馃О feat: Share Explicit Environment Tool Resources - #287
Merged
Merged
Conversation
danny-avila
added this pull request to stack #290
October 2, 2026 03:06
danny-avila
force-pushed
the
danny-avila/shared-environment-resources
branch
from
October 2, 2026 03:11
1ee768b to
24d104a
Compare
danny-avila
removed this pull request from stack #290
October 2, 2026 03:13
danny-avila
changed the base branch from
danny-avila/environment-preparation
to
main
October 2, 2026 03:13
danny-avila
force-pushed
the
danny-avila/shared-environment-resources
branch
from
October 2, 2026 03:14
24d104a to
cea4edf
Compare
danny-avila
force-pushed
the
danny-avila/shared-environment-resources
branch
from
October 2, 2026 03:21
308756c to
db04a6a
Compare
danny-avila
added this pull request to stack #292
October 2, 2026 11:23
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Worktree-local package caches and browser downloads multiply storage even when tasks use identical tools. Add explicit per-environment stores for npm/uv downloads and Playwright browser binaries, without granting a broad parent directory or sharing mutable installations.
Mechanism
Operator YAML declares each known resource kind, absolute existing directory and read-only/read-write access. The worker loads private inode-bound roots, rejects overlap with every workspace/control path including Linux mount aliases, and forwards only that environment's grants through native executor IPC. Root commands, linked lanes and conversation instances receive fixed cache variables from the loaded definition.
Native SRT grants precisely those resource roots. Browser profiles, service data and build output remain checkout-local. Read-only resources stay read-only; speculative programmatic probes may read resources but cannot write them. Replacing a resource root rejects commands before dispatch, with mutation-atomic diagnostics rather than an unnecessary quarantine.
This is stack slice 2, based on #286. It shares downloads and browser binaries, not installed dependency trees, and does not yet add eviction or quotas. Configuration and trust-domain limitations are documented in the worker README. Nothing changed on a live worker.
Verification
git diff --check.A broader native-sandbox unit run also exposed an existing macOS
/varalias fixture failure; it reproduces unchanged on the parent of this slice. Existing FileHandle GC warnings also remain outside this change. Broad cross-platform coverage is left to CI.