You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Unsized ephemeral roots currently force an 8 GiB tmpfs disk in the built-in driver, exceeding the default 2 GiB memory allocation. Delegate unsized disks to the runtime default while retaining explicit storage sizing, matching the published external provider v0.1.7 repair.
Add six shared scenarios across both drivers: default and explicit ephemeral capacity with root reset on restart, persistence of host workspace and named-volume content through restart/recreation, and fresh oversized-root rejection without a test-labeled VM or source changes. Active configuration, guest capacity, creation time and boot IDs distinguish the behaviors. Pin the shared external fixture to the actual published v0.1.7 release and add the required KVM CI entry.
Local validation passed: the unsized-argument regression fails against the old implementation and passes with the fix; uncached race tests for the driver, provider and E2E up packages, vet, strict lint, module verification and all 13 repository hooks are green. The dry run selects all six new cases. Fresh full committed local CodeRabbit review completed with zero findings across all seven PR files. All 77 implementation CI jobs passed on the current head, including actual lifecycle (2), image (6), mount (10), resource (12), persistent-storage (6), and ephemeral-root (6) scenarios with both drivers and published external v0.1.7. Fresh Greptile review covers the current head with confidence 5/5 and no actionable findings. Full remote CodeRabbit review completed on the current head across all seven files with no actionable findings. Retained scope caveats and the private-helper docstring warning are dispositioned in the review discussion.
This changes RAM-backed root sizing, not the runtime's separate sandbox-record deletion flag. Validation before destructive invalid recreation remains a separate correctness task before provider cutover. Egress, prebuilds, Dockerless behavior, logs, cancellation and compatibility coverage remain separate work.
Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 1 remain after this review.
📝 Walkthrough
📝 Walkthrough
📝 Walkthrough
Walkthrough
The Microsandbox driver now leaves unspecified ephemeral root sizing to the runtime. New end-to-end tests cover default and explicit sizing, root reset and persistence through lifecycle operations, and rejection of oversized roots. CI and runtime protocol documentation include the new suite.
The end-to-end suite covers default and explicit root sizing for built-in and external providers. It checks root reset, workspace and volume persistence, sandbox identity changes, and rejection of a root larger than initial memory. The external provider version is updated to v0.1.7.
Suite wiring and documentation .github/workflows/pr-ci.yml, sites/docs-devsy-sh/content/docs/developing-providers/runtime-protocol.mdx
The CI matrix adds the ephemeral-provider suite. The runtime protocol documentation describes its checks and command.
No actionable issue was established that would prevent merging. The new scenarios check sizing and lifecycle behavior, though the runtime default was not independently confirmed from runtime source.
Security Architecture Review
Security architecture risk:🔵 Low · up to 8a819
The change preserves explicit sizing and existing isolation controls. No introduced security issue was established. Risk remains low rather than minimal because the exact default capacity and external-provider behavior were not independently verified, and destructive recreation still has existing recovery limitations.
Retained concerns
No architecture-level concerns identified.
Security review details
Security Blast Radius
inferred — The directly affected resource is the writable root of a MicroSandbox VM created with ephemeral mode enabled and no explicit storage size. The changed branch does not select additional tenants, assets, credentials or services. Host workspace and named-volume data remain separate persistence owners; broader host effects of the external runtime were not verified.
Trust Boundaries and Controls
observed — Default-capacity selection crosses from driver policy into runtime policy. Explicit sizing still crosses as a numeric argument, and BlockEgress still produces the runtime egress-deny option. Repository source establishes these requests, not the external runtime’s enforcement or sizing formula.
Resilience and Maintainability Implications
observed — For non-platform CLI operations, up holds the workspace lock through execution and result saving. Stop quiesces provisioning before and after acquiring that lock. Locks are keyed by workspace identity, with an additional machine lock where applicable. These existing controls counter a blanket concurrency concern but do not establish platform-mode or direct-runtime serialization.
observed — The new tests retain cleanup ownership through cancellation using independently bounded, cancellation-detached cleanup for providers, labeled sandboxes and named volumes. This improves test-resource containment but does not prove recovery from runtime-process termination.
Hardening Proposals
proposed — Validate the final root-size and memory combination before destructive replacement, and exercise invalid or interrupted recreation. This would strengthen rollback and failure containment for the pre-existing replacement workflow; it is not an observed regression introduced by this PR.
Pre-merge checks | 4 | 1
❌ Failed checks (1 warning)
Check name
Status
Explanation
Resolution
Docstring Coverage
Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 9 functions across 4 files. (3 skipped: 3 …
Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name
Status
Explanation
Linked Issues check
Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check
Check skipped because no linked issues were found for this pull request.
Description Check
Check skipped - CodeRabbit’s high-level summary is enabled.
Title check
The title clearly and concisely describes the primary change: aligning MicroSandbox ephemeral root defaults with the runtime behavior.
Full details: Docstring Coverage
Explanation
Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 9 functions across 4 files. (3 skipped: 3 unsupported.)
Fix all pre-merge checks with AI
✨ Finishing Touches
✨ Simplify code
Commit to this branch
Create a new PR
Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.
Full CodeRabbit run 470ded42-f2c3-4ee7-b8ce-56d6c82def2b completed on 8a819f5 across all seven files with no actionable findings. I inspected the retained security and merge-risk notes. The runtime-default and external-provider caveats are covered by checksum-pinned MicroSandbox v0.7.7 source inspection and actual current-head CI: all six ephemeral scenarios passed, including both default-capacity and explicit-capacity cases, restart/recreation persistence, and fresh oversized-root rejection using published provider v0.1.7. All 42 selected MicroSandbox scenarios and all 77 implementation jobs passed.
Invalid recreation preservation remains a separate pre-cutover correctness gate, explicitly excluded from this PR’s claims and tracked in the driver campaign. The generic docstring-coverage warning concerns private implementation/test helpers (with unsupported files included); their names and focused invariant comments express the contract. Adding repetitive docstrings solely for this metric would not improve the code, so no change is needed.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Unsized ephemeral roots currently force an 8 GiB tmpfs disk in the built-in driver, exceeding the default 2 GiB memory allocation. Delegate unsized disks to the runtime default while retaining explicit storage sizing, matching the published external provider v0.1.7 repair.
Add six shared scenarios across both drivers: default and explicit ephemeral capacity with root reset on restart, persistence of host workspace and named-volume content through restart/recreation, and fresh oversized-root rejection without a test-labeled VM or source changes. Active configuration, guest capacity, creation time and boot IDs distinguish the behaviors. Pin the shared external fixture to the actual published v0.1.7 release and add the required KVM CI entry.
Local validation passed: the unsized-argument regression fails against the old implementation and passes with the fix; uncached race tests for the driver, provider and E2E up packages, vet, strict lint, module verification and all 13 repository hooks are green. The dry run selects all six new cases. Fresh full committed local CodeRabbit review completed with zero findings across all seven PR files. All 77 implementation CI jobs passed on the current head, including actual lifecycle (2), image (6), mount (10), resource (12), persistent-storage (6), and ephemeral-root (6) scenarios with both drivers and published external v0.1.7. Fresh Greptile review covers the current head with confidence 5/5 and no actionable findings. Full remote CodeRabbit review completed on the current head across all seven files with no actionable findings. Retained scope caveats and the private-helper docstring warning are dispositioned in the review discussion.
This changes RAM-backed root sizing, not the runtime's separate sandbox-record deletion flag. Validation before destructive invalid recreation remains a separate correctness task before provider cutover. Egress, prebuilds, Dockerless behavior, logs, cancellation and compatibility coverage remain separate work.