Repository navigation
🐛 Bugfix: 支持 Windows 本机 runtime 使用 Docker Linux 沙箱 - #3985
Conversation
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
There are at least two correctness/security-impacting issues in the current diff (sandbox policy precedence vs DB config, and a path-boundary bypass in bind-mode tool path resolution) that should be fixed before approval.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 2
Open (2)
What changed in this PR
This PR improves Nexent’s Docker sandbox compatibility when running the Nexent runtime natively on Windows while executing code inside Linux containers (Docker Desktop), including workspace path mapping, dynamic host port discovery, kernel channel readiness handshakes, stricter failure behavior, and safer shared-container lifecycle handling.
Changes:
- Add bind-mounted workspace mapping (host ↔ container) and propagate it through sandbox runners and file/S3 tools.
- Switch native (non-containerized) system sandbox to bridge networking with dynamically assigned loopback ports and recovery using the effective published mapping.
- Add kernel channel readiness handshake + bounded reconnect behavior, plus cancellation/cleanup hardening and targeted regressions tests.
| File | Description |
|---|---|
| test/sdk/core/agents/test_sandbox.py | Updates/extends unit tests for dynamic port mapping, executor builder signatures, readiness stubbing, and stale-container label behavior. |
| test/sdk/core/agents/test_sandbox_workspace.py | New tests for host/container path mapping, traversal/symlink escape protection, bind mounts, strict failure policy, and tool path roundtrips. |
| test/sdk/core/agents/test_sandbox_workspace_config.py | New tests validating config defaults and rejection of invalid workspace/failure policy values. |
| test/sdk/core/agents/test_sandbox_system_network.py | New regression tests for native system sandbox bridge networking, dynamic port recovery, and cancellation ownership semantics. |
| test/sdk/core/agents/test_sandbox_channel_readiness.py | New tests for channel-readiness handshake, bounded reconnect, and “never replay code” behavior. |
| test/sdk/core/agents/test_run_agent.py | Adds test ensuring kernel bootstrap cancellation is treated as “stopped” without surfacing a run error message. |
| test/sdk/core/agents/test_nexent_agent.py | Updates tool binding test to include the new workspace_mapping argument. |
| test/sdk/core/agents/test_nexent_agent_bind_workspace.py | New tests for bind workspace bootstrap, permission probing, cancellation behavior, and S3 download path translation. |
| test/backend/services/test_application_execute_attempt.py | Removes StopAsyncIteration-catching in the test now that the backend consumer cleanup no longer re-raises it. |
| sdk/nexent/core/tools/upload_to_s3_tool.py | Adds workspace_mapping-based path resolution for uploads under bind-mode mapping. |
| sdk/nexent/core/tools/read_file_tool.py | Adds workspace_mapping-based path resolution and returns container-visible absolute paths when mapped. |
| sdk/nexent/core/tools/download_from_s3_tool.py | Adds workspace_mapping-based path resolution and returns container-visible local paths when mapped. |
| sdk/nexent/core/tools/delete_file_tool.py | Adds workspace_mapping-based path resolution and returns container-visible absolute paths when mapped. |
| sdk/nexent/core/tools/create_file_tool.py | Adds workspace_mapping-based path resolution and returns container-visible absolute paths when mapped. |
| sdk/nexent/core/agents/sandbox.py | Implements bind workspace support, dynamic port discovery/recovery, channel readiness handshake + retries, improved cancellation semantics, stricter failure policy handling, and safer shared-container cleanup. |
| sdk/nexent/core/agents/sandbox_workspace.py | Introduces the host/container workspace mapping helper, validation, and bind-mount matching/probing utilities. |
| sdk/nexent/core/agents/run_agent.py | Treats concurrent.futures.CancelledError as a stopped attempt outcome. |
| sdk/nexent/core/agents/nexent_agent.py | Wires workspace mapping through tools and skill runner, adds cancellation checks, improves sandbox readiness/failure logging, and adjusts cleanup behavior for bind workspaces. |
| deploy/env/.env.example | Documents optional Windows-native + Docker Desktop bind-workspace configuration env vars. |
| backend/services/human_interaction/application.py | Suppresses StopAsyncIteration during anext_task cancellation await to avoid re-raising on normal shutdown. |
| backend/consts/const.py | Adds env var reads for sandbox workspace mode, container workspace root, and failure policy. |
| backend/agents/create_agent_info.py | Injects env-configured sandbox workspace mode/root/failure policy into SandboxConfig and adjusts extra_kwargs setup for workspace parameters. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Codecov Report❌ Patch coverage is 📢 Thoughts on this report? Let us know! |
|
恢复了 “Agent 初始化失败后重新分配 kernel” 的特性。修改后的流程是:
|
|
解决了 HTTPS 检查成功、但 WSS 错走环境代理导致沙箱连接失败的问题。
|







修复 Windows 本机启动 Nexent 时的沙箱兼容性问题:
修改文件