Repository navigation
feat(execution): add Run-owned command runtime - #110
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
摘要
command-runtime.v2:支持 1–4 条有序前台命令和 Run-owned 后台 Job;提供固定 PowerShell/Bash profile 与绝对路径原生进程 profile,并完整约束 argv、Workspace 相对 cwd、受限环境变量、stdin、timeout、输出、网络、凭据及fail_fast|continue批次语义。command_runtime仅向 Code/Local/Deliver 的 root Supervisor 暴露,并要求当前full_access权限快照、有效 execution generation、进程内 permission-control + danger-full-access 启动能力、普通 Policy 审计以及真实 runtime adapter 同时成立。interrupted,绝不重放持久化 intent,也不按数据库中的旧 PID 发信号。Closes #100.
协议与命令边界
command-runtime.v2按 action 使用互斥的严格对象结构;未知字段、缺失字段、null和跨 action 字段均 fail closed。run接受 1–4 条完整命令,先对整个批次做预检和 Policy 审计,再顺序启动;前台批次总时限固定为 25 秒。start只启动一个后台 Job;list、read、wait、write_stdin、cancel、kill必须属于同一 Run,并重新验证当前授权绑定。-NoLogo -NoProfile -NonInteractive -Command;Bash 固定使用--noprofile --norc -c。continue可返回完整批次,fail_fast可确定性停止。流式输出、stdin 与 Artifact
base_cursor与dropped明确表示淘汰,最小 4 字节读取保证跨 UTF-8 分片仍可前进。inline_window|artifact_limit原因;溢出内容走既有 Run Artifact 路径,工具 metadata 只保存 Artifact ID/hash。所有权、恢复与持久化
Supervisor turn lease 只 fence 启动前的 write-ahead intent。后台进程由独立随机 owner、正数 generation 和 15 秒可续租 heartbeat 持有,因此同一 API/Desktop 进程中的后续 turn 可以继续读取或写 stdin。
interrupted;不会重执行 intent,也不会向可能已复用的持久 PID/process group 发信号。CreateProcess中绑定 kill-on-close Job Object,仅继承明确 allowlist 中的 handle。Pdeathsig。full_access残余风险,不把它描述成可安全收养的 Job。schema v116 保存启动绑定、规范化 intent、可执行文件/env/root 指纹、owner lease、有界清洗输出和终态结果;同时在保留 schema v115 workspace-tool authority JSON 与全部既有调用的前提下,把
command_runtime加入持久 Supervisor 调用账本。安全与兼容边界
network=disabled与credentials=none;显式网络程序/标记及 Policy 判定需审阅的命令会被拒绝。full_access仍是非沙箱宿主执行,无法证明本机凭据文件不可读;需要网络/凭据的操作必须使用独立精确审阅路径,要求隔离证据时应使用 Dockernetwork none。API、Desktop、UI 与 CLI
run step、run execute与 wake consumption 需显式启用两项启动 flag;CLI 进程退出时会终止其拥有的后台 Job。command_runtime_enabled,实际执行仍由认证 Run execution 所有。command_runtime_enabled = run_execution_enabled && danger_full_access_enabled;process/shell 兼容字段与真实可用性保持一致。主线合并说明
本分支已合并当前
main(cc6fd76,包含 PR #109 的模型工作区工具):authority_json和全部workspace_*调用,同时加入 authority 必须为空的command_runtime。agent-code-tools.v1与command_runtime:前者是有界 Workspace 工具,后者是禁网、无凭据、Run-owned 的普通执行;两者不能互相扩大权限。验证
go test -timeout 20m -count=1 ./...:全仓通过;internal/application405.305s、internal/httpapi171.263s、internal/store完整 v1–v116 迁移/恢复矩阵 821.790s。command_runtime以空 authority 加入共享账本。go test -race定向覆盖 command runtime、runner、Supervisor、agent-code 合并边界、store 与 gateway。go test -tags "desktop,wv2runtime.error" -count=1 ./cmd/cyberagent-desktop ./internal/desktop ./internal/webui。go mod verify、go mod tidy -diff、go vet ./...。staticcheck -checks='SA*,S1*,QF*'覆盖受影响 Go 包;internal/runner与internal/outputsafe在当前扫描器下无告警。npm run check:api、完整npm test(60 files / 246 tests)、npm run typecheck、npm run build。npm audit:0 vulnerabilities。git diff --check、schema/ADR 旧引用扫描、冲突标记扫描和隔离 worktree 清洁检查。go vet、govulncheck(No vulnerabilities found),Windows/macOS Desktop shell,Rust/TypeScript,以及 release 依赖/许可证和可复现 Portable ZIP 全部成功;PR 场景的 publish 按预期跳过。审计
仍需人工证据
PR 暂时保持 Draft,仅剩 reviewer-facing Desktop 交互证据:
0xffff0000+System.Management.Automation.Utils启动失败,只有该精确签名稳定 skip;本机真实 Windows PowerShell 5 smoke 通过。