Repository navigation
Conversation
✅ Deploy Preview for devsydev ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: true
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
✅ Deploy Preview for images-devsy-sh canceled.
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Existing MicroSandbox workspaces could stall during SSH handshakes, lose guest stderr through JSON log parsing, or omit the external runtime binary when the content folder already existed. Reusing an external VM also needed a read-only ownership check so incompatible developer identity or mount-policy changes preserve the VM and return explicit recreation guidance.
Prepare declared binaries for existing content folders, keep guest stderr separate from helper diagnostics, preserve raw binary stdout through the container tunnel, and negotiate ReusePreflight before workspace reuse. Text redaction can retain the last byte of an SSH packet when it matches a secret prefix, stalling the peer; tunnel commands now bypass that text filter while ordinary command output remains redacted.
For external runtimes, refresh creation-time developer identity only when runtime ownership validation is negotiated, retaining prior identity resolution for unsupported runtimes. For supported runtimes, retain image and feature metadata, including older managed workspaces with a structural signature. Preserve unmarked image metadata because its creation-config provenance is ambiguous.
Use published SDK v1.5.2 and external provider v0.1.5. The SDK supervisor reaps only its leased command group so detached MicroSandbox VMM sessions do not block operation cleanup; the provider reports the protocol's
stoppedstate after Stop. The shared built-in/external E2E scenario covers binary SSH streams, separate non-newline stderr and exit status, agent delivery, identity and mount ownership, stop/start, recreation, VM-local data preservation on rejected reuse, and deletion. CI installs checksum-pinned MicroSandbox 0.7.7, requires KVM, and bounds each scenario and job.Validation: twelve targeted packages passed race tests with published dependencies. Deterministic regressions fail before the raw-stream and unsupported-identity fixes and pass afterward; ordinary text redaction remains covered. The local agentworkspace suite excludes only its preexisting environment-dependent Docker-discovery test. Published provider binaries passed checksum verification; release CI passed native packaging and real host installation. Strict lint and all pre-commit hooks (including formatting and actionlint) passed. A fresh complete committed local CodeRabbit review covered all 18 PR files with zero findings. Module tidy/verification passed. Final-head CI, including both real VM scenarios, and remote review gates remain pending.
This is the lifecycle and ownership baseline. Complete parity, later D5 scenarios, and replacement of the built-in provider remain outside this PR.