Files
microsoft--agent-framework/python/packages/tools/tests/test_docker_shell_tool.py
T
Eduard van Valkenburg 6e95517659 Python: Split type checkers by target (pyright source, 5 checkers on tests/samples) (#6443)
* Python: Split type checkers by target (pyright source, 5 checkers on tests/samples)

Rework the typing setup along the lines of the 'too many type checkers'
approach:

- Pyright (strict) is now the sole source-code type checker; mypy is
  removed from source and its [tool.mypy] block becomes a relaxed profile
  used only for tests/samples.
- Tests are checked by all five checkers (pyright relaxed, mypy, pyrefly,
  ty, zuban); samples by pyright, pyrefly, and ty. All run in a relaxed/
  basic profile so authors aren't forced into over-annotation.
- Add pyrightconfig.tests.json and bump sample pyright configs to basic.
- Unify test/sample typing onto the same parallel fan-out used by source
  pyright via run_command_items in task_runner.py.
- Make version-conditional imports symmetric: keep or drop the
  '# type: ignore' on both branches so results match across interpreter
  versions (local vs CI).
- Update SKILL.md, DEV_SETUP.md, and CODING_STANDARD.md for the five
  gating checkers and pyright on source+tests+samples.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Python: Fix merge regressions from main (typing + runtime)

Merging main into the type-checker split branch surfaced regressions that
the new five-checker test suite and unit tests caught:

Runtime fixes:
- anthropic: restore the dropped `cache_read_input_token_count` mapping in
  _parse_usage_from_anthropic (lost during merge conflict resolution).
- gemini: _get_function_calling_mode test helper returned str(enum)
  ('FunctionCallingConfigMode.AUTO') instead of the enum value ('AUTO').
- openai: _response_id_from_token test helper was an infinite self-recursion;
  return token['response_id'].
- orchestrations: reset output_events per approval iteration so the terminal
  output assertion counts only the final run.
- core: drop a stale duplicate harness test whose message ('non-negative')
  contradicted the source ('positive').
- purview: import PolicyLocation/PolicyScope/ProtectionScopeActivities/
  ExecutionMode used by the processor tests.

Type-checker fixes (tests, relaxed profile):
- core: pyright/mypy/pyrefly/ty/zuban green-ups across the harness, MCP,
  observability and types tests.
- anthropic/openai: route provider-namespaced UsageDetails keys through a
  dict cast (extra_items TypedDict unsupported by mypy/ty).
- purview: typed model constructors and cache-mock casts.
- ag-ui: annotate WorkflowContext[Any, Any] so yield_output accepts test
  payloads, guard Optional forwarded_props, and ty-ignore intentional bad args.

Source pyright (sole source checker) flagged unnecessary ignores newly
introduced by merged code in core _tools.py and declarative _declarative_base.py.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Python: Isolate per-package mypy cache in test-typing fan-out

The parallel test-typing fan-out runs many mypy processes concurrently,
all defaulting to a single shared ./.mypy_cache. Concurrent writes corrupt
the cache and mypy aborts with INTERNAL ERROR (intermittently, depending on
worker timing) -- which is why CI's Test Typing job failed on a shifting set
of packages while a single-package run was fine.

Give each mypy invocation an isolated cache dir keyed by its target paths so
incremental caching still works per package without races. Other checkers
(zuban/pyrefly/ty/pyright) maintain their own caches and are unaffected.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Python: Make lab pyright-only on source (drop source mypy)

Lab was the last package still running mypy on its source code, requiring
mypy-only `# type: ignore` comments that pyright (the sole source checker
everywhere else) flags as unnecessary. Align lab with the rest of the
monorepo:

- Remove the lab source mypy poe tasks (mypy-gaia/lightning/tau2) and the
  now-dead strict [tool.mypy] config block.
- Drop the 'Run lab mypy' CI step; lab source is type-checked by pyright only.

Lab tests remain covered by the workspace test-typing fan-out (mypy, pyrefly,
ty, zuban, pyright over tests using the relaxed root config).

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Python: Fix test-typing regressions from latest main merge

A fresh merge from main brought in new test code never run under the
five-checker test-typing suite. Green up across the affected packages:

- core: narrow Optional span.attributes with 'and' guards in span filters
  and assert+cast the json.loads(...attributes[...]) reads (test_observability);
  match the existing as_agent ignore on the protocol-typed fixture (test_clients).
- openai: align new streaming tests with the established chat_options dict
  pattern (ChatOptions TypedDict isn't assignable to dict), route Optional
  .annotations[0] access through a small _first_annotation helper (mirrors the
  file's assert-not-None convention), and annotate a mapped ResponseStream.
- foundry_hosting: annotate error: dict[str, Any] = body.get(...) or {}
  (zuban needs the annotation).
- foundry: narrow ignores for the live AIProjectClient credential arg (pyrefly)
  and connections.get_default (zuban) SDK type gaps.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* updated pyright version

* pyright fix

* Python: Fix source typing for pyright 1.1.410

Pyright 1.1.410 tightened several checks. Apply the same source fixes as
upstream PR #6275:

- anthropic: import AsyncAnthropicBedrock from anthropic.lib.bedrock and
  AsyncAnthropicVertex from anthropic.lib.vertex (no longer re-exported from
  the anthropic top-level package -> reportPrivateImportUsage).
- core _types.py: cast the transform-hook result to UpdateT (reportAssignmentType).
- core _workflows/_events.py: annotate the @contextmanager helper as
  Generator[None] instead of Iterator[None] (reportDeprecated).
- redis: build the combined filter expression with an explicit loop instead of
  reduce(and_, ...), which pyright could no longer fully type (drops the now
  unused functools.reduce / operator.and_ imports).

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Python: Accept plain-text body in Azure Functions workflow/run endpoint

The workflow_orchestrator already accepts plain strings as well as JSON
objects via context.get_input(), but the start_workflow_orchestration HTTP
handler only accepted JSON and returned 400 for any non-JSON body. This made
the functions integration tests that POST text/plain to /api/workflow/run
(e.g. test_09_workflow_shared_state) fail consistently with 400 != 202.

Fall back to the raw request body (decoded as UTF-8) when the body is not
JSON, rejecting only a truly empty body. The JSON path is unchanged.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-06-18 15:06:20 +00:00

