You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
fix(runtime): support MicroSandbox Dockerless setup - #1466
Fixes bootstrap SSH setup for shell-free MicroSandbox Dockerless images: the generated helper starts with literal arguments through the existing argv capability. Drivers without it retain command-string execution. Raw streams, startup watchdog and caller cancellation remain intact; an argv error never triggers a second shell execution.
Adds eight actual-VM Dockerless scenarios across built-in and published external provider v0.1.7. Both host Docker CLI and API are directed to owned failures; the explicit --force-dockerless path must perform a real guest Dockerfile and local Feature build. Root coverage checks image PATH, DOCKER_CONFIG, Feature environment, hooks/SSH and build reuse through repeat up, stop/start and recreation. Nonroot off/private must work; strict/relaxed fresh creation must refuse before VM or build-volume creation while preserving host data. Cleanup targets only each fixture’s owned resources.
Validation: the old SSH dispatch fails the new regression with the bootstrap shell absent; literal-argv dispatch passes, including quoted arguments, raw bytes, fallback and cancellation. Fresh full affected-package race tests, vet, strict lint (zero issues), module verification and all 13 pre-commit hooks passed. The prior eight-spec dry run proves selection only. A fresh full committed local CodeRabbit review completed with zero findings and exact coverage of all nine PR files. All 80 current-head CI jobs passed, including all 58 actual VM scenarios across both drivers. Fresh Greptile completed at 5/5. Explicit full remote CodeRabbit run 770116d5 completed all nine files with no actionable findings, no retained architecture-level concern and minimal merge risk. Both commits have valid GitHub signatures; there are no review threads. The private-helper docstring metric is not a correctness finding. The review correctly identifies invalid-recreate recovery as a separate, already tracked campaign gate; this slice makes no rollback claim.
Scope remains the explicit Dockerless path. Automatic fallback, invalid-recreate preservation and the later driver cutover are not claimed.
Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 1 remain after this review.
📝 Walkthrough
📝 Walkthrough
📝 Walkthrough
Walkthrough
The change adds argv-based startup for the bootstrap SSH helper when the driver supports it. It also adds Microsandbox Dockerless end-to-end scenarios for built-in and external providers, plus the CI matrix entry and runtime protocol documentation for those checks.
Setup passes literal SSH helper arguments to argv-capable drivers and retains shell-command execution as a fallback. Tests cover arguments, streams, fallback behavior, and cancellation. The runtime protocol documents both execution paths.
The suite checks provider behavior with host Docker unavailable, including policy outcomes, workspace writes and preservation, and root lifecycle state. The CI matrix adds the suite, and the protocol documentation describes its scenarios and requirements.
sequenceDiagram
participant executeSetup
participant execSetupSSHServer
participant ArgvExecDriver
participant CommandDevContainer
executeSetup->>execSetupSSHServer: Pass generated SSH helper arguments
alt Driver supports argv execution and arguments are present
execSetupSSHServer->>ArgvExecDriver: CommandContainerArgv with request streams
else No argv support or no arguments
execSetupSSHServer->>CommandDevContainer: Execute shell command
end
Loading
Merge Risk:⚪ Minimal · up to d8326
No actionable issue is established for the SSH startup change or Dockerless checks; the change is mergeable after normal checks.
Security Architecture Review
Security architecture risk:🔵 Low · up to d8326
Literal-argument execution removes the guest-shell requirement while preserving compatibility and the inspected drivers’ execution privileges. No introduced security concern was established, but workspace-ownership and partial-failure recovery coverage remains incomplete.
Retained concerns
No architecture-level concerns identified.
Security review details
Security Blast Radius
inferred — The execution change propagates to every argv-capable driver. Inspected implementations continue targeting the selected workspace sandbox or pod/container: external and Microsandbox execution remain root, while Kubernetes uses the same container execution identity on both paths. No additional host or cross-workspace authority was established by this change; isolation beyond these inspected execution boundaries remains unproven.
Trust Boundaries and Controls
observed — Configuration-derived executable and auth-socket values cross the execution boundary as literal arguments on the argv path, avoiding shell interpretation. Regression assertions include quotes and shell metacharacters, binary stream payloads, workspace targeting and an execution error that must not trigger a second shell invocation.
observed — The Dockerless fixture redirects host Docker CLI and API access to owned failures and supplies policy and developer identity through existing configuration. Fresh non-root strict/relaxed cases assert refusal, no build start, no VM or build volume, and preserved source ownership, permissions and contents. These are validation assertions, not new production enforcement.
Resilience and Maintainability Implications
observed — The fixture prechecks resource absence and scopes cleanup to its temporary workspace, generated sandbox and build-volume names, and isolated provider configuration. Its root lifecycle assertions distinguish reuse and restart from recreation, but do not establish production rollback under interruption or changed ownership policy.
observed — The pre-existing Microsandbox replacement path prepares volumes before removing an existing VM and creating its replacement, with direct error returns and no local compensation shown. It explicitly warns that removal cannot be rolled back. Caller-level recovery remains unresolved; this PR did not establish a worsening of that existing behavior.
Pre-merge checks | 4 | 1
❌ Failed checks (1 warning)
Check name
Status
Explanation
Resolution
Docstring Coverage
Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 16 functions across 4 files. (5 skipped: 5…
Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name
Status
Explanation
Linked Issues check
Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check
Check skipped because no linked issues were found for this pull request.
Description Check
Check skipped - CodeRabbit’s high-level summary is enabled.
Title check
The title clearly identifies the main change: fixing runtime support for MicroSandbox Dockerless setup.
Full details: Docstring Coverage
Explanation
Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 16 functions across 4 files. (5 skipped: 5 unsupported.)
Fix all pre-merge checks with AI
✨ Finishing Touches
✨ Simplify code
Commit to this branch
Create a new PR
Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.
The full current-head CodeRabbit review has been inspected, including Security Architecture and Merge Risk. Its retained observation about pre-existing MicroSandbox replacement and partial-failure recovery is valid and is tracked separately in the driver campaign: SDK1.6.0 now negotiates explicit recreation, followed by provider/host integration and actual running/stopped invalid-effective-config preservation tests. This Dockerless slice neither changes that deletion boundary nor claims rollback. Literal argv, inspected execution privileges, workspace targeting, raw streams, fallback and cancellation are covered here.
The docstring percentage warning concerns private helpers and test functions; their names, explicit assertions and protocol documentation communicate the contract. No comments that restate implementation are added for a coverage metric. Local validation, all 80 implementation CI jobs and 58 actual VM scenarios passed; Greptile is 5/5 and the full nine-file CodeRabbit review completed without actionable findings.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes bootstrap SSH setup for shell-free MicroSandbox Dockerless images: the generated helper starts with literal arguments through the existing argv capability. Drivers without it retain command-string execution. Raw streams, startup watchdog and caller cancellation remain intact; an argv error never triggers a second shell execution.
Adds eight actual-VM Dockerless scenarios across built-in and published external provider v0.1.7. Both host Docker CLI and API are directed to owned failures; the explicit
--force-dockerlesspath must perform a real guest Dockerfile and local Feature build. Root coverage checks image PATH, DOCKER_CONFIG, Feature environment, hooks/SSH and build reuse through repeat up, stop/start and recreation. Nonroot off/private must work; strict/relaxed fresh creation must refuse before VM or build-volume creation while preserving host data. Cleanup targets only each fixture’s owned resources.Validation: the old SSH dispatch fails the new regression with the bootstrap shell absent; literal-argv dispatch passes, including quoted arguments, raw bytes, fallback and cancellation. Fresh full affected-package race tests, vet, strict lint (zero issues), module verification and all 13 pre-commit hooks passed. The prior eight-spec dry run proves selection only. A fresh full committed local CodeRabbit review completed with zero findings and exact coverage of all nine PR files. All 80 current-head CI jobs passed, including all 58 actual VM scenarios across both drivers. Fresh Greptile completed at 5/5. Explicit full remote CodeRabbit run 770116d5 completed all nine files with no actionable findings, no retained architecture-level concern and minimal merge risk. Both commits have valid GitHub signatures; there are no review threads. The private-helper docstring metric is not a correctness finding. The review correctly identifies invalid-recreate recovery as a separate, already tracked campaign gate; this slice makes no rollback claim.
Scope remains the explicit Dockerless path. Automatic fallback, invalid-recreate preservation and the later driver cutover are not claimed.