Repository navigation
feat(runtime): negotiate recreation on RunImage - #31
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info
📝 Walkthrough
Merge Risk: ⚪ Minimal · up to No concrete issue requiring a change before merge is established; complete the normal checks. Security Architecture Review
Pre-merge checks |
|
|
@greptileai review |
|
|
@greptileai review |
|
@coderabbitai full review |
✅ Action performedFull review finished. |
|
The full current-head review covers all 13 selected source/docs/test files at d4d2d46; the organization filter excludes runtimev1/runtime.pb.go. The generated binding was covered by the full 14-file committed local review, two identical pinned generations, and passing generated-bindings CI. No actionable inline issues remain. The docstring percentage is a generic coverage warning over primarily private fixture/conformance helpers. The wire fields, compatibility boundary and authorization/validation ordering are documented in the schema and README; adding implementation-restating comments to satisfy a percentage would not improve this contract. No code change is warranted. CodeRabbit's Buf compatibility tool could not fetch old schema blob bd59cab3279f10effb9a5a8d4162ca47ca67bf24 through its unavailable proxy. That blob exactly matches the schema on current origin/main df5943d. Independently running pinned Buf 1.73.0 breaking checks against an exported copy of that exact base passed; CI Buf lint/format and generated bindings also passed. This dispositions the tool availability warning with actual compatibility evidence. The production-adoption caveat is retained: this SDK protocol/fake/conformance change does not establish production caller ownership, concurrency, retries/cancellation or later materialization/launch recovery. Those are separate provider/host integration and actual-VM campaign gates; the contract does not promise rollback of later launch failures. |
ON_RUN lets a compatible host leave an existing workspace intact until RunImage validates its effective replacement configuration. API 1.3 adds host opt-in during discovery and an explicit per-request replacement permission; old hosts retain DELETE behavior and existing providers retain their legacy modes. Discovery never grants replacement permission, including when each RPC launches a fresh process.
The optional fake-runtime profile and reusable conformance cases cover running and stopped targets, unauthorized duplicates, invalid authorized requests (including nonempty-image requests with unsupported workspace and additional mount types), valid replacement and process restarts. These tests establish the protocol contract; actual MicroSandbox replacement safety remains a separate provider and host integration gate.
Validation: full uncached SDK race suite, vet, strict lint, all nine pre-commit hooks, module verification, protobuf lint/format and two identical pinned binding generations passed. Fresh full committed local CodeRabbit reviewed all 14 files with zero findings. The follow-up conformance race suite, vet, strict lint and all nine hooks passed. All ten applicable final-head CI jobs passed, including three-platform race/spawn coverage. Fresh Greptile scored 5/5. The completed full remote CodeRabbit reviewed all 13 selected files with no actionable findings; its generated-binding exclusion is covered locally and by generation CI. The generic private-helper docstring warning and unavailable remote Buf fetch were independently dispositioned; pinned local Buf breaking checks against the exact old schema passed. Production adoption remains a separate integration gate.