Skip to content

fix(runtime): align MicroSandbox ephemeral root defaults - #1460

Merged
skevetter merged 1 commit into
mainfrom
codex/microsandbox-ephemeral-parity
Oct 11, 2026
Merged

skevetter merged 1 commit into
mainfrom
codex/microsandbox-ephemeral-parity

Conversation

@skevetter

@skevetter skevetter commented Oct 11, 2026 •

Copy link
Copy Markdown
Contributor

Unsized ephemeral roots currently force an 8 GiB tmpfs disk in the built-in driver, exceeding the default 2 GiB memory allocation. Delegate unsized disks to the runtime default while retaining explicit storage sizing, matching the published external provider v0.1.7 repair.

Add six shared scenarios across both drivers: default and explicit ephemeral capacity with root reset on restart, persistence of host workspace and named-volume content through restart/recreation, and fresh oversized-root rejection without a test-labeled VM or source changes. Active configuration, guest capacity, creation time and boot IDs distinguish the behaviors. Pin the shared external fixture to the actual published v0.1.7 release and add the required KVM CI entry.

Local validation passed: the unsized-argument regression fails against the old implementation and passes with the fix; uncached race tests for the driver, provider and E2E up packages, vet, strict lint, module verification and all 13 repository hooks are green. The dry run selects all six new cases. Fresh full committed local CodeRabbit review completed with zero findings across all seven PR files. All 77 implementation CI jobs passed on the current head, including actual lifecycle (2), image (6), mount (10), resource (12), persistent-storage (6), and ephemeral-root (6) scenarios with both drivers and published external v0.1.7. Fresh Greptile review covers the current head with confidence 5/5 and no actionable findings. Full remote CodeRabbit review completed on the current head across all seven files with no actionable findings. Retained scope caveats and the private-helper docstring warning are dispositioned in the review discussion.

This changes RAM-backed root sizing, not the runtime's separate sandbox-record deletion flag. Validation before destructive invalid recreation remains a separate correctness task before provider cutover. Egress, prebuilds, Dockerless behavior, logs, cancellation and compatibility coverage remain separate work.

@netlify

netlify Bot commented Oct 11, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for devsydev ready!

Name Link
🔨 Latest commit 8a819f5
🔍 Latest deploy log https://app.netlify.com/projects/devsydev/deploys/6acb6a20817d36000752139c
😎 Deploy Preview https://deploy-preview-1460--devsydev.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@coderabbitai

coderabbitai Bot commented Oct 11, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 470ded42-f2c3-4ee7-b8ce-56d6c82def2b



📥 Commits

Reviewing files that changed from the base of the PR and between b55112c and 8a819f5.




📒 Files selected for processing (7)
  • .github/workflows/pr-ci.yml
  • e2e/tests/up/provider_microsandbox.go
  • e2e/tests/up/provider_microsandbox_ephemeral.go
  • pkg/driver/microsandbox/cliclient.go
  • pkg/driver/microsandbox/cliclient_test.go
  • providers/microsandbox/provider.yaml
  • sites/docs-devsy-sh/content/docs/developing-providers/runtime-protocol.mdx



Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 1 remain after this review.





📝 Walkthrough
📝 Walkthrough
📝 Walkthrough

Walkthrough

The Microsandbox driver now leaves unspecified ephemeral root sizing to the runtime. New end-to-end tests cover default and explicit sizing, root reset and persistence through lifecycle operations, and rejection of oversized roots. CI and runtime protocol documentation include the new suite.

Changes

Ephemeral root sizing and lifecycle

Layer / File(s) Summary
Runtime-default ephemeral sizing
pkg/driver/microsandbox/cliclient.go, pkg/driver/microsandbox/cliclient_test.go, providers/microsandbox/provider.yaml
When ephemeral root storage is unspecified, the driver now emits tmpfs. The unit test and provider description reflect the runtime default.
Ephemeral provider lifecycle checks
e2e/tests/up/provider_microsandbox.go, e2e/tests/up/provider_microsandbox_ephemeral.go
The end-to-end suite covers default and explicit root sizing for built-in and external providers. It checks root reset, workspace and volume persistence, sandbox identity changes, and rejection of a root larger than initial memory. The external provider version is updated to v0.1.7.
Suite wiring and documentation
.github/workflows/pr-ci.yml, sites/docs-devsy-sh/content/docs/developing-providers/runtime-protocol.mdx
The CI matrix adds the ephemeral-provider suite. The runtime protocol documentation describes its checks and command.

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~25 minutes

Change: Bug fix





Merge Risk: ⚪ Minimal · up to 8a819

No actionable issue was established that would prevent merging. The new scenarios check sizing and lifecycle behavior, though the runtime default was not independently confirmed from runtime source.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 8a819

The change preserves explicit sizing and existing isolation controls. No introduced security issue was established. Risk remains low rather than minimal because the exact default capacity and external-provider behavior were not independently verified, and destructive recreation still has existing recovery limitations.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The directly affected resource is the writable root of a MicroSandbox VM created with ephemeral mode enabled and no explicit storage size. The changed branch does not select additional tenants, assets, credentials or services. Host workspace and named-volume data remain separate persistence owners; broader host effects of the external runtime were not verified.

Trust Boundaries and Controls

  • observed — Default-capacity selection crosses from driver policy into runtime policy. Explicit sizing still crosses as a numeric argument, and BlockEgress still produces the runtime egress-deny option. Repository source establishes these requests, not the external runtime’s enforcement or sizing formula.

Resilience and Maintainability Implications

  • observed — For non-platform CLI operations, up holds the workspace lock through execution and result saving. Stop quiesces provisioning before and after acquiring that lock. Locks are keyed by workspace identity, with an additional machine lock where applicable. These existing controls counter a blanket concurrency concern but do not establish platform-mode or direct-runtime serialization.
  • observed — The new tests retain cleanup ownership through cancellation using independently bounded, cancellation-detached cleanup for providers, labeled sandboxes and named volumes. This improves test-resource containment but does not prove recovery from runtime-process termination.

Hardening Proposals

  • proposed — Validate the final root-size and memory combination before destructive replacement, and exercise invalid or interrupted recreation. This would strengthen rollback and failure containment for the pre-existing replacement workflow; it is not an observed regression introduced by this PR.



Pre-merge checks | Passed 4 | Failed 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 9 functions across 4 files. (3 skipped: 3 … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check Passed Check skipped because no linked issues were found for this pull request.
Description Check Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check Passed The title clearly and concisely describes the primary change: aligning MicroSandbox ephemeral root defaults with the runtime behavior.

Full details: Docstring Coverage

Explanation

Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 9 functions across 4 files. (3 skipped: 3 unsupported.)


  • Fix all pre-merge checks with AI
✨ Finishing Touches
✨ Simplify code
  • Commit to this branch
  • Create a new PR





  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@netlify

netlify Bot commented Oct 11, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for images-devsy-sh canceled.

Name Link
🔨 Latest commit 8a819f5
🔍 Latest deploy log https://app.netlify.com/projects/images-devsy-sh/deploys/6acb6a20e0c1ac000807bcca

@skevetter

Copy link
Copy Markdown
Contributor Author

@greptileai review

@greptile-apps

greptile-apps Bot commented Oct 11, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[Medium impact] This PR appears safe to merge; no actionable issues were found.

Summary

Unsized MicroSandbox ephemeral roots now use the runtime default. Explicit storage sizes stay unchanged.

  • Unsized ephemeral roots use the runtime's default capacity.
  • Ephemeral-root scenarios check both MicroSandbox providers.

Diagram

%%{init: {'theme': 'neutral'}}%%
flowchart TD
  A[Build root disk arguments] --> B{Ephemeral root?}
  B -->|Yes| C{Explicit storage size?}
  C -->|No| D[Pass tmpfs; runtime chooses capacity]
  C -->|Yes| E[Pass tmpfs with explicit capacity]
  B -->|No| F[Keep existing persistent disk arguments]
Loading

Reviews (1) · Last reviewed commit: "fix(runtime): align MicroSandbox ephemer..." · Reviewed by Greptile

@skevetter

Copy link
Copy Markdown
Contributor Author

@coderabbitai full review

@coderabbitai

coderabbitai Bot commented Oct 11, 2026 •

Copy link
Copy Markdown
✅ Action performed

Full review finished.

@skevetter

Copy link
Copy Markdown
Contributor Author

Full CodeRabbit run 470ded42-f2c3-4ee7-b8ce-56d6c82def2b completed on 8a819f5 across all seven files with no actionable findings. I inspected the retained security and merge-risk notes. The runtime-default and external-provider caveats are covered by checksum-pinned MicroSandbox v0.7.7 source inspection and actual current-head CI: all six ephemeral scenarios passed, including both default-capacity and explicit-capacity cases, restart/recreation persistence, and fresh oversized-root rejection using published provider v0.1.7. All 42 selected MicroSandbox scenarios and all 77 implementation jobs passed.

Invalid recreation preservation remains a separate pre-cutover correctness gate, explicitly excluded from this PR’s claims and tracked in the driver campaign. The generic docstring-coverage warning concerns private implementation/test helpers (with unsupported files included); their names and focused invariant comments express the contract. Adding repetitive docstrings solely for this metric would not improve the code, so no change is needed.

@skevetter
skevetter marked this pull request as ready for review October 11, 2026 12:55
@skevetter
skevetter merged commit 2a72a4c into main Oct 11, 2026
99 checks passed
@skevetter
skevetter deleted the codex/microsandbox-ephemeral-parity branch October 11, 2026 12:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant