Add the oac-sandbox-io binary - #345
Merged
Merged
Conversation
oac-sandbox-io reads the Provider's bootstrap file, becomes a child subreaper running the one reap loop, and serves the File service (world at /) and the Process service as the Link serve peer, with attachment loss, restore and close wired to the process ownership hooks. SIGTERM stops accepting streams and cancels live operations through the new processservice Shutdown before exiting. Startup failures exit nonzero with a typed step and never the credential. Adds make build-sandbox-io (static Linux), runs apps/sandboxio in check-go, routes apps/sandboxio changes to the backend CI job, and documents the launch, responsibilities and readiness.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds
oac-sandbox-io, the Sandbox I/O service: the one process a Sandbox Provider starts in a sandbox. It reads the bootstrap file, connects to the relay as the Link serve peer, and serves the File and Process protocols on the streams the relay binds. It is wiring only.apps/sandboxio/cmd/oac-sandbox-io(Linux). Startup runs in this order:processservice.Init();--bootstrap-fileflag, its only input;PR_SET_CHILD_SUBREAPER;processservice.Reap, the process's only wait;sandboxio.Rununder a SIGTERM/SIGINT context.apps/sandboxio/internal/sandboxio,Run(ctx, path):worldat/and the Process service;*StartupError{Step, Err}, whose message never includes the credential;processservice.Shutdown(ctx). On SIGTERM it cancels live operations as ownership cleanup does (TERM, then KILL after the grace limit) and waits for them to end.make build-sandbox-iobuilds a static Linux binary (CGO_ENABLED=0). It is not added to an image or a Provider yet.apps/sandboxio/is classified as backend, so sandbox PRs no longer run the full gate as "Unclassified input".docs/sandbox-bootstrap.md: the launch command and a "Responsibilities and readiness" section.docs/process-protocol.md:Shutdown.docs/development.md: the repository-map row now names the binary and links the File and Process docs.docs/sandbox-link-protocol.md: the cancel/write race residual that the File and Process docs already state.The Network service is wired by the network protocol PR.
Test: an in-process end-to-end test runs
runagainst the test relay with a temporary bootstrap file and a temp-dir root. It covers:world;sh -c 'echo hi; exit 7'givinghi,Exited7 andOutputClosed;InstanceChanged;Checks:
go test -raceoverapps/sandboxio/...check-namesmake build-sandbox-ioproduced a static ELFPart of the agent-outside-sandbox work, milestone M1, lane L3b.
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.