Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
117 commits
Select commit Hold shift + click to select a range
297fead
🩹 fix(codeapi): add session cache recovery utility (#60)
upman Aug 26, 2026
587c79b
chore(codeapi): remediate SCA dependency findings (#3414) (#71)
github-actions[bot] Sep 1, 2026
da8775f
feat: add outbound stateful code bridge (#66)
danny-avila Sep 1, 2026
89afb4e
feat: add secure code worker pairing (#67)
danny-avila Sep 1, 2026
18dadd5
🪪 feat: Add Principal-Bound Bridge Workers (#69)
danny-avila Sep 1, 2026
ea872fc
🧯 fix: Fence Worker Pairing Revocation (#70)
danny-avila Sep 1, 2026
45449ee
fix(codeapi): add UTF-8 charset defaults to busboy in upload routes (…
chottokun Sep 2, 2026
a7afac5
🧶 fix: Large Tool Inputs Break Bash PTC Replay and Pending-Call Seria…
danny-avila Sep 2, 2026
b43d127
fix(runner): reject NUL bytes in file paths (#46)
fallintoplace Sep 2, 2026
d25bdf1
🧰 feat: Add Stateful Runtime Supervisor (#72)
danny-avila Sep 2, 2026
733c832
fix(runner): fail safe on invalid output size config (#47)
fallintoplace Sep 2, 2026
0e2aec1
🧰 feat: Add Docker Runtime Supervisor (#73)
danny-avila Sep 2, 2026
5739d26
🧰 feat: Add Docker Supervisor CLI Mode (#74)
danny-avila Sep 2, 2026
0640e72
🏷️ feat: Add tagged releases (#77)
danny-avila Sep 2, 2026
50368e0
🛖 feat: Add Local NsJail Runtime Profile (#78)
danny-avila Sep 2, 2026
6967ba9
🎴 fix: Rotate PTC Replay Client Tokens (#82)
danny-avila Sep 2, 2026
543bf4e
📛 fix: Preserve Uploaded Filenames Without Metadata (#79)
danny-avila Sep 2, 2026
a1fd45e
🪫 chore: Detect Compose Sandbox Clock Drift (#81)
danny-avila Sep 2, 2026
0eb0f3a
🛳 fix: Fetch Bitnami Subcharts From OCI (#83)
danny-avila Sep 2, 2026
117c23e
🛜 feat: Add Networkless BYOM File Relay (#80)
danny-avila Sep 2, 2026
0739f3d
🗑️ fix: Make Code Environment File Deletion Work (#85)
danny-avila Sep 2, 2026
48526ef
🌳 feat: Add Confined Local Workspace Tools (#88)
danny-avila Sep 2, 2026
6508482
🏓 feat: Dispatch Worker-Local Workspace Tools (#89)
danny-avila Sep 2, 2026
0498f7d
🎖️ feat: Expose Authenticated Workspace Tool API (#90)
danny-avila Sep 3, 2026
adf2adf
🗺️ feat: List Attached Workspace Files (#92)
danny-avila Sep 3, 2026
578c8a1
🌱 feat: Create an Explicit Default Workspace (#93)
danny-avila Sep 3, 2026
e116d10
🏡 feat: Add Hosted App Runner (#57)
danny-avila Sep 3, 2026
f210c90
build(deps): bump qs to 6.16.0 and express to 5.2.1 in /api (#94)
dependabot[bot] Sep 3, 2026
b3db89c
✍️ feat: Add Opt-In BYOM Workspace Mutations (#95)
danny-avila Sep 3, 2026
82ca4f6
🖥️ feat: Define BYOM Command Protocol (#97)
danny-avila Sep 3, 2026
2b1a929
🧱 feat: Compose Sandboxed Workspace Commands (#98)
danny-avila Sep 3, 2026
1f6da22
🧰 feat: Run BYOM Commands in NsJail (#100)
danny-avila Sep 4, 2026
94c21a2
🛖 feat: Run BYOM Commands in Native Sandboxes (#101)
danny-avila Sep 4, 2026
f51fdc3
🔂 feat: Continue Bounded Workspace Listings (#106)
danny-avila Sep 4, 2026
5510e76
🔤 fix: Stabilize Truncated Workspace Search Results (#109)
danny-avila Sep 4, 2026
003524b
🧫 ci: Run Code Package Tests on Pull Requests (#110)
danny-avila Sep 4, 2026
6a3bb9c
🎖️ fix: Enforce Owner-Only Worker Credentials (#107)
danny-avila Sep 4, 2026
81610a7
🏯 fix: Guard Worker Credentials From Local Accounts (#112)
danny-avila Sep 4, 2026
3968527
📡 feat: Report BYOM Worker Readiness (#114)
danny-avila Sep 4, 2026
6043181
🚢 fix: Pack Code Protocol Into Egress Gateway Image (#108)
SSIG-IT Sep 5, 2026
8b6b2de
🔐 feat: Add Sandboxed GitHub Authentication (#115)
danny-avila Sep 6, 2026
595ade0
fix: Forward hardened Compose bridge configuration (#118)
danny-avila Sep 6, 2026
9df5cf8
🏘️ feat: Add Hosted App Control Plane (#58)
danny-avila Sep 6, 2026
5cf56df
🏺 fix: Report Artifact Delivery Failures (#119)
danny-avila Sep 6, 2026
f77e960
fix: validate sandbox workspace requests before dispatch (#124)
danny-avila Sep 7, 2026
489bc9a
fix: arbitrate bridge settlement and dispatch closure atomically (#125)
danny-avila Sep 7, 2026
49d1b67
fix: preserve terminal bridge failures and recovery guidance (#126)
danny-avila Sep 7, 2026
4650240
fix: preserve required native sandbox environment names (#129)
danny-avila Sep 7, 2026
70e8d53
fix: clean sandbox state on pre-spawn exits (#130)
danny-avila Sep 7, 2026
6365863
fix: continue bounded listings after skipped candidate windows (#132)
danny-avila Sep 7, 2026
2634f31
fix: fail closed when credential ACL verification is unavailable (#138)
danny-avila Sep 7, 2026
10bd0db
fix: validate every credential storage ancestor (#139)
danny-avila Sep 7, 2026
3104227
fix: reject identity mount targets before pairing (#140)
danny-avila Sep 7, 2026
2163130
fix(codeapi): continue bounded listings after skipped candidate windo…
github-actions[bot] Sep 8, 2026
f300263
fix: restore macOS private storage with native ACL verification (#146)
danny-avila Sep 8, 2026
1ef326a
fix: clamp runtime timeout caps at the sandbox limit (#148)
danny-avila Sep 8, 2026
394edaf
fix: honor timeout caps on plain execution requests (#145)
danny-avila Sep 8, 2026
6da7d0a
fix: validate private storage through open descriptors (#147)
danny-avila Sep 8, 2026
dc34012
fix: bind GitHub App token requests to the enterprise host (#150)
danny-avila Sep 8, 2026
5fdeeeb
fix(code): support declared Node engine range (#151)
danny-avila Sep 8, 2026
725f799
fix: use runner DNS for KVM artifact service discovery (#152)
danny-avila Sep 8, 2026
d50e9bb
fix: preserve preview auth on first navigation (#153)
danny-avila Sep 8, 2026
5ee769e
🧾 fix: Log Workspace Tool HTTP Outcomes (#154)
danny-avila Sep 8, 2026
b243c93
🛟 fix: Recover Hosted App Stop Failures (#155)
danny-avila Sep 8, 2026
1d556c0
fix: encode the KVM resolver handoff for the kernel command line (#157)
danny-avila Sep 8, 2026
3842a7b
🚐 fix: Queue Contended BYOM Workspace Requests (#159)
danny-avila Sep 8, 2026
01a1905
fix: Isolate Native Sandbox Scratch Storage (#160)
danny-avila Sep 8, 2026
1e32bda
fix: Separate BYOM Admission and Execution Deadlines ⏱️ (#161)
danny-avila Sep 8, 2026
499fb58
fix: Fence Native SRT Lifecycle Ownership (#162)
danny-avila Sep 8, 2026
c888fec
feat: Isolate Native SRT Executor Processes (#163)
danny-avila Sep 8, 2026
feb9ed5
fix: Preserve Replacement Bridge Lease Ownership (#165)
danny-avila Sep 9, 2026
bf466d3
feat(codeapi): import Isolate Native SRT Executor Processes (#166)
github-actions[bot] Sep 9, 2026
f3572e0
fix: Harden Native Scratch Cleanup (#168)
danny-avila Sep 9, 2026
71308b5
feat: Add Bounded Concurrent BYOM Workspace Leases (#167)
danny-avila Sep 9, 2026
6abed11
🫗 fix: Drain Cancelled BYOM Settlements (#172)
danny-avila Sep 9, 2026
9cbff26
fix(codeapi): require bridge credentials only when configured (#171)
github-actions[bot] Sep 10, 2026
1198759
fix(api): stream uploads to the file-server with fetch; bump Bun to 1…
mihidumh Sep 10, 2026
3142a2f
fix: fail denied input downloads once per batch (#177)
danny-avila Sep 11, 2026
794df9e
fix: preserve retries for transient egress ledger conflicts (#179)
danny-avila Sep 11, 2026
dead07b
perf: reuse authorized input versions and make egress accounting atom…
danny-avila Sep 11, 2026
a992ec0
🧹 fix: Evict Stale File-Object Index Entries (#182)
danny-avila Sep 12, 2026
c3fd558
perf: enable authorized input reuse by default (#183)
danny-avila Sep 12, 2026
76129e1
fix: honor requested input destinations (#184)
danny-avila Sep 12, 2026
9d3936f
fix: disambiguate legacy dotted object identities (#186)
danny-avila Sep 12, 2026
3946ffb
fix: helm egress deployment getting stuck on install (#176)
Ian321 Sep 12, 2026
8a90f6d
feat: Add Trusted VM Command Policy (#187)
danny-avila Sep 12, 2026
31def17
fix: Retry Clean Cancelled BYOM Settlements Through Stop Grace (#188)
danny-avila Sep 13, 2026
118eb9b
fix: Release Unassigned Workspace Slots When Dispatch Cleanup Fails (…
danny-avila Sep 13, 2026
8764d01
fix: Exit Cleanly When Native Executor Shuts Down Concurrently (#191)
danny-avila Sep 13, 2026
25f3841
fix: authenticate GitHub App Git operations (#192)
danny-avila Sep 14, 2026
1c7af88
fix: isolate file deletion rate limits (#193)
danny-avila Sep 14, 2026
737f498
feat: broker GitHub CLI authentication (#194)
danny-avila Sep 14, 2026
03e2fc1
feat: Run PTC in Selected BYOM Workspaces (#195)
danny-avila Sep 14, 2026
e4815fa
feat: Report Truncated Output Artifacts (#199)
danny-avila Sep 14, 2026
f181b4d
fix: cancel selected-workspace PTC across processes (#196)
danny-avila Sep 14, 2026
3e7b107
fix: classify capped artifact probe candidates (#206)
danny-avila Sep 14, 2026
6ca38b2
feat: Report Deleted Code Session Files (#200)
danny-avila Sep 14, 2026
926569e
fix: preserve trusted jq path for PTC (#207)
danny-avila Sep 14, 2026
10ac19b
fix: isolate native PTC readiness and watchdog phases (#208)
danny-avila Sep 14, 2026
3a2c2a0
feat: Declare Named Worker Project Environments (#209)
danny-avila Sep 14, 2026
f2dcb93
fix: Allow Trusted Own-Root Environment Symlinks (#212)
danny-avila Sep 15, 2026
840537b
fix: Retain Quarantine After Failed Environment Setup (#213)
danny-avila Sep 15, 2026
9a3f5db
fix: Allow Lambda MicroVM metadata in hardened mode (#215)
danny-avila Sep 15, 2026
c03d309
docs: add self-hosted worker setup runbook (#219)
danny-avila Sep 16, 2026
6dbf03b
fix: bound memory buffering for streamed file uploads (#218)
jacksonriding Sep 16, 2026
3a3003a
ci: Automate Auditable Main Releases (#216)
danny-avila Sep 16, 2026
f6cdfb3
fix: forward input-file limit into sandbox guests (#217)
jacksonriding Sep 16, 2026
b35c503
feat: Inspect Local Coding Projects (#221)
danny-avila Sep 16, 2026
999c2e5
docs(project): add upstream v1.1.0 integration plan
Sep 17, 2026
680df07
chore(reconcile): merge upstream v1.1.0 with fork behaviors retained
Sep 17, 2026
967e622
docs(fork): re-inventory patch ledger for upstream v1.1.0
Sep 17, 2026
53ed390
fix(reconcile): address final-review findings on the v1.1.0 merge
Sep 17, 2026
5e49e0d
docs(project): record v1.1.0 integration progress and ignore local re…
Sep 17, 2026
598793a
docs(project): record draft PR #24 and remaining gated dispositions
Sep 17, 2026
a0ebd3c
fix(reconcile): close confirmation-review findings on the v1.1.0 merge
Sep 17, 2026
4f610b7
docs(project): record the confirmation review and its fix commit
Sep 17, 2026
277bea9
docs(project): mark the v1.1.0 integration plan executed
Sep 17, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
16 changes: 16 additions & 0 deletions .env.example
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,22 @@ SANDBOX_RUN_CPU_TIME=10000
SANDBOX_RUN_TIMEOUT=15000
SANDBOX_OUTPUT_MAX_SIZE=65536

# Docker Compose keeps hardened mode enabled. Its API exposes bridge routes even
# with the default HTTP sandbox backend, so configure a private enrollment token
# of at least 32 bytes before starting Compose (generate with: openssl rand -hex 32).
# Do not use a shared example token. These defaults accept paired dynamic workers;
# enrollment still requires the token. Never provide this token to sandbox code.
CODEAPI_BRIDGE_TOKEN=
CODEAPI_BRIDGE_AUTH_MODE=paired
CODEAPI_BRIDGE_DYNAMIC_WORKERS=true
# For a fixed worker, set DYNAMIC_WORKERS=false and WORKER_ID to that worker's ID.
CODEAPI_BRIDGE_WORKER_ID=

# Remote stateful code bridge (Code API deployment)
# CODEAPI_SANDBOX_BACKEND=remote-bridge
# CODEAPI_EXECUTION_PROFILE=stateful
# CODEAPI_RUNTIME_SESSION_MODE=affinity

# Service Configuration
PYTHON_CONCURRENCY=5
OTHER_CONCURRENCY=15
Expand Down
31 changes: 31 additions & 0 deletions .github/release.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,31 @@
# Categories for the changelog `gh release create --generate-notes` appends to
# every release body (see .github/workflows/release.yml). Labels are matched
# against the merged pull requests in the range; anything unlabelled lands in
# "Other changes" rather than being dropped, which matters here because sync
# pull requests from the internal monorepo usually carry no labels.
changelog:
exclude:
labels:
- duplicate
- invalid
- wontfix
categories:
- title: Security
labels:
- security
- title: Features
labels:
- enhancement
- feature
- title: Fixes
labels:
- bug
- title: Documentation
labels:
- documentation
- title: Dependencies
labels:
- dependencies
- title: Other changes
labels:
- '*'
65 changes: 65 additions & 0 deletions .github/scripts/next-release-version.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,65 @@
#!/usr/bin/env bash

set -euo pipefail

if [ "$#" -ne 2 ]; then
echo "usage: $0 <current-vMAJOR.MINOR.PATCH> <git-revision-range>" >&2
exit 2
fi

CURRENT_TAG="$1"
REVISION_RANGE="$2"

if [[ ! "$CURRENT_TAG" =~ ^v([0-9]+)[.]([0-9]+)[.]([0-9]+)$ ]]; then
echo "current release must be a stable vMAJOR.MINOR.PATCH tag (got '$CURRENT_TAG')" >&2
exit 2
fi

# Documentation, workflow, and test-only changes remain auditable in git but do
# not produce a deployable release. Any unrecognised path is treated as
# deployable so a newly added runtime component cannot silently miss a release.
DEPLOYABLE=false
while IFS= read -r path; do
case "$path" in
.github/*|docs/*|tests/*|*.md|*/README|*/README.*|*.test.*|*.spec.*)
;;
*)
DEPLOYABLE=true
break
;;
esac
done < <(git diff --name-only "$REVISION_RANGE")

if [ "$DEPLOYABLE" = "false" ]; then
exit 0
fi

COMMIT_MESSAGES="$(git log --format='%s%n%b' "$REVISION_RANGE")"
BUMP=patch

if grep -Eq '^[[:alnum:]_-]+(\([^)]*\))?!:' <<<"$COMMIT_MESSAGES" \
|| grep -Eq '^BREAKING([ -])CHANGE:' <<<"$COMMIT_MESSAGES"; then
BUMP=major
elif grep -Eq '^feat(\([^)]*\))?:' <<<"$COMMIT_MESSAGES"; then
BUMP=minor
fi

VERSION="${CURRENT_TAG#v}"
IFS=. read -r MAJOR MINOR PATCH <<<"$VERSION"

case "$BUMP" in
major)
MAJOR=$((MAJOR + 1))
MINOR=0
PATCH=0
;;
minor)
MINOR=$((MINOR + 1))
PATCH=0
;;
patch)
PATCH=$((PATCH + 1))
;;
esac

printf 'v%s.%s.%s\n' "$MAJOR" "$MINOR" "$PATCH"
106 changes: 100 additions & 6 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -31,14 +31,44 @@ jobs:
- name: Block-root package delivery
run: tests/block_root_package_delivery.sh

- name: KVM guest resolver handoff
run: tests/kvm_guest_dns.sh

- name: Sandbox-runner liveness checks
run: tests/sandbox_runner_healthcheck.sh

- name: Bridge pairing rollout safety
run: tests/bridge_pairing_rollout.sh

- name: Compose bridge configuration
run: node tests/compose-bridge-config.cjs

- name: Release versioning
run: tests/release-versioning.sh

- name: Validate sandbox Dockerfiles
run: |
docker buildx build --check -f api/Dockerfile .
docker buildx build --check -f docker/Dockerfile.worker-sandbox .

launcher-unit-tests:
name: Launcher Unit Tests
runs-on: ubuntu-latest
container: fedora:43
defaults:
run:
working-directory: launcher
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6

- name: Install Rust and libkrun
# Mirrors launcher/Dockerfile's builder stage; libkrun is only packaged
# for Fedora, and the guest-environment checks link against it.
run: dnf install -y --setopt=install_weak_deps=False rust cargo libkrun-devel gcc

- name: Cargo tests
run: cargo test

api-unit-tests:
name: API Unit Tests
runs-on: ubuntu-latest
Expand Down Expand Up @@ -113,12 +143,70 @@ jobs:
- name: Install dependencies
run: bun ci

- name: Install Redis for ledger integration tests
run: sudo apt-get update && sudo apt-get install -y redis-server

- name: Build service
run: bun run build

- name: Bun tests
run: bun run test

code-package-tests:
name: Code Package Tests (Node ${{ matrix.node-version }})
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
node-version: ['20.11.0', '22.21.0', '24.16.0']
defaults:
run:
working-directory: packages/code
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6

- uses: actions/setup-node@249970729cb0ef3589644e2896645e5dc5ba9c38 # v6
with:
node-version: ${{ matrix.node-version }}
cache: npm
cache-dependency-path: packages/code/package-lock.json

- name: Install ripgrep
# list_files and search_text shell out to rg. Without it the workspace
# tools degrade to LIST_UNAVAILABLE / SEARCH_UNAVAILABLE and 37 tests
# fail, so the dependency is part of the job, not an assumption.
run: |
sudo apt-get update
sudo apt-get install -y --no-install-recommends ripgrep

- name: Install dependencies
run: npm ci

- name: Tests
run: npm test

macos-storage-tests:
name: macOS Storage ACL Tests
runs-on: macos-14
defaults:
run:
working-directory: packages/code
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
- uses: actions/setup-node@249970729cb0ef3589644e2896645e5dc5ba9c38 # v6
with:
node-version: 24.16.0
- run: npm ci
- run: npm run build
- name: Native environment containment tests
run: node --test dist/environment.test.js
- name: Native ACL and credential lifecycle tests
run: node --test dist/macos-storage.test.js dist/private-storage.test.js dist/storage.test.js dist/github.test.js
- name: Native environment setup lifecycle tests
env:
LIBRECHAT_CODE_LIVE_SRT_TESTS: '1'
run: node --test dist/environment-live.test.js

lambda-microvm-provisioning:
name: Lambda MicroVM Provisioning
runs-on: ubuntu-latest
Expand Down Expand Up @@ -156,12 +244,17 @@ jobs:
shellcheck scripts/build-lambda-microvm-artifact.sh

- name: Validate runner Dockerfile
run: >-
docker buildx build --check
--platform linux/arm64
--target lambda-microvm-runner
-f api/Dockerfile
.
run: |
docker buildx build --check \
--platform linux/arm64 \
--target lambda-microvm-runner \
-f api/Dockerfile \
.
docker buildx build --check \
--platform linux/arm64 \
--target lambda-microvm-app-host \
-f api/Dockerfile \
.

- uses: hashicorp/setup-terraform@dfe3c3f87815947d99a8997f908cb6525fc44e9e # v4.0.1
with:
Expand All @@ -174,6 +267,7 @@ jobs:
terraform fmt -check -recursive
terraform init -backend=false -input=false -lockfile=readonly
terraform validate
terraform test

lambda-microvm-runner-build:
name: Lambda MicroVM Runner Image (arm64)
Expand Down
Loading