Repository navigation
feat(provider):Ollama 本地 Provider 与能力探测(#48) - #63
Merged
Merged
Conversation
… probing Add a keyless local Provider that connects only to an explicitly configured loopback endpoint (CYBERAGENT_OLLAMA_BASE_URL + CYBERAGENT_OLLAMA_MODEL). Non-loopback hosts, HTTPS, URL credentials, queries, fragments, path prefixes, redirects, and proxy-bearing transports are rejected. The native /api/tags model list, /api/chat (sync and NDJSON streaming with cancellation/truncation/trailing-event rejection), /api/show capability probing, usage estimation, and stable error mapping (model_not_found/capacity/rate_limit/network plus an explainable service-unreachable diagnostic) are implemented. tools/vision/JSON/context capabilities stay unknown and therefore unsupported until the daemon reports them; the no-tool safe path rejects tool schemas at both the Harness (ToolStrategy none) and Provider layers. The registry wires kind ollama and transport ollama_chat into CLI/HTTP/OpenAPI/Desktop/Web, probes capabilities before route selection, qualification, and diagnostics, and keeps the credential allowlist at four providers.
… (ADR 0100) Bilingual README, usage manual, task book, project status, resume memory, and the ADR document the explicit loopback enablement, fail-closed capability semantics, the no-tool safe path, usage estimation, stable diagnostics, and the optional real-Ollama smoke steps.
5 tasks done
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
背景
Issue #48 要求为离线、本地优先场景实现 Ollama Provider,并对模型是否支持工具、JSON、视觉和上下文窗口做显式探测,避免因为“本地模型存在”就假设其具备完整 Agent 能力。基线里
llm.Provider、Router、Registry 与 Harness qualification 已留好扩展点,但所有外部 Provider 都是凭证驱动,且能力来自静态配置而非真实探测。本次改动
1. 无凭证、显式 loopback 的 Ollama Provider
新增
internal/llm/ollama.go:CYBERAGENT_OLLAMA_BASE_URL(仅 loopbackhttp,默认http://127.0.0.1:11434)与CYBERAGENT_OLLAMA_MODEL才启用;缺省永不探测、永不扫描局域网;Proxy=nil(即使进程环境有HTTP_PROXY)并拒绝 redirect;/api/tags模型列表、/api/chat(同步 + NDJSON 流式)、/api/show能力探测;done/done_reason(closed set)、daemon token 计数、超限文本、重复 tool_calls、done 之后的尾随事件、截断流与取消;not found→model_not_found、out of memory→capacity、rate limit→rate_limit、连接类 →network,服务未启动时给出固定的可解释诊断(不携带 host/路径/payload)。2. 能力探测与失败关闭
capabilities字段存在即表示模型已探测;tools/vision来自 closed set,context window 只接受model_info中数值型<family>.context_length的最大值并限界;Router.SetContextWindow(source=ollama_probe)进入真实预算规划。3. no-tool 安全路径
DescribeModelHarness输出ollama_chattransport:tools 未确认 →ToolStrategy=none、JSON 未确认 →JSONStrategy=none;prepareRequest层再设一道防线:向未确认 tools 能力的模型发送 Tool schema 直接失败,绝不透传 schema,也绝不伪造 tool call;4. 入口接线
ProviderKindOllama,OpenAPI 的 provider 路径枚举与transport_protocol枚举加入ollama/ollama_chat;configs/models.yaml只保留文档级示例。测试覆盖
fake-server 离线测试(
internal/llm/ollama_test.go)覆盖:构造器拒绝非 loopback/HTTPS/路径/凭证/代理 transport;代理禁用与 redirect 拒绝;/api/tags能力已知/未知语义;/api/show探测(tools/vision/context,字符串与非数值忽略);同步 Chat、usage 计数与估算、tool call ID/arguments 规范化;错误分类(model_not_found/capacity/500 正文升级);no-tool 安全路径(fake server 断言零 Tool schema 到达);NDJSON 流式文本/usage/tool calls、done 后尾随事件、截断流、上下文取消;服务不可达的稳定诊断。Registry 侧新增:显式 loopback 启用、非 loopback/缺模型 →invalid_configuration、路由选择时探测并写入 harness profile 与 context window。验证结果
已在只包含本 issue 改动的隔离工作树中完成:
go build ./...、go vet ./...go test -timeout 30m ./...(internal/analyzer 的低权限 helper 在本机服务会话以0xc0000142环境性失败,该包零改动、与本次 diff 无关)go test -race ./internal/llm ./internal/modelregistrynpm run check:api(OpenAPI 再生确定一致)全部通过ollama pull llama3.2:3b→ 设两个CYBERAGENT_OLLAMA_*变量 →model set/provider test/provider qualify),fake-server 测试可完全离线运行安全边界与非目标
详细设计与不变量记录见 ADR 0100。
Closes #48