Skip to content

🐛 Bugfix: 支持 Windows 本机 runtime 使用 Docker Linux 沙箱 - #3985

Merged
YehongPan merged 11 commits into
developfrom
fix/duyuxiao-windows-sandbox
Oct 8, 2026
Merged

YehongPan merged 11 commits into
developfrom
fix/duyuxiao-windows-sandbox

Conversation

@DoYX

@DoYX DoYX commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

修复 Windows 本机启动 Nexent 时的沙箱兼容性问题:

  • 区分 Windows 宿主机路径与 Linux 容器路径,修复挂载目标、工作目录及文件工具的路径转换,打通文件输入、执行和 MinIO 上传下载链路。
  • system 沙箱使用 bridge 网络,由 Docker 动态分配宿主机回环端口;创建与恢复容器时读取实际映射,避免依赖固定 8888。
  • 修复 HTTP API 可访问但 kernel WebSocket 消息通道未就绪的问题:执行前增加就绪握手和有限重连,业务代码提交后不自动重发。
  • 完善取消和清理流程,避免停止一个运行时删除其他运行仍在使用的共享容器。
  • 增加诊断日志及严格失败策略,明确报告 Docker 启动失败,避免静默回退影响验收判断。

修改文件

| 文件名 | 修改 |
| --- | --- |
| backend/consts/const.py、backend/agents/create_agent_info.py | 配置读取与传递 |
| deploy/env/.env.example | 配置说明与示例 |
| sdk/nexent/core/agents/sandbox_workspace.py | 新增宿主机与容器路径映射、挂载校验 |
| sdk/nexent/core/agents/sandbox.py | 网络、动态端口、容器恢复、通道握手及取消处理 |
| sdk/nexent/core/agents/nexent_agent.py、run_agent.py | 工作目录初始化、文件工具映射及取消状态处理 |
| sdk/nexent/core/tools/ 下创建、读取、删除、上传、下载文件工具 | 文件路径转换 |
| backend/services/human_interaction/application.py | 修复正常流结束时重复抛出 StopAsyncIteration |
| 相关测试文件 | 增加路径、端口、握手、恢复与共享容器保护测试 |

Copilot AI lite review requested due to automatic review settings September 21, 2026 06:59

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

There are at least two correctness/security-impacting issues in the current diff (sandbox policy precedence vs DB config, and a path-boundary bypass in bind-mode tool path resolution) that should be fixed before approval.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 2 Medium severity

Open (2)
What changed in this PR

This PR improves Nexent’s Docker sandbox compatibility when running the Nexent runtime natively on Windows while executing code inside Linux containers (Docker Desktop), including workspace path mapping, dynamic host port discovery, kernel channel readiness handshakes, stricter failure behavior, and safer shared-container lifecycle handling.

Changes:

  • Add bind-mounted workspace mapping (host ↔ container) and propagate it through sandbox runners and file/S3 tools.
  • Switch native (non-containerized) system sandbox to bridge networking with dynamically assigned loopback ports and recovery using the effective published mapping.
  • Add kernel channel readiness handshake + bounded reconnect behavior, plus cancellation/cleanup hardening and targeted regressions tests.
File Description
test/​sdk/​core/​agents/​test_sandbox.py Updates/extends unit tests for dynamic port mapping, executor builder signatures, readiness stubbing, and stale-container label behavior.
test/​sdk/​core/​agents/​test_sandbox_workspace.py New tests for host/container path mapping, traversal/symlink escape protection, bind mounts, strict failure policy, and tool path roundtrips.
test/​sdk/​core/​agents/​test_sandbox_workspace_config.py New tests validating config defaults and rejection of invalid workspace/failure policy values.
test/​sdk/​core/​agents/​test_sandbox_system_network.py New regression tests for native system sandbox bridge networking, dynamic port recovery, and cancellation ownership semantics.
test/​sdk/​core/​agents/​test_sandbox_channel_readiness.py New tests for channel-readiness handshake, bounded reconnect, and “never replay code” behavior.
test/​sdk/​core/​agents/​test_run_agent.py Adds test ensuring kernel bootstrap cancellation is treated as “stopped” without surfacing a run error message.
test/​sdk/​core/​agents/​test_nexent_agent.py Updates tool binding test to include the new workspace_mapping argument.
test/​sdk/​core/​agents/​test_nexent_agent_bind_workspace.py New tests for bind workspace bootstrap, permission probing, cancellation behavior, and S3 download path translation.
test/​backend/​services/​test_application_execute_attempt.py Removes StopAsyncIteration-catching in the test now that the backend consumer cleanup no longer re-raises it.
sdk/​nexent/​core/​tools/​upload_to_s3_tool.py Adds workspace_mapping-based path resolution for uploads under bind-mode mapping.
sdk/​nexent/​core/​tools/​read_file_tool.py Adds workspace_mapping-based path resolution and returns container-visible absolute paths when mapped.
sdk/​nexent/​core/​tools/​download_from_s3_tool.py Adds workspace_mapping-based path resolution and returns container-visible local paths when mapped.
sdk/​nexent/​core/​tools/​delete_file_tool.py Adds workspace_mapping-based path resolution and returns container-visible absolute paths when mapped.
sdk/​nexent/​core/​tools/​create_file_tool.py Adds workspace_mapping-based path resolution and returns container-visible absolute paths when mapped.
sdk/​nexent/​core/​agents/​sandbox.py Implements bind workspace support, dynamic port discovery/recovery, channel readiness handshake + retries, improved cancellation semantics, stricter failure policy handling, and safer shared-container cleanup.
sdk/​nexent/​core/​agents/​sandbox_workspace.py Introduces the host/container workspace mapping helper, validation, and bind-mount matching/probing utilities.
sdk/​nexent/​core/​agents/​run_agent.py Treats concurrent.futures.CancelledError as a stopped attempt outcome.
sdk/​nexent/​core/​agents/​nexent_agent.py Wires workspace mapping through tools and skill runner, adds cancellation checks, improves sandbox readiness/failure logging, and adjusts cleanup behavior for bind workspaces.
deploy/​env/​.env.example Documents optional Windows-native + Docker Desktop bind-workspace configuration env vars.
backend/​services/​human_interaction/​application.py Suppresses StopAsyncIteration during anext_task cancellation await to avoid re-raising on normal shutdown.
backend/​consts/​const.py Adds env var reads for sandbox workspace mode, container workspace root, and failure policy.
backend/​agents/​create_agent_info.py Injects env-configured sandbox workspace mode/root/failure policy into SandboxConfig and adjusts extra_kwargs setup for workspace parameters.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread backend/agents/create_agent_info.py Outdated
Comment thread sdk/nexent/core/agents/sandbox_workspace.py
@codecov

codecov Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

Comment thread test/sdk/core/agents/test_sandbox_tls.py Fixed
@DoYX

DoYX commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor Author

恢复了 “Agent 初始化失败后重新分配 kernel” 的特性。修改后的流程是:

  1. WebSocket 建连或就绪握手失败,最多尝试三次。
  2. 耗尽后标记当前 kernel 不健康,初始化流程自动换核,恢复变量、工具和工作区状态。
  3. 同一次初始化恢复链最多换核一次,避免递归或多层重复重试。
  4. 已提交的业务代码不自动重放;取消当前任务不影响其他 Agent 或共享容器。
    之前的 HTTP 问题分两部分处理:控制接口已升级为 HTTPS,执行通道升级为 WSS,保留证书验证;同时保留消息通道就绪检查。

Docker启动的系统级沙箱:
image
image

Docker启动的会话级沙箱:
image

本地启动会话级沙箱:
image

本地启动系统级沙箱:
image
image

@DoYX

DoYX commented Sep 22, 2026

Copy link
Copy Markdown
Contributor Author

解决了 HTTPS 检查成功、但 WSS 错走环境代理导致沙箱连接失败的问题。

  • 仅让当前沙箱主机直连,兼容现有 websocket-client 的参数处理,不修改全局代理。
  • 禁止自动重定向,握手必须返回 101,否则关闭连接。
  • 保留 TLS 证书验证、连接重试及初始化失败换 kernel 的机制。

@YehongPan
YehongPan merged commit e7417f8 into develop Oct 8, 2026
12 of 13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants