按 agent_swarm#14/#15 冻结契约做 HM 读侧适配(客户端 #28 消费): - 注册 6 类新事件(event-schema v1):swarm.completed/failed/stopped、approval.approved/rejected、 handoff.created(categories + requiredFields 两表;必填先最小集,待 agent_swarm PR #28 §4 精校)。 - AgentCallbackEvent 增 Sequence(per-swarm 严格递增序号),回调入库透传 envelope.sequence; 事件视图暴露 sequence 供客户端去重/排序。游标仍用稳定 id(next_after)避免 sequence 未全量 上线时回归。 - 脱敏键补 credential_ref/signing_secret_ref(envelope 按设计透传 azkv:// 引用,客户端视图剔除)。 - artifact.created → 扁平视图 {uri,checksum,task_id,size_bytes?,created_at}(无 secret_ref; size 未知省略不伪造)。 - 状态展示映射 §4.1:display_status(blocked→degraded;不臆造 preparing/verifying)。 测试:状态映射、artifact 视图(脱敏 + size 省略)、6 类事件注册;controller+model 全回归通过, go build/vet 干净。文档 §5.2 更新。 未含(下一 PR):stop 真实运行时接入(写路径,复用 agentRuntimeClientConfigForMode("swarm"))。 Affects: Manager only(只读查询契约适配)。AgentCallbackEvent 加列(AutoMigrate);无计费改动。 Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
295 lines
11 KiB
Go
295 lines
11 KiB
Go
package controller
|
|
|
|
import (
|
|
"errors"
|
|
"strconv"
|
|
"strings"
|
|
|
|
"github.com/gin-gonic/gin"
|
|
"github.com/heicode/manager/common"
|
|
"github.com/heicode/manager/model"
|
|
"gorm.io/gorm"
|
|
)
|
|
|
|
// HM-side Swarm Run query (#45 Phase1: list / status / events?after / artifacts / stop).
|
|
//
|
|
// 设计要点(关键):**只读查询全部基于 HM 本地已持久化的数据**——Swarm 运行时通过带签名回调
|
|
// (`/api/agent/callbacks/runtime-events`,见 agent_callback.go)把生命周期事件推给 HM,HM 落
|
|
// 到 AgentDeployment + AgentCallbackEvent。因此 list/status/events/artifacts **无需**调用 Swarm
|
|
// 运行时,也就**不依赖 `agent_swarm#2` 尚未冻结的拉取契约**,返工风险低。
|
|
//
|
|
// 仅 `stop`(写操作)需要真正调用 Swarm 运行时;在契约冻结 + `SWARM_RUNTIME_ENABLED=true` 前
|
|
// 默认关闭并明确提示(不 mock,不臆造未冻结的写接口)。
|
|
//
|
|
// 字段口径对齐 agent_swarm/docs/integration/runtime-contract.md(草案):
|
|
// deployment_id ↔ swarm_id ↔ manager_deployment_id 三者映射;事件按 swarm_id/deployment_id 持久化。
|
|
|
|
// findUserSwarmDeployment 按 :id(匹配 deployment_id / runtime_swarm_id / correlation_id)加载
|
|
// 当前用户的 swarm 部署。非本人或非 swarm 模式 → 失败。
|
|
func findUserSwarmDeployment(c *gin.Context) (model.AgentDeployment, bool) {
|
|
userID := c.GetInt("id")
|
|
id := strings.TrimSpace(c.Param("id"))
|
|
var dep model.AgentDeployment
|
|
err := model.DB.Where(
|
|
"user_id = ? AND (deployment_id = ? OR runtime_swarm_id = ? OR correlation_id = ?)",
|
|
strconv.Itoa(userID), id, id, id,
|
|
).First(&dep).Error
|
|
if err != nil {
|
|
if errors.Is(err, gorm.ErrRecordNotFound) {
|
|
agentError(c, "POLICY_REJECTED", "swarm run not found")
|
|
} else {
|
|
agentError(c, "DEPLOYMENT_CONFLICT", "failed to load swarm run")
|
|
}
|
|
return model.AgentDeployment{}, false
|
|
}
|
|
if !isSwarmDeployment(dep) {
|
|
agentError(c, "POLICY_REJECTED", "deployment is not a swarm run")
|
|
return model.AgentDeployment{}, false
|
|
}
|
|
return dep, true
|
|
}
|
|
|
|
func isSwarmDeployment(dep model.AgentDeployment) bool {
