Repository navigation
test(runtime): cover MicroSandbox mount parity - #1453
Conversation
✅ Deploy Preview for devsydev ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info
📝 Walkthrough
Merge Risk: ⚪ Minimal · up to No actionable issue remains from this review; the change is mergeable after normal checks. Security Architecture Review
Pre-merge checks |
|
✅ Deploy Preview for images-devsy-sh canceled.
|
|
@greptileai review |
|
|
@coderabbitai full review |
✅ Action performedFull review finished. |
|
Final-head review disposition for Full CodeRabbit run The docstring coverage warning does not justify a source change: the newly introduced functions are private, descriptively named E2E fixture/assertion/command helpers and a Go test entry point, rather than exported production API. Three functions are also marked unsupported by the analyzer. Existing comments retain the non-obvious cache, ownership, connectivity, and cleanup invariants. Strict Go lint and all repository pre-commit hooks passed. Adding comments that repeat these function names would not improve the code. All 74 implementation jobs passed, including lifecycle 2/2, image 6/6, and mount 10/10 against built-in/external v0.1.6. Fresh Greptile is 5/5 with no findings; full local review covers all six files; all five commits have valid GitHub signatures. No review threads remain. |
MicroSandbox's parity gate lacked real VM coverage for extra mounts and alternate workspace permission policies. Add ten shared scenarios across the built-in driver and external provider v0.1.6: writable/read-only binds, named-volume and tmpfs lifetime through stop/start and recreation, and strict/relaxed/off stat virtualization with private host permissions.
The tests verify guest and host contents and metadata, including read-only write rejection with a subsequent successful SSH read. Host-created permission fixtures appear after setup so recursive chown cannot mask fallback ownership. Their host owner must differ from the guest fallback, including when CI runs as root. Named volumes use unique test-owned names and are removed after workspace cleanup. A dedicated KVM CI matrix installs checksum-pinned MicroSandbox v0.7.7 with bounded suite/job deadlines; documentation records the new coverage and remaining parity work.
Validation:
e2e/tests/upande2e/framework; Ginkgo dry run selects all ten new specs.The actual VM run exposed an unquoted YAML
offenum in both manifests. The built-in manifest now quotes the policy, with an actual-parser regression that failed before the fix. External provider PR #16 published the same correction in v0.1.6, whose native release digests, manifest checksums, downloaded host bytes, and real host parser/download/version smoke were verified. All lifecycle, image, and mount suites now pin that actual release. This change keeps the built-in provider and preserves resource/networking policies. Remaining parity coverage must pass before provider cutover.The next VM run passed lifecycle (2/2), images (6/6), and eight mount cases. Both
offcases exposed a test assumption: MicroSandbox v0.7.7 caches attributes for five seconds, and bind mounts retain that default. The test now polls the same host owner and mode600for at most 15 seconds after host chmod, with a cancellable context and immediate failure on SSH errors. Strict/relaxed checks remain immediate; spec, suite, and job deadlines are unchanged. The final-head VM run passed bothoffcases and all ten mount specs.