Repository navigation
feat(sandboxes): add Python session and execution facade - #372
Conversation
|
@codex review |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 2ca167225e
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 0cc65f1855
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
swkeever
left a comment
There was a problem hiding this comment.
Approving. Transport, per-operation credential routing, idempotency headers, binary encoding, and the exec timeout budget all line up with Hosting#1354, and both Codex threads are addressed.
Inline comments are non-blocking, but the public-type ones (timestamps/state as str, public internals) are much cheaper to change before release than after.
tkkhq
left a comment
There was a problem hiding this comment.
The credential-routing and cleanup findings are resolved: created handles retain service credentials, and cleanup accepts terminating sessions and HTTP 404. The focused Sandbox tests passed; granted-user hosted acceptance must use Hosting with the expired-token HTTP 401 fix.
Summary
Add the Python Sandbox facade for one-shot commands, sessions, lifecycle operations, binary files, scoped HTTP access, and backend-managed user grants. Preserve caller request IDs, nonzero command results, credential scope, refresh identity, and body exceptions during cleanup.
Synced with current main. The vendored contract preserves existing operations and adds canonical Hosting Sandbox operations; generated implementation stays internal.
One-shot execution options now exclude session-only lifecycle fields, with native typing regressions. Public preset discovery works for anonymous, signed-in, and service clients without sending Authorization; management and granted-session credential rules remain scoped.
Ordinary requests retain the configured client timeout. Only command execution adds an explicit command budget, while preserving longer client timeouts. Removed an immediately overwritten public-client timeout setting and verified the final HTTP endpoint and timeout behavior.
Created handles retain service credentials for their lifetime, while
get()continues to use refreshable user credentials. Context cleanup skips terminating/terminated sessions, accepts an already-removed 404, and preserves body exceptions. Session metadata is read-only; expiry values and grant arguments use awaredatetimevalues and state usesSandboxState.Synced the three public preset request properties with Hosting's catalog-owned string contract and regenerated the internal models. Documentation distinguishes session timeout results from one-shot 504 errors and same-key 409 unknown-outcome retries.
Sandbox generation now runs a scoped native Ruff post-hook to remove trailing whitespace and extra EOF lines. Fresh generation is deterministic and
git diff --check origin/main...HEADpasses; generated runtime syntax and values are unchanged.The binary file example uses
/workspace/input.binfor write, read, and command access, matching the guest file API's workspace boundary.Validation
_transport_baseand_transport_sandboxpassed: 18 killed and 29 type-checked mutants, zero surviving mutants or failures._sandbox,sandbox_session,sandboxes, andclientpassed after the latest review fixes: 484 killed and 478 type-checked mutants; zero survivors or gate failures.156bbcb. Generator whitespace fix74c7a7apassed the full 2,336-test suite, deterministic generation, whole-repository format/lint/policy checks, and branch diff integrity; its remote CI is pending.6417239passed the native whole-repository format check and branch diff integrity; current remote CI is pending.33a44d2wheel 0.13.5 passed isolated installed-package binding discovery for all 51 scenarios. This was native discovery only, not container or live execution.Coordination
Hosting Kong/volcano-hosting#1354; JavaScript Kong/volcano-sdk-js#270; Ruby Kong/volcano-sdk-ruby#316. Hosting staging acceptance uses SDK main, so merge the SDK PRs before final cross-language acceptance. No package publication.