// Copyright (c) Microsoft. All rights reserved. using System; using System.Collections.Generic; using System.Diagnostics.CodeAnalysis; using System.Linq; using System.Text.Encodings.Web; using System.Text.Json; using System.Threading; using System.Threading.Tasks; using Microsoft.Extensions.Logging; using Microsoft.Extensions.Logging.Abstractions; using Microsoft.SemanticKernel.ChatCompletion; namespace Microsoft.SemanticKernel.Connectors.FunctionCalling; /// /// Class responsible for providing function calling configuration and processing AI function calls. As part of the processing, it will: /// 1. Iterate over items representing AI model function calls in the collection. /// 2. Look up each function in the . /// 3. Invoke the auto function invocation filter, if registered, for each function. /// 4. Invoke each function and add the function result to the . /// [ExcludeFromCodeCoverage] internal sealed class FunctionCallsProcessor { /// /// The maximum number of auto-invokes that can be in-flight at any given time as part of the current /// asynchronous chain of execution. /// /// /// This is a fail-safe mechanism. If someone accidentally manages to set up execution settings in such a way that /// auto-invocation is invoked recursively, and in particular where a prompt function is able to auto-invoke itself, /// we could end up in an infinite loop. This const is a backstop against that happening. We should never come close /// to this limit, but if we do, auto-invoke will be disabled for the current flow in order to prevent runaway execution. /// With the current setup, the way this could possibly happen is if a prompt function is configured with built-in /// execution settings that opt-in to auto-invocation of everything in the kernel, in which case the invocation of that /// prompt function could advertize itself as a candidate for auto-invocation. We don't want to outright block that, /// if that's something a developer has asked to do (e.g. it might be invoked with different arguments than its parent /// was invoked with), but we do want to limit it. This limit is arbitrary and can be tweaked in the future and/or made /// configurable should need arise. /// private const int MaxInflightAutoInvokes = 128; /// /// Error message returned when a connector does not support ImageContent in tool results. /// public const string ImageContentNotSupportedErrorMessage = "Error: This model does not support image content in tool results."; /// /// The maximum number of function auto-invokes that can be made in a single user request. /// /// /// After this number of iterations as part of a single user request is reached, auto-invocation /// will be disabled. This is a safeguard against possible runaway execution if the model routinely re-requests /// the same function over and over. /// internal const int MaximumAutoInvokeAttempts = 128; /// Tracking for . /// /// It is temporarily made internal to allow code that uses the old function model to read it and decide whether to continue auto-invocation or not. /// It should be made private when the old model is deprecated. /// Despite the field being static, its value is unique per execution flow. So if thousands of requests hit it in parallel, each request will see its unique value. /// internal static readonly AsyncLocal s_inflightAutoInvokes = new(); /// /// The logger. /// private readonly ILogger _logger; /// /// Initializes a new instance of the class. /// /// The logger. public FunctionCallsProcessor(ILogger? logger = null) { this._logger = logger ?? NullLogger.Instance; } /// /// Retrieves the configuration of the specified . /// /// The function choice behavior. /// The chat history. /// Request sequence index. /// The . /// The configuration of the specified . public FunctionChoiceBehaviorConfiguration? GetConfiguration(FunctionChoiceBehavior? behavior, ChatHistory chatHistory, int requestIndex, Kernel? kernel) { // If no behavior is specified, return null. if (behavior is null) { return null; } var configuration = behavior.GetConfiguration(new(chatHistory) { Kernel = kernel, RequestSequenceIndex = requestIndex }); this._logger.LogFunctionChoiceBehaviorConfiguration(configuration); // Disable auto invocation if no kernel is provided. configuration.AutoInvoke = kernel is not null && configuration.AutoInvoke; // Disable auto invocation if we've exceeded the allowed auto-invoke limit. int maximumAutoInvokeAttempts = configuration.AutoInvoke ? MaximumAutoInvokeAttempts : 0; if (requestIndex >= maximumAutoInvokeAttempts) { configuration.AutoInvoke = false; this._logger.LogMaximumNumberOfAutoInvocationsPerUserRequestReached(maximumAutoInvokeAttempts); } // Disable auto invocation if we've exceeded the allowed limit of in-flight auto-invokes. See XML comment for the "MaxInflightAutoInvokes" const for more details. else if (s_inflightAutoInvokes.Value >= MaxInflightAutoInvokes) { configuration.AutoInvoke = false; this._logger.LogMaximumNumberOfInFlightAutoInvocationsReached(MaxInflightAutoInvokes); } return