6e95517659
* Python: Split type checkers by target (pyright source, 5 checkers on tests/samples) Rework the typing setup along the lines of the 'too many type checkers' approach: - Pyright (strict) is now the sole source-code type checker; mypy is removed from source and its [tool.mypy] block becomes a relaxed profile used only for tests/samples. - Tests are checked by all five checkers (pyright relaxed, mypy, pyrefly, ty, zuban); samples by pyright, pyrefly, and ty. All run in a relaxed/ basic profile so authors aren't forced into over-annotation. - Add pyrightconfig.tests.json and bump sample pyright configs to basic. - Unify test/sample typing onto the same parallel fan-out used by source pyright via run_command_items in task_runner.py. - Make version-conditional imports symmetric: keep or drop the '# type: ignore' on both branches so results match across interpreter versions (local vs CI). - Update SKILL.md, DEV_SETUP.md, and CODING_STANDARD.md for the five gating checkers and pyright on source+tests+samples. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Python: Fix merge regressions from main (typing + runtime) Merging main into the type-checker split branch surfaced regressions that the new five-checker test suite and unit tests caught: Runtime fixes: - anthropic: restore the dropped `cache_read_input_token_count` mapping in _parse_usage_from_anthropic (lost during merge conflict resolution). - gemini: _get_function_calling_mode test helper returned str(enum) ('FunctionCallingConfigMode.AUTO') instead of the enum value ('AUTO'). - openai: _response_id_from_token test helper was an infinite self-recursion; return token['response_id']. - orchestrations: reset output_events per approval iteration so the terminal output assertion counts only the final run. - core: drop a stale duplicate harness test whose message ('non-negative') contradicted the source ('positive'). - purview: import PolicyLocation/PolicyScope/ProtectionScopeActivities/ ExecutionMode used by the processor tests. Type-checker fixes (tests, relaxed profile): - core: pyright/mypy/pyrefly/ty/zuban green-ups across the harness, MCP, observability and types tests. - anthropic/openai: route provider-namespaced UsageDetails keys through a dict cast (extra_items TypedDict unsupported by mypy/ty). - purview: typed model constructors and cache-mock casts. - ag-ui: annotate WorkflowContext[Any, Any] so yield_output accepts test payloads, guard Optional forwarded_props, and ty-ignore intentional bad args. Source pyright (sole source checker) flagged unnecessary ignores newly introduced by merged code in core _tools.py and declarative _declarative_base.py. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Python: Isolate per-package mypy cache in test-typing fan-out The parallel test-typing fan-out runs many mypy processes concurrently, all defaulting to a single shared ./.mypy_cache. Concurrent writes corrupt the cache and mypy aborts with INTERNAL ERROR (intermittently, depending on worker timing) -- which is why CI's Test Typing job failed on a shifting set of packages while a single-package run was fine. Give each mypy invocation an isolated cache dir keyed by its target paths so incremental caching still works per package without races. Other checkers (zuban/pyrefly/ty/pyright) maintain their own caches and are unaffected. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Python: Make lab pyright-only on source (drop source mypy) Lab was the last package still running mypy on its source code, requiring mypy-only `# type: ignore` comments that pyright (the sole source checker everywhere else) flags as unnecessary. Align lab with the rest of the monorepo: - Remove the lab source mypy poe tasks (mypy-gaia/lightning/tau2) and the now-dead strict [tool.mypy] config block. - Drop the 'Run lab mypy' CI step; lab source is type-checked by pyright only. Lab tests remain covered by the workspace test-typing fan-out (mypy, pyrefly, ty, zuban, pyright over tests using the relaxed root config). Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Python: Fix test-typing regressions from latest main merge A fresh merge from main brought in new test code never run under the five-checker test-typing suite. Green up across the affected packages: - core: narrow Optional span.attributes with 'and' guards in span filters and assert+cast the json.loads(...attributes[...]) reads (test_observability); match the existing as_agent ignore on the protocol-typed fixture (test_clients). - openai: align new streaming tests with the established chat_options dict pattern (ChatOptions TypedDict isn't assignable to dict), route Optional .annotations[0] access through a small _first_annotation helper (mirrors the file's assert-not-None convention), and annotate a mapped ResponseStream. - foundry_hosting: annotate error: dict[str, Any] = body.get(...) or {} (zuban needs the annotation). - foundry: narrow ignores for the live AIProjectClient credential arg (pyrefly) and connections.get_default (zuban) SDK type gaps. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * updated pyright version * pyright fix * Python: Fix source typing for pyright 1.1.410 Pyright 1.1.410 tightened several checks. Apply the same source fixes as upstream PR #6275: - anthropic: import AsyncAnthropicBedrock from anthropic.lib.bedrock and AsyncAnthropicVertex from anthropic.lib.vertex (no longer re-exported from the anthropic top-level package -> reportPrivateImportUsage). - core _types.py: cast the transform-hook result to UpdateT (reportAssignmentType). - core _workflows/_events.py: annotate the @contextmanager helper as Generator[None] instead of Iterator[None] (reportDeprecated). - redis: build the combined filter expression with an explicit loop instead of reduce(and_, ...), which pyright could no longer fully type (drops the now unused functools.reduce / operator.and_ imports). Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Python: Accept plain-text body in Azure Functions workflow/run endpoint The workflow_orchestrator already accepts plain strings as well as JSON objects via context.get_input(), but the start_workflow_orchestration HTTP handler only accepted JSON and returned 400 for any non-JSON body. This made the functions integration tests that POST text/plain to /api/workflow/run (e.g. test_09_workflow_shared_state) fail consistently with 400 != 202. Fall back to the raw request body (decoded as UTF-8) when the body is not JSON, rejecting only a truly empty body. The JSON path is unchanged. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
250 lines
7.7 KiB
Python
250 lines
7.7 KiB
Python
# Copyright (c) Microsoft. All rights reserved.
|
|
|
|
"""Tests for DockerShellTool.
|
|
|
|
Argv-builder tests are pure-functional and run everywhere. Integration
|
|
tests that actually spawn containers are gated on
|
|
:func:`is_docker_available` and skipped otherwise (Docker is rarely
|
|
available in CI / dev sandboxes).
|
|
"""
|
|
|
|
from __future__ import annotations
|
|
|
|
import sys
|
|
|
|
import pytest
|
|
|
|
from agent_framework_tools.shell import (
|
|
DockerShellTool,
|
|
ShellExecutor,
|
|
is_docker_available,
|
|
)
|
|
from agent_framework_tools.shell._docker import (
|
|
build_exec_argv,
|
|
build_run_argv,
|
|
)
|
|
|
|
# Integration tests use Linux container images (alpine) that don't run
|
|
# under Docker Desktop's default Windows-container mode.
|
|
_skip_if_no_linux_docker = pytest.mark.skipif(
|
|
not is_docker_available() or sys.platform == "win32",
|
|
reason="docker daemon unavailable or running Windows containers",
|
|
)
|
|
|
|
# --------------------------------------------------------------------- argv builders
|
|
|
|
|
|
def test_build_run_argv_minimal_defaults():
|
|
argv = build_run_argv(
|
|
binary="docker",
|
|
image="ubuntu:24.04",
|
|
container_name="af-shell-test",
|
|
user="65534:65534",
|
|
network="none",
|
|
memory="512m",
|
|
pids_limit=256,
|
|
workdir="/workspace",
|
|
host_workdir=None,
|
|
mount_readonly=True,
|
|
read_only_root=True,
|
|
extra_env=None,
|
|
extra_args=None,
|
|
)
|
|
assert argv[0] == "docker"
|
|
assert argv[1] == "run"
|
|
assert "-d" in argv
|
|
assert "--rm" in argv
|
|
assert "--network" in argv and argv[argv.index("--network") + 1] == "none"
|
|
assert "--user" in argv and argv[argv.index("--user") + 1] == "65534:65534"
|
|
assert "--cap-drop" in argv and argv[argv.index("--cap-drop") + 1] == "ALL"
|
|
assert "no-new-privileges" in argv
|
|
assert "--read-only" in argv
|
|
# Image and the trailing sleep are last.
|
|
assert argv[-3:] == ["ubuntu:24.04", "sleep", "infinity"]
|
|
|
|
|
|
def test_build_run_argv_with_host_workdir_readonly():
|
|
argv = build_run_argv(
|
|
binary="docker",
|
|
image="img",
|
|
container_name="x",
|
|
user="u",
|
|
network="none",
|
|
memory="1g",
|
|
pids_limit=64,
|
|
workdir="/work",
|
|
host_workdir="/tmp/host",
|
|
mount_readonly=True,
|
|
read_only_root=True,
|
|
extra_env=None,
|
|
extra_args=None,
|
|
)
|
|
assert "-v" in argv
|
|
mount = argv[argv.index("-v") + 1]
|
|
assert mount == "/tmp/host:/work:ro"
|
|
|
|
|
|
def test_build_run_argv_with_host_workdir_writable():
|
|
argv = build_run_argv(
|
|
binary="docker",
|
|
image="img",
|
|
container_name="x",
|
|
user="u",
|
|
network="none",
|
|
memory="1g",
|
|
pids_limit=64,
|
|
workdir="/work",
|
|
host_workdir="/data",
|
|
mount_readonly=False,
|
|
read_only_root=False,
|
|
extra_env=None,
|
|
extra_args=None,
|
|
)
|
|
mount = argv[argv.index("-v") + 1]
|
|
assert mount == "/data:/work:rw"
|
|
assert "--read-only" not in argv
|
|
|
|
|
|
def test_build_run_argv_passes_extra_env_and_args():
|
|
argv = build_run_argv(
|
|
binary="podman",
|
|
image="alpine",
|
|
container_name="c",
|
|
user="0:0",
|
|
network="bridge",
|
|
memory="64m",
|
|
pids_limit=16,
|
|
workdir="/w",
|
|
host_workdir=None,
|
|
mount_readonly=True,
|
|
read_only_root=True,
|
|
extra_env={"FOO": "bar", "X": "y z"},
|
|
extra_args=("--label", "team=af"),
|
|
)
|
|
assert argv[0] == "podman"
|
|
assert "-e" in argv
|
|
# Both env vars present.
|
|
env_pairs = [argv[i + 1] for i, a in enumerate(argv) if a == "-e"]
|
|
assert "FOO=bar" in env_pairs
|
|
assert "X=y z" in env_pairs
|
|
# Extra args land before image+sleep.
|
|
image_idx = argv.index("alpine")
|
|
assert "--label" in argv[:image_idx]
|
|
assert "team=af" in argv[:image_idx]
|
|
|
|
|
|
def test_build_exec_argv_interactive():
|
|
argv = build_exec_argv(binary="docker", container_name="c", interactive=True)
|
|
assert argv == ["docker", "exec", "-i", "c", "bash", "--noprofile", "--norc"]
|
|
|
|
|
|
# --------------------------------------------------------------------- extra_run_args validation
|
|
|
|
|
|
@pytest.mark.parametrize(
|
|
"extra",
|
|
[
|
|
("--privileged",),
|
|
("--network=host",),
|
|
("--network", "host"),
|
|
("--net=host",),
|
|
("-v", "/:/host:rw"),
|
|
("--volume=/etc:/etc",),
|
|
("--cap-add=ALL",),
|
|
("--cap-add", "SYS_ADMIN"),
|
|
("--security-opt", "seccomp=unconfined"),
|
|
("--device", "/dev/kvm"),
|
|
("--pid=host",),
|
|
("--ipc=host",),
|
|
("--userns=host",),
|
|
("--user=0:0",),
|
|
("--read-only=false",),
|
|
("--tmpfs", "/var:rw"),
|
|
("--gpus", "all"),
|
|
("--add-host", "evil:1.2.3.4"),
|
|
("--label", "x=1", "--privileged"), # mixed safe + unsafe
|
|
],
|
|
)
|
|
def test_dockershell_rejects_isolation_breaking_extra_run_args(extra):
|
|
with pytest.raises(ValueError, match="isolation defaults"):
|
|
DockerShellTool(extra_run_args=list(extra))
|
|
|
|
|
|
def test_dockershell_accepts_benign_extra_run_args():
|
|
# Should not raise.
|
|
DockerShellTool(extra_run_args=("--label", "team=af", "--name-suffix", "x"))
|
|
|
|
|
|
def test_build_exec_argv_non_interactive_appends_dash_c():
|
|
argv = build_exec_argv(binary="docker", container_name="c", interactive=False)
|
|
assert argv == ["docker", "exec", "-i", "c", "bash", "-c"]
|
|
|
|
|
|
# --------------------------------------------------------------------- DockerShellTool
|
|
|
|
|
|
def test_docker_shell_tool_validates_mode():
|
|
with pytest.raises(ValueError, match="mode must be"):
|
|
DockerShellTool(mode="bogus") # type: ignore[arg-type] # ty: ignore[invalid-argument-type]
|
|
|
|
|
|
def test_docker_shell_tool_does_not_require_acknowledge_unsafe():
|
|
"""The container is the boundary; never_require should NOT raise."""
|
|
# No exception means the security model is trusting the sandbox, as
|
|
# advertised in the docstring.
|
|
DockerShellTool(approval_mode="never_require")
|
|
|
|
|
|
def test_docker_shell_tool_generates_unique_container_names():
|
|
a = DockerShellTool()
|
|
b = DockerShellTool()
|
|
assert a._container_name != b._container_name
|
|
assert a._container_name.startswith("af-shell-")
|
|
|
|
|
|
def test_docker_shell_tool_implements_shell_executor_protocol():
|
|
tool = DockerShellTool()
|
|
assert isinstance(tool, ShellExecutor)
|
|
|
|
|
|
def test_as_function_carries_shell_kind():
|
|
from agent_framework._tools import SHELL_TOOL_KIND_VALUE
|
|
|
|
fn = DockerShellTool().as_function()
|
|
# Approval mode flows through; tool is tagged as a shell tool.
|
|
assert (
|
|
getattr(fn, "additional_properties", {}).get("kind") == SHELL_TOOL_KIND_VALUE
|
|
or getattr(fn, "kind", None) == SHELL_TOOL_KIND_VALUE
|
|
or SHELL_TOOL_KIND_VALUE in str(getattr(fn, "_kind", ""))
|
|
)
|
|
|
|
|
|
# --------------------------------------------------------------------- integration
|
|
|
|
|
|
@_skip_if_no_linux_docker
|
|
async def test_docker_persistent_session_preserves_state():
|
|
async with DockerShellTool(image="alpine:3", shell="sh", network="none") as shell:
|
|
r1 = await shell.run("export AF_X=hello")
|
|
assert r1.exit_code == 0
|
|
r2 = await shell.run("echo $AF_X")
|
|
assert r2.exit_code == 0
|
|
assert "hello" in r2.stdout
|
|
|
|
|
|
@_skip_if_no_linux_docker
|
|
async def test_docker_stateless_each_command_isolated():
|
|
shell = DockerShellTool(mode="stateless", image="alpine:3", shell="sh", network="none")
|
|
r1 = await shell.run("export AF_X=hello")
|
|
assert r1 is not None # noqa: S101
|
|
r2 = await shell.run('echo "${AF_X:-unset}"')
|
|
assert "unset" in r2.stdout
|
|
|
|
|
|
@_skip_if_no_linux_docker
|
|
async def test_docker_no_network_by_default():
|
|
async with DockerShellTool(image="alpine:3", shell="sh") as shell:
|
|
# busybox wget against a host that should be unreachable with --network none
|
|
r = await shell.run("wget -q -T 2 -O- http://example.com || echo NOACCESS")
|
|
assert "NOACCESS" in r.stdout
|