mirror of
https://github.com/usestrix/strix.git
synced 2026-08-16 17:27:26 +02:00
Five rounds of sweep across the tree. Net ~544 lines removed. Removed: - Section-divider banners and one-line section labels (# Display utilities, # ----- list_requests -----, # CVSS breakdown, etc.). - Module-level prose docstrings on internal modules. Kept one-line summaries; trimmed multi-paragraph narration about SDK/Strix responsibility splits, cache strategies, three-source precedence. - Internal-helper docstrings that just restate the function name — caido_api helpers (caido_url, get_client, view_request, etc.), settings-class one-liners (LLMSettings, RuntimeSettings, ...), UI helper docstrings. - Args/Returns blocks on non-LLM-facing internal helpers (build_strix_agent, render_system_prompt, create_or_reuse, bootstrap_caido) — kept only the genuinely non-obvious params. - Internal-history phrasing — "Mirrors main-branch shape", "pre-SDK harness", "previous lookup matched no attribute". - Narrative comments inside function bodies that explained what the next line does, design rationale obvious from the surrounding code, or "we used to..." asides. - Trailing periods on every error-string literal across the tool tree. - Duplicated roundtripTime quirk comment (kept the LLM-facing copy in tools/proxy/tools.py). Kept (every one names an upstream bug, vendored-code provenance, or non-obvious data quirk): - core/runner.py: SDK replay-with-empty-initial-input + on_agent_end lifecycle gap. - runtime/docker_client.py: VERBATIM COPY block of the upstream _create_container body, pinned to SDK v0.14.6. - runtime/session_manager.py: NO_PROXY for agent-browser CDP loopback. - tools/proxy/caido_api.py: generated-pydantic Request.raw quirk, replay double-history pitfall. - tools/proxy/tools.py: Caido roundtripTime=0 quirk for proxy captures. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
134 lines
4.2 KiB
Python
134 lines
4.2 KiB
Python
"""Per-scan sandbox session lifecycle."""
|
|
|
|
from __future__ import annotations
|
|
|
|
import logging
|
|
from pathlib import Path
|
|
from typing import Any
|
|
|
|
from agents.sandbox.entries import BaseEntry, LocalDir
|
|
from agents.sandbox.manifest import Environment, Manifest
|
|
|
|
from strix.config import load_settings
|
|
from strix.runtime.backends import get_backend
|
|
from strix.runtime.caido_bootstrap import bootstrap_caido
|
|
|
|
|
|
logger = logging.getLogger(__name__)
|
|
|
|
|
|
# In-container Caido sidecar port (matches the image's caido-cli bind).
|
|
_CONTAINER_CAIDO_PORT = 48080
|
|
|
|
|
|
_SESSION_CACHE: dict[str, dict[str, Any]] = {}
|
|
|
|
|
|
async def create_or_reuse(
|
|
scan_id: str,
|
|
*,
|
|
image: str,
|
|
local_sources: list[dict[str, str]],
|
|
) -> dict[str, Any]:
|
|
"""Return the existing session bundle for ``scan_id`` or create a new one.
|
|
|
|
Each ``local_sources`` entry mounts its host ``source_path`` at
|
|
``/workspace/<workspace_subdir>`` inside the container.
|
|
"""
|
|
cached = _SESSION_CACHE.get(scan_id)
|
|
if cached is not None:
|
|
logger.info("Reusing existing sandbox session for scan %s", scan_id)
|
|
return cached
|
|
|
|
entries: dict[str | Path, BaseEntry] = {}
|
|
for src in local_sources:
|
|
ws_subdir = src.get("workspace_subdir") or ""
|
|
host_path = src.get("source_path") or ""
|
|
if not ws_subdir or not host_path:
|
|
continue
|
|
entries[ws_subdir] = LocalDir(src=Path(host_path).expanduser().resolve())
|
|
|
|
# Caido runs as an in-container sidecar; HTTP(S) traffic from any
|
|
# process started via ``session.exec`` (the SDK's Shell tool, etc.)
|
|
# picks up these env vars automatically. ``NO_PROXY`` keeps the
|
|
# agent-browser CDP daemon's localhost traffic from looping back
|
|
# through Caido.
|
|
container_caido_url = f"http://127.0.0.1:{_CONTAINER_CAIDO_PORT}"
|
|
manifest = Manifest(
|
|
entries=entries,
|
|
environment=Environment(
|
|
value={
|
|
"PYTHONUNBUFFERED": "1",
|
|
"HOST_GATEWAY": "host.docker.internal",
|
|
"http_proxy": container_caido_url,
|
|
"https_proxy": container_caido_url,
|
|
"ALL_PROXY": container_caido_url,
|
|
"NO_PROXY": "localhost,127.0.0.1",
|
|
},
|
|
),
|
|
)
|
|
|
|
backend_name = load_settings().runtime.backend
|
|
backend = get_backend(backend_name)
|
|
|
|
logger.info(
|
|
"Creating sandbox session for scan %s (backend=%s, image=%s)",
|
|
scan_id,
|
|
backend_name,
|
|
image,
|
|
)
|
|
client, session = await backend(
|
|
image=image,
|
|
manifest=manifest,
|
|
exposed_ports=(_CONTAINER_CAIDO_PORT,),
|
|
)
|
|
|
|
caido_endpoint = await session.resolve_exposed_port(_CONTAINER_CAIDO_PORT)
|
|
host_caido_url = f"http://{caido_endpoint.host}:{caido_endpoint.port}"
|
|
logger.debug("Caido host endpoint resolved: %s", host_caido_url)
|
|
|
|
caido_client = await bootstrap_caido(
|
|
session,
|
|
host_url=host_caido_url,
|
|
container_url=container_caido_url,
|
|
)
|
|
|
|
bundle = {
|
|
"client": client,
|
|
"session": session,
|
|
"caido_client": caido_client,
|
|
}
|
|
_SESSION_CACHE[scan_id] = bundle
|
|
logger.info("Sandbox session for scan %s ready and cached", scan_id)
|
|
return bundle
|
|
|
|
|
|
async def cleanup(scan_id: str) -> None:
|
|
"""Tear down ``scan_id``'s container and drop its cache entry.
|
|
|
|
Best-effort: any error during ``client.delete`` is logged and
|
|
swallowed. We never want a cleanup failure to prevent the next
|
|
scan from starting; the worst case is a stranded container that
|
|
Docker's normal reaping will catch on next ``docker prune``.
|
|
"""
|
|
bundle = _SESSION_CACHE.pop(scan_id, None)
|
|
if bundle is None:
|
|
logger.debug("cleanup(%s): no cached session", scan_id)
|
|
return
|
|
|
|
caido_client = bundle.get("caido_client")
|
|
if caido_client is not None:
|
|
try:
|
|
await caido_client.aclose()
|
|
except Exception: # noqa: BLE001
|
|
logger.debug("cleanup(%s): caido_client.aclose() raised", scan_id, exc_info=True)
|
|
|
|
try:
|
|
await bundle["client"].delete(bundle["session"])
|
|
logger.info("Cleaned up sandbox session for scan %s", scan_id)
|
|
except Exception:
|
|
logger.exception(
|
|
"cleanup(%s): client.delete raised; container may need manual reaping",
|
|
scan_id,
|
|
)
|