docs: add minimal container / agent sandbox instructions to AGENTS.md - #2832
Conversation
release: promote dev into main for v2.32.1
# Conflicts: # package.json
[WRONG BRANCH] merge dev into main for the v2.33.0 release
Promotes the dev integration line onto main. The resulting tree is byte-identical to origin/dev, including package.json at 2.34.0. The package.json conflict is resolved to dev's side, NOT to main's stale 2.33.0. Earlier promotions (#2553, #2507) kept the target's version so the release bump would land on its own "release: vX.Y.Z" commit. That is no longer legal: this very delta adds tests/release-version-line.test.ts, which fails when the in-tree version sits behind the highest release tag. With v2.34.0-preview.20260827 now published, 2.33.0 orders behind it, so a promotion carrying the stale line turns CI red on every shard that runs the suite. The consequence for the release step is that scripts/release.ts skips the bump (release.ts:568, currentVersion === version), so v2.34.0 gets tagged on this merge commit rather than on a separate release commit. The workflow creates the tag itself after publishing and validates expected-sha against the checked-out commit, so the tag still names exactly the audited tree.
[WRONG BRANCH] promote dev onto main for v2.34.0
[WRONG BRANCH] promote dev onto main for v2.35.0
Add .cursor/environment.json so Cloud Agents boot ready for the Bun-native runtime: install bun + project/gui dependencies, expose the proxy on port 8899, and run 'ocx start' as a persistent terminal. Co-authored-by: JUN <jun@lidgeai.com>
|
Caution Review failedThe pull request is closed. ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Plus Run ID: 📒 Files selected for processing (1)
📝 WalkthroughWalkthrough
ChangesMinimal container documentation
Estimated code review effort: 1 (Trivial) | ~5 minutes Suggested reviewers: ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
✅ Deterministic PR hygiene checks passed. |
Drop the .cursor/environment.json added earlier on this branch and document the same knowledge as a 'Cursor Cloud specific instructions' section: Bun is not preinstalled (install via the official installer), how to run the proxy, and the five environment-only test failures (no systemd init; container filesystem mtime granularity) so future agents do not re-investigate them. Co-authored-by: JUN <jun@lidgeai.com>
Retitle the section 'Minimal containers and agent sandboxes' and phrase the guidance so it covers any fresh dev container or agent sandbox (Cursor Cloud, devcontainers, CI images): Bun is often absent, service tests need a running systemd init, and two integrity tests need fine mtime granularity. Co-authored-by: JUN <jun@lidgeai.com>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: e4ef2972f9
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| - `package tree integrity > an in-place rewrite of the same byte length is | ||
| still a replacement` and `Codex Log Guard inspection > repeat inspection is | ||
| memoized and invalidated by a write` rely on filesystem mtime granularity | ||
| that some container filesystems do not provide. |
There was a problem hiding this comment.
Do not dismiss guard failures as container-only
On filesystems whose modification timestamp does not advance for these writes, the failures demonstrate real runtime behavior rather than harmless test flakiness: createPackageTreeIntegrityGuard cannot detect a same-size in-place package replacement, and the Codex log inspection cache can return stale metrics after a database write. Telling agents not to investigate these failures can therefore hide broken integrity and cache-invalidation guarantees; fix or explicitly disable the unsupported runtime behavior instead of treating the tests as known-safe failures.
AGENTS.md reference: AGENTS.md:L325-L327
Useful? React with 👍 / 👎.
| Run the proxy with `bun run src/cli/index.ts start --port <port>`. `/healthz` | ||
| reports status, `/` serves the dashboard, and the management API requires the | ||
| admin token the server writes to `$OPENCODEX_HOME/admin-api-token` at startup. |
There was a problem hiding this comment.
Document the default admin-token path
In the fresh-container scenario described here, OPENCODEX_HOME is normally unset, while getConfigDir() falls back to ~/.opencodex. An agent following this text literally will therefore look for /admin-api-token after shell expansion instead of the actual ~/.opencodex/admin-api-token and will be unable to authenticate direct management API requests. State both the default path and the environment-variable override.
Useful? React with 👍 / 👎.
…lidge-jun#2832) * release: v2.32.1 * release: v2.33.0 * chore: add Cloud Agent dev environment config Add .cursor/environment.json so Cloud Agents boot ready for the Bun-native runtime: install bun + project/gui dependencies, expose the proxy on port 8899, and run 'ocx start' as a persistent terminal. Co-authored-by: JUN <jun@lidgeai.com> * docs: record Cloud Agent setup in AGENTS.md instead of environment.json Drop the .cursor/environment.json added earlier on this branch and document the same knowledge as a 'Cursor Cloud specific instructions' section: Bun is not preinstalled (install via the official installer), how to run the proxy, and the five environment-only test failures (no systemd init; container filesystem mtime granularity) so future agents do not re-investigate them. Co-authored-by: JUN <jun@lidgeai.com> * docs: generalize sandbox setup notes beyond Cursor Cloud Retitle the section 'Minimal containers and agent sandboxes' and phrase the guidance so it covers any fresh dev container or agent sandbox (Cursor Cloud, devcontainers, CI images): Bun is often absent, service tests need a running systemd init, and two integrity tests need fine mtime granularity. Co-authored-by: JUN <jun@lidgeai.com> --------- Co-authored-by: Cursor Agent <cursoragent@cursor.com>
…lidge-jun#2832) * release: v2.32.1 * release: v2.33.0 * chore: add Cloud Agent dev environment config Add .cursor/environment.json so Cloud Agents boot ready for the Bun-native runtime: install bun + project/gui dependencies, expose the proxy on port 8899, and run 'ocx start' as a persistent terminal. Co-authored-by: JUN <jun@lidgeai.com> * docs: record Cloud Agent setup in AGENTS.md instead of environment.json Drop the .cursor/environment.json added earlier on this branch and document the same knowledge as a 'Cursor Cloud specific instructions' section: Bun is not preinstalled (install via the official installer), how to run the proxy, and the five environment-only test failures (no systemd init; container filesystem mtime granularity) so future agents do not re-investigate them. Co-authored-by: JUN <jun@lidgeai.com> * docs: generalize sandbox setup notes beyond Cursor Cloud Retitle the section 'Minimal containers and agent sandboxes' and phrase the guidance so it covers any fresh dev container or agent sandbox (Cursor Cloud, devcontainers, CI images): Bun is often absent, service tests need a running systemd init, and two integrity tests need fine mtime granularity. Co-authored-by: JUN <jun@lidgeai.com> --------- Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Summary
## Minimal containers and agent sandboxessection toAGENTS.mdso future agent runs and fresh dev containers do not rediscover the same setup facts. Written generically — applies to Cursor Cloud, devcontainers, CI images, and similar sandboxes, not one product.bun installat the root and ingui/).ocx start --port), where the admin token is written, and which endpoints prove it is up.bun run testfailures that are environment-only in such containers (three need a running systemd init — PID 1 is typicallytinior another minimal init; two depend on filesystem mtime granularity), so they are not re-investigated as regressions.This replaces an earlier revision of this branch that added
.cursor/environment.json; per maintainer feedback, this knowledge belongs inAGENTS.mdinstead.Verification
Ran on a fresh Cloud Agent VM while setting up the environment:
1.4.0(matches the pinnedbundependency) via the official installer;bun install(root) andbun install(gui/) resolved frombun.lock.bun run typecheck— passed (tsc --noEmit, strict).bun run test— 15480 pass, 16 skip, 5 fail; the 5 failures are exactly the environment-only set now documented inAGENTS.md(clean tree, no code changes).cd gui && bun run build— Vite 8 production build succeeded (261 modules).ocx start --port 8899):GET /healthz→{"status":"ok","version":"2.35.0",...}; authenticatedGET /api/config|settings|models→200; unauthenticated →401;GET /serves the dashboard (screenshot below).opencodex dashboard overview, proxy online v2.35.0
Checklist
To show artifacts inline, enable in settings.
Summary by CodeRabbit