configuration; } /// /// Processes AI function calls by iterating over the function calls, invoking them and adding the results to the chat history. /// /// The chat message content representing AI model response and containing function calls. /// The prompt execution settings. /// The chat history to add function invocation results to. /// AI model function(s) call request sequence index. /// Callback to check if a function was advertised to AI model or not. /// Function choice behavior options. /// The . /// Boolean flag which indicates whether an operation is invoked within streaming or non-streaming mode. /// The to monitor for cancellation requests. /// Last chat history message if function invocation filter requested processing termination, otherwise null. public async Task ProcessFunctionCallsAsync( ChatMessageContent chatMessageContent, PromptExecutionSettings? executionSettings, ChatHistory chatHistory, int requestIndex, Func checkIfFunctionAdvertised, FunctionChoiceBehaviorOptions options, Kernel? kernel, bool isStreaming, CancellationToken cancellationToken) { // Add the result message to the caller's chat history; // this is required for AI model to understand the function results. chatHistory.Add(chatMessageContent); FunctionCallContent[] functionCalls = FunctionCallContent.GetFunctionCalls(chatMessageContent).ToArray(); this._logger.LogFunctionCalls(functionCalls); List>? functionTasks = options.AllowConcurrentInvocation && functionCalls.Length > 1 ? new(functionCalls.Length) : null; // We must send back a result for every function call, regardless of whether we successfully executed it or not. // If we successfully execute it, we'll add the result. If we don't, we'll add an error. for (int functionCallIndex = 0; functionCallIndex < functionCalls.Length; functionCallIndex++) { FunctionCallContent functionCall = functionCalls[functionCallIndex]; // Check if the function call is valid to execute. if (!TryValidateFunctionCall(functionCall, checkIfFunctionAdvertised, kernel, out KernelFunction? function, out string? errorMessage)) { this.AddFunctionCallErrorToChatHistory(chatHistory, functionCall, errorMessage); continue; } // Prepare context for the auto function invocation filter and invoke it. AutoFunctionInvocationContext invocationContext = new(kernel!, // Kernel cannot be null if function-call is valid function, result: new(function) { Culture = kernel!.Culture }, chatHistory, chatMessageContent) { Arguments = functionCall.Arguments, RequestSequenceIndex = requestIndex, FunctionSequenceIndex = functionCallIndex, FunctionCount = functionCalls.Length, CancellationToken = cancellationToken, IsStreaming = isStreaming, ToolCallId = functionCall.Id, ExecutionSettings = executionSettings }; s_inflightAutoInvokes.Value++; Task functionTask = this.ExecuteFunctionCallAsync(invocationContext, functionCall, function, kernel, cancellationToken); // If concurrent invocation is enabled, add the task to the list for later waiting. Otherwise, join with it now. if (functionTasks is not null) { functionTasks.Add(functionTask); } else { FunctionResultContext functionResult = await functionTask.ConfigureAwait(false); this.AddFunctionCallResultToChatHistory(chatHistory, functionResult); // If filter requested termination, return last chat history message. if (functionResult.Context.Terminate) { this._logger.LogAutoFunctionInvocationProcessTermination(functionResult.Context); return chatHistory.Last(); } } } // If concurrent invocation is enabled, join with all the tasks now. if (functionTasks is not null) { bool terminationRequested = false; // Wait for all the function invocations to complete, then add the results to the chat, but stop when we hit a // function for which termination was requested. FunctionResultContext[] resultContexts = await Task.WhenAll(functionTasks).ConfigureAwait(false); foreach (FunctionResultContext resultContext in resultContexts) { this.AddFunctionCallResultToChatHistory(chatHistory, resultContext); if (resultContext.Context.Terminate) { this._logger.LogAutoFunctionInvocationProcessTermination(resultContext.Context); terminationRequested = true; } } // If filter requested termination, return last chat history message. if (terminationRequested) { return chatHistory.Last(); } } return null; } /// /// Processes function calls specifically for Open AI Assistant API. In this context, the chat-history is not /// present in local memory. /// /// The chat message content representing AI model response and containing function calls. /// Callback to check if a function was advertised to AI model or not. /// Function choice behavior options. /// The . /// Boolean flag which indicates whether an operation is invoked within streaming or non-streaming mode. /// The to monitor for cancellation requests. /// Last chat history message if function invocation filter requested processing termination, otherwise null. public async ValueTask InvokeFunctionCallsAsync( ChatMessageContent chatMessageContent, Func checkIfFunctionAdvertised, FunctionChoiceBehaviorOptions options, Kernel kernel, bool isStreaming, CancellationToken cancellationToken) { FunctionCallContent[] functionCalls = FunctionCallContent.GetFunctionCalls(chatMessageContent).ToArray(); ChatHistory history = [chatMessageContent]; List results = []; this._logger.LogFunctionCalls(functionCalls); List> functionTasks = new(functionCalls.Length); // We must send back a result for every function call, regardless of whether we successfully executed it or not. // If we successfully execute it, we'll add the result. If we don't, we'll add an error. for (int functionCallIndex = 0; functionCallIndex < functionCalls.Length; functionCallIndex++) { FunctionCallContent functionCall = functionCalls[functionCallIndex]; // Check if the function call is valid to execute. if (!TryValidateFunctionCall(functionCall, checkIfFunctionAdvertised, kernel, out KernelFunction? function, out string? errorMessage)) { results.Add(this.GenerateResultContent(functionCall, result: null, errorMessage)); continue; } // Prepare context for the auto function invocation filter and invoke it. AutoFunctionInvocationContext invocationContext = new(kernel!, // Kernel cannot be null if function-call is valid function, result: new(function) { Culture = kernel!.Culture }, history, chatMessageContent) { Arguments = functionCall.Arguments, FunctionSequenceIndex = functionCallIndex, FunctionCount = functionCalls.Length, CancellationToken = cancellationToken, IsStreaming = isStreaming, ToolCallId = functionCall.Id }; s_inflightAutoInvokes.Value++; functionTasks.Add(this.ExecuteFunctionCallAsync(invocationContext, functionCall, function, kernel, cancellationToken)); } // Wait for all of the function invocations to complete, then add the results to the chat, but stop when we hit a // function for which termination was requested. FunctionResultContext[] resultContexts = await Task.WhenAll(functionTasks).ConfigureAwait(false); foreach (var context in resultContexts) { results.Add(this.GenerateResultContent(context)); } return [.. results]; } private static bool TryValidateFunctionCall( FunctionCallContent functionCall, Func checkIfFunctionAdvertised, Kernel? kernel, [NotNullWhen(true)] out KernelFunction? function, out string? errorMessage) { function = null; // Check if the function call has an exception. if (functionCall.Exception is not null) { errorMessage = $"Error: Function call processing failed. Correct yourself. {functionCall.Exception.Message}"; return false; } // Make sure the requested function is one of the functions that was advertised to the AI model. if (!checkIfFunctionAdvertised(functionCall)) { errorMessage = "Error: Function call request for a function that wasn't defined. Correct yourself."; return false; } // Look up the function in the kernel if (kernel?.Plugins.TryGetFunction(functionCall.PluginName, functionCall.FunctionName, out function) ?? false) { errorMessage = null; return true; } errorMessage = "Error: Requested function could not be found. Correct yourself."; return false; } private record struct FunctionResultContext(AutoFunctionInvocationContext Context, FunctionCallContent FunctionCall, object? Result, string? ErrorMessage); private async Task ExecuteFunctionCallAsync( AutoFunctionInvocationContext invocationContext, FunctionCallContent functionCall, KernelFunction function, Kernel kernel, CancellationToken cancellationToken) { try { invocationContext = await this.OnAutoFunctionInvocationAsync( kernel, invocationContext, async (context) => { // Check if filter requested termination. if (context.Terminate) { return; } // Note that we explicitly do not use executionSettings here; those pertain to the all-up operation and not necessarily to any // further calls made as part of this function invocation. In particular, we must not use function calling settings naively here, // as the called function could in turn telling the model about itself as a possible candidate for invocation. context.Result = await function.InvokeAsync(kernel, invocationContext.Arguments, cancellationToken: cancellationToken).ConfigureAwait(false); }).ConfigureAwait(false); } #pragma warning disable CA1031 // Do not catch general exception types catch (Exception e) #pragma warning restore CA1031 // Do not catch general exception types { return new FunctionResultContext(invocationContext, functionCall, null, $"Error: Exception while invoking function. {e.Message}"); } // Apply any changes from the auto function invocation filters context to final result. object result = ProcessFunctionResult(invocationContext.Result.GetValue() ?? string.Empty); return new FunctionResultContext(invocationContext, functionCall, result, null); } /// /// Adds the function call result or error message to the chat history. /// /// The chat history to add the function call result to. /// The function result context. private void AddFunctionCallResultToChatHistory(ChatHistory chatHistory, FunctionResultContext resultContext) { // When Result is ImageContent, Content will be null - the actual result is in FunctionResultContent.Result var message = new ChatMessageContent(role: AuthorRole.Tool, content: resultContext.Result as string); message.Items.Add(this.GenerateResultContent(resultContext)); chatHistory.Add(message); } /// /// Adds the function call result or error message to the chat history. /// /// The chat history to add the function call result to. /// The function call content. /// An error message. private void AddFunctionCallErrorToChatHistory(ChatHistory chatHistory, FunctionCallContent functionCall, string? errorMessage) { var message = new ChatMessageContent(role: AuthorRole.Tool, content: errorMessage); message.Items.Add(this.GenerateResultContent(functionCall, result: null, errorMessage)); chatHistory.Add(message); } /// /// Creates a instance. /// /// The function result context. private FunctionResultContent GenerateResultContent(FunctionResultContext resultContext) { return this.GenerateResultContent(resultContext.FunctionCall, resultContext.Result, resultContext.ErrorMessage); } /// /// Creates a instance. /// /// The function call content. /// The function result, if available. Can be string or ImageContent. /// An error message. private FunctionResultContent GenerateResultContent(FunctionCallContent functionCall, object? result, string? errorMessage) { // Log any error if (errorMessage is not null) { this._logger.LogFunctionCallRequestFailure(functionCall, errorMessage); } // FunctionResultContent.Result is object? - pass through string or ImageContent directly return new FunctionResultContent(functionCall.FunctionName, functionCall.PluginName, functionCall.Id, result ?? errorMessage ?? string.Empty); } /// /// Invokes the auto function invocation filters. /// /// The . /// The auto function invocation context. /// The function to call after the filters. /// The auto function invocation context. private async Task OnAutoFunctionInvocationAsync( Kernel kernel, AutoFunctionInvocationContext context, Func functionCallCallback) { await this.InvokeFilterOrFunctionAsync(kernel.AutoFunctionInvocationFilters, functionCallCallback, context).ConfigureAwait(false); return context; } /// /// This method will execute auto function invocation filters and function recursively. /// If there are no registered filters, just function will be executed. /// If there are registered filters, filter on position will be executed. /// Second parameter of filter is callback. It can be either filter on + 1 position or function if there are no remaining filters to execute. /// Function will be always executed as last step after all filters. /// private async Task InvokeFilterOrFunctionAsync( IList? autoFunctionInvocationFilters, Func functionCallCallback, AutoFunctionInvocationContext context, int index = 0) { if (autoFunctionInvocationFilters is { Count: > 0 } && index < autoFunctionInvocationFilters.Count) { this._logger.LogAutoFunctionInvocationFilterContext(context); await autoFunctionInvocationFilters[index].OnAutoFunctionInvocationAsync( context, (context) => this.InvokeFilterOrFunctionAsync(autoFunctionInvocationFilters, functionCallCallback, context, index + 1) ).ConfigureAwait(false); } else { await functionCallCallback(context).ConfigureAwait(false); } } /// /// Processes the function result into the form a connector should serialize into a tool/function response. /// /// The result of the function call. /// /// One of: /// /// The original when is a string. /// The original instance when is an , so multimodal-capable connectors (e.g., Gemini 3+) can attach it natively. Connectors that do not support multimodal tool results must detect this case and substitute . /// A JSON-serialized representation of any other type (with and short-circuited to their text form). /// /// public static object ProcessFunctionResult(object functionResult) { if (functionResult is string stringResult) { return stringResult; } // Preserve ImageContent for connectors that support multimodal tool results (e.g., Gemini 3+, Anthropic) // Connectors that don't support this should check for ImageContent and return an appropriate error message. if (functionResult is ImageContent) { return functionResult; } // This is an optimization to use ChatMessageContent content directly // without unnecessary serialization of the whole message content class. if (functionResult is ChatMessageContent chatMessageContent) { return chatMessageContent.ToString(); } // Same optimization but for a enumerable of ChatMessageContent if (functionResult is IEnumerable chatMessageContents) { return string.Join(",", chatMessageContents.Select(c => c.ToString())); } return JsonSerializer.Serialize(functionResult, s_functionResultSerializerOptions); } /// /// The which will be used in . /// /// /// is very likely to escape characters and generates LLM unfriendly results by default. /// private static readonly JsonSerializerOptions s_functionResultSerializerOptions = new() { Encoder = JavaScriptEncoder.UnsafeRelaxedJsonEscaping, }; }