Skip to content

📦 feat: Restore Isolated Dependency Snapshots - #288

Merged
danny-avila merged 2 commits into
mainfrom
danny-avila/dependency-snapshots
Oct 2, 2026
Merged

danny-avila merged 2 commits into
mainfrom
danny-avila/dependency-snapshots

Conversation

@danny-avila

Copy link
Copy Markdown
Collaborator

Summary

Fresh coding checkouts currently repeat installation and allocate a full mutable dependency tree even when their declared install inputs match. Add an opt-in private copy-on-write snapshot store to environment preparation. Existing definitions and existing installations retain their behavior.

Mechanism

declared inputs + recipe + project + policy + toolchain
                      │
                portable key lock
                      │
       missing installation ── snapshot exists
                      │               │
                 sandbox setup    isolated reflink restore
                      └──── readiness + unchanged inputs ────┐
                                                   checkout receipt
  • Keep the store outside source, credentials and granted tool caches, denied to native commands.
  • Preserve relative checkout-local package links; reject escaping links, special files and bounded traversal overflows. Descriptor-anchored access and exclusive rename prevent replacement of existing destinations.
  • Publish only a complete snapshot. Require actual filesystem clones, never writable hardlinks or a full-copy fallback. Unsupported or cross-filesystem configurations fail before setup.
  • Serialize one fingerprint with kernel locks, leaving other fingerprints independent. Revalidate the store after waiting.

This is stacked on #287. It handles startup and fresh managed conversation preparation, not automatic installation in manually created linked lanes, Python virtualenv relocation, arbitrary shell-write quotas or garbage collection. Ordinary ext4 deployments should leave this option disabled.

Verification

  • Worker TypeScript build passed.
  • Focused preparation, environment, storage, root-access and real CLI checks: 63 passed, 4 platform-fixture skips.
  • Included real APFS cloning and native-SRT canaries: separate file inodes, write isolation, preserved local links, changed lockfile invalidation, skipped second setup and denied store access.
  • git diff --check passed.

Live workers and deployments are unchanged. Linux reflink integration requires a clone-capable volume and the explicit live-snapshot test flag; it was not exercised locally on this Mac.

@danny-avila
danny-avila added this pull request to stack #290 October 2, 2026 03:06
@danny-avila
danny-avila force-pushed the danny-avila/shared-environment-resources branch from 1ee768b to 24d104a Compare October 2, 2026 03:11
@danny-avila
danny-avila force-pushed the danny-avila/dependency-snapshots branch from ea00213 to 94e7069 Compare October 2, 2026 03:11
@danny-avila
danny-avila removed this pull request from stack #290 October 2, 2026 03:13
@danny-avila
danny-avila force-pushed the danny-avila/shared-environment-resources branch from 24d104a to cea4edf Compare October 2, 2026 03:14
@danny-avila
danny-avila force-pushed the danny-avila/dependency-snapshots branch from 94e7069 to 491f3f3 Compare October 2, 2026 03:23
@danny-avila
danny-avila added this pull request to stack #292 October 2, 2026 11:23
@danny-avila
danny-avila force-pushed the danny-avila/dependency-snapshots branch from 491f3f3 to 7241de1 Compare October 2, 2026 11:28
@danny-avila
danny-avila force-pushed the danny-avila/shared-environment-resources branch from db04a6a to 42a7fcd Compare October 2, 2026 11:29
@danny-avila
danny-avila removed this pull request from stack #292 October 2, 2026 11:37
@danny-avila
danny-avila changed the base branch from danny-avila/shared-environment-resources to main October 2, 2026 11:37
@danny-avila
danny-avila merged commit cdb457d into main Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant