From b93617feaf7a9337a4f68610a5a6ad8b24f01621 Mon Sep 17 00:00:00 2001 From: ymq Date: Sat, 5 Sep 2026 15:27:00 +0800 Subject: [PATCH] =?UTF-8?q?fix(isolation):=20=E7=AC=AC7=E5=B1=82=E6=B3=84?= =?UTF-8?q?=E6=BC=8F=E2=80=94=E2=80=94=E9=80=9A=E7=94=A8=E4=BC=9A=E8=AF=9D?= =?UTF-8?q?=E5=8E=86=E5=8F=B2=E5=9B=9E=E6=94=BE=E4=B8=8D=E8=BF=87=E6=BB=A4?= =?UTF-8?q?=E4=BA=A7=E7=BA=BF=EF=BC=8C=E8=B7=A8=E4=BA=A7=E7=BA=BF=E5=AF=B9?= =?UTF-8?q?=E8=AF=9D=E8=BF=9B=E4=B8=8A=E4=B8=8B=E6=96=87?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit 实测:工具/文件系统隔离生效后,通用助手仍复述出产线项目ID。 根因:_load_history 无 session_id 分支按 created_by 全量回放该用户 所有产线的最近对话(项目名称/ID 随历史泄漏)。 修复:通用会话只回放 pipeline_id='' 的历史(存库时 store_pl='' 与 此过滤对称);有 session_id 的分支同样加通用会话空产线过滤。 --- pipeline_service/agent_loop_v2.py | 17 ++++++++++++++++- 1 file changed, 16 insertions(+), 1 deletion(-) diff --git a/pipeline_service/agent_loop_v2.py b/pipeline_service/agent_loop_v2.py index 09a7d44..e1b3f4c 100644 --- a/pipeline_service/agent_loop_v2.py +++ b/pipeline_service/agent_loop_v2.py @@ -1531,11 +1531,16 @@ class AgentExecutor: # 产线隔离(2026-08-31 修复跨产线串扰):各产线页面默认 tab 共用 # session_id='default',历史若不按产线过滤,投标页会加载开发页的 # 对话(如"元景项目/新建demo项目"),LLM 跟着最后上下文答错产线。 + # 2026-09-05 第7层泄漏修复:通用会话(存库时 pipeline_id='')只回放 + # 自己的历史,否则会加载该用户各产线的最近对话——项目名称/ID + # 等产线信息随历史泄漏进通用助手。 sql = ("SELECT role, content FROM pipeline_conversations " "WHERE session_id=${sid}$ AND created_by=${uid}$ ") params = {"sid": self.session_id, "uid": self.user_id or "", "lim": self.config.history_limit} - if self.pipeline_id and not self.generic: + if self.generic: + sql += "AND (pipeline_id='' OR pipeline_id IS NULL) " + elif self.pipeline_id: sql += "AND pipeline_id=${pl}$ " params["pl"] = self.pipeline_id sql += "ORDER BY created_at DESC LIMIT ${lim}$" @@ -1550,6 +1555,16 @@ class AgentExecutor: "ORDER BY created_at DESC LIMIT ${lim}$", {"pid": pid, "uid": self.user_id or "", "lim": self.config.history_limit}, ) + elif self.generic: + # 2026-09-05 第7层泄漏修复:通用会话只回放自己的历史 + # (存库时 generic 会话 pipeline_id=''),禁止按 user_id 全量 + # 回放——否则用户各产线最近对话(含项目名称/ID)全部泄漏。 + recs = await sor.sqlExe( + "SELECT role, content FROM pipeline_conversations " + "WHERE created_by=${uid}$ AND (pipeline_id='' OR pipeline_id IS NULL) " + "ORDER BY created_at DESC LIMIT ${lim}$", + {"uid": self.user_id or "", "lim": self.config.history_limit}, + ) else: recs = await sor.sqlExe( "SELECT role, content FROM pipeline_conversations "