|
|
return strings.EqualFold(dep.SubMode, "swarm") || strings.TrimSpace(dep.RuntimeSwarmID) != ""
|
|
}
|
|
|
|
// swarmDeploymentView 是 swarm 运行的状态摘要视图(脱敏:不含 plan/payload 等大字段与凭据)。
|
|
func swarmDeploymentView(dep model.AgentDeployment) gin.H {
|
|
return gin.H{
|
|
"deployment_id": dep.DeploymentID,
|
|
"swarm_id": dep.RuntimeSwarmID,
|
|
"runtime_deployment_id": dep.RuntimeDeploymentID,
|
|
"correlation_id": dep.CorrelationID,
|
|
"status": dep.Status, // 运行时真实状态(契约 §4)
|
|
"display_status": swarmDisplayStatus(dep.Status), // 客户端展示态(契约 §4.1 映射)
|
|
"phase": dep.Phase,
|
|
"runtime_state": dep.RuntimeState,
|
|
"failure_reason": dep.FailureReason,
|
|
"created_at": dep.CreatedAtText,
|
|
"updated_at": dep.UpdatedAtText,
|
|
"runtime_last_sync_at": dep.RuntimeLastSyncAtText,
|
|
}
|
|
}
|
|
|
|
// swarmDisplayStatus 把运行时真实状态映射到客户端展示态(agent_swarm runtime-contract §4.1)。
|
|
// 运行时只有 waiting_approval/running/blocked/completed/failed/stopped;`blocked` 展示为
|
|
// `degraded`,其余直通。preparing/verifying 是 running 的子态、由运行时阶段决定,HM 未单独存,
|
|
// 不臆造(规则:无信号不造态)。
|
|
func swarmDisplayStatus(status string) string {
|
|
if strings.EqualFold(strings.TrimSpace(status), "blocked") {
|
|
return "degraded"
|
|
}
|
|
return status
|
|
}
|
|
|
|
// swarmSensitivePayloadKeys 是事件 payload 中**绝不下发**给客户端的键(凭据/大字段)。
|
|
// 递归剔除(#45 复审 #1:回调 envelope 可能含 secret_ref,如 approval.requested)。
|
|
var swarmSensitivePayloadKeys = map[string]bool{
|
|
"secret_ref": true, "secretref": true, "credentials": true, "credential": true,
|
|
// agent_swarm event-schema v1(#15):envelope 按设计透传 azkv:// 引用,客户端可见视图须剔除。
|
|
"credential_ref": true, "signing_secret_ref": true,
|
|
"secret": true, "token": true, "access_token": true, "refresh_token": true,
|
|
"api_key": true, "apikey": true, "private_key": true, "access_key": true,
|
|
"password": true, "passwd": true,
|
|
// 大字段/内部结构,避免顺带泄漏
|
|
"plan": true, "payload": true, "permission_manifest": true, "env": true,
|
|
}
|
|
|
|
// stripSensitiveKeys 递归删除敏感键(键名小写匹配 swarmSensitivePayloadKeys)。
|
|
func stripSensitiveKeys(v any) any {
|
|
switch t := v.(type) {
|
|
case map[string]any:
|
|
out := make(map[string]any, len(t))
|
|
for k, val := range t {
|
|
if swarmSensitivePayloadKeys[strings.ToLower(strings.TrimSpace(k))] {
|
|
continue
|
|
}
|
|
out[k] = stripSensitiveKeys(val)
|
|
}
|
|
return out
|
|
case []any:
|
|
out := make([]any, 0, len(t))
|
|
for _, item := range t {
|
|
out = append(out, stripSensitiveKeys(item))
|
|
}
|
|
return out
|
|
default:
|
|
return v
|
|
}
|
|
}
|
|
|
|
// sanitizeSwarmPayload 递归剔除敏感/大字段键,再对序列化结果跑一次 RedactText 兜底
|
|
// (剥离 sk-/Bearer/URL token/JSON 密钥字段)。
|
|
func sanitizeSwarmPayload(raw string) map[string]any {
|
|
m := unmarshalResourceJSON(raw)
|
|
if m == nil {
|
|
return nil
|
|
}
|
|
cleaned, _ := stripSensitiveKeys(m).(map[string]any)
|
|
if b, err := common.Marshal(cleaned); err == nil {
|
|
var out map[string]any
|
|
if err := common.UnmarshalJsonStr(model.RedactText(string(b)), &out); err == nil {
|
|
return out
|
|
}
|
|
}
|
|
return cleaned
|
|
}
|
|
|
|
// swarmEventView maps a persisted callback event to the client view (payload 脱敏)。
|
|
func swarmEventView(e model.AgentCallbackEvent) gin.H {
|
|
return gin.H{
|
|
"id": e.Id, // HM 不透明分页游标(next_after);单调,兼容 sequence 未上线
|
|
"sequence": e.Sequence, // agent_swarm v1 per-swarm 序号(客户端去重/排序;0=envelope 未带)
|
|
"event_id": e.EventID,
|
|
"event_type": e.EventType,
|
|
"task_id": e.TaskID,
|
|
"agent_instance_id": e.AgentInstanceID,
|
|
"result": e.Result,
|
|
"occurred_at": e.OccurredAt,
|
|
"created_at_ms": e.CreatedAtMs,
|
|
"payload": sanitizeSwarmPayload(e.PayloadJSON),
|
|
}
|
|
}
|
|
|
|
// HeicodeListSwarms: GET /api/heicode/swarms — 列出当前用户的 swarm 运行(读 HM 本地部署表)。
|
|
func HeicodeListSwarms(c *gin.Context) {
|
|
userID := c.GetInt("id")
|
|
if userID <= 0 {
|
|
agentError(c, "POLICY_REJECTED", "authentication required")
|
|
return
|
|
}
|
|
if model.DB == nil {
|
|
agentError(c, "DEPLOYMENT_PERSIST_FAILED", "database not initialised")
|
|
return
|
|
}
|
|
var rows []model.AgentDeployment
|
|
err := model.DB.Where(
|
|
"user_id = ? AND (LOWER(sub_mode) = ? OR runtime_swarm_id <> '')",
|
|
strconv.Itoa(userID), "swarm",
|
|
).Order("created_at_ms desc, id desc").Limit(200).Find(&rows).Error
|
|
if err != nil {
|
|
agentError(c, "DEPLOYMENT_CONFLICT", "failed to list swarm runs")
|
|
return
|
|
}
|
|
items := make([]gin.H, 0, len(rows))
|
|
for _, r := range rows {
|
|
items = append(items, swarmDeploymentView(r))
|
|
}
|
|
common.ApiSuccess(c, gin.H{"items": items, "total": len(items)})
|
|
}
|
|
|
|
// HeicodeGetSwarmStatus: GET /api/heicode/swarms/:id — 单个 swarm 运行状态。
|
|
func HeicodeGetSwarmStatus(c *gin.Context) {
|
|
dep, ok := findUserSwarmDeployment(c)
|
|
if !ok {
|
|
return
|
|
}
|
|
common.ApiSuccess(c, swarmDeploymentView(dep))
|
|
}
|
|
|
|
// HeicodeListSwarmEvents: GET /api/heicode/swarms/:id/events?after=&limit= — 事件增量拉取。
|
|
func HeicodeListSwarmEvents(c *gin.Context) {
|
|
dep, ok := findUserSwarmDeployment(c)
|
|
if !ok {
|
|
return
|
|
}
|
|
after, _ := strconv.Atoi(strings.TrimSpace(c.Query("after")))
|
|
limit, _ := strconv.Atoi(strings.TrimSpace(c.Query("limit")))
|
|
events, err := model.ListSwarmCallbackEventsAfter(strconv.Itoa(c.GetInt("id")), dep.DeploymentID, dep.RuntimeSwarmID, after, limit)
|
|
if err != nil {
|
|
agentError(c, "DEPLOYMENT_CONFLICT", "failed to list swarm events")
|
|
return
|
|
}
|
|
items := make([]gin.H, 0, len(events))
|
|
nextAfter := after
|
|
for _, e := range events {
|
|
items = append(items, swarmEventView(e))
|
|
if e.Id > nextAfter {
|
|
nextAfter = e.Id
|
|
}
|
|
}
|
|
common.ApiSuccess(c, gin.H{"items": items, "next_after": nextAfter, "count": len(items)})
|
|
}
|
|
|
|
// HeicodeListSwarmArtifacts: GET /api/heicode/swarms/:id/artifacts — 从已持久化事件中筛产物。
|
|
// 当前从 event_type 含 "artifact" 的回调事件派生(真实数据);专用 artifact 端点待 agent_swarm#2 冻结后补。
|
|
func HeicodeListSwarmArtifacts(c *gin.Context) {
|
|
dep, ok := findUserSwarmDeployment(c)
|
|
if !ok {
|
|
return
|
|
}
|
|
events, err := model.ListSwarmCallbackEventsAfter(strconv.Itoa(c.GetInt("id")), dep.DeploymentID, dep.RuntimeSwarmID, 0, 1000)
|
|
if err != nil {
|
|
agentError(c, "DEPLOYMENT_CONFLICT", "failed to list swarm artifacts")
|
|
return
|
|
}
|
|
items := make([]gin.H, 0)
|
|
for _, e := range events {
|
|
if strings.Contains(strings.ToLower(e.EventType), "artifact") {
|
|
items = append(items, swarmArtifactView(e))
|
|
}
|
|
}
|
|
common.ApiSuccess(c, gin.H{"items": items, "total": len(items)})
|
|
}
|
|
|
|
// swarmArtifactView 从 artifact.created 事件产出客户端扁平视图(agent_swarm event-schema v1):
|
|
// {uri, checksum, task_id, size_bytes?, created_at}。值取自(已脱敏的)payload —— uri/checksum
|
|
// 非敏感保留;**绝不含 secret_ref**。size 未知则省略(不伪造,契约要求)。
|
|
func swarmArtifactView(e model.AgentCallbackEvent) gin.H {
|
|
p := sanitizeSwarmPayload(e.PayloadJSON)
|
|
get := func(k string) any {
|
|
if p == nil {
|
|
return nil
|
|
}
|
|
return p[k]
|
|
}
|
|
createdAt := get("created_at")
|
|
if createdAt == nil || createdAt == "" {
|
|
createdAt = e.OccurredAt
|
|
}
|
|
out := gin.H{
|
|
"event_id": e.EventID,
|
|
"sequence": e.Sequence,
|
|
"task_id": firstNonNil(get("task_id"), e.TaskID),
|
|
"uri": get("uri"),
|
|
"checksum": get("checksum"),
|
|
"created_at": createdAt,
|
|
}
|
|
if sz := get("size_bytes"); sz != nil { // 未知则省略,不伪造
|
|
out["size_bytes"] = sz
|
|
}
|
|
return out
|
|
}
|
|
|
|
// firstNonNil 返回第一个非 nil/非空的值。
|
|
func firstNonNil(vals ...any) any {
|
|
for _, v := range vals {
|
|
if v != nil && v != "" {
|
|
return v
|
|
}
|
|
}
|
|
return nil
|
|
}
|
|
|
|
// HeicodeStopSwarm: POST /api/heicode/swarms/:id/stop — 停止 swarm 运行(写操作)。
|
|
// 这是唯一需要真正调用 Swarm 运行时的操作。在 agent_swarm#2 契约冻结 + SWARM_RUNTIME_ENABLED=true
|
|
// 前默认关闭并明确提示(不臆造未冻结的写接口)。冻结后在此接入运行时 stop(草案路径
|
|
// /api/agent/swarm/deployments/{id}/stop)。
|
|
func HeicodeStopSwarm(c *gin.Context) {
|
|
dep, ok := findUserSwarmDeployment(c)
|
|
if !ok {
|
|
return
|
|
}
|
|
// 运行时 stop 的真实接入随 agent_swarm#2 契约冻结落地。**在此之前一律不伪造 accepted**
|
|
// (#45 复审 #2:开关打开也不能返回 accepted:true 误导客户端/审计)。无论开关如何,均返回
|
|
// 明确的「未实现/待契约」语义,直到真正接上运行时 stop。
|
|
_ = dep
|
|
if !common.GetEnvOrDefaultBool("SWARM_RUNTIME_ENABLED", false) {
|
|
agentError(c, "POLICY_REJECTED",
|
|
"swarm stop not enabled: set SWARM_RUNTIME_ENABLED=true after agent_swarm#2 runtime-contract freeze")
|
|
return
|
|
}
|
|
agentError(c, "NOT_IMPLEMENTED",
|
|
"swarm stop runtime wiring is pending agent_swarm#2 contract freeze; not forwarded to runtime")
|
|
}
|