Repository navigation
Wave 5: runtime-docker - #7
Conversation
🤖 CodeAnt AI — Review Status
|
📝 WalkthroughSummary by CodeRabbit
WalkthroughThis PR adds content-addressed operation IDs shared by Core and IR, updates planning and DAG tests, and implements the Docker runtime package with execution policies, digest verification, caching, artifact handling, error types, CLI timeouts, exports, and tests. ChangesCore planning and Docker runtime
Estimated code review effort: 5 (Critical) | ~120 minutes Sequence Diagram(s)sequenceDiagram
participant DockerExecutor
participant DockerCacheManager
participant verifyImageDigest
participant runDocker
participant DockerCLI
DockerExecutor->>DockerCacheManager: prepare cache inputs
DockerExecutor->>verifyImageDigest: verify expected image digest
verifyImageDigest->>runDocker: inspect or pull image
DockerExecutor->>runDocker: execute container command
runDocker->>DockerCLI: spawn Docker process
DockerCLI-->>runDocker: return logs and exit status
DockerExecutor->>DockerCacheManager: collect execution outputs
Possibly related PRs
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
MergerCommit |
|
Running ultrareview automatically — Because this PR lands the security-sensitive Docker executor (isolation flags, credential allowlisting, image digest pinning, mount policy, cache/artifact paths), where a subtle bug could leak secrets, escape the sandbox, or break every run, a deeper review is warranted.. I'll post findings when complete. |
Up to standards ✅🟢 Issues
|
| Metric | Results |
|---|---|
| Complexity | 155 |
| Duplication | 6 |
AI Reviewer: first review requested successfully. AI can make mistakes. Always validate suggestions.
TIP This summary will be updated as you push new changes.
PR Summary by QodoAdd runtime-docker package with DockerExecutor, policies, and testable docker CLI seam
AI Description
Diagram
High-Level Assessment
Files changed (17)
|
There was a problem hiding this comment.
Summary
This PR implements a Docker runtime executor with strong security policies. However, 6 critical defects must be fixed before merge:
Critical Issues (Must Fix)
- Docker socket bypass vulnerabilities (2 locations): Simple substring checks can be evaded via path traversals or symlinks, allowing container escape
- Secret regex false positives: Incorrectly blocks legitimate variables like
MY_KEY_VALUE - Unhandled cache collection crash: Missing try-catch will terminate execution on file errors
- Cache path collision bug: Incorrect path calculation causes cache key conflicts
- Artifact path traversal vulnerability: Absolute paths allow arbitrary host file exfiltration
All issues have specific fixes provided. The test coverage is excellent (58 tests), but these logic errors and security vulnerabilities must be addressed before the code is production-ready.
You can now have the agent implement changes and create commits directly on your pull request's source branch. Simply comment with /q followed by your request in natural language to ask the agent to make changes.
There was a problem hiding this comment.
Pull Request Overview
The pull request implements the @sverka/runtime-docker package but is currently not up to standards due to a significant volume of quality issues and critical logic errors.
The most pressing issues involve the DockerExecutor implementation: it includes an unsupported --timeout flag that will cause all container executions to fail, and it misses a mandatory architectural step to call verifyImageDigest before execution. Furthermore, a security risk was identified in artifact collection where absolute paths could allow the exfiltration of host files.
Logic gaps in DockerCacheManager will cause file collisions and failures with directories, as the implementation flattens input structures and uses non-recursive copy operations.
About this PR
- Artifact collection allows absolute paths, which permits the exfiltration of arbitrary host files readable by the executor process, potentially bypassing the intended workspace boundary. Artifact paths should be strictly validated as relative to the workspace.
- The DockerCacheManager.prepare implementation flattens input files into the root of the cache directory, which will cause collisions for different files that share a basename (e.g., 'src/index.ts' and 'test/index.ts').
Test suggestions
- Found recommended test scenario: DockerExecutor.canExecute identifies docker operations and rejects others
- Found recommended test scenario: buildDockerArgs correctly constructs CLI flags for security policy and resource limits
- Found recommended test scenario: Network policy correctly maps to Docker network modes
- Missing recommended test scenario: Execution fails with ContainerPolicyError if timeout or image digest is missing
- Found recommended test scenario: Environment variables are filtered by credential declarations and secret-like patterns are blocked
- Found recommended test scenario: Docker socket references in mounts or env vars trigger a policy violation error
- Found recommended test scenario: verifyImageDigest correctly handles inspect failures by pulling the image
- Found recommended test scenario: Logs exceeding maxLogBytes are truncated and appended with a notice
- Found recommended test scenario: Artifacts are copied from the workspace to the artifactDir after execution
- Missing recommended test scenario: DockerCacheManager preserves output structure and correctly restores cached inputs
Prompt proposal for missing tests
Consider implementing these tests if applicable:
1. Missing recommended test scenario: Execution fails with ContainerPolicyError if timeout or image digest is missing
2. Missing recommended test scenario: DockerCacheManager preserves output structure and correctly restores cached inputs
TIP Improve review quality by adding custom instructions
TIP How was this review? Give us feedback
Code Review by Qodo
1.
|
There was a problem hiding this comment.
Ultrareview completed in 9m 13s
All reported issues were addressed across 17 files
Tip: instead of fixing issues one by one fix them all with cubic
Re-trigger cubic
611136e to
ecf9429
Compare
ecf9429 to
20bf781
Compare
20bf781 to
318ec73
Compare
318ec73 to
6aebc91
Compare
6aebc91 to
9d1ab14
Compare
Core's assignId/assignIds used human-readable string derivation
(kind:name-or-command-or-index with collision counter) and passed
user spec.id through as-is, violating ADR-006. Now uses SHA-256
content-addressed ids: op-<64 hex> via node:crypto.createHash over
canonical JSON of {kind, name, context}, with spec.id folded into
hash context as userId.
- Created packages/core/src/internal/canonical.ts (computeOperationId)
- Rewrote packages/core/src/internal/ids.ts + plan.ts for SHA-256
- Exported computeOperationId from core public index.ts
- Fixed all tests to assert op-<64hex> format (90 core tests pass)
- Added cross-consistency test: core === ir computeOperationId (87 ir tests)
- Full monorepo: 16 projects test+typecheck+build green
Generated with [Devin](https://devin.ai)
Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
… surrogates) and update runtime-modes expectations Co-Authored-By: Petr Plenkov <petr.plenkov@gmail.com>
fafdb9e to
aa1a4ae
Compare
fix: Core ID assignment — SHA-256 content-addressed IDs (ADR-006)
DockerExecutor implementation: container lifecycle, image pulling, volume mounts, env/credential passing, artifact collection, cache management, timeout handling. Mockable docker-cli.ts seam for unit tests without Docker daemon. Integration tests skip if no Docker. 58 tests pass + 2 skipped (integration). Spec 04 amended to match built runtime contract. Reviewer APPROVED after rework (sv-b3u): collectArtifacts + mount-socket throw test added. <details> - 58 tests pass + 2 skipped (integration) - typecheck clean - build green (dist index.mjs 11.40kB + index.d.mts 4.89kB) - lint clean - reviewer approved (sv-1i2) </details> Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
…ult to reduce complexity
aa1a4ae to
818a725
Compare
There was a problem hiding this comment.
Actionable comments posted: 16
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@packages/core/src/__tests__/matrix.test.ts`:
- Around line 28-39: Update the multi-dimension cartesian-product test to use
two values for both node and os, then assert four operations with distinct ids
and the expected matrix environment values. Restore coverage for duplicate
matrix values, asserting the duplicate-id CompositionError from assignIds, and
for values with identical text but different types (1, "1", true), asserting
they receive distinct ids via canonicalStringify.
In `@packages/core/src/internal/plan.ts`:
- Line 489: Update the dependency handling in resolveEdges, detectCycles, and
topoSort so missing byId entries are not silently skipped. Replace the
byId.has(dep) guards with an explicit invariant failure that raises
CompositionError, while preserving normal traversal and ordering for resolved
dependencies.
- Around line 164-177: Preserve each matrix child’s __matrixCombo when
flattenArtifacts rebuilds nodes via makeNodeWith, including artifact-predecessor
and propagated-join paths. Thread the combination through flattenArtifacts,
assignIds, and contextFor, or retain it as typed node metadata, so contextFor
includes matrix values and generated operation IDs remain distinct.
In `@packages/ir/src/__tests__/core-consistency.test.ts`:
- Around line 5-27: Update the ADR-006 consistency test to stop comparing
coreComputeOperationId with irComputeOperationId, since the latter is
re-exported from core and cannot detect drift. Replace the self-comparison cases
with assertions against committed, precomputed golden hash values for each
input, and revise the test comment to describe the shared algorithm and
golden-value regression coverage accurately.
In `@packages/runtime-docker/src/__tests__/integration.test.ts`:
- Around line 13-16: Update the integration test setup around the busybox image
configuration and both test cases so no dummy digest is used. Require
SVERKA_BUSYBOX_DIGEST whenever SVERKA_DOCKER enables the suite, or skip the
entire suite unless both environment variables are set; preserve normal behavior
when integration tests are disabled.
In `@packages/runtime-docker/src/cache.ts`:
- Around line 8-12: Update the CacheManager.collect contract and its
implementations/call sites to receive or otherwise retain the cache key used by
prepare. Ensure collected outputs are written beneath the same <cacheDir>/<key>
directory returned by prepare, while preserving relative output paths within
that key-scoped directory.
- Around line 23-46: Update prepare and collect to resolve each target path and
reject any candidate that escapes cacheDir; validate the resolved prepare target
derived from key and each collect destination derived from sourceDir/output
before creating directories or copying files. Preserve valid nested paths, and
add traversal tests covering escaping key values and outputs outside sourceDir.
In `@packages/runtime-docker/src/config.ts`:
- Around line 12-13: Make the runAs property in the configuration type optional
to match its documented default, then apply "1000:1000" within DockerExecutor
whenever the value is absent. Preserve explicitly provided runAs values and
update the executor’s container configuration path accordingly.
In `@packages/runtime-docker/src/docker-executor.ts`:
- Around line 272-275: Update truncateLogs so truncated output, including
TRUNCATION_NOTICE, never exceeds maxLogBytes. Reserve the notice length when
calculating the slice boundary, and handle limits smaller than the notice by
returning only the allowed number of characters without exceeding the configured
limit.
- Around line 143-149: Update DockerExecutor.execute and its cache flow to use
the configured DockerExecutorConfig.cacheDir consistently instead of mounting
request.cacheDir. Establish a single cache ownership contract, call
DockerCacheManager.prepare() for the operation’s key before runContainer(), and
call DockerCacheManager.collect() for declared outputs after execution while
preserving result finalization.
- Line 289: Validate the destination derived in the artifact-copy flow around
dest before mkdir() or copyFile() runs: resolve artifactDir and the
artifact.name ?? artifact.path target, then reject targets outside the resolved
artifactDir, including traversal in both named and unnamed artifacts. Add tests
covering traversal through artifact.name and artifact.path while preserving
valid destinations.
In `@packages/runtime-docker/src/errors.ts`:
- Around line 26-29: Update ContainerPolicyError to accept a specific policy
error code and pass that code to DockerExecutorError instead of always using
CONTAINER_POLICY_VIOLATION. Revise every ContainerPolicyError call site to
provide the appropriate code, including MISSING_TIMEOUT, MISSING_DIGEST,
UNDECLARED_SECRET, and DOCKER_SOCKET_DENIED, and update tests to assert those
codes.
In `@packages/runtime-docker/src/image.ts`:
- Around line 28-36: Update the image inspection flow around runDocker so a pull
occurs only when the inspect result confirms the image is absent, and return
immediately for timedOut results. Validate the pull result before re-inspecting,
stopping on pull failure, and include Docker’s error output in the raised error
context instead of allowing an empty digest mismatch.
- Around line 28-44: Update the image verification flow around verifyImageDigest
to compare the registry manifest digest from RepoDigests, or inspect the
immutable image@expectedDigest reference, instead of comparing docker inspect’s
.Id configuration digest. Ensure DockerExecutor invokes verifyImageDigest on the
execution path before using the image, while preserving the existing
pull-and-reinspect behavior and ImageDigestError reporting.
In `@packages/runtime-docker/src/internal/docker-cli.ts`:
- Around line 65-70: Update DockerExecutor.runDocker and its stdout/stderr data
handlers to accept the configured maxLogBytes limit, append output only while
the accumulated byte count remains within that limit, and record that truncation
occurred once the limit is exceeded. Continue consuming both child streams after
truncation, and preserve the existing DockerExecutor.truncateLogs behavior for
final output handling.
- Around line 55-62: Update the timeout handling around the child process and
its "close" handler to track whether the child has actually closed, rather than
checking child.killed. Clear the grace-period timer when the close handler runs,
and send SIGKILL after GRACE_PERIOD_MS only when the tracked closed state
remains false.
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: 333ff9e5-c755-4078-8339-eba48ef0bc40
📒 Files selected for processing (31)
engdocs/architecture/wave-05-runtime-docker-plan.mdpackages/core/src/__tests__/composables/workflow.test.tspackages/core/src/__tests__/dag.test.tspackages/core/src/__tests__/ids.test.tspackages/core/src/__tests__/laziness.test.tspackages/core/src/__tests__/matrix.test.tspackages/core/src/__tests__/public-api.test.tspackages/core/src/__tests__/runtime-modes.test.tspackages/core/src/index.tspackages/core/src/internal/canonical.tspackages/core/src/internal/ids.tspackages/core/src/internal/plan.tspackages/ir/src/__tests__/core-consistency.test.tspackages/ir/src/ids.tspackages/ir/src/internal/canonical.tspackages/runtime-docker/project.jsonpackages/runtime-docker/src/__tests__/cache.test.tspackages/runtime-docker/src/__tests__/docker-executor.test.tspackages/runtime-docker/src/__tests__/errors.test.tspackages/runtime-docker/src/__tests__/helpers/fixtures.tspackages/runtime-docker/src/__tests__/image.test.tspackages/runtime-docker/src/__tests__/integration.test.tspackages/runtime-docker/src/__tests__/public-api.test.tspackages/runtime-docker/src/cache.tspackages/runtime-docker/src/config.tspackages/runtime-docker/src/docker-executor.tspackages/runtime-docker/src/errors.tspackages/runtime-docker/src/image.tspackages/runtime-docker/src/index.tspackages/runtime-docker/src/internal/docker-cli.tsspecs/04-runtime-docker/spec.md
📜 Review details
⏰ Context from checks skipped due to timeout. (1)
- GitHub Check: Codacy Static Code Analysis
🧰 Additional context used
🪛 ast-grep (0.45.1)
packages/runtime-docker/src/internal/docker-cli.ts
[warning] Importing child_process exposes a command-execution surface; ensure any command/argument built from input is validated, and prefer execFile/spawn with an argument array over exec.
Context: import { spawn } from "node:child_process";
Note: [CWE-78] Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection').
(detect-child-process-typescript)
🪛 markdownlint-cli2 (0.23.2)
engdocs/architecture/wave-05-runtime-docker-plan.md
[warning] 77-77: Fenced code blocks should have a language specified
(MD040, fenced-code-language)
[warning] 119-119: Fenced code blocks should be surrounded by blank lines
(MD031, blanks-around-fences)
[warning] 130-130: Headings should be surrounded by blank lines
Expected: 1; Actual: 0; Below
(MD022, blanks-around-headings)
[warning] 137-137: Headings should be surrounded by blank lines
Expected: 1; Actual: 0; Below
(MD022, blanks-around-headings)
[warning] 138-138: Ordered list item prefix
Expected: 1; Actual: 3; Style: 1/2/3
(MD029, ol-prefix)
[warning] 140-140: Ordered list item prefix
Expected: 2; Actual: 4; Style: 1/2/3
(MD029, ol-prefix)
[warning] 142-142: Headings should be surrounded by blank lines
Expected: 1; Actual: 0; Below
(MD022, blanks-around-headings)
[warning] 143-143: Ordered list item prefix
Expected: 1; Actual: 5; Style: 1/1/1
(MD029, ol-prefix)
[warning] 150-150: Headings should be surrounded by blank lines
Expected: 1; Actual: 0; Below
(MD022, blanks-around-headings)
[warning] 151-151: Ordered list item prefix
Expected: 1; Actual: 6; Style: 1/2/3
(MD029, ol-prefix)
[warning] 157-157: Ordered list item prefix
Expected: 2; Actual: 7; Style: 1/2/3
(MD029, ol-prefix)
[warning] 166-166: Ordered list item prefix
Expected: 3; Actual: 8; Style: 1/2/3
(MD029, ol-prefix)
[warning] 170-170: Headings should be surrounded by blank lines
Expected: 1; Actual: 0; Below
(MD022, blanks-around-headings)
[warning] 171-171: Ordered list item prefix
Expected: 1; Actual: 9; Style: 1/2/3
(MD029, ol-prefix)
[warning] 175-175: Ordered list item prefix
Expected: 2; Actual: 10; Style: 1/2/3
(MD029, ol-prefix)
[warning] 178-178: Headings should be surrounded by blank lines
Expected: 1; Actual: 0; Below
(MD022, blanks-around-headings)
[warning] 179-179: Ordered list item prefix
Expected: 1; Actual: 11; Style: 1/2/3
(MD029, ol-prefix)
[warning] 184-184: Ordered list item prefix
Expected: 2; Actual: 12; Style: 1/2/3
(MD029, ol-prefix)
[warning] 187-187: Headings should be surrounded by blank lines
Expected: 1; Actual: 0; Below
(MD022, blanks-around-headings)
[warning] 188-188: Ordered list item prefix
Expected: 1; Actual: 13; Style: 1/2/3
(MD029, ol-prefix)
[warning] 194-194: Ordered list item prefix
Expected: 2; Actual: 14; Style: 1/2/3
(MD029, ol-prefix)
[warning] 197-197: Ordered list item prefix
Expected: 3; Actual: 15; Style: 1/2/3
(MD029, ol-prefix)
[warning] 200-200: Headings should be surrounded by blank lines
Expected: 1; Actual: 0; Below
(MD022, blanks-around-headings)
[warning] 201-201: Ordered list item prefix
Expected: 1; Actual: 16; Style: 1/2/3
(MD029, ol-prefix)
[warning] 211-211: Ordered list item prefix
Expected: 2; Actual: 17; Style: 1/2/3
(MD029, ol-prefix)
[warning] 215-215: Headings should be surrounded by blank lines
Expected: 1; Actual: 0; Below
(MD022, blanks-around-headings)
[warning] 216-216: Ordered list item prefix
Expected: 1; Actual: 18; Style: 1/2/3
(MD029, ol-prefix)
[warning] 222-222: Ordered list item prefix
Expected: 2; Actual: 19; Style: 1/2/3
(MD029, ol-prefix)
[warning] 225-225: Headings should be surrounded by blank lines
Expected: 1; Actual: 0; Below
(MD022, blanks-around-headings)
[warning] 226-226: Ordered list item prefix
Expected: 1; Actual: 20; Style: 1/2/3
(MD029, ol-prefix)
[warning] 234-234: Ordered list item prefix
Expected: 2; Actual: 21; Style: 1/2/3
(MD029, ol-prefix)
[warning] 238-238: Headings should be surrounded by blank lines
Expected: 1; Actual: 0; Below
(MD022, blanks-around-headings)
[warning] 239-239: Ordered list item prefix
Expected: 1; Actual: 22; Style: 1/1/1
(MD029, ol-prefix)
[warning] 245-245: Headings should be surrounded by blank lines
Expected: 1; Actual: 0; Below
(MD022, blanks-around-headings)
[warning] 246-246: Ordered list item prefix
Expected: 1; Actual: 23; Style: 1/2/3
(MD029, ol-prefix)
[warning] 250-250: Ordered list item prefix
Expected: 2; Actual: 24; Style: 1/2/3
(MD029, ol-prefix)
[warning] 251-251: Ordered list item prefix
Expected: 3; Actual: 25; Style: 1/2/3
(MD029, ol-prefix)
🔇 Additional comments (25)
packages/runtime-docker/src/docker-executor.ts (2)
54-55: Remove the unsupported Docker timeout flag.
docker rundoes not support--timeout. The Docker CLI command will fail before it starts the container.
143-149: Verify the image digest before starting the container.
execute()never callsverifyImageDigest(). The digest verification utility is therefore bypassed.packages/core/src/__tests__/composables/workflow.test.ts (1)
36-45: LGTM!packages/core/src/__tests__/dag.test.ts (1)
9-10: LGTM!Also applies to: 12-28, 31-45, 47-58, 68-77, 85-87
packages/core/src/__tests__/laziness.test.ts (1)
58-62: LGTM!packages/runtime-docker/src/config.ts (1)
1-11: LGTM!Also applies to: 14-18
packages/runtime-docker/src/internal/docker-cli.ts (1)
1-53: LGTM!Also applies to: 72-91
packages/runtime-docker/src/image.ts (1)
18-26: LGTM!packages/runtime-docker/src/__tests__/image.test.ts (1)
1-97: LGTM!packages/runtime-docker/src/__tests__/helpers/fixtures.ts (1)
1-64: LGTM!packages/runtime-docker/src/__tests__/public-api.test.ts (1)
1-51: LGTM!packages/runtime-docker/src/index.ts (1)
2-8: LGTM!packages/core/src/__tests__/ids.test.ts (1)
1-67: LGTM!packages/core/src/__tests__/matrix.test.ts (1)
6-26: LGTM!Also applies to: 48-52
packages/core/src/__tests__/public-api.test.ts (1)
46-72: LGTM!packages/core/src/__tests__/runtime-modes.test.ts (1)
38-41: LGTM!Also applies to: 51-52, 75-95, 104-112, 128-130, 143-152, 165-173
packages/core/src/index.ts (1)
28-28: LGTM!packages/core/src/internal/canonical.ts (1)
2-18: LGTM!Also applies to: 68-70, 108-113, 144-144
packages/core/src/internal/ids.ts (1)
1-28: LGTM!packages/core/src/internal/plan.ts (4)
327-357: LGTM!
402-442: LGTM!
4-4: LGTM!Also applies to: 29-41, 88-97
371-390: 🎯 Functional CorrectnessDo not expand
contextForto include the full operation spec.The documented operation-ID contract uses matrix values,
userId,command, andargs. Other operation fields are included in the emitted operation and therefore affectcomputePlanId; they are not inputs tocomputeOperationId.> Likely an incorrect or invalid review comment.packages/ir/src/internal/canonical.ts (1)
1-8: LGTM!packages/ir/src/ids.ts (1)
2-2: 🗄️ Data Integrity & IntegrationNo dependency change is required.
packages/ir/package.jsondeclares@sverka/coreunderdependencies, so published consumers can resolve the runtime import.> Likely an incorrect or invalid review comment.
…wave-5 - matrix tests: strengthen multi-dim test and add duplicate/type tests - plan.ts: preserve __matrixCombo in makeNodeWith; throw on unknown topo deps - core-consistency: assert ir re-export and pin golden op- hashes - runtime-docker: wire DockerCacheManager, fix cache ownership and path traversal - runtime-docker: runAs default, specific ContainerPolicyError codes - runtime-docker: log truncation reserves notice length - runtime-docker: artifact collection validates destinations under artifactDir - runtime-docker: image digest verification uses RepoDigests with timeout/pull checks - docker-cli: track child close, cap output while streaming Co-Authored-By: Petr Plenkov <petr.plenkov@gmail.com>
…, cache paths, and artifacts - Canonicalize paths before checking for docker.sock mount/env references. - Reject absolute artifact paths and keep workspace-relative source resolution. - Preserve cache input directory structure using the workspace root. - Skip missing cache outputs during collect instead of aborting. - Tighten SECRET_DENYLIST to avoid PUBLIC_KEY false positives. Co-Authored-By: Petr Plenkov <petr.plenkov@gmail.com>
- plan.ts: split topoSort into buildDependencyGraph + kahnSort helpers. - docker-executor.ts: split buildDockerArgs into buildBaseArgs/buildMountArgs. - image.ts: extract dockerOptions, dockerInspect, dockerPull, and assertInspectOk helpers. Co-Authored-By: Petr Plenkov <petr.plenkov@gmail.com>
- core/project.json: remove --passWithNoTests from test target - core/ids.test.ts: add mixed-type context test - core/plan.ts: suppress finalize rejection and extract outcomeForSkipped - ir/validate.ts: recompute id by omitting identity fields, remove validateAcyclic early return, validate operation kind - ir/validate.test.ts: remove unused plan constant, add extra top-level field test - ir/core-consistency.test.ts: use OperationKind type and remove as never casts Co-Authored-By: Petr Plenkov <petr.plenkov@gmail.com>
…mplexity Co-Authored-By: Petr Plenkov <petr.plenkov@gmail.com>
Co-Authored-By: Petr Plenkov <petr.plenkov@gmail.com>
|



User description
Summary
Test plan
Stacked on #5
Generated with Devin
Summary by cubic
Adds
DockerExecutorto@sverka/runtime-dockerfor secure, digest-verified container runs, and switches@sverka/coreand@sverka/irto deterministic SHA-256op-IDs. Also hardens@sverka/runtime-hostto treat process spawn failures as runtime errors.ImageDigestError.request.artifactDir, rejects absolute destinations, uses workspace-relative sources, and blocks traversal with specificContainerPolicyErrorcodes./cache.runAsis "1000:1000"; tightened secret denylist to avoidPUBLIC_KEYfalse positives and added specific codes for blocked socket and undeclared secrets.__matrixCombo, throws on unknown dependency IDs, suppresses finalize rejections, and unifies skipped outcomes;@sverka/irre-exportscomputeOperationId, validates operation kinds, recomputes plan IDs ignoring identity fields, and accepts extra top-level fields in ID calculation.error.Written for commit c0e424f. Summary will update on new commits.
CodeAnt-AI Description
Add secure Docker execution and content-addressed operation IDs
What Changed
op-IDs based on operation content, including matrix values and commands; dependency references and duplicate detection use these IDsImpact
✅ Sandboxed Docker execution✅ Reproducible operation and matrix IDs✅ Blocked Docker socket and undeclared secret access🔄 Retrigger CodeAnt AI Review
💡 Usage Guide
Checking Your Pull Request
Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.
Talking to CodeAnt AI
Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:
This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.
Example
Preserve Org Learnings with CodeAnt
You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:
This helps CodeAnt AI learn and adapt to your team's coding style and standards.
Example
Retrigger review
Ask CodeAnt AI to review the PR again, by typing:
Check Your Repository Health
To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.