250 lines
7.7 KiB
Python

# Copyright (c) Microsoft. All rights reserved.
"""Tests for DockerShellTool.
Argv-builder tests are pure-functional and run everywhere. Integration
tests that actually spawn containers are gated on
:func:`is_docker_available` and skipped otherwise (Docker is rarely
available in CI / dev sandboxes).
"""
from __future__ import annotations
import sys
import pytest
from agent_framework_tools.shell import (
DockerShellTool,
ShellExecutor,
is_docker_available,
)
from agent_framework_tools.shell._docker import (
build_exec_argv,
build_run_argv,
)
# Integration tests use Linux container images (alpine) that don't run
# under Docker Desktop's default Windows-container mode.
_skip_if_no_linux_docker = pytest.mark.skipif(
not is_docker_available() or sys.platform == "win32",
reason="docker daemon unavailable or running Windows containers",
)
# --------------------------------------------------------------------- argv builders
def test_build_run_argv_minimal_defaults():
argv = build_run_argv(
binary="docker",
image="ubuntu:24.04",
container_name="af-shell-test",
user="65534:65534",
network="none",
memory="512m",
pids_limit=256,
workdir="/workspace",
host_workdir=None,
mount_readonly=True,
read_only_root=True,
extra_env=None,
extra_args=None,
)
assert argv[0] == "docker"
assert argv[1] == "run"
assert "-d" in argv
assert "--rm" in argv
assert "--network" in argv and argv[argv.index("--network") + 1] == "none"
assert "--user" in argv and argv[argv.index("--user") + 1] == "65534:65534"
assert "--cap-drop" in argv and argv[argv.index("--cap-drop") + 1] == "ALL"
assert "no-new-privileges" in argv
assert "--read-only" in argv
# Image and the trailing sleep are last.
assert argv[-3:] == ["ubuntu:24.04", "sleep", "infinity"]
def test_build_run_argv_with_host_workdir_readonly():
argv = build_run_argv(
binary="docker",
image="img",
container_name="x",
user="u",
network="none",
memory="1g",
pids_limit=64,
workdir="/work",
host_workdir="/tmp/host",
mount_readonly=True,
read_only_root=True,
extra_env=None,
extra_args=None,
)
assert "-v" in argv
mount = argv[argv.index("-v") + 1]
assert mount == "/tmp/host:/work:ro"
def test_build_run_argv_with_host_workdir_writable():
argv = build_run_argv(
binary="docker",
image="img",
container_name="x",
user="u",
network="none",
memory="1g",
pids_limit=64,
workdir="/work",
host_workdir="/data",
mount_readonly=False,
read_only_root=False,
extra_env=None,
extra_args=None,
)
mount = argv[argv.index("-v") + 1]
assert mount == "/data:/work:rw"
assert "--read-only" not in argv
def test_build_run_argv_passes_extra_env_and_args():
argv = build_run_argv(
binary="podman",
image="alpine",
container_name="c",
user="0:0",
network="bridge",
memory="64m",
pids_limit=16,
workdir="/w",
host_workdir=None,
mount_readonly=True,
read_only_root=True,
extra_env={"FOO": "bar", "X": "y z"},
extra_args=("--label", "team=af"),
)
assert argv[0] == "podman"
assert "-e" in argv
# Both env vars present.
env_pairs = [argv[i + 1] for i, a in enumerate(argv) if a == "-e"]
assert "FOO=bar" in env_pairs
assert "X=y z" in env_pairs
# Extra args land before image+sleep.
image_idx = argv.index("alpine")
assert "--label" in argv[:image_idx]
assert "team=af" in argv[:image_idx]
def test_build_exec_argv_interactive():
argv = build_exec_argv(binary="docker", container_name="c", interactive=True)
assert argv == ["docker", "exec", "-i", "c", "bash", "--noprofile", "--norc"]
# --------------------------------------------------------------------- extra_run_args validation
@pytest.mark.parametrize(
"extra",
[
("--privileged",),
("--network=host",),
("--network", "host"),
("--net=host",),
("-v", "/:/host:rw"),
("--volume=/etc:/etc",),
("--cap-add=ALL",),
("--cap-add", "SYS_ADMIN"),
("--security-opt", "seccomp=unconfined"),
("--device", "/dev/kvm"),
("--pid=host",),
("--ipc=host",),
("--userns=host",),
("--user=0:0",),
("--read-only=false",),
("--tmpfs", "/var:rw"),
("--gpus", "all"),
("--add-host", "evil:1.2.3.4"),
("--label", "x=1", "--privileged"), # mixed safe + unsafe
],
)
def test_dockershell_rejects_isolation_breaking_extra_run_args(extra):
with pytest.raises(ValueError, match="isolation defaults"):
DockerShellTool(extra_run_args=list(extra))
def test_dockershell_accepts_benign_extra_run_args():
# Should not raise.
DockerShellTool(extra_run_args=("--label", "team=af", "--name-suffix", "x"))
def test_build_exec_argv_non_interactive_appends_dash_c():
argv = build_exec_argv(binary="docker", container_name="c", interactive=False)
assert argv == ["docker", "exec", "-i", "c", "bash", "-c"]
# --------------------------------------------------------------------- DockerShellTool
def test_docker_shell_tool_validates_mode():
with pytest.raises(ValueError, match="mode must be"):
DockerShellTool(mode="bogus") # type: ignore[arg-type] # ty: ignore[invalid-argument-type]
def test_docker_shell_tool_does_not_require_acknowledge_unsafe():
"""The container is the boundary; never_require should NOT raise."""
# No exception means the security model is trusting the sandbox, as
# advertised in the docstring.
DockerShellTool(approval_mode="never_require")
def test_docker_shell_tool_generates_unique_container_names():
a = DockerShellTool()
b = DockerShellTool()
assert a._container_name != b._container_name
assert a._container_name.startswith("af-shell-")
def test_docker_shell_tool_implements_shell_executor_protocol():
tool = DockerShellTool()
assert isinstance(tool, ShellExecutor)
def test_as_function_carries_shell_kind():
from agent_framework._tools import SHELL_TOOL_KIND_VALUE
fn = DockerShellTool().as_function()
# Approval mode flows through; tool is tagged as a shell tool.
assert (
getattr(fn, "additional_properties", {}).get("kind") == SHELL_TOOL_KIND_VALUE
or getattr(fn, "kind", None) == SHELL_TOOL_KIND_VALUE
or SHELL_TOOL_KIND_VALUE in str(getattr(fn, "_kind", ""))
)
# --------------------------------------------------------------------- integration
@_skip_if_no_linux_docker
async def test_docker_persistent_session_preserves_state():
async with DockerShellTool(image="alpine:3", shell="sh", network="none") as shell:
r1 = await shell.run("export AF_X=hello")
assert r1.exit_code == 0
r2 = await shell.run("echo $AF_X")
assert r2.exit_code == 0
assert "hello" in r2.stdout
@_skip_if_no_linux_docker
async def test_docker_stateless_each_command_isolated():
shell = DockerShellTool(mode="stateless", image="alpine:3", shell="sh", network="none")
r1 = await shell.run("export AF_X=hello")
assert r1 is not None # noqa: S101
r2 = await shell.run('echo "${AF_X:-unset}"')
assert "unset" in r2.stdout
@_skip_if_no_linux_docker
async def test_docker_no_network_by_default():
async with DockerShellTool(image="alpine:3", shell="sh") as shell:
# busybox wget against a host that should be unreachable with --network none
r = await shell.run("wget -q -T 2 -O- http://example.com || echo NOACCESS")
assert "NOACCESS" in r.stdout