| feat(execd): add isolation package with bwrap support (#1008) * feat(execd): add isolation package with bwrap support (OSEP-0013 Phase 1) - Add pkg/isolation/ package: Isolator interface, bwrap argv builder, startup probe, upper directory management, seccomp loading - Switch bwrap distribution from //go:embed to Dockerfile static build (musl-gcc) and init container injection alongside execd - Add isolation flags (upper root, max bytes, diff max bytes, allowed writable) with env var overrides - Add smoke test: Docker build, extract binaries, verify static link, bwrap namespace test, execd probe - Add smoke_bwrap.sh to CI workflow (ubuntu-latest only) - Defer diff/commit to Phase 2 (stub returning 503) Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * feat(execd): implement isolated session API (OSEP-0013 Phase 2) - Add isolated session model types and /v1/isolated/* router (17 endpoints) - Implement session lifecycle: Create/Get/Run/Delete with bwrap+bash - SSE streaming via basicController writeSingleEvent (context-aware) - MergedView overlay filesystem with whiteout support (20 unit tests) - Filesystem proxy endpoints (10 handlers via MergedView) - Idle GC: background goroutine scavenges sessions past idle_timeout - Bwrap integration tests (43 tests, linux+bwrap build tag) - Isolated session unit tests (15 tests, stub isolator) - CI job bwrap-smoke: meson build bwrap v0.11.2 + sudo go test - Windows stubs for cross-platform compilation - Fix: cmd.Wait() zombie cleanup, context cancellation propagation, setpriv skip when uid=0, correct v0.11.x overlay syntax Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * feat(execd): Phase 3 — seccomp, telemetry, OpenAPI spec, coverage tests (OSEP-0013) Seccomp BPF: - pkg/isolation/seccomp_gen.go — BPF generator (elastic/go-seccomp-bpf, pure Go) - Default-allow denylist: 40+ dangerous syscalls blocked (mount, ptrace, etc.) - BPF passed to bwrap via memfd + ExtraFiles fd Telemetry: - execd.isolation.session.count (gauge) - execd.isolation.run.duration (histogram, ms) - execd.isolation.upper.usage_bytes (gauge) - IsolationStatsProvider pattern for gauge callbacks OpenAPI Spec: - specs/execd-api.yaml: 17 endpoints, 10 schemas, ServiceUnavailable response Integration tests (64 total in bwrap_test/): - 5 seccomp tests (filter active, normal syscalls, ptrace block, mount block, persist) - 3 ExtraWritable tests (write, read-write roundtrip, multiple sessions) - 11 gap-coverage tests (stderr, recovery, cancellation, network iso, 100x stress, delete-recreate, bash builtins, large file, subprocess cleanup, buffer size, workspace isolation) Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * docs(spec): add /v1/isolated API to OpenAPI spec (OSEP-0013) 17 endpoints, 10 new schemas, ServiceUnavailable response. FS proxy endpoints reuse same schemas as /files/* and /directories/*. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * feat(execd): PR review fixes, TOML config, API simplification, VFS interface (OSEP-0013) Review fixes: - Fix session lifecycle: done channel prevents stdin close on normal return - Fix overlay mode: pass upper/work dirs to bwrap WrapOptions - Fix end marker mid-line concatenation with strings.Index - Extract scanUntilMarker() to reduce cognitive complexity - Add runMu serialization, upperID tracking, validateExtraWritable() - Delete dead seccomp.go (replaced by seccomp_gen.go + memfd) - Fix MergedView.ReadDir upper-takes-precedence via entryMap - Fix UpperManager.Collect delete-on-success only TOML config (replaces 4 --isolation-* flags): - New isolation.Config + LoadConfig() with go-toml/v2 - Seccomp override: [seccomp].deny fully replaces built-in denylist - configs/isolation.example.toml with documented defaults - Single --isolation-config flag + EXECD_ISOLATION_CONFIG env API simplification: - Flatten CreateIsolatedSessionRequest (remove isolation wrapper) - Delete dead PersistSpec, ArtifactURLs, IsolationSpec types - Wire up envs param with shell-escaped export prepend - Remove unused cwd from IsolatedRunRequest - Update OpenAPI spec to match VFS interface: - New pkg/vfs.FS interface for filesystem abstraction - MergedView satisfies vfs.FS (compile-time check) - Isolated file handlers use vfs.FS instead of concrete MergedView - TODO for FilesystemController migration Tests: - 6 end-to-end workflow tests (Run↔File API interop) - 2 seccomp config override e2e tests - 8 config loading tests - Document overlayfs API→Run limitation in MergedView Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * feat(sdks,server): 5-language SDK, server bwrap distribution, E2E tests (OSEP-0013) Python/Go/JS/Kotlin/C# SDKs: - IsolationService + IsolationSession handle pattern (sandbox.isolation.create() → session.run/get/delete/files) - Models, service interfaces, adapters for all 5 languages Server: - bwrap binary distribution (Docker cache + K8s init container) - bootstrap.execd.isolation=enable extension grants CAP_SYS_ADMIN + apparmor/seccomp=unconfined for bwrap namespace operations - K8s: seccompProfile + appArmorProfile on container securityContext Execd: - Probe diagnostic message in capabilities API response - bwrap path /opt/opensandbox/bwrap (alongside execd) - Shared parseUploadForm between filesystem and isolated handlers E2E tests (Python/Go/JS/Java/C#): - capabilities, lifecycle, echo, PID isolation, env injection, state persistence, /tmp isolation (strict), SSE handlers, overlay mode, file operations via run Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(execd): address PR review — env defaults, prefix bypass, timeout, EOF (OSEP-0013) 1. P1: Apply deny-blacklist env defaults when EnvPassthroughMode is empty — prevents leaking execd secrets (*_TOKEN, *_SECRET) into isolated sessions 2. P1: Use path-component comparison for extra_writable allowlist validation — rejects sibling paths like /workspace/cache-escape when only /workspace/cache is allowed 3. P2: Honor timeout_seconds in Run handler — wrap context with WithTimeout when value is positive 4. P2: Detect EOF without end marker — return error instead of exit code 0 when bash process dies before outputting the marker Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(execd): address 7 more review issues (OSEP-0013) Security: - #1 P1: Hide upper root from namespace with --tmpfs to prevent cross-session data access - #2 P1: Use per-run UUID marker instead of fixed string to prevent exit code spoofing - #3 P1: SDK profile/mode fields now Optional (None = server default), prevents SDK defaults from overriding server configuration Correctness: - #6: Close seccomp memfd after cmd.Start() to prevent fd leak - #10: Call Validate() on create and run request bodies - #11: Skip --tmpfs /tmp when workspace is /tmp to avoid mount override - #12: Return HTTP 201 for session creation per OpenAPI spec Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(execd,sdks): symlink guard, env scoping, GC safety, 404, SDK defaults, spec (OSEP-0013) Security: - Reject symlink targets in MergedView write paths (WriteFile, WriteFileReader) Correctness: - Scope per-run envs in subshell so they don't leak across runs - GC skips sessions with active runs (TryLock on runMu) - Return 404 (not 500) when running in a nonexistent session - Kotlin/C# SDK: profile and mode default to null (server decides) - OpenAPI spec: add message field to CapabilitiesResponse Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(execd): version parsing, overlay probe, upper limit enforcement (OSEP-0013) - Fix bwrap version parsing: read stdout instead of stderr - Implement probeOverlayMount() to test overlay capability at startup - Enforce UpperMaxBytes in Allocate() with ErrUpperLimitExceeded - Add tests for limit exceeded and no-limit-when-zero scenarios Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(execd): death-watch, startup check, memfd cleanup, mode validation, probe ns (OSEP-0013) - Add doneCh death-watch goroutine to detect dead bwrap processes - GC collects dead sessions; Run returns clear error for dead sessions - Add 100ms startup check to detect immediate bwrap failures - Close ExtraFiles (seccomp memfds) on Wrap error path - Validate workspace mode in CreateIsolatedSessionRequest.Validate() - Add --unshare-pid/uts/ipc to probe smoke test - Extract magic strings to constants (session status, workspace mode, profile, env mode) Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(execd): profile validation, SSE error struct, workspace auto-create, UID defaults (OSEP-0013) - Reject unknown isolation profiles instead of silently defaulting to strict - Use --clear-groups instead of --init-groups for arbitrary UIDs without passwd entries - Populate SSE Error field with structured ErrorOutput on isolated run failures - Auto-create workspace directory if it doesn't exist - Default merged-view uid/gid to process owner instead of root Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(execd): align isolated filesystem API with normal filesystem contract (OSEP-0013) - Search: return []FileInfo (not []string), accept path query as root, skip directories - Rename/Replace/Mkdir: read from JSON body to match normal API contract - Chmod: parse mode as octal, copy-up from lower before modifying - Download: add Range header and offset/limit line-based reading support - FileInfo: include type, owner mode (octal format), matching normal buildFileInfo - Add ListDirectory handler and route (GET /directories/list) - MergedView: reject symlinks on upper read paths (Stat/Open/ReadFile) - MergedView: create whiteout on Remove/Rename for lower-only files - Fix upper root hiding: hide entire isolation root, not just current session dir - Update vfs.FS Search signature to accept root parameter Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(execd,server,tests): safePath fix, tmpfs/emptyDir for overlay, comprehensive e2e tests (OSEP-0013) - Fix MergedView.safePath to strip workspace prefix from absolute paths, preventing double-join (e.g. /tmp/tmp/file.txt) - Docker provider: add tmpfs mount at isolation upper root for overlay support - K8s providers: add emptyDir volume + volumeMount for isolation upper root - Extract ISOLATION_UPPER_MOUNT_PATH constant to avoid magic strings - Add 37 e2e tests covering rw/ro/overlay modes for both session and filesystem API - Overlay tests skip gracefully when environment lacks overlayfs support Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(execd): overlay probe on upper root, whiteout-aware reads, capabilities merge (OSEP-0013) - Probe overlay mount on upper root (tmpfs) instead of /tmp (overlay2), fixing false negative in Docker environments - Capabilities endpoint merges probe result with bwrap capabilities, fixing commit_supported/diff_supported always returning false - MergedView Stat/Open/ReadFile respect whiteout markers, returning 404 for files that were deleted via the API - Add diagnostic logging to overlay probe for debugging Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * test: add filesystem API + RO + overlay e2e tests for all SDKs (OSEP-0013) Add comprehensive isolated session e2e tests covering rw/ro/overlay modes and full filesystem API for Go, JavaScript, Java/Kotlin, and C# SDKs. Each SDK now has ~35 tests covering: - Core session operations (capabilities, lifecycle, run, PID, envs, state, /tmp) - RW mode filesystem API (upload, download, info, search, mkdir, delete, move, chmod, replace, list directory, host visibility) - RO mode (read existing, write denied, API read/search/list) - Overlay mode (CoW isolation, host file reading, filesystem API through upper layer, whiteout on delete, merged search/list) Overlay tests skip gracefully when overlayfs is not available. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(execd): test expectation, timeout kill, exit code, 400 errors, chown mkdir (OSEP-0013) - Fix bwrap_test.go: update --init-groups to --clear-groups in assertions - Timeout cancellation sends SIGINT to process group instead of closing stdin, preserving the persistent bash session for reuse - SSE error events extract numeric exit code as EValue (e.g. "42" not "command exited with code 42") with EName="ExitError" - Create session returns 400 for validation errors (allowlist, profile) - MkdirAll chowns created directories to session uid/gid Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(sdks): use auto-generated API clients for isolated filesystem endpoints (OSEP-0013) Replace URL prefix composition hack with proper generated API calls for isolated filesystem operations in Python, JS, and Kotlin SDKs. Fix spec to align isolated endpoints with normal filesystem contract, regenerate all SDK API clients, and fix JS e2e test expectations. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(execd,server): default env denylist, K8s seccomp/apparmor, overlay RemoveAll whiteout (OSEP-0013) - Apply strictEnvBlacklist by default when env_passthrough is omitted - Serialize seccompProfile and appArmorProfile in K8s security context - Create whiteout markers in RemoveAll for lower-only overlay paths Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(execd,sdks,server): address 13 review issues — security, correctness, compat (OSEP-0013) - Reject symlinks in all upper path components, not just final element - Fix BatchSandbox volumes variable shadowing (P1) - Don't advertise unimplemented diff/commit as supported - Add verbose query param to isolated replace spec - Wait for stdout scanner goroutine on run cancellation - Use UpperManager.Remove (not Release) to reclaim disk on delete - Guard isolated file endpoints when runner is nil (return 503) - Preserve original file permissions during replace operations - Return not-found error for missing directories in ReadDir - Propagate endpoint headers in Go SDK isolated file client - Validate env_passthrough.mode in create request (400 not 500) - Separate timed/streaming fetch in JS isolated adapter - Make ExecdStack.isolation optional for backward compatibility Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(sdk/kotlin): pass verbose param to isolatedReplaceContent (OSEP-0013) Generated API now requires verbose parameter after spec update. Pass verbose=false for replaceContents, verbose=true for detailed. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(execd): update bwrap integration test for Search(root, pattern) signature (OSEP-0013) Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * style: fix ruff lint and Kotlin spotless formatting (OSEP-0013) Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * style: fix ruff I001 import sorting in filesystem_model_converter (OSEP-0013) Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * style: gofmt isolated_session.go (OSEP-0013) Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * style: fix golangci-lint gocognit/nilerr issues (OSEP-0013) - Extract unsetBlacklistedEnv() helper to reduce bwrapEnvSegment complexity - Add nolint:nilerr for WalkDir callbacks (intentional skip-on-error) - Add nolint:gocognit for Search (3-pass walk is inherently complex) Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * style: move nolint:nilerr to return line for golangci-lint (OSEP-0013) Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(execd): update unit tests for whiteout behavior and temp workspace paths (OSEP-0013) - TestMergedView_Remove_LowerOnly: expect whiteout creation, not error - Runtime tests: use t.TempDir() instead of /workspace for CI compat Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> | 3 个月前 |
| fix(meta): point server and cli metadata at opensandbox-group repo (#1140) | 3 个月前 |
| feat(egress): support multiple user mitm addon scripts via comma-separated env (#1126) OPENSANDBOX_EGRESS_MITMPROXY_SCRIPT now accepts comma-separated paths (e.g. "/a.py,/b.py"), each passed as a separate -s flag to mitmdump after the system addon. Single-path usage remains unchanged. - Config.ScriptPath string → ScriptPaths []string - Extract buildMitmdumpArgs() for testability - Add parseScriptPaths() for comma-separated env parsing - Add 4 unit tests covering single, multiple, and empty/whitespace cases - Update docs and comments Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> | 3 个月前 |
| chore: bump execd to v1.0.20 | 3 个月前 |
| Merge pull request #1144 from opensandbox-group/bump/execd-v1.0.20 chore: bump execd to v1.0.20 | 3 个月前 |
| Merge pull request #1143 from Spground/feature/pool-assign-cap-predicate feat(k8s): Add capacity predicate in pool-assign | 3 个月前 |
| docs(oseps): add OSEP-0015 Kata VM snapshot and full snapshot platform Propose full-VM snapshot support (process + memory + CPU/device state + writable layer) for kata-firecracker sandboxes, built around 4 user stories: create snapshot (template), restore from template, artifact warming, and affinity scheduling on restore. Key design points: - Extend SandboxSnapshot CR with policy.type=VMSnapshot, artifact metadata, runtime fingerprint, and pinned resources; add WarmMapping CRD for per-node warm state - New checkpoint-agent DaemonSet drives containerd Checkpoint/Restore via CR-claim tasks; artifacts stored as OCI checkpoint archives in S3/GCS with sha256 verification - Restore produces a standard K8s Pod (image ref osb-vm-snap/<name>, RestoreTask on the container start path); fingerprint equality is a hard scheduling gate, warm-readiness a soft preference - 13 stable error codes, centralized timeout config, finalizer-based template deletion cascading to WarmMapping and S3 objects - Honest Phase 0 gate: community Kata shim Checkpoint/Restore is unimplemented (3.9.0-4.1.0), blocking on a reproducible downstream BOM plus six canary validations | 1 个月前 |
| docs: comprehensive docs site refactoring (#1090) * docs: comprehensive docs site refactoring - Replace 856-line manifest auto-generation with direct VitePress docs - Restructure from flat 4-section layout to 10-section information architecture (Getting Started, Architecture, Guides, SDKs, Components, Kubernetes, API, CLI, Examples, Community) - Establish single source of truth: docs/ owns user-facing content, READMEs are slim pointers - Remove incomplete Chinese i18n (30-40% coverage), keep English only - Add VitePress features: custom containers, code groups, edit links, footer, dark mode - Simplify build: just vitepress build, no docs:sync or docs:spec preprocessing - Add documentation rules to AGENTS.md and CLAUDE.md Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * docs: simplify CLAUDE.md to point at AGENTS.md Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix: resolve 38 broken links, stale paths, and content issues across docs - Fix 16 broken inbound links to moved docs pages (README, CONTRIBUTING, SECURITY, ROADMAP, GOVERNANCE, server/configuration, kubernetes/) - Move sandbox.kill() inside async-with block in quick start and README - Update execd paths from /opt/opensandbox/bin/ to /opt/opensandbox/ - Fix wrong batchsandbox-template GitHub raw URL - Remove references to deleted RELEASE_NOTE_TEMPLATE and removed scripts - Add missing cd context to server, egress, and MCP command snippets - Add missing OSEP-0012 (multi-tenancy) and OSEP-0013 to index - Fix timeout described as mandatory (it is optional) - Replace duplicated contributing/code-of-conduct with GitHub pointers - Fix broken Chinese doc references in SDK README_zh files - Remove dead Chinese docs link from README Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * docs: align README links with versioned docs * docs: address remaining review comments * docs: clarify README ownership for components * docs: fix remaining navigation and example comments * docs: refine documentation ownership rules * docs: remove obsolete spec doc generator --------- Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> | 3 个月前 |
| docs: comprehensive docs site refactoring (#1090) * docs: comprehensive docs site refactoring - Replace 856-line manifest auto-generation with direct VitePress docs - Restructure from flat 4-section layout to 10-section information architecture (Getting Started, Architecture, Guides, SDKs, Components, Kubernetes, API, CLI, Examples, Community) - Establish single source of truth: docs/ owns user-facing content, READMEs are slim pointers - Remove incomplete Chinese i18n (30-40% coverage), keep English only - Add VitePress features: custom containers, code groups, edit links, footer, dark mode - Simplify build: just vitepress build, no docs:sync or docs:spec preprocessing - Add documentation rules to AGENTS.md and CLAUDE.md Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * docs: simplify CLAUDE.md to point at AGENTS.md Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix: resolve 38 broken links, stale paths, and content issues across docs - Fix 16 broken inbound links to moved docs pages (README, CONTRIBUTING, SECURITY, ROADMAP, GOVERNANCE, server/configuration, kubernetes/) - Move sandbox.kill() inside async-with block in quick start and README - Update execd paths from /opt/opensandbox/bin/ to /opt/opensandbox/ - Fix wrong batchsandbox-template GitHub raw URL - Remove references to deleted RELEASE_NOTE_TEMPLATE and removed scripts - Add missing cd context to server, egress, and MCP command snippets - Add missing OSEP-0012 (multi-tenancy) and OSEP-0013 to index - Fix timeout described as mandatory (it is optional) - Replace duplicated contributing/code-of-conduct with GitHub pointers - Fix broken Chinese doc references in SDK README_zh files - Remove dead Chinese docs link from README Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * docs: align README links with versioned docs * docs: address remaining review comments * docs: clarify README ownership for components * docs: fix remaining navigation and example comments * docs: refine documentation ownership rules * docs: remove obsolete spec doc generator --------- Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> | 3 个月前 |
| fix(sdks/python): sync snapshot API with server and skip execd for snapshot restore Sync Python SDK snapshot API with server changes from ded135dd and fix snapshot restore for E2B sandboxes that have no execd process. Spec & generated code: - spec: snapshot create response 202→201, add image/teamId to Snapshot schema - generated: add 201 branch to post_sandboxes_sandbox_id_snapshots - generated: add image/teamId to Snapshot model (to_dict/from_dict) - generated: harden delete_snapshots_snapshot_id _parse_response against empty-body error responses (return None instead of crashing on json()) - response_handler: include response body in error message when parsed is None but content exists Handwritten models: - SnapshotInfo: add image and team_id fields - SandboxModelConverter: map image/team_id from API model Snapshot restore fix (async Sandbox + sync SandboxSync): - When snapshot_id is provided to create(), skip get_sandbox_endpoint for execd and egress ports (E2B sandboxes have no execd process) - Pass None for filesystem/command/health/metrics/egress/isolation services - Skip check_ready / health check - Property accessors (files/commands/metrics/credential_vault) raise a clear SandboxException instead of crashing on None - is_healthy()/_ping() return False when health service is None | 20 天前 |
| fix(server): runtime 分流适配层修复 Docker/K8s 模式 async 化半成品问题 问题1:ce2503bb 把 lifecycle/proxy/renew_intent 全部改 await,但 Docker/K8s service 方法仍为同步 def,8+2 处调用 await 非协程对象 必然抛 TypeError,Docker/K8s 模式相关端点 100% 失败。 问题2:5a804db3 把共享函数 _delete_workload_or_404 改 async 但 kubernetes_service.py:974 同步调用未 await,返回的 coroutine 从不 执行——K8s 沙箱删除静默失效,404 分支与 PVC 清理全部失灵, 产生孤儿 workload 和孤儿 PVC。 修复: - 新增 AsyncSandboxServiceAdapter:同步 service 实现的异步包装, 生命周期方法经 asyncio.to_thread 派发到线程池不阻塞事件循环; 继承 SandboxService+ExtensionService 保持 isinstance 契约; create_sandbox 直 await(全实现本就 async),devops 三方法同步 透传(sync def 端点走 FastAPI 线程池);get_endpoint 按签名 感知透传兼容不同参数子集;构造 guard 防止误包 async 实现 - factory 按 runtime 分流:flux 直返原生实例(grpc.aio 零开销), docker/kubernetes 包适配器 - _delete_workload_or_404 回退同步(修复 K8s 删除链路), 新增 _delete_workload_or_404_async 供 flux 使用 - 8 个 routes 测试文件的同步 Stub 统一包适配器,与 factory 行为一致 验证: - 全套单测 42 失败→3 失败(仅剩 3 个与本次无关的基线存量失败), 净修复 39 个,其中 4 个 K8s 删除测试证明问题2修复生效 - 新 server 镜像 5 轮 benchmark(30000×30000 并发):创建/删除 全 100%,最佳 QPS 1735,controller handler p50 252.7ms 与基线 一致,flux 模式零性能影响 TODO:Docker/K8s service 原生 async 化后删除适配层。 | 1 个月前 |
| feat: add osb skills command and move skills to project root Move skill files from .claude/skills/ to skills/ at project root so they serve as distributable assets for all AI coding tools, not just Claude Code. Add osb skills install/list/uninstall CLI commands supporting 6 targets: Claude Code, Cursor, Codex, GitHub Copilot, Windsurf, and Cline. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> | 6 个月前 |
| fix(sdks/python): sync snapshot API with server and skip execd for snapshot restore Sync Python SDK snapshot API with server changes from ded135dd and fix snapshot restore for E2B sandboxes that have no execd process. Spec & generated code: - spec: snapshot create response 202→201, add image/teamId to Snapshot schema - generated: add 201 branch to post_sandboxes_sandbox_id_snapshots - generated: add image/teamId to Snapshot model (to_dict/from_dict) - generated: harden delete_snapshots_snapshot_id _parse_response against empty-body error responses (return None instead of crashing on json()) - response_handler: include response body in error message when parsed is None but content exists Handwritten models: - SnapshotInfo: add image and team_id fields - SandboxModelConverter: map image/team_id from API model Snapshot restore fix (async Sandbox + sync SandboxSync): - When snapshot_id is provided to create(), skip get_sandbox_endpoint for execd and egress ports (E2B sandboxes have no execd process) - Pass None for filesystem/command/health/metrics/egress/isolation services - Skip check_ready / health check - Property accessors (files/commands/metrics/credential_vault) raise a clear SandboxException instead of crashing on None - is_healthy()/_ping() return False when health service is None | 20 天前 |
| feat(execd): add isolation package with bwrap support (#1008) * feat(execd): add isolation package with bwrap support (OSEP-0013 Phase 1) - Add pkg/isolation/ package: Isolator interface, bwrap argv builder, startup probe, upper directory management, seccomp loading - Switch bwrap distribution from //go:embed to Dockerfile static build (musl-gcc) and init container injection alongside execd - Add isolation flags (upper root, max bytes, diff max bytes, allowed writable) with env var overrides - Add smoke test: Docker build, extract binaries, verify static link, bwrap namespace test, execd probe - Add smoke_bwrap.sh to CI workflow (ubuntu-latest only) - Defer diff/commit to Phase 2 (stub returning 503) Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * feat(execd): implement isolated session API (OSEP-0013 Phase 2) - Add isolated session model types and /v1/isolated/* router (17 endpoints) - Implement session lifecycle: Create/Get/Run/Delete with bwrap+bash - SSE streaming via basicController writeSingleEvent (context-aware) - MergedView overlay filesystem with whiteout support (20 unit tests) - Filesystem proxy endpoints (10 handlers via MergedView) - Idle GC: background goroutine scavenges sessions past idle_timeout - Bwrap integration tests (43 tests, linux+bwrap build tag) - Isolated session unit tests (15 tests, stub isolator) - CI job bwrap-smoke: meson build bwrap v0.11.2 + sudo go test - Windows stubs for cross-platform compilation - Fix: cmd.Wait() zombie cleanup, context cancellation propagation, setpriv skip when uid=0, correct v0.11.x overlay syntax Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * feat(execd): Phase 3 — seccomp, telemetry, OpenAPI spec, coverage tests (OSEP-0013) Seccomp BPF: - pkg/isolation/seccomp_gen.go — BPF generator (elastic/go-seccomp-bpf, pure Go) - Default-allow denylist: 40+ dangerous syscalls blocked (mount, ptrace, etc.) - BPF passed to bwrap via memfd + ExtraFiles fd Telemetry: - execd.isolation.session.count (gauge) - execd.isolation.run.duration (histogram, ms) - execd.isolation.upper.usage_bytes (gauge) - IsolationStatsProvider pattern for gauge callbacks OpenAPI Spec: - specs/execd-api.yaml: 17 endpoints, 10 schemas, ServiceUnavailable response Integration tests (64 total in bwrap_test/): - 5 seccomp tests (filter active, normal syscalls, ptrace block, mount block, persist) - 3 ExtraWritable tests (write, read-write roundtrip, multiple sessions) - 11 gap-coverage tests (stderr, recovery, cancellation, network iso, 100x stress, delete-recreate, bash builtins, large file, subprocess cleanup, buffer size, workspace isolation) Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * docs(spec): add /v1/isolated API to OpenAPI spec (OSEP-0013) 17 endpoints, 10 new schemas, ServiceUnavailable response. FS proxy endpoints reuse same schemas as /files/* and /directories/*. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * feat(execd): PR review fixes, TOML config, API simplification, VFS interface (OSEP-0013) Review fixes: - Fix session lifecycle: done channel prevents stdin close on normal return - Fix overlay mode: pass upper/work dirs to bwrap WrapOptions - Fix end marker mid-line concatenation with strings.Index - Extract scanUntilMarker() to reduce cognitive complexity - Add runMu serialization, upperID tracking, validateExtraWritable() - Delete dead seccomp.go (replaced by seccomp_gen.go + memfd) - Fix MergedView.ReadDir upper-takes-precedence via entryMap - Fix UpperManager.Collect delete-on-success only TOML config (replaces 4 --isolation-* flags): - New isolation.Config + LoadConfig() with go-toml/v2 - Seccomp override: [seccomp].deny fully replaces built-in denylist - configs/isolation.example.toml with documented defaults - Single --isolation-config flag + EXECD_ISOLATION_CONFIG env API simplification: - Flatten CreateIsolatedSessionRequest (remove isolation wrapper) - Delete dead PersistSpec, ArtifactURLs, IsolationSpec types - Wire up envs param with shell-escaped export prepend - Remove unused cwd from IsolatedRunRequest - Update OpenAPI spec to match VFS interface: - New pkg/vfs.FS interface for filesystem abstraction - MergedView satisfies vfs.FS (compile-time check) - Isolated file handlers use vfs.FS instead of concrete MergedView - TODO for FilesystemController migration Tests: - 6 end-to-end workflow tests (Run↔File API interop) - 2 seccomp config override e2e tests - 8 config loading tests - Document overlayfs API→Run limitation in MergedView Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * feat(sdks,server): 5-language SDK, server bwrap distribution, E2E tests (OSEP-0013) Python/Go/JS/Kotlin/C# SDKs: - IsolationService + IsolationSession handle pattern (sandbox.isolation.create() → session.run/get/delete/files) - Models, service interfaces, adapters for all 5 languages Server: - bwrap binary distribution (Docker cache + K8s init container) - bootstrap.execd.isolation=enable extension grants CAP_SYS_ADMIN + apparmor/seccomp=unconfined for bwrap namespace operations - K8s: seccompProfile + appArmorProfile on container securityContext Execd: - Probe diagnostic message in capabilities API response - bwrap path /opt/opensandbox/bwrap (alongside execd) - Shared parseUploadForm between filesystem and isolated handlers E2E tests (Python/Go/JS/Java/C#): - capabilities, lifecycle, echo, PID isolation, env injection, state persistence, /tmp isolation (strict), SSE handlers, overlay mode, file operations via run Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(execd): address PR review — env defaults, prefix bypass, timeout, EOF (OSEP-0013) 1. P1: Apply deny-blacklist env defaults when EnvPassthroughMode is empty — prevents leaking execd secrets (*_TOKEN, *_SECRET) into isolated sessions 2. P1: Use path-component comparison for extra_writable allowlist validation — rejects sibling paths like /workspace/cache-escape when only /workspace/cache is allowed 3. P2: Honor timeout_seconds in Run handler — wrap context with WithTimeout when value is positive 4. P2: Detect EOF without end marker — return error instead of exit code 0 when bash process dies before outputting the marker Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(execd): address 7 more review issues (OSEP-0013) Security: - #1 P1: Hide upper root from namespace with --tmpfs to prevent cross-session data access - #2 P1: Use per-run UUID marker instead of fixed string to prevent exit code spoofing - #3 P1: SDK profile/mode fields now Optional (None = server default), prevents SDK defaults from overriding server configuration Correctness: - #6: Close seccomp memfd after cmd.Start() to prevent fd leak - #10: Call Validate() on create and run request bodies - #11: Skip --tmpfs /tmp when workspace is /tmp to avoid mount override - #12: Return HTTP 201 for session creation per OpenAPI spec Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(execd,sdks): symlink guard, env scoping, GC safety, 404, SDK defaults, spec (OSEP-0013) Security: - Reject symlink targets in MergedView write paths (WriteFile, WriteFileReader) Correctness: - Scope per-run envs in subshell so they don't leak across runs - GC skips sessions with active runs (TryLock on runMu) - Return 404 (not 500) when running in a nonexistent session - Kotlin/C# SDK: profile and mode default to null (server decides) - OpenAPI spec: add message field to CapabilitiesResponse Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(execd): version parsing, overlay probe, upper limit enforcement (OSEP-0013) - Fix bwrap version parsing: read stdout instead of stderr - Implement probeOverlayMount() to test overlay capability at startup - Enforce UpperMaxBytes in Allocate() with ErrUpperLimitExceeded - Add tests for limit exceeded and no-limit-when-zero scenarios Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(execd): death-watch, startup check, memfd cleanup, mode validation, probe ns (OSEP-0013) - Add doneCh death-watch goroutine to detect dead bwrap processes - GC collects dead sessions; Run returns clear error for dead sessions - Add 100ms startup check to detect immediate bwrap failures - Close ExtraFiles (seccomp memfds) on Wrap error path - Validate workspace mode in CreateIsolatedSessionRequest.Validate() - Add --unshare-pid/uts/ipc to probe smoke test - Extract magic strings to constants (session status, workspace mode, profile, env mode) Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(execd): profile validation, SSE error struct, workspace auto-create, UID defaults (OSEP-0013) - Reject unknown isolation profiles instead of silently defaulting to strict - Use --clear-groups instead of --init-groups for arbitrary UIDs without passwd entries - Populate SSE Error field with structured ErrorOutput on isolated run failures - Auto-create workspace directory if it doesn't exist - Default merged-view uid/gid to process owner instead of root Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(execd): align isolated filesystem API with normal filesystem contract (OSEP-0013) - Search: return []FileInfo (not []string), accept path query as root, skip directories - Rename/Replace/Mkdir: read from JSON body to match normal API contract - Chmod: parse mode as octal, copy-up from lower before modifying - Download: add Range header and offset/limit line-based reading support - FileInfo: include type, owner mode (octal format), matching normal buildFileInfo - Add ListDirectory handler and route (GET /directories/list) - MergedView: reject symlinks on upper read paths (Stat/Open/ReadFile) - MergedView: create whiteout on Remove/Rename for lower-only files - Fix upper root hiding: hide entire isolation root, not just current session dir - Update vfs.FS Search signature to accept root parameter Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(execd,server,tests): safePath fix, tmpfs/emptyDir for overlay, comprehensive e2e tests (OSEP-0013) - Fix MergedView.safePath to strip workspace prefix from absolute paths, preventing double-join (e.g. /tmp/tmp/file.txt) - Docker provider: add tmpfs mount at isolation upper root for overlay support - K8s providers: add emptyDir volume + volumeMount for isolation upper root - Extract ISOLATION_UPPER_MOUNT_PATH constant to avoid magic strings - Add 37 e2e tests covering rw/ro/overlay modes for both session and filesystem API - Overlay tests skip gracefully when environment lacks overlayfs support Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(execd): overlay probe on upper root, whiteout-aware reads, capabilities merge (OSEP-0013) - Probe overlay mount on upper root (tmpfs) instead of /tmp (overlay2), fixing false negative in Docker environments - Capabilities endpoint merges probe result with bwrap capabilities, fixing commit_supported/diff_supported always returning false - MergedView Stat/Open/ReadFile respect whiteout markers, returning 404 for files that were deleted via the API - Add diagnostic logging to overlay probe for debugging Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * test: add filesystem API + RO + overlay e2e tests for all SDKs (OSEP-0013) Add comprehensive isolated session e2e tests covering rw/ro/overlay modes and full filesystem API for Go, JavaScript, Java/Kotlin, and C# SDKs. Each SDK now has ~35 tests covering: - Core session operations (capabilities, lifecycle, run, PID, envs, state, /tmp) - RW mode filesystem API (upload, download, info, search, mkdir, delete, move, chmod, replace, list directory, host visibility) - RO mode (read existing, write denied, API read/search/list) - Overlay mode (CoW isolation, host file reading, filesystem API through upper layer, whiteout on delete, merged search/list) Overlay tests skip gracefully when overlayfs is not available. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(execd): test expectation, timeout kill, exit code, 400 errors, chown mkdir (OSEP-0013) - Fix bwrap_test.go: update --init-groups to --clear-groups in assertions - Timeout cancellation sends SIGINT to process group instead of closing stdin, preserving the persistent bash session for reuse - SSE error events extract numeric exit code as EValue (e.g. "42" not "command exited with code 42") with EName="ExitError" - Create session returns 400 for validation errors (allowlist, profile) - MkdirAll chowns created directories to session uid/gid Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(sdks): use auto-generated API clients for isolated filesystem endpoints (OSEP-0013) Replace URL prefix composition hack with proper generated API calls for isolated filesystem operations in Python, JS, and Kotlin SDKs. Fix spec to align isolated endpoints with normal filesystem contract, regenerate all SDK API clients, and fix JS e2e test expectations. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(execd,server): default env denylist, K8s seccomp/apparmor, overlay RemoveAll whiteout (OSEP-0013) - Apply strictEnvBlacklist by default when env_passthrough is omitted - Serialize seccompProfile and appArmorProfile in K8s security context - Create whiteout markers in RemoveAll for lower-only overlay paths Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(execd,sdks,server): address 13 review issues — security, correctness, compat (OSEP-0013) - Reject symlinks in all upper path components, not just final element - Fix BatchSandbox volumes variable shadowing (P1) - Don't advertise unimplemented diff/commit as supported - Add verbose query param to isolated replace spec - Wait for stdout scanner goroutine on run cancellation - Use UpperManager.Remove (not Release) to reclaim disk on delete - Guard isolated file endpoints when runner is nil (return 503) - Preserve original file permissions during replace operations - Return not-found error for missing directories in ReadDir - Propagate endpoint headers in Go SDK isolated file client - Validate env_passthrough.mode in create request (400 not 500) - Separate timed/streaming fetch in JS isolated adapter - Make ExecdStack.isolation optional for backward compatibility Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(sdk/kotlin): pass verbose param to isolatedReplaceContent (OSEP-0013) Generated API now requires verbose parameter after spec update. Pass verbose=false for replaceContents, verbose=true for detailed. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(execd): update bwrap integration test for Search(root, pattern) signature (OSEP-0013) Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * style: fix ruff lint and Kotlin spotless formatting (OSEP-0013) Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * style: fix ruff I001 import sorting in filesystem_model_converter (OSEP-0013) Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * style: gofmt isolated_session.go (OSEP-0013) Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * style: fix golangci-lint gocognit/nilerr issues (OSEP-0013) - Extract unsetBlacklistedEnv() helper to reduce bwrapEnvSegment complexity - Add nolint:nilerr for WalkDir callbacks (intentional skip-on-error) - Add nolint:gocognit for Search (3-pass walk is inherently complex) Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * style: move nolint:nilerr to return line for golangci-lint (OSEP-0013) Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(execd): update unit tests for whiteout behavior and temp workspace paths (OSEP-0013) - TestMergedView_Remove_LowerOnly: expect whiteout creation, not error - Runtime tests: use t.TempDir() instead of /workspace for CI compat Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> | 3 个月前 |
| feat(k8s): Add auto-assign pool for batchsandbox | 4 个月前 |
| initial commit Co-authored-by: Wenxiang Jin <wenxiang.jin@alibaba-inc.com> Co-authored-by: Peipei Shi <anchen.spp@alibaba-inc.com> Co-authored-by: Yutian Tao <yutian.taoyt@alibaba-inc.com> Co-authored-by: Nan Ni <ninan.nn@alibaba-inc.com> | 9 个月前 |
| docs: comprehensive docs site refactoring (#1090) * docs: comprehensive docs site refactoring - Replace 856-line manifest auto-generation with direct VitePress docs - Restructure from flat 4-section layout to 10-section information architecture (Getting Started, Architecture, Guides, SDKs, Components, Kubernetes, API, CLI, Examples, Community) - Establish single source of truth: docs/ owns user-facing content, READMEs are slim pointers - Remove incomplete Chinese i18n (30-40% coverage), keep English only - Add VitePress features: custom containers, code groups, edit links, footer, dark mode - Simplify build: just vitepress build, no docs:sync or docs:spec preprocessing - Add documentation rules to AGENTS.md and CLAUDE.md Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * docs: simplify CLAUDE.md to point at AGENTS.md Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix: resolve 38 broken links, stale paths, and content issues across docs - Fix 16 broken inbound links to moved docs pages (README, CONTRIBUTING, SECURITY, ROADMAP, GOVERNANCE, server/configuration, kubernetes/) - Move sandbox.kill() inside async-with block in quick start and README - Update execd paths from /opt/opensandbox/bin/ to /opt/opensandbox/ - Fix wrong batchsandbox-template GitHub raw URL - Remove references to deleted RELEASE_NOTE_TEMPLATE and removed scripts - Add missing cd context to server, egress, and MCP command snippets - Add missing OSEP-0012 (multi-tenancy) and OSEP-0013 to index - Fix timeout described as mandatory (it is optional) - Replace duplicated contributing/code-of-conduct with GitHub pointers - Fix broken Chinese doc references in SDK README_zh files - Remove dead Chinese docs link from README Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * docs: align README links with versioned docs * docs: address remaining review comments * docs: clarify README ownership for components * docs: fix remaining navigation and example comments * docs: refine documentation ownership rules * docs: remove obsolete spec doc generator --------- Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> | 3 个月前 |
| docs: comprehensive docs site refactoring (#1090) * docs: comprehensive docs site refactoring - Replace 856-line manifest auto-generation with direct VitePress docs - Restructure from flat 4-section layout to 10-section information architecture (Getting Started, Architecture, Guides, SDKs, Components, Kubernetes, API, CLI, Examples, Community) - Establish single source of truth: docs/ owns user-facing content, READMEs are slim pointers - Remove incomplete Chinese i18n (30-40% coverage), keep English only - Add VitePress features: custom containers, code groups, edit links, footer, dark mode - Simplify build: just vitepress build, no docs:sync or docs:spec preprocessing - Add documentation rules to AGENTS.md and CLAUDE.md Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * docs: simplify CLAUDE.md to point at AGENTS.md Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix: resolve 38 broken links, stale paths, and content issues across docs - Fix 16 broken inbound links to moved docs pages (README, CONTRIBUTING, SECURITY, ROADMAP, GOVERNANCE, server/configuration, kubernetes/) - Move sandbox.kill() inside async-with block in quick start and README - Update execd paths from /opt/opensandbox/bin/ to /opt/opensandbox/ - Fix wrong batchsandbox-template GitHub raw URL - Remove references to deleted RELEASE_NOTE_TEMPLATE and removed scripts - Add missing cd context to server, egress, and MCP command snippets - Add missing OSEP-0012 (multi-tenancy) and OSEP-0013 to index - Fix timeout described as mandatory (it is optional) - Replace duplicated contributing/code-of-conduct with GitHub pointers - Fix broken Chinese doc references in SDK README_zh files - Remove dead Chinese docs link from README Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * docs: align README links with versioned docs * docs: address remaining review comments * docs: clarify README ownership for components * docs: fix remaining navigation and example comments * docs: refine documentation ownership rules * docs: remove obsolete spec doc generator --------- Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> | 3 个月前 |
| initial commit Co-authored-by: Wenxiang Jin <wenxiang.jin@alibaba-inc.com> Co-authored-by: Peipei Shi <anchen.spp@alibaba-inc.com> Co-authored-by: Yutian Tao <yutian.taoyt@alibaba-inc.com> Co-authored-by: Nan Ni <ninan.nn@alibaba-inc.com> | 9 个月前 |
| docs: comprehensive docs site refactoring (#1090) * docs: comprehensive docs site refactoring - Replace 856-line manifest auto-generation with direct VitePress docs - Restructure from flat 4-section layout to 10-section information architecture (Getting Started, Architecture, Guides, SDKs, Components, Kubernetes, API, CLI, Examples, Community) - Establish single source of truth: docs/ owns user-facing content, READMEs are slim pointers - Remove incomplete Chinese i18n (30-40% coverage), keep English only - Add VitePress features: custom containers, code groups, edit links, footer, dark mode - Simplify build: just vitepress build, no docs:sync or docs:spec preprocessing - Add documentation rules to AGENTS.md and CLAUDE.md Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * docs: simplify CLAUDE.md to point at AGENTS.md Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix: resolve 38 broken links, stale paths, and content issues across docs - Fix 16 broken inbound links to moved docs pages (README, CONTRIBUTING, SECURITY, ROADMAP, GOVERNANCE, server/configuration, kubernetes/) - Move sandbox.kill() inside async-with block in quick start and README - Update execd paths from /opt/opensandbox/bin/ to /opt/opensandbox/ - Fix wrong batchsandbox-template GitHub raw URL - Remove references to deleted RELEASE_NOTE_TEMPLATE and removed scripts - Add missing cd context to server, egress, and MCP command snippets - Add missing OSEP-0012 (multi-tenancy) and OSEP-0013 to index - Fix timeout described as mandatory (it is optional) - Replace duplicated contributing/code-of-conduct with GitHub pointers - Fix broken Chinese doc references in SDK README_zh files - Remove dead Chinese docs link from README Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * docs: align README links with versioned docs * docs: address remaining review comments * docs: clarify README ownership for components * docs: fix remaining navigation and example comments * docs: refine documentation ownership rules * docs: remove obsolete spec doc generator --------- Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> | 3 个月前 |
| docs: comprehensive docs site refactoring (#1090) * docs: comprehensive docs site refactoring - Replace 856-line manifest auto-generation with direct VitePress docs - Restructure from flat 4-section layout to 10-section information architecture (Getting Started, Architecture, Guides, SDKs, Components, Kubernetes, API, CLI, Examples, Community) - Establish single source of truth: docs/ owns user-facing content, READMEs are slim pointers - Remove incomplete Chinese i18n (30-40% coverage), keep English only - Add VitePress features: custom containers, code groups, edit links, footer, dark mode - Simplify build: just vitepress build, no docs:sync or docs:spec preprocessing - Add documentation rules to AGENTS.md and CLAUDE.md Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * docs: simplify CLAUDE.md to point at AGENTS.md Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix: resolve 38 broken links, stale paths, and content issues across docs - Fix 16 broken inbound links to moved docs pages (README, CONTRIBUTING, SECURITY, ROADMAP, GOVERNANCE, server/configuration, kubernetes/) - Move sandbox.kill() inside async-with block in quick start and README - Update execd paths from /opt/opensandbox/bin/ to /opt/opensandbox/ - Fix wrong batchsandbox-template GitHub raw URL - Remove references to deleted RELEASE_NOTE_TEMPLATE and removed scripts - Add missing cd context to server, egress, and MCP command snippets - Add missing OSEP-0012 (multi-tenancy) and OSEP-0013 to index - Fix timeout described as mandatory (it is optional) - Replace duplicated contributing/code-of-conduct with GitHub pointers - Fix broken Chinese doc references in SDK README_zh files - Remove dead Chinese docs link from README Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * docs: align README links with versioned docs * docs: address remaining review comments * docs: clarify README ownership for components * docs: fix remaining navigation and example comments * docs: refine documentation ownership rules * docs: remove obsolete spec doc generator --------- Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> | 3 个月前 |
| initial commit Co-authored-by: Wenxiang Jin <wenxiang.jin@alibaba-inc.com> Co-authored-by: Peipei Shi <anchen.spp@alibaba-inc.com> Co-authored-by: Yutian Tao <yutian.taoyt@alibaba-inc.com> Co-authored-by: Nan Ni <ninan.nn@alibaba-inc.com> | 9 个月前 |
| docs: add Discord community links | 3 个月前 |
| docs: comprehensive docs site refactoring (#1090) * docs: comprehensive docs site refactoring - Replace 856-line manifest auto-generation with direct VitePress docs - Restructure from flat 4-section layout to 10-section information architecture (Getting Started, Architecture, Guides, SDKs, Components, Kubernetes, API, CLI, Examples, Community) - Establish single source of truth: docs/ owns user-facing content, READMEs are slim pointers - Remove incomplete Chinese i18n (30-40% coverage), keep English only - Add VitePress features: custom containers, code groups, edit links, footer, dark mode - Simplify build: just vitepress build, no docs:sync or docs:spec preprocessing - Add documentation rules to AGENTS.md and CLAUDE.md Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * docs: simplify CLAUDE.md to point at AGENTS.md Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix: resolve 38 broken links, stale paths, and content issues across docs - Fix 16 broken inbound links to moved docs pages (README, CONTRIBUTING, SECURITY, ROADMAP, GOVERNANCE, server/configuration, kubernetes/) - Move sandbox.kill() inside async-with block in quick start and README - Update execd paths from /opt/opensandbox/bin/ to /opt/opensandbox/ - Fix wrong batchsandbox-template GitHub raw URL - Remove references to deleted RELEASE_NOTE_TEMPLATE and removed scripts - Add missing cd context to server, egress, and MCP command snippets - Add missing OSEP-0012 (multi-tenancy) and OSEP-0013 to index - Fix timeout described as mandatory (it is optional) - Replace duplicated contributing/code-of-conduct with GitHub pointers - Fix broken Chinese doc references in SDK README_zh files - Remove dead Chinese docs link from README Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * docs: align README links with versioned docs * docs: address remaining review comments * docs: clarify README ownership for components * docs: fix remaining navigation and example comments * docs: refine documentation ownership rules * docs: remove obsolete spec doc generator --------- Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> | 3 个月前 |
| docs: comprehensive docs site refactoring (#1090) * docs: comprehensive docs site refactoring - Replace 856-line manifest auto-generation with direct VitePress docs - Restructure from flat 4-section layout to 10-section information architecture (Getting Started, Architecture, Guides, SDKs, Components, Kubernetes, API, CLI, Examples, Community) - Establish single source of truth: docs/ owns user-facing content, READMEs are slim pointers - Remove incomplete Chinese i18n (30-40% coverage), keep English only - Add VitePress features: custom containers, code groups, edit links, footer, dark mode - Simplify build: just vitepress build, no docs:sync or docs:spec preprocessing - Add documentation rules to AGENTS.md and CLAUDE.md Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * docs: simplify CLAUDE.md to point at AGENTS.md Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix: resolve 38 broken links, stale paths, and content issues across docs - Fix 16 broken inbound links to moved docs pages (README, CONTRIBUTING, SECURITY, ROADMAP, GOVERNANCE, server/configuration, kubernetes/) - Move sandbox.kill() inside async-with block in quick start and README - Update execd paths from /opt/opensandbox/bin/ to /opt/opensandbox/ - Fix wrong batchsandbox-template GitHub raw URL - Remove references to deleted RELEASE_NOTE_TEMPLATE and removed scripts - Add missing cd context to server, egress, and MCP command snippets - Add missing OSEP-0012 (multi-tenancy) and OSEP-0013 to index - Fix timeout described as mandatory (it is optional) - Replace duplicated contributing/code-of-conduct with GitHub pointers - Fix broken Chinese doc references in SDK README_zh files - Remove dead Chinese docs link from README Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * docs: align README links with versioned docs * docs: address remaining review comments * docs: clarify README ownership for components * docs: fix remaining navigation and example comments * docs: refine documentation ownership rules * docs: remove obsolete spec doc generator --------- Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> | 3 个月前 |