Skip to content

fix(runtime): preserve workspace reuse and SSH streams - #1424

Draft
skevetter wants to merge 17 commits into
mainfrom
codex/microsandbox-parity
Draft

skevetter wants to merge 17 commits into
mainfrom
codex/microsandbox-parity

Conversation

@skevetter

@skevetter skevetter commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Existing MicroSandbox workspaces could stall during SSH handshakes, lose guest stderr through JSON log parsing, or omit the external runtime binary when the content folder already existed. Reusing an external VM also needed a read-only ownership check so incompatible developer identity or mount-policy changes preserve the VM and return explicit recreation guidance.

Prepare declared binaries for existing content folders, keep guest stderr separate from helper diagnostics, preserve raw binary stdout through the container tunnel, and negotiate ReusePreflight before workspace reuse. Text redaction can retain the last byte of an SSH packet when it matches a secret prefix, stalling the peer; tunnel commands now bypass that text filter while ordinary command output remains redacted.

For external runtimes, refresh creation-time developer identity only when runtime ownership validation is negotiated, retaining prior identity resolution for unsupported runtimes. For supported runtimes, retain image and feature metadata, including older managed workspaces with a structural signature. Preserve unmarked image metadata because its creation-config provenance is ambiguous.

Use published SDK v1.5.2 and external provider v0.1.5. The SDK supervisor reaps only its leased command group so detached MicroSandbox VMM sessions do not block operation cleanup; the provider reports the protocol's stopped state after Stop. The shared built-in/external E2E scenario covers binary SSH streams, separate non-newline stderr and exit status, agent delivery, identity and mount ownership, stop/start, recreation, VM-local data preservation on rejected reuse, and deletion. CI installs checksum-pinned MicroSandbox 0.7.7, requires KVM, and bounds each scenario and job.

Validation: twelve targeted packages passed race tests with published dependencies. Deterministic regressions fail before the raw-stream and unsupported-identity fixes and pass afterward; ordinary text redaction remains covered. The local agentworkspace suite excludes only its preexisting environment-dependent Docker-discovery test. Published provider binaries passed checksum verification; release CI passed native packaging and real host installation. Strict lint and all pre-commit hooks (including formatting and actionlint) passed. A fresh complete committed local CodeRabbit review covered all 18 PR files with zero findings. Module tidy/verification passed. Final-head CI, including both real VM scenarios, and remote review gates remain pending.

This is the lifecycle and ownership baseline. Complete parity, later D5 scenarios, and replacement of the built-in provider remain outside this PR.

@netlify

netlify Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for devsydev ready!

Name Link
🔨 Latest commit 8115758
🔍 Latest deploy log https://app.netlify.com/projects/devsydev/deploys/6ac88dfbcdb8b80008df33b0
😎 Deploy Preview https://deploy-preview-1424--devsydev.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@coderabbitai

coderabbitai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true
  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added the size/l label Oct 8, 2026
@netlify

netlify Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for images-devsy-sh canceled.

Name Link
🔨 Latest commit 8115758
🔍 Latest deploy log https://app.netlify.com/projects/images-devsy-sh/deploys/6ac88dfbe5df2100080349f1

@skevetter skevetter changed the title test(microsandbox): add shared external provider parity baseline fix(runtime): preserve workspace reuse and SSH stderr Oct 8, 2026
@github-actions github-actions Bot added size/xl and removed size/l labels Oct 8, 2026
@skevetter skevetter changed the title fix(runtime): preserve workspace reuse and SSH stderr fix(runtime): preserve workspace reuse and SSH streams Oct 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant