Files
zhenxun_bot/zhenxun/services/ai/sandbox/manager.py
T
80fc5b86a7 ✨ feat!(llm): 重构并升级大语言模型服务为全新 AI 智能体框架 (#2146)
* ✨ feat!(llm): 重构并升级大语言模型服务为全新 AI 智能体框架

- 【重构】将原 services/llm 重构并迁移至全新的 services/ai 架构,提供向下兼容垫片
- 【新增】引入 Agent、Team、Workflow 三大智能体与工作流编排范式
- 【新增】引入基于 RAG 的长期向量记忆与中期槽位记忆系统
- 【新增】引入基于 Docker 的安全代码执行沙箱环境
- 【新增】支持 MCP 协议,允许动态管理和调用 MCP 服务
- 【新增】引入输入输出安全合规护栏与自愈反思机制
- 【优化】重构并优化多厂商 API 适配器 (Gemini, OpenAI, DeepSeek, GLM 等)
- 【优化】优化日志脱敏与 Token 预估机制
- 【移除】移除旧版 llm default 和 llm reset-key 命令,新增 llm mcp 管理命令

* 🔧 chore(deps): 更新项目依赖与配置

- 添加 mcp、jieba 和 aiodocker 依赖到配置文件及 requirements.txt
- 在 pyright 配置中设置 reportMissingImports 为 none
- 调整 .gitignore 中 resources 目录的忽略规则

* ♻️ refactor(tools): 重构工具终止机制并清理知识库日志输出

- 统一使用 `context.state["__end_run__"]` 替代 `EndRunResult` 控制任务结束
- 移除文件系统和向量知识库检索工具中 `ToolResult` 的 `.with_log` 调用
- 调整指令处理器(Directive)的返回值为 `tool_res.output`
- 修复部分类型检查警告并优化联合类型判断语法

* ♻️ refactor(tools): 重构工具副作用指令与控制流熔断机制

- 引入 `DirectivePayload` 及 `ToolResult` 的子类以结构化表达工具副作用
- 移除通过 `context.state` 传递魔术变量的隐式控制流设计
- 重构 `DirectiveManager` 处理器接口,直接在处理器中修改 `AgentState` 并构建 `AgentRunResult`
- 在 `StandardAgentExecutor` 中统一通过 `directive_manager` 调度工具返回的副作用指令
- 补全 `MessageBuilder` 中部分核心方法的文档注释

* 🐛 fix(sandbox): 修复 Docker 沙箱容器状态检测与会话清理逻辑

-【修复】修正 `is_alive` 中直接读取私有属性的问题,改用 `show()` 返回值
-【修复】解决 `execute_code` 中缓存的执行器与当前会话不一致的问题
-【优化】在清理工作区前增加容器存活检测,避免向已死容器发送请求
-【优化】创建容器时增加运行状态校验,若已停止则自动从缓存中移除并重建
-【优化】优化容器销毁和清理逻辑,静默处理容器不存在 (404) 的异常

* 📝 docs(core): 补充核心模块初始化方法的文档注释

* 🚨 auto fix by pre-commit hooks

---------

Co-authored-by: webjoin111 <455457521@qq.com>
Co-authored-by: pre-commit-ci[bot] <66853113+pre-commit-ci[bot]@users.noreply.github.com>
2026-07-03 08:53:56 +08:00

