompt verbatim, Date.now throw, phases cap, test fidelity (P1)
* fix(core): construct Math+Date in vm realm, sever proto chains on injected closures (P1)
* fix(core): sever Array.prototype on args, cap deep-null-proto recursion, consolidate WorkflowAgentResult (P1)
* fix(core): stub parallel/pipeline/workflow/budget globals with P1-unsupported errors
* fix(core): harden budget inner functions, regression-test anti-recursion + args threading
* fix(core): P2/P5 forward-compat injection seams + document error.stack limitation (P1)
* fix(core): vm-realm wrap async sandbox globals + stripExportMeta hardening (PR #4732 R1)
Closes T1/T8/T14: thrown Errors and async-function Promises used to leak the
host Function constructor through their prototype chains. PoC:
agent('x').constructor.constructor('return process')()
try { throw } catch(e) { e.constructor.constructor('return process')() }
Build every async/sync global (agent, parallel, pipeline, workflow, budget,
console, phase, log, args) inside the vm-realm via the existing init
script. Host only exposes a primitive bridge that the init script reads
once and deletes from globalThis. Both rejection and resolution paths
cross the boundary as vm-realm values.
Closes T2: deepNullProto used to setPrototypeOf(null) on array args,
breaking for-of / .map / .filter / spread / destructuring. Replaced with
vm-realm JSON.parse of an args string — arrays retain vm-realm
Array.prototype methods.
Closes T13: runtime allowlist on agent() opts catches typos like 'scema'.
Closes T9/T16/T17: stripExportMeta now recognises //, /* */, and regex
literals; throws on unbalanced braces instead of silently returning ''.
Closes T6: validateArgs rejects functions, BigInt, circular refs, and
over-deep nesting (previously functions silently disappeared).
Closes T5: regression test for console.log/warn/error → getLogs routing.
* fix(core): change WorkflowTool export to type-only (PR #4732 R1 T3)
Production callers use Config.createToolRegistry's registerLazy path which
dynamic-imports './tools/workflow/workflow.js'. The barrel export at index.ts
previously forced eager evaluation of the workflow.js → workflow-orchestrator
→ workflow-sandbox → node:vm module chain for every consumer of
@qwen-code/core, even when workflows are disabled.
Sibling tool exports (AgentTool, SkillTool) are type-only; align WorkflowTool
with the same pattern. SDK consumers can still annotate types; instantiation
happens through the registry, not the barrel.
* fix(core): subagent terminateMode + bounded runConfig + disallowedTools + failure context + defensive serialization (PR #4732 R1)
Closes T10: runReasoningLoop returns terminateMode = CANCELLED|MAX_TURNS|
TIMEOUT|ERROR rather than throwing. Without checking it, await agent(...)
resolved to '' on user cancel and the workflow kept looping. Now check
getTerminateMode() after execute() and throw on non-GOAL — mirrors
AgentTool's existing handling.
Closes T11: workflow subagents previously ran with runConfig: {} (no
max_turns / max_time_minutes guard) and tools: ['*'] without
disallowedTools. A single agent() could loop the model indefinitely. Bound
to 50 turns / 10 minutes; add disallowedTools: [SEND_MESSAGE, EXIT_PLAN_MODE]
to mirror upstream Tg8 — defense in depth with the §XmO system prompt.
Closes T19: phases / logs accumulated before a script failure used to be
discarded with the sandbox instance. WorkflowExecutionError carries them
through the rejection so the user-visible display can show what ran.
Closes T12 / T18: defensive serialization. A successful workflow returning
a BigInt or circular value used to be reported as 'Workflow failed:
Converting circular structure to JSON' because JSON.stringify was inside
the try block. safeStringifyResult / safeStringifyDisplayPayload degrade
to a clear placeholder so a serialization issue doesn't masquerade as a
run failure.
Closes T4: regression test for ToolErrorType.EXECUTION_FAILED assertion.
Closes T7: vi as vitest alias removed (now matches every other test file).
* chore(core): add missing @license headers + remove stale config-session-env reference (PR #4732 R1)
Closes T20: 6 of 9 new workflow files were missing the standard @license
Apache-2.0 header. Add Qwen-style header (matches sibling tools/agent/agent.ts
and others) to: workflow-sandbox.ts, workflow-sandbox.test.ts,
workflow-orchestrator.ts, workflow-orchestrator.test.ts,
workflow-prompts.ts, workflow.test.ts.
Closes T21: config.workflows.test.ts and config.workflow-registration.test.ts
both contained 'mirrors config-session-env.test.ts' in a setup comment, but
that file does not exist in the repo. Drop the dangling reference.
* chore(core): clean up stray rebase conflict marker (PR #4732)
* fix(core): sever sandboxGlobals proto + add async wall-clock timeout (PR #4732 R2)
Closes T22: sandboxGlobals was a plain host-realm Object literal. Its
prototype chain reached host Object → host Function → host process,
bypassing every per-global hardening measure. PoC confirmed leak via
`globalThis.constructor.constructor('return process')()` returning
host process before fix. Fix: Object.setPrototypeOf(null) on both
sandboxGlobals and the bridge object before vm.createContext.
Regression tests cover both globalThis.constructor and implicit-this
escape paths.
Closes T23: vm.runInContext timeout only covers synchronous execution.
Once the async IIFE yields its first await, the watchdog disarms and
`return new Promise(() => {})` hangs forever. Fix: wrap in
Promise.race with a wall-clock timeout (default 30 minutes, configurable
via SandboxOptions.maxWallClockMs or QWEN_CODE_MAX_WORKFLOW_SECONDS env
var). This is a permanent defense-in-depth — not P1-only: P2/P3/P5
all add resource caps measured in agent-calls or tokens, but a
0-token / 0-agent hang requires a wall-clock cap.
Documented limitation: an in-script async microtask loop continues
consuming microtasks after the outer wall-clock rejects (node:vm
provides no way to halt async execution). In production the workflow
surface returns the timeout error and the vm context becomes
unreferenced; the leaked microtask loop is a host-process concern
that requires worker_threads-level isolation (out of P1 scope).
* fix(core): pre-sanitize non-serializable result before display payload (PR #4732 R3)
Sibling drift of the R1 T12/T18 fix. safeStringifyResult already degrades
per-field when the script's `result` is a BigInt / circular value, so
llmContent survives. But the success-path display payload wraps
{runId, phases, logs, result} in a single JSON.stringify — one bad
`result` collapsed the whole display to the generic
"(display payload not JSON-serializable)" string and the user lost the
runId (needed for log correlation), the accumulated phases, AND the
logs. Pre-sanitize `result` only; runId / phases / logs are always
serializable.
Add regression test that scripts a circular `result` with a `phase()`
in front: assertions check runId, the phase, and the non-JSON-serializable
placeholder all appear in returnDisplay, and that the atomic-failure
fallback string does NOT appear.
RED at 10:56:23 → fix → GREEN at 10:56:48. 14/14 workflow.test, 109/109
across the workflow test suite, typecheck silent.
* refactor(core): push display-payload per-field fallback into the helper (PR #4732)
Post-R3 /simplify pass. The R3 fix special-cased `result` at the call
site by pre-probing JSON.stringify and substituting a placeholder. Four
review angles (reuse / simplification / efficiency / altitude) all
converged on the same root cause: per-field degradation belongs in
`safeStringifyDisplayPayload`, not duplicated at every caller.
- Altitude: the bug ("all-or-nothing stringify is too coarse") names a
property of the helper; the fix now lives in the helper. Any new
payload field that becomes non-serializable in a future round
(`metrics: bigint`, etc.) is handled without a fresh call-site patch.
- Reuse: the third try/JSON.stringify probe in this file is gone;
the helper owns the probe.
- Simplification: call site reverts to the pre-R3 clean shape.
- Efficiency: success path is back to one stringify per payload.
Helper behavior:
happy path → 1 stringify (unchanged)
one field fails → walk top-level keys, probe each, replace failing
value with `(non-JSON-serializable value of type X)`,
re-stringify; total 2 stringifies of payload + N
field probes. Fall through to the original generic
fallback if the sanitized re-stringify also fails.
R3 regression test (`execute() preserves runId/phases/logs in
returnDisplay when result is non-JSON-serializable`) passes unchanged
— it tests observable behavior, not the implementation site. 109/109
across the workflow suite, typecheck silent.
* fix(core): honest description + meta-strip anchor + wall-clock cancellation + stray gitignore (PR #4732 R4)
Four fixes from R4 review:
T32 (workflow.ts tool description) — P1 description claimed "sequential
only" but `Promise.all([agent(), agent()])` bypasses the claim because
the vm cannot intercept JS built-ins. Rewrite the description to be
honest: P1 ships sequential primitives only (no parallel/pipeline);
Promise.all spawns concurrent subagents that share Config and may race
on file edits. Matches upstream Claude Code behavior — they also expose
Promise.all without enforcement.
T33 (workflow-sandbox.ts stripExportMeta) — drop the `/m` flag on the
anchor regex. With `/m`, a template literal containing
`\nexport const meta = {\n` triggered a false match, and the brace
walker ripped content out of the string body, silently corrupting the
script. Per design intent ("required first statement of every script")
meta must be file-start; anchoring there closes the corruption surface.
Adds two RED-confirmed regression tests (template literal + leading
code) and a sanity test for leading whitespace.
T35 (packages/core/.gitignore) — removed. The `.qwen/computer-use/`
entry was stray scope pollution committed accidentally in R1's license-
header cleanup (`d118c55f8`) and unrelated to the Workflow P1 surface.
T40 (sandbox.ts + orchestrator.ts + workflow.ts) — completes the R2
wall-clock defense. When the timer fires the sandbox now `abort()`s a
caller-supplied AbortController BEFORE rejecting; the controller's
signal is also threaded into `createProductionDispatch`, so in-flight
subagent.execute() calls see the cancellation and stop burning tokens.
Without this, R2's "30 min wall-clock" still let subagents run for up
to their internal `max_time_minutes: 10` after the user-side timed out.
WorkflowTool.execute now derives `dispatchController`, forwards caller
signal abort to it, passes its signal to dispatch and the controller
itself to `orchestrator.run({abortOnTimeout})`. A `finally` block
aborts the controller on natural completion (cancel any straggler
subagent) and detaches the caller-signal listener to avoid leaks.
Adds two sandbox unit tests (RED-confirmed): controller IS aborted on
timeout, controller is NOT aborted on normal completion.
114/114 workflow suite tests pass, typecheck silent.
* refactor(core): use createChildAbortController for T40 dispatch-signal bridge (PR #4732)
Post-R4 /simplify pass. Four review angles converged on one finding:
the T40 manual AbortController-bridging at the call site re-implements
`createChildAbortController` from `packages/core/src/utils/abortController.ts:61`,
which is already the project-idiomatic helper for this exact pattern
(used at agent-headless.ts:231, agent-interactive.ts:157, agent-core.ts:603 & 952).
The replacement collapses 5 lines of imperative listener wiring at
`workflow.ts:execute()` head + 1 line of finally cleanup into a single
`createChildAbortController(signal)` call, plus inherits the helper's
hardenings:
- WeakRef on the parent (so a long-lived caller signal doesn't pin the
child controller)
- Auto-removal of the parent listener when the child fires (covers
both the wall-clock-fire path and the natural-completion path)
- Default 50-listener cap via `setMaxListeners`
No behavior change at the API boundary — the wall-clock `abortOnTimeout`
contract and the test assertions for T40's two cases (controller IS
aborted on wall-clock; controller is NOT aborted on normal completion)
all still hold. The /simplify "altitude" finding (push the bridging
into the orchestrator) is deferred — that would change WorkflowOrchestrator's
constructor/run signature and is outside this PR's scope.
Also trims a redundant inline comment at workflow-orchestrator.ts:172
(the `abortOnTimeout: req.abortOnTimeout` line; the field's type
comment at line 71-81 already explains the contract).
114/114 workflow suite tests pass, typecheck silent.
* chore(core): compress over-weight T40 comments after createChildAbortController refactor (PR #4732)
The previous commit moved the bridging logic into the helper, so the
inline comments restating the helper's contract (parent forwarding,
already-aborted fast path, WeakRef, auto-removal) became redundant —
that's the helper's job to document.
Compress to the load-bearing semantics: the child controller sees
both caller-driven and wall-clock-driven aborts, and `finally` cancels
stragglers on normal completion. No code change.
* chore(core): align copyright header to Qwen on 2 PR-new test files (PR #4732 R7 F4)
Both files were derived from a template (the stale `config-session-env.test.ts`
reference cleaned up in R1 T21) and retained the upstream `Copyright 2025
Google LLC` header. The other six new workflow source/test files in this
PR carry `Copyright 2025 Qwen`. Align for same-PR consistency.
Per DragonnZhang R7 F4. No behavior change; header text only.
---------
Co-authored-by: tanzhenxin <tanzhenxing1987@gmail.com>
1 parent cc141ff commit 7757d87
13 files changed
Lines changed: 3112 additions & 0 deletions
File tree
- packages/core/src
- agents/runtime
- config
- tools
- workflow
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
100 | 100 | | |
101 | 101 | | |
102 | 102 | | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
103 | 107 | | |
104 | 108 | | |
105 | 109 | | |
| |||
Lines changed: 294 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
| 130 | + | |
| 131 | + | |
| 132 | + | |
| 133 | + | |
| 134 | + | |
| 135 | + | |
| 136 | + | |
| 137 | + | |
| 138 | + | |
| 139 | + | |
| 140 | + | |
| 141 | + | |
| 142 | + | |
| 143 | + | |
| 144 | + | |
| 145 | + | |
| 146 | + | |
| 147 | + | |
| 148 | + | |
| 149 | + | |
| 150 | + | |
| 151 | + | |
| 152 | + | |
| 153 | + | |
| 154 | + | |
| 155 | + | |
| 156 | + | |
| 157 | + | |
| 158 | + | |
| 159 | + | |
| 160 | + | |
| 161 | + | |
| 162 | + | |
| 163 | + | |
| 164 | + | |
| 165 | + | |
| 166 | + | |
| 167 | + | |
| 168 | + | |
| 169 | + | |
| 170 | + | |
| 171 | + | |
| 172 | + | |
| 173 | + | |
| 174 | + | |
| 175 | + | |
| 176 | + | |
| 177 | + | |
| 178 | + | |
| 179 | + | |
| 180 | + | |
| 181 | + | |
| 182 | + | |
| 183 | + | |
| 184 | + | |
| 185 | + | |
| 186 | + | |
| 187 | + | |
| 188 | + | |
| 189 | + | |
| 190 | + | |
| 191 | + | |
| 192 | + | |
| 193 | + | |
| 194 | + | |
| 195 | + | |
| 196 | + | |
| 197 | + | |
| 198 | + | |
| 199 | + | |
| 200 | + | |
| 201 | + | |
| 202 | + | |
| 203 | + | |
| 204 | + | |
| 205 | + | |
| 206 | + | |
| 207 | + | |
| 208 | + | |
| 209 | + | |
| 210 | + | |
| 211 | + | |
| 212 | + | |
| 213 | + | |
| 214 | + | |
| 215 | + | |
| 216 | + | |
| 217 | + | |
| 218 | + | |
| 219 | + | |
| 220 | + | |
| 221 | + | |
| 222 | + | |
| 223 | + | |
| 224 | + | |
| 225 | + | |
| 226 | + | |
| 227 | + | |
| 228 | + | |
| 229 | + | |
| 230 | + | |
| 231 | + | |
| 232 | + | |
| 233 | + | |
| 234 | + | |
| 235 | + | |
| 236 | + | |
| 237 | + | |
| 238 | + | |
| 239 | + | |
| 240 | + | |
| 241 | + | |
| 242 | + | |
| 243 | + | |
| 244 | + | |
| 245 | + | |
| 246 | + | |
| 247 | + | |
| 248 | + | |
| 249 | + | |
| 250 | + | |
| 251 | + | |
| 252 | + | |
| 253 | + | |
| 254 | + | |
| 255 | + | |
| 256 | + | |
| 257 | + | |
| 258 | + | |
| 259 | + | |
| 260 | + | |
| 261 | + | |
| 262 | + | |
| 263 | + | |
| 264 | + | |
| 265 | + | |
| 266 | + | |
| 267 | + | |
| 268 | + | |
| 269 | + | |
| 270 | + | |
| 271 | + | |
| 272 | + | |
| 273 | + | |
| 274 | + | |
| 275 | + | |
| 276 | + | |
| 277 | + | |
| 278 | + | |
| 279 | + | |
| 280 | + | |
| 281 | + | |
| 282 | + | |
| 283 | + | |
| 284 | + | |
| 285 | + | |
| 286 | + | |
| 287 | + | |
| 288 | + | |
| 289 | + | |
| 290 | + | |
| 291 | + | |
| 292 | + | |
| 293 | + | |
| 294 | + | |
0 commit comments