Repository navigation
Conversation
Schema v98 adds the sealed read-only input projection ledger, bounded stdout/stderr log capture receipts, strict output staging receipts, and atomic output commit receipts with per-file entries. The sandbox domain pins one path rule set for Windows and Linux, demuxes and redacts the attach stream under byte/line/deadline caps, walks the exported archive with traversal/symlink/duplicate/size rejection, and commits accepted manifests in one replay-safe store transaction. The I/O transport exposes exactly two closed daemon endpoints (attach with stream=0 and archive of the dedicated output mount). The application service stays unwired from any product entry, matching the lifecycle slice boundary.
Update the project memory, status, progress, and task ledgers with the schema-v98 slice for issue CWNU-Open-Source-Community#39 and add ADR 0098 documenting the sealed read-only input projection, bounded log capture, strict output staging, atomic commit, and the closed two-endpoint daemon surface.
5 tasks done
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #39
Summary
sandbox_docker_input_projection.v1(schema v98):规范化相对路径 + SHA-256 + 大小 + 媒体类型封印到 lifecycle attempt/generation、Plan、Observation、Run/Mission/Workspace 与 Spec 指纹;输入挂载固定/run/cyberagent/inputs只读;新增真实 inspect Mounts 隔离校验——唯一可写挂载必须是专用输出挂载,输入/工作区树必须只读(容器无法写原始 Workspace)。sandbox_docker_log_capture.v1:只经POST containers/{id}/attach?logs=1&stderr=1&stdout=1&stream=0(无 live streaming);解复用器按流限制 256 KiB / 4096 行 + 墙钟时限,拒绝畸形/超大帧,非法 UTF-8 替换并计数,Secret 脱敏,只落库元数据与摘要回执(raw 不持久化)。sandbox_docker_output_staging.v1:只导出专用输出挂载的GET containers/{id}/archive;tar 走查在 Windows/Linux 同一路径规则下拒绝 absolute/traversal/反斜杠/盘符、symlink/hardlink/设备节点、重复项,限制 64 文件 / 单文件 4 MiB / 总量 16 MiB,媒体类型检测与文本脱敏后写入进程内暂存目录;被拒归档不带受信清单。sandbox_docker_output_commit.v1:接受清单必须与已完成暂存回执逐项精确一致;从暂存目录重读复哈希后,回执与全部条目在同一 SQLite 事务写入(operation key 幂等);失败不残留半提交行。Artifact 含 SHA-256、字节数、媒体类型、Run/Attempt/generation 与创建时间。Validation
go build ./...、go vet ./...go test ./internal/sandbox ./internal/store ./internal/application ./internal/events -count=1全量通过(含 v83-v97 迁移重放测试链更新至 v98)go test -race ./internal/sandbox ./internal/application -count=1通过TestREADMEListsEverySchemaVersionInOrderAudit