210 lines
7.2 KiB
Python

import asyncio
from typing import Any, cast
import nonebot
from zhenxun.services.ai.config import get_llm_config
from zhenxun.services.ai.sandbox.models import (
SandboxBlueprint,
)
from zhenxun.services.log import logger
from zhenxun.utils.lifespan import LifespanManager
from .drivers.base import BaseSandboxClient, BaseSandboxSession
from .registry import SandboxRegistry
_startup_tasks = set()
class SandboxManager:
"""
沙箱底层环境的全局调度中心。
负责读取用户配置,并动态分发给对应的安全 Driver 执行。
"""
def __init__(self):
self._active_sessions: dict[str, BaseSandboxSession] = {}
self._session_locks: dict[str, asyncio.Lock] = {}
self.lifespan_manager = LifespanManager()
def _get_lock(self, session_id: str) -> asyncio.Lock:
if session_id not in self._session_locks:
self._session_locks[session_id] = asyncio.Lock()
return self._session_locks[session_id]
def _get_client(
self,
blueprint: SandboxBlueprint,
) -> BaseSandboxClient:
global_type = get_llm_config().sandbox.sandbox_type
effective_type = (
blueprint.sandbox_type
if blueprint.sandbox_type and blueprint.sandbox_type != "auto"
else global_type
)
clients = SandboxRegistry.get_all_clients()
if effective_type not in clients:
raise RuntimeError(f"未找到指定的沙箱客户端: {effective_type}")
return cast(BaseSandboxClient, clients[effective_type]())
async def get_or_create_session(
self,
session_id: str,
blueprint: SandboxBlueprint | None = None,
) -> BaseSandboxSession:
"""根据 Session ID 获取或创建持久化沙箱环境"""
if not get_llm_config().sandbox.enable_sandbox:
from zhenxun.services.ai.core.exceptions import SandboxFatalError
raise SandboxFatalError(
"全局沙箱功能已关闭(enable_sandbox=False),无法创建运行环境。"
)
async with self._get_lock(session_id):
if not blueprint:
blueprint = SandboxBlueprint()
if blueprint.setup_steps:
blueprint.enable_network = True
cleanup_timeout = get_llm_config().sandbox.cleanup_timeout
await self.lifespan_manager.register(
session_id,
ttl=float(cleanup_timeout),
cleanup_callback=self.close_session,
)
if session_id in self._active_sessions:
session = self._active_sessions[session_id]
is_alive = await session.is_alive()
if not is_alive:
logger.warning(
f"⚠️ Session '{session_id}' 容器已死亡,重建中。",
command="SandboxManager",
)
await self.release_resource(session_id)
else:
session.touch()
if blueprint.setup_steps:
await session.install_dependencies(blueprint)
await session.apply_blueprint(blueprint)
for p in blueprint.required_extensions:
await session.mount_extension(p)
return session
logger.info(
f"为 Session '{session_id}' 创建沙箱环境...", command="SandboxManager"
)
client = self._get_client(blueprint)
try:
session = await client.create(session_id, blueprint)
await session.apply_blueprint(blueprint)
if blueprint.setup_steps:
await session.install_dependencies(blueprint)
for p in blueprint.required_extensions:
await session.mount_extension(p)
self._active_sessions[session_id] = session
return session
except Exception as e:
import traceback
from zhenxun.services.ai.core.exceptions import SandboxFatalError
err_msg = str(e) or type(e).__name__
logger.error(
f"创建 Session 失败: {err_msg}\n{traceback.format_exc()}",
command="SandboxManager",
)
if not isinstance(e, SandboxFatalError):
raise SandboxFatalError(f"沙箱初始化异常: {err_msg}") from e
raise e
async def setup_workspace_environment(
self, session_id: str, workspace_dir: str
) -> bool:
"""统一扫描指定工作区,通过 Provisioner 体系完成环境装配"""
if session_id not in self._active_sessions:
logger.warning(
f"找不到活跃的 Session '{session_id}',无法配置环境。",
command="SandboxManager",
)
return False
session = self._active_sessions[session_id]
from zhenxun.services.ai.sandbox.environments import ProvisionerRegistry
for prov in ProvisionerRegistry.get_all().values():
await prov.scan_and_setup_workspace(cast(Any, session), workspace_dir)
return True
async def release_resource(self, resource_id: str):
if resource_id in self._active_sessions:
session = self._active_sessions.pop(resource_id)
try:
client_cls = SandboxRegistry.get_client_cls(session.state.sandbox_type)
client = client_cls()
await client.delete(cast(Any, session))
except Exception as e:
logger.error(
f"销毁沙箱环境失败 (Session: {resource_id}): {e}",
command="SandboxManager",
)
async def close_session(self, session_id: str) -> None:
await self.lifespan_manager.unregister(session_id)
await self.release_resource(session_id)
async def shutdown_all(self) -> None:
keys = list(self._active_sessions.keys())
for sid in keys:
await self.close_session(sid)
await self.lifespan_manager.stop()
sandbox_manager = SandboxManager()
driver = nonebot.get_driver()
@driver.on_startup
async def _startup_sandboxes():
if not get_llm_config().sandbox.enable_sandbox:
return
clients = SandboxRegistry.get_all_clients()
if "docker" in clients:
from .drivers.docker import DockerSandboxClient
async def _delayed_silent_cleanup():
await asyncio.sleep(15)
try:
await DockerSandboxClient.silent_prune_orphans()
except Exception:
pass
task = asyncio.create_task(_delayed_silent_cleanup())
_startup_tasks.add(task)
task.add_done_callback(_startup_tasks.discard)
@driver.on_shutdown
async def _shutdown_sandboxes():
if not get_llm_config().sandbox.enable_sandbox:
return
await sandbox_manager.shutdown_all()
clients = SandboxRegistry.get_all_clients()
if "docker" in clients and getattr(clients["docker"], "_engine_available", False):
from .drivers.docker import DockerSandboxClient
await DockerSandboxClient.close_env()