Feat v0.8.0 files sandbox module
All checks were successful
CI/CD / detect-changes (pull_request) Successful in 4s
CI/CD / test-frontend (pull_request) Has been skipped
CI/CD / test-runners (pull_request) Has been skipped
CI/CD / e2e-smoke (pull_request) Has been skipped
CI/CD / test-go-pg (pull_request) Successful in 2m44s
CI/CD / test-sqlite (pull_request) Successful in 2m57s
CI/CD / build-and-deploy (pull_request) Successful in 1m25s
All checks were successful
CI/CD / detect-changes (pull_request) Successful in 4s
CI/CD / test-frontend (pull_request) Has been skipped
CI/CD / test-runners (pull_request) Has been skipped
CI/CD / e2e-smoke (pull_request) Has been skipped
CI/CD / test-go-pg (pull_request) Successful in 2m44s
CI/CD / test-sqlite (pull_request) Successful in 2m57s
CI/CD / build-and-deploy (pull_request) Successful in 1m25s
Bridge ObjectStore (PVC/S3) into the Starlark sandbox with extension-scoped key namespacing. New files module with put/get/meta/list/delete/exists builtins gated by files.read and files.write permissions. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
24
CHANGELOG.md
24
CHANGELOG.md
@@ -2,6 +2,30 @@
|
||||
|
||||
All notable changes to Armature are documented here.
|
||||
|
||||
## v0.8.0 — Files Module
|
||||
|
||||
New `files` sandbox module. Bridges the existing ObjectStore (PVC/S3) into
|
||||
the Starlark sandbox with extension-scoped key namespacing.
|
||||
|
||||
**files module (permissions: `files.read`, `files.write`)**
|
||||
|
||||
- `files.put(name, content, content_type, metadata)` — store a file with optional metadata companion. Accepts string or bytes content. 50 MB default limit (configurable via `EXT_FILES_MAX_SIZE`).
|
||||
- `files.get(name)` — read a file. Returns dict with `content` (bytes), `content_type`, `size`, `metadata`. Returns None if not found.
|
||||
- `files.meta(name)` — read metadata only (no content transfer).
|
||||
- `files.list(prefix, limit)` — list files by prefix. Returns list of dicts. Filters out internal `_meta/` companions.
|
||||
- `files.delete(name)` — delete a file and its metadata companion. Idempotent.
|
||||
- `files.delete_prefix(prefix)` — delete all files under a prefix.
|
||||
- `files.exists(name)` — check existence without reading.
|
||||
|
||||
**Internal**
|
||||
|
||||
- New file: `sandbox/files_module.go`.
|
||||
- New permission constants: `ExtPermFilesRead`, `ExtPermFilesWrite`.
|
||||
- `ObjectStore` interface gains `List(ctx, prefix, limit)` method; implemented for PVC and S3.
|
||||
- Runner wiring: `SetObjectStore()` setter, `buildModulesWithLibCtx` creates files module when permission granted.
|
||||
- All keys scoped to `ext/{packageID}/`. Metadata stored as companion JSON at `ext/{packageID}/_meta/{name}`.
|
||||
- 16 new tests (15 files module + 1 PVC list).
|
||||
|
||||
## v0.7.12 — Concurrent Execution Primitive
|
||||
|
||||
New `batch` sandbox module. Enables extensions to parallelize arbitrary
|
||||
|
||||
Reference in New Issue
Block a user