User Story
As an operator running scripts in a sandbox, I need command output and downloaded files to arrive intact before a successful exit is reported, so automation can trust the bytes it receives.
Problem Statement
Large stdout and stderr streams from sandbox exec and direct SSH lose bytes while returning exit 0. The sandbox's 1 MiB rolling output log evicts unread chunks; the boundary attachment logs a lag warning and continues to publish the successful exit. Tar-over-SSH downloads can fail extraction because their input is truncated.
Impact / Why This Matters
Scripts can silently consume incomplete results as successful output. sandbox download may retry and sometimes succeed, but that is unreliable and does not protect direct SSH or stdout consumers. The workaround is manual byte-count and hash verification, which callers cannot assume for arbitrary command output.
Acceptance Criteria
Reproduction Steps
- Run a gateway and sandbox from
main at a00ea31c6.
- Run
openshell sandbox exec -n <sandbox> --no-tty --no-login-shell -- sh -c 'yes A | head -c 8388608', redirecting stdout to a file.
- Observe exit 0 but only 7,155,712 of 8,388,608 bytes received. At 16 MiB, 9,342,976 of 16,777,216 bytes arrived.
- Over direct SSH,
cat a 20,971,520-byte sandbox file. Five trials all exited 0 while returning between 20,168,704 and 20,869,120 bytes.
- A 20 MiB tar stream exited 0 with an unexpectedly short archive in three of five trials.
sandbox download failed extraction twice before a retry succeeded.
Environment
- OpenShell CLI/gateway/runtime:
0.0.117-dev.279+ga00ea31c6
- Host: Linux ARM64, Docker compute driver
- Gateway: dedicated local plaintext gateway on port 19083; supervisor and sandbox runtime built from the same commit
Logs
Sandbox log repeatedly reports main process attachment resumed after dropping retained output during the reproduction.
User Story
As an operator running scripts in a sandbox, I need command output and downloaded files to arrive intact before a successful exit is reported, so automation can trust the bytes it receives.
Problem Statement
Large stdout and stderr streams from
sandbox execand direct SSH lose bytes while returning exit 0. The sandbox's 1 MiB rolling output log evicts unread chunks; the boundary attachment logs a lag warning and continues to publish the successful exit. Tar-over-SSH downloads can fail extraction because their input is truncated.Impact / Why This Matters
Scripts can silently consume incomplete results as successful output.
sandbox downloadmay retry and sometimes succeed, but that is unreliable and does not protect direct SSH or stdout consumers. The workaround is manual byte-count and hash verification, which callers cannot assume for arbitrary command output.Acceptance Criteria
sandbox execand direct SSH are delivered byte for byte, including with a slow consumer.Reproduction Steps
mainata00ea31c6.openshell sandbox exec -n <sandbox> --no-tty --no-login-shell -- sh -c 'yes A | head -c 8388608', redirecting stdout to a file.cata 20,971,520-byte sandbox file. Five trials all exited 0 while returning between 20,168,704 and 20,869,120 bytes.sandbox downloadfailed extraction twice before a retry succeeded.Environment
0.0.117-dev.279+ga00ea31c6Logs
Sandbox log repeatedly reports
main process attachment resumed after dropping retained outputduring the reproduction.