Skip to content

feat(protocol): carry workspace developer identity - #22

Merged
skevetter merged 1 commit into
mainfrom
codex/runtime-workspace-identity
Oct 7, 2026
Merged

skevetter merged 1 commit into
mainfrom
codex/runtime-workspace-identity

Conversation

@skevetter

@skevetter skevetter commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Runtime Protocol v1 currently drops the developer identity and Dockerless provisioning mode from Devsy’s image-run intent. MicroSandbox uses both to resolve bind-mount ownership and reject unsafe ownership resolution before resource changes.

Add RunImageRequest.remote_user (field 20) and dockerless (field 21), regenerate the Go bindings, and advance the Info API minor from 0 to 1. Keep the process user separate from the developer identity; an empty remote user falls back to the process user, then root. Document that Dockerless image contents may not yet contain the final developer identity.

The README defines each field and the required host/runtime handoff. The SDK is not deployed yet, so this change follows current Devsy semantics without a legacy compatibility layer or old-schema fixtures.

This is a prerequisite for MicroSandbox server integration. Devsy host forwarding and the runtime’s ownership implementation follow after this SDK release; this PR does not switch providers or change resource replacement policy.

Validation:

  • Full race-enabled Go tests and vet passed, including existing process/stream probes.
  • Strict Go lint/formatting and all prek hooks passed.
  • Protobuf lint/formatting, pinned binding regeneration, and Buf breaking check against origin/main passed.
  • Fresh local CodeRabbit review covered all four changed files with zero findings.
  • Commit a8b968f has a GitHub-verified signature. All nine applicable CI jobs passed; Release Please skipped as expected for a PR. Greptile reviewed this head at 5/5 with zero findings. Full GitHub CodeRabbit review completed for this head with no actionable findings or retained architectural concerns. It reviewed all three authored files; generated bindings were excluded by its normal filter, included in fresh local review, and verified by CI regeneration. Its embedded Buf tool could not fetch the base schema because its runner proxy was unavailable; independent local schema checks and CI Buf/generation checks passed. All applicable checks are successful, and the PR remains draft for human review.

@coderabbitai

coderabbitai Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 4baa9144-b62c-4842-a563-19bd4b93c53e
📥 Commits

Reviewing files that changed from the base of the PR and between f0e065b and a8b968f.

⛔ Files ignored due to path filters (1)
  • runtimev1/runtime.pb.go is excluded by !**/*.pb.go
📒 Files selected for processing (3)
  • README.md
  • proto/devsy/runtime/v1/runtime.proto
  • runtimev1/validate.go

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The API minor version advances to 1. RunImageRequest adds fields for workspace identity and host-side environment provisioning. The README documents their behavior and constraints.

Changes

API 1.1 workspace identity

Layer / File(s) Summary
API 1.1 contract and documentation
proto/devsy/runtime/v1/runtime.proto, runtimev1/validate.go, README.md
RunImageRequest adds remote_user and dockerless. APIMinor changes to 1. The README documents identity fallback, provisioning intent, and constraints on modifying workspace resources.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Feature

Merge Risk: ⚪ Minimal · up to a8b96

This change adds the documented API fields and generated accessors, with no demonstrated current in-repository compatibility failure.

Security Architecture Review

Security architecture risk: 🔵 Low · up to a8b96

The change adds identity and provisioning information without changing current resource operations. Correct ownership handling depends on a later host/runtime integration that is not included here.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The intended sensitive outcome is workspace ownership resolution by a consuming runtime, potentially including bind-mounted host data. The changed SDK surface carries the inputs but does not establish an independently attackable host-filesystem mutation path, tenant scope, or privilege gain. Those exposures depend on the downstream implementation.

Trust Boundaries and Controls

  • observed — The existing executable trust boundary remains host-owned: the host selects a trusted executable, and the handshake cookie neither authenticates nor sandboxes it. The new workspace identity is distinct from process identity and does not authorize resource replacement.

Hardening Proposals

  • proposed — Before enabling ownership-dependent integration, establish support for the new semantics explicitly and validate the authoritative developer identity within the allowed workspace scope. Integration checks should cover identity fallback, an identity absent from a Dockerless image, rejection before mutation, and retry or interruption recovery without unintended replacement.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 1…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the primary protocol change: carrying workspace developer identity. This matches the added remote_user field and related protocol updates.
✨ Finishing Touches
✨ Simplify code
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@skevetter

Copy link
Copy Markdown
Contributor Author

@greptileai review

@greptile-apps

greptile-apps Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[Critical risk] Extends the runtime protocol with new workspace identity fields.

This PR appears safe to merge.

What we checked:

  • New fields survive forwarding: The bindings declare both fields, and the server forwards the decoded request without rebuilding it.
  • Minor bump preserves connections: ValidateInfo checks only the major version. The tests explicitly allow a newer minor version.

Summary

Adds workspace developer identity and provisioning intent to Runtime Protocol API 1.1.

  • Image-run requests carry workspace identity and Dockerless intent.
Diagram
%%{init: {'theme': 'neutral'}}%%
flowchart LR
  H["Host: RunImageRequest"] --> U["user: process identity"]
  H --> R["remote_user: workspace identity"]
  H --> D["dockerless: host provisions later"]
  R --> F["Empty: use user, then root"]
  D --> V["Runtime checks identity before workspace changes"]
  F --> V
Loading

Reviews (1) · Last reviewed commit: "feat(protocol): carry workspace develope..." · Reviewed by Greptile

@skevetter

Copy link
Copy Markdown
Contributor Author

@coderabbitai full review

@coderabbitai

coderabbitai Bot commented Oct 7, 2026 •

Copy link
Copy Markdown
✅ Action performed

Full review finished.

@skevetter

Copy link
Copy Markdown
Contributor Author

Final-head review is complete for a8b968f: Greptile 5/5, full CodeRabbit review with no actionable findings or retained architectural concerns, all nine CI jobs successful, and a verified signature. CodeRabbit’s embedded Buf tool could not fetch the base schema because its runner proxy was unavailable. Independent local buf lint, buf format, and buf breaking against origin/main passed; CI also passed Buf lint/format and pinned binding regeneration. The generated bindings were included in the fresh local CodeRabbit review. Host forwarding and runtime ownership validation remain follow-up integration work, as described in the PR.

@skevetter
skevetter marked this pull request as ready for review October 7, 2026 14:51
@skevetter
skevetter merged commit 3963197 into main Oct 7, 2026
12 checks passed
@skevetter
skevetter deleted the codex/runtime-workspace-identity branch October 7, 2026 14:51
@devsy-app devsy-app Bot mentioned this pull request Oct 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant