Commit 9322ba8
authored
Surface DIFC-filtered items in tool responses to prevent targeted dispatch drift (#2175)
## Summary
Fixes the core gateway-side issue described in gh-aw#21784.
When DIFC integrity policy removes items from a tool response (e.g.
`list_issues`) in filter/propagate mode, the agent previously received
only the accessible items with **no indication that filtering
occurred**. An empty result looked identical to a genuine "no items"
response, causing targeted-dispatch workflows to silently fall back to
scheduled/backlog-scan mode.
## Root cause
In `callBackendTool` (Phase 5 of the DIFC reference-monitor pipeline),
after `FilterCollection` removes low-integrity items, `ToResult()`
returns only the accessible items as a plain array. The
`FilteredCollectionLabeledData` struct tracked filtered details
internally (for audit logging) but never exposed them to the caller.
## Fix
After converting the filtered result to an SDK `CallToolResult`, append
an additional `TextContent` block if any items were removed:
```
[DIFC] 1 item(s) in this response were removed by integrity policy and are not shown: issue:org/repo#14 (integrity too low for agent context).
```
For up to 5 filtered items the notice includes per-item description +
reason. For larger sets only the count is reported.
This applies only in filter/propagate enforcement modes. Strict mode
already returns an explicit error blocking the entire response.
## Changes
| File | Change |
|---|---|
| `internal/server/difc_log.go` | `buildDIFCFilteredNotice` helper +
`maxFilteredItemsInNotice` constant |
| `internal/server/unified.go` | Track `difcFiltered` in
`callBackendTool`; append notice after `ConvertToCallToolResult` |
| `internal/server/difc_log_test.go` | 6 new unit tests: nil input,
empty, single item, within limit, exceeds limit, no description |
## Testing
- All existing unit and integration tests pass (`make agent-finished`)
- 6 new tests for `buildDIFCFilteredNotice`
- CodeQL: 0 alerts
## Security Summary
No new security vulnerabilities introduced. The notice text contains
only the count of filtered items and their already-logged resource
descriptions and denial reasons — no data from the filtered items'
payload is exposed.3 files changed
Lines changed: 169 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
3 | 3 | | |
4 | 4 | | |
5 | 5 | | |
| 6 | + | |
6 | 7 | | |
7 | 8 | | |
8 | 9 | | |
| |||
93 | 94 | | |
94 | 95 | | |
95 | 96 | | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
| 130 | + | |
| 131 | + | |
| 132 | + | |
| 133 | + | |
| 134 | + | |
| 135 | + | |
| 136 | + | |
| 137 | + | |
| 138 | + | |
| 139 | + | |
| 140 | + | |
| 141 | + | |
| 142 | + | |
| 143 | + | |
| 144 | + | |
| 145 | + | |
| 146 | + | |
| 147 | + | |
| 148 | + | |
| 149 | + | |
| 150 | + | |
| 151 | + | |
| 152 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
2 | 2 | | |
3 | 3 | | |
4 | 4 | | |
| 5 | + | |
5 | 6 | | |
6 | 7 | | |
7 | 8 | | |
| |||
274 | 275 | | |
275 | 276 | | |
276 | 277 | | |
| 278 | + | |
| 279 | + | |
| 280 | + | |
| 281 | + | |
| 282 | + | |
| 283 | + | |
| 284 | + | |
| 285 | + | |
| 286 | + | |
| 287 | + | |
| 288 | + | |
| 289 | + | |
| 290 | + | |
| 291 | + | |
| 292 | + | |
| 293 | + | |
| 294 | + | |
| 295 | + | |
| 296 | + | |
| 297 | + | |
| 298 | + | |
| 299 | + | |
| 300 | + | |
| 301 | + | |
| 302 | + | |
| 303 | + | |
| 304 | + | |
| 305 | + | |
| 306 | + | |
| 307 | + | |
| 308 | + | |
| 309 | + | |
| 310 | + | |
| 311 | + | |
| 312 | + | |
| 313 | + | |
| 314 | + | |
| 315 | + | |
| 316 | + | |
| 317 | + | |
| 318 | + | |
| 319 | + | |
| 320 | + | |
| 321 | + | |
| 322 | + | |
| 323 | + | |
| 324 | + | |
| 325 | + | |
| 326 | + | |
| 327 | + | |
| 328 | + | |
| 329 | + | |
| 330 | + | |
| 331 | + | |
| 332 | + | |
| 333 | + | |
| 334 | + | |
| 335 | + | |
| 336 | + | |
| 337 | + | |
| 338 | + | |
| 339 | + | |
| 340 | + | |
| 341 | + | |
| 342 | + | |
| 343 | + | |
| 344 | + | |
| 345 | + | |
| 346 | + | |
| 347 | + | |
| 348 | + | |
| 349 | + | |
| 350 | + | |
| 351 | + | |
| 352 | + | |
| 353 | + | |
| 354 | + | |
| 355 | + | |
| 356 | + | |
| 357 | + | |
| 358 | + | |
| 359 | + | |
| 360 | + | |
| 361 | + | |
| 362 | + | |
| 363 | + | |
| 364 | + | |
| 365 | + | |
| 366 | + | |
| 367 | + | |
| 368 | + | |
| 369 | + | |
| 370 | + | |
| 371 | + | |
| 372 | + | |
| 373 | + | |
| 374 | + | |
| 375 | + | |
| 376 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
958 | 958 | | |
959 | 959 | | |
960 | 960 | | |
| 961 | + | |
961 | 962 | | |
962 | 963 | | |
963 | 964 | | |
| |||
986 | 987 | | |
987 | 988 | | |
988 | 989 | | |
| 990 | + | |
989 | 991 | | |
990 | 992 | | |
991 | 993 | | |
| |||
1028 | 1030 | | |
1029 | 1031 | | |
1030 | 1032 | | |
| 1033 | + | |
| 1034 | + | |
| 1035 | + | |
| 1036 | + | |
| 1037 | + | |
| 1038 | + | |
| 1039 | + | |
| 1040 | + | |
| 1041 | + | |
| 1042 | + | |
1031 | 1043 | | |
1032 | 1044 | | |
1033 | 1045 | | |
| |||
0 commit comments