mirror of
https://github.com/microsoft/agent-framework.git
synced 2026-06-16 21:04:09 +08:00
* Add Microsoft.Agents.AI.Hyperlight package for CodeAct integration Introduces a new Microsoft.Agents.AI.Hyperlight package that enables CodeAct-style sandboxed code execution via Hyperlight (hyperlight-sandbox .NET SDK, PR #46) for .NET agents, following the docs/features/code_act/dotnet-implementation.md design and the Python agent_framework_hyperlight reference. Highlights: - HyperlightCodeActProvider (AIContextProvider): injects an execute_code tool and CodeAct guidance per invocation; single-instance-per-agent via a fixed StateKeys value; supports multiple provider-owned tools (exposed inside the sandbox via call_tool), file mounts, and an outbound domain allow-list; snapshot/restore per run. - HyperlightExecuteCodeFunction: standalone AIFunction for manual/static wiring when the sandbox configuration is fixed. - Approval model via CodeActApprovalMode (AlwaysRequire / NeverRequire) with propagation from ApprovalRequiredAIFunction-wrapped tools. - Unit tests (instruction builder, tool bridge, approval computation, provider CRUD, ProvideAIContextAsync snapshot isolation and approval wrapping). - Env-gated integration test (HYPERLIGHT_PYTHON_GUEST_PATH). - Three samples under samples/02-agents/AgentWithCodeAct (interpreter, tool-enabled, manual wiring). Build is not yet runnable: requires .NET SDK 10.0.200 and the not-yet-published HyperlightSandbox.Api 0.1.0-preview NuGet package. Package is marked IsPackable=false until the dependency is available. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Address PR #5329 review feedback for Hyperlight CodeAct provider - A. Build-breakers: drop unused usings, override test TargetFrameworks off net472, drop redundant Microsoft.Extensions.AI.Abstractions PackageRef. - B. API: keep CRUD but rebuild sandbox when config fingerprint changes; add HyperlightCodeActProviderOptions.CreateForWasm/CreateForJavaScript factory methods (Backend/ModulePath now read-only); rename WorkspaceRoot to HostInputDirectory; convert AllowedDomain & FileMount from record to sealed class; drop ToolBridge.Unwrap (ApprovalRequiredAIFunction is invocable as-is). - C. ToolBridge: collapse SerializeResult switch; add comment explaining AOT-driven choice to keep JsonNode.Parse over typed Deserialize. - D. InstructionBuilder: drop language-specific 'Python code' phrasing; strip host filesystem paths from execute_code description. - E. Style polish: ternary expression-body for ComputeApprovalRequired, .Where(x is not null), .ToList() over .ToArray() in IReadOnlyList returns. - F. Samples: add guest-module / KVM-WHP build instructions to Step01; note future Excel-upload sample in Step02. Also adds SandboxExecutorTests covering the new RunSnapshot.ComputeFingerprint used for sandbox-rebuild detection. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Align Hyperlight package id and JS warm-up with merged upstream SDK The .NET SDK in hyperlight-dev/hyperlight-sandbox PR #46 has merged. The published package id is Hyperlight.HyperlightSandbox.Api (the bare HyperlightSandbox.Api remains the assembly/namespace) and the reference CodeExecutionTool uses 'void 0;' as the JavaScript warm-up no-op. Update the package reference, project comment, README, and SandboxExecutor warm-up accordingly. No functional change beyond that — all other public APIs we depend on (SandboxBuilder.With*, Sandbox.Run/RegisterToolAsync/AllowDomain/Snapshot/ Restore, ExecutionResult, SandboxBackend) match the merged shape. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Bump Hyperlight package to 0.4.0 and fix build/test issues Hyperlight.HyperlightSandbox.Api 0.4.0 is now published on nuget.org. Bump the version reference and address the analyzer/runtime issues that surfaced once restore could complete: - Add HyperlightJsonContext source-generated JsonSerializerContext for the execute_code result + tool error envelopes; route arbitrary AIFunction results through AIJsonUtilities.DefaultOptions to keep IsAotCompatible=true. - Replace explicit ObjectDisposedException throws with ObjectDisposedException.ThrowIf (CA1513). - Use HyperlightSandbox.Api.SandboxBackend in cref docs to disambiguate. - Update tests to match AIContext.Tools being IEnumerable<AITool>, drop ConfigureAwait(false) in xUnit test methods (xUnit1030), use collection expressions for AllowedDomain methods. - Add 'using OpenAI.Chat;' to all three samples so AsAIAgent resolves. - Verified: dotnet build of all four hyperlight projects + samples succeeds on net8/9/10; dotnet test for the unit tests passes 32/32 on net10.0. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Fix CI check failures: file encoding (UTF-8 BOM + LF) and broken markdown link - Convert all new .cs/.csproj files to UTF-8 with BOM and LF line endings to satisfy the dotnet/.editorconfig charset/end_of_line settings enforced by check-format. - Drop unused System.Collections.Generic using in HyperlightCodeActProviderTests. - Add missing using Microsoft.Extensions.AI in CodeActApprovalMode.cs and shorten ApprovalRequiredAIFunction cref (IDE0001). - Fix broken README link to docs/decisions/0024-codeact-integration.md. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Address PR review: AIFunction inheritance, packaging, GetService approval check - HyperlightExecuteCodeFunction now inherits AIFunction directly. The AsAIFunction() indirection is gone; instances are accepted anywhere an AIFunction is. Approval requirement is surfaced via GetService<ApprovalRequiredAIFunction>() which lazily exposes a wrapping ApprovalRequiredAIFunction proxy when the effective ApprovalMode/tool stack requires it. - ComputeApprovalRequired now uses GetService<ApprovalRequiredAIFunction>() so approval-required tools nested anywhere in the AITool decorator stack are detected (not just the top-most class). - csproj: drop IsPackable=false (ready to release with the published Hyperlight.HyperlightSandbox.Api 0.4.0 dependency); add PackageReadmeFile and pack README.md at the package root, matching the pattern used by Aspire.Hosting.AgentFramework.DevUI / Microsoft.Agents.AI.DurableTask. - Update Step03 sample and README wording to reflect direct AIFunction usage. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
163 lines
6.2 KiB
C#
163 lines
6.2 KiB
C#
// Copyright (c) Microsoft. All rights reserved.
|
|
|
|
using System;
|
|
using System.Linq;
|
|
using System.Text.Json;
|
|
using System.Threading;
|
|
using System.Threading.Tasks;
|
|
using Microsoft.Agents.AI.Hyperlight.Internal;
|
|
using Microsoft.Extensions.AI;
|
|
|
|
namespace Microsoft.Agents.AI.Hyperlight;
|
|
|
|
/// <summary>
|
|
/// Standalone <c>execute_code</c> <see cref="AIFunction"/> backed by a
|
|
/// Hyperlight sandbox. Use this for manual/static wiring when an
|
|
/// <see cref="AIContextProvider"/> lifecycle is not needed — for example
|
|
/// when the tool registry and capability configuration are fixed for the
|
|
/// lifetime of the agent.
|
|
/// </summary>
|
|
/// <remarks>
|
|
/// Unlike <see cref="HyperlightCodeActProvider"/>, this type does not hook
|
|
/// into the <see cref="AIContextProvider"/> pipeline. It captures a single
|
|
/// snapshot of the provided <see cref="HyperlightCodeActProviderOptions"/>
|
|
/// at construction time and reuses it for the lifetime of the instance.
|
|
/// The instance can be passed directly anywhere an <see cref="AIFunction"/>
|
|
/// is accepted; when the configuration requires approval (per
|
|
/// <see cref="HyperlightCodeActProviderOptions.ApprovalMode"/> or because a
|
|
/// configured tool is itself an <see cref="ApprovalRequiredAIFunction"/>),
|
|
/// the instance surfaces an <see cref="ApprovalRequiredAIFunction"/> via
|
|
/// <see cref="AITool.GetService(Type, object?)"/>, which is how the rest of
|
|
/// the framework discovers approval requirements.
|
|
/// </remarks>
|
|
public sealed class HyperlightExecuteCodeFunction : AIFunction, IDisposable
|
|
{
|
|
private const string ExecuteCodeName = "execute_code";
|
|
|
|
private static readonly JsonElement s_schema = JsonDocument.Parse(
|
|
"""
|
|
{
|
|
"type": "object",
|
|
"properties": {
|
|
"code": {
|
|
"type": "string",
|
|
"description": "Code to execute using the provider's configured backend/runtime behavior."
|
|
}
|
|
},
|
|
"required": ["code"]
|
|
}
|
|
""").RootElement;
|
|
|
|
private readonly SandboxExecutor _executor;
|
|
private readonly SandboxExecutor.RunSnapshot _snapshot;
|
|
private readonly string _description;
|
|
private readonly bool _approvalRequired;
|
|
private ApprovalRequiredAIFunction? _approvalProxy;
|
|
private bool _disposed;
|
|
|
|
/// <summary>
|
|
/// Initializes a new instance of the <see cref="HyperlightExecuteCodeFunction"/> class.
|
|
/// </summary>
|
|
/// <param name="options">
|
|
/// Optional configuration options. When <see langword="null"/> the defaults of
|
|
/// <see cref="HyperlightCodeActProviderOptions"/> are used.
|
|
/// </param>
|
|
public HyperlightExecuteCodeFunction(HyperlightCodeActProviderOptions? options = null)
|
|
{
|
|
var effective = options ?? new HyperlightCodeActProviderOptions();
|
|
this._executor = new SandboxExecutor(effective);
|
|
|
|
var tools = (effective.Tools?.Where(t => t is not null) ?? []).ToList();
|
|
var fileMounts = (effective.FileMounts?.Where(m => m is not null) ?? []).ToList();
|
|
var allowedDomains = (effective.AllowedDomains?.Where(d => d is not null) ?? []).ToList();
|
|
|
|
this._snapshot = new SandboxExecutor.RunSnapshot(tools, fileMounts, allowedDomains, effective.HostInputDirectory);
|
|
|
|
this._description = InstructionBuilder.BuildExecuteCodeDescription(
|
|
this._snapshot.Tools,
|
|
this._snapshot.FileMounts,
|
|
this._snapshot.AllowedDomains,
|
|
hasHostInputDirectory: !string.IsNullOrEmpty(this._snapshot.HostInputDirectory));
|
|
|
|
this._approvalRequired = HyperlightCodeActProvider.ComputeApprovalRequired(effective.ApprovalMode, this._snapshot.Tools);
|
|
}
|
|
|
|
/// <inheritdoc />
|
|
public override string Name => ExecuteCodeName;
|
|
|
|
/// <inheritdoc />
|
|
public override string Description => this._description;
|
|
|
|
/// <inheritdoc />
|
|
public override JsonElement JsonSchema => s_schema;
|
|
|
|
/// <summary>
|
|
/// Builds a CodeAct instruction string describing the available tools and capabilities.
|
|
/// </summary>
|
|
/// <param name="toolsVisibleToModel">
|
|
/// When <see langword="false"/>, the instructions assume tools are only accessible
|
|
/// through CodeAct (via <c>call_tool</c>). When <see langword="true"/>, the instructions
|
|
/// are abbreviated for cases where the same tools are already visible to the model as
|
|
/// direct agent tools.
|
|
/// </param>
|
|
public string BuildInstructions(bool toolsVisibleToModel = false)
|
|
{
|
|
this.ThrowIfDisposed();
|
|
return InstructionBuilder.BuildContextInstructions(toolsVisibleToModel);
|
|
}
|
|
|
|
/// <inheritdoc />
|
|
public override object? GetService(Type serviceType, object? serviceKey = null)
|
|
{
|
|
if (serviceKey is null
|
|
&& this._approvalRequired
|
|
&& serviceType == typeof(ApprovalRequiredAIFunction))
|
|
{
|
|
return this._approvalProxy ??= new ApprovalRequiredAIFunction(this);
|
|
}
|
|
|
|
return base.GetService(serviceType, serviceKey);
|
|
}
|
|
|
|
/// <inheritdoc />
|
|
protected override async ValueTask<object?> InvokeCoreAsync(
|
|
AIFunctionArguments arguments,
|
|
CancellationToken cancellationToken)
|
|
{
|
|
this.ThrowIfDisposed();
|
|
|
|
if (arguments is null || !arguments.TryGetValue("code", out var codeObj) || codeObj is null)
|
|
{
|
|
throw new ArgumentException("Missing required parameter 'code'.", nameof(arguments));
|
|
}
|
|
|
|
var code = codeObj switch
|
|
{
|
|
string s => s,
|
|
JsonElement { ValueKind: JsonValueKind.String } el => el.GetString() ?? string.Empty,
|
|
_ => codeObj.ToString() ?? string.Empty,
|
|
};
|
|
|
|
if (string.IsNullOrWhiteSpace(code))
|
|
{
|
|
throw new ArgumentException("Parameter 'code' must not be empty.", nameof(arguments));
|
|
}
|
|
|
|
return await this._executor.ExecuteAsync(this._snapshot, code, cancellationToken).ConfigureAwait(false);
|
|
}
|
|
|
|
private void ThrowIfDisposed() => ObjectDisposedException.ThrowIf(this._disposed, this);
|
|
|
|
/// <summary>Releases the underlying sandbox and associated native resources.</summary>
|
|
public void Dispose()
|
|
{
|
|
if (this._disposed)
|
|
{
|
|
return;
|
|
}
|
|
|
|
this._disposed = true;
|
|
this._executor.Dispose();
|
|
}
|
|
}
|