Repository navigation
Define the Sandbox Provider protocol in one file - #521
Merged
Merged
Conversation
This was referenced Oct 7, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
AGENTS.md gives each boundary exactly one protocol: one code file and one document. Support is learned only through declarations, never through type assertions. The Core–Sandbox Provider boundary was spread over five files (
sandbox_provider.go,suspension.go,selection.go,configuration.go,runtimeobs/source.go). Every interface was already required by a reflection check, yet callers still discovered support by casting, 28 times. This is T1a in the architecture audit.sandbox_provider.gois the protocol file.SandboxProvidercovers the allocation lifecycle, the nine checkpoint methods andObserve. Every method is required at compile time, andProviderOperationsdeclares which ones are supported. A reflection test keeps the operation groups equal to the interface's method set.ConfigurationAdapteris the setup-time half: decode, encode, normalize,DiscoverConfiguration,DiscoverSelectionandVerifyCredential, each declared inConfigurationRequirements. The registry checks a declaration before every call, and turns "unsupported" from an operation declared supported intoErrContract. Prepare branches on the declaration, so nothing falls back implicitly.CheckpointProvider,SelectionDiscoverer,CredentialVerifierandConfigurationDiscoverer;providerInterfaces,sandbox.Checkpoint()and the reflectionImplementscheck;runtimeobsowns the observation types, and imports stay one-way.runtimeobs.NewServicetakes the deployment's Provider and its registered kind directly.ResolveObservationSource,SourceResolverand its one-entry map;ObserveBatch,BatchSourceandreadBatch. The batch path never ran in production, because routers redeclared it unsupported.ObservationProviderTypeis deleted; every implementation returned the registered kind.MaxObservationReferencesis gone.Quiescentis a declared field of the built generation, besideProbeandClose, set by the microsandbox builder. The anonymousQuiescent()assertions are gone.docs/sandbox-provider.md(en/zh) describes the protocol and states the existing registration rule that checkpoint is admitted only fornodes-mode Providers.runtime-observability*.mdand the E2B helper README are updated.CheckpointProvideridentifier now reads "the declared checkpoint lifecycle".Behaviour
source_not_configurednow means only that this Core has no managed installation identity.ErrContractinstead of being silently skipped.deployment.AllocationSetupalready rejects a retained generation whose Provider differs from the current one, and the blind review verified this.Review
A fresh-context blind review found no must-fix. Its verdict was "merge after fixes". Both should-fixes are fixed: the implicit fallback in prepare, and hand-kept operation lists with no test. So are the nits: the
source_not_configureddoc, a zeroSelectionon error, aQuiescentassertion, and the boundary wording.Checks
go build ./...andgo vet ./....tests/integration: 722 passed.-raceonsandbox/node,contractgen --check, and the E2B helper Python tests (180) and template tests (11).make openapi(no diff),TestCoreErrorCatalog, the translation test andcheck-names.Net: non-test −474, tests −320, docs −10.
🤖 Generated with Claude Code
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.