Feat v0.8.1 workspace module
All checks were successful
CI/CD / detect-changes (pull_request) Successful in 3s
CI/CD / test-frontend (pull_request) Has been skipped
CI/CD / test-runners (pull_request) Has been skipped
CI/CD / e2e-smoke (pull_request) Has been skipped
CI/CD / test-go-pg (pull_request) Successful in 2m47s
CI/CD / test-sqlite (pull_request) Successful in 2m55s
CI/CD / build-and-deploy (pull_request) Successful in 1m10s
All checks were successful
CI/CD / detect-changes (pull_request) Successful in 3s
CI/CD / test-frontend (pull_request) Has been skipped
CI/CD / test-runners (pull_request) Has been skipped
CI/CD / e2e-smoke (pull_request) Has been skipped
CI/CD / test-go-pg (pull_request) Successful in 2m47s
CI/CD / test-sqlite (pull_request) Successful in 2m55s
CI/CD / build-and-deploy (pull_request) Successful in 1m10s
Managed disk directories for extensions needing real filesystem access
(git, compilers, media tools). Five builtins: create, path, list,
delete, usage. Extension-scoped to {WORKSPACE_ROOT}/{packageID}/{name}/.
- New sandbox/workspace_module.go with path traversal + symlink protection
- Permission: workspace.manage; config: WORKSPACE_ROOT, WORKSPACE_QUOTA_MB
- Runner wiring with graceful degradation (module absent if root unwritable)
- 16 new tests, all passing with -race
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -176,6 +176,14 @@ func main() {
|
||||
starlarkRunner.SetAllowPrivateIPs(true)
|
||||
log.Printf(" ⚠️ Extension SSRF protection relaxed: private IPs allowed")
|
||||
}
|
||||
if cfg.WorkspaceRoot != "" {
|
||||
if err := os.MkdirAll(cfg.WorkspaceRoot, 0755); err == nil {
|
||||
starlarkRunner.SetWorkspaceRoot(cfg.WorkspaceRoot, cfg.WorