Repository navigation
feat(driver): host external runtime lifecycle operations - #1383
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
⛔ Files ignored due to path filters (1)
📒 Files selected for processing (14)
Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThis change adds an external runtime host that negotiates Runtime Protocol v1 capabilities and forwards lifecycle operations through supervised plugin processes. It adds the hidden supervisor command, error conversion and redaction, runtime validation, tests, dependency records, and driver documentation. ChangesExternal runtime host
Priority: ➖ Normal Estimated code review effort: 4 (Complex) | ~60 minutes Change: Feature Sequence Diagram(s)sequenceDiagram
participant HostNew as Host.New
participant HostCall as Host.call
participant Supervisor as internal runtime-supervisor
participant RuntimePlugin as Runtime plugin
HostNew->>HostCall: Request runtime Info
HostCall->>Supervisor: Launch supervised plugin call
Supervisor->>RuntimePlugin: Start plugin process
RuntimePlugin-->>HostCall: Return InfoResponse
HostCall-->>HostNew: Return validated InfoResponse
Merge Risk: ⚪ Minimal · up to No actionable issue was established in the new external runtime host. It is mergeable after normal checks. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The new runtime executes trusted provider code with inherited environment access, making executable integrity and cleanup important. Workspace integration remains deferred, and no introduced security vulnerability was established. Provider provenance and recovery from interrupted backend changes still need validation before broader use. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 13.33% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 15 functions across 10 files. (4 skipped: 4 unsupported.)
✨ Finishing Touches✨ Simplify code
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
✅ Deploy Preview for devsydev canceled.
|
✅ Deploy Preview for images-devsy-sh ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
|
@greptileai review |
|
|
This pull request does not currently match the merge queue conditions, so it cannot be queued from here. The box comes back if it matches again. |
|
@greptileai review |
|
CodeRabbit completed its full base-to-head review of e6444a6 with no actionable findings. The docstring coverage warning is advisory: comments are retained for process ownership, handshake cancellation, declaration snapshots, launch identity, and redaction boundaries. Blanket comments on straightforward RPC forwarding methods would restate the code. CLI lint, pre-commit, tests, and all applicable CI checks pass, so no additional code change is warranted for that metric. |
External runtime declarations can now be exercised through an internal process host. The host verifies the prepared runtime before each operation, launches it through the SDK supervisor embedded as a hidden Devsy helper, negotiates Info, and performs preflight, Find, TargetArchitecture, RunImage, Start, Stop, and Delete calls. Each call closes and reaps its owned session; caller cancellation also interrupts handshake, and constructor Info negotiation has a bounded timeout.
Found container state is validated and converted to Devsy details, including mapping protocol
stoppedto Devsyexited. RunImage rejects unsupported mounts before RPC. Structured failures preserve canonical status, runtime category, and retryability while redacting returned messages and backend diagnostics. Runtime environment inheritance is retained, transport metadata has precedence, and workspace environment values participate in per-request redaction. Relative executable declarations additionally reject symlink escapes; these checks remain a trusted-code integrity check, not an atomic execution guarantee or a sandbox.This is workstream C2. Exec, Logs, conversion from Devsy RunOptions into protocol intent, and drivercreate/workspace registration remain subsequent stages. No image backend, custom-driver environment helper, or built-in runtime behavior is changed. Per-operation ownership remains the initial implementation; real-runtime compatibility and measurements against a full workspace launch remain gates before cutover or pooling.
Import Runtime SDK v1.2.0 and refresh generated dependency notices, including version drift already present on main. The project owner selected MPL-2.0 for the SDK; merged SDK PR #21 adds its license file. An explicit detector entry covers the published v1.2.0 archive, which lacks that file.
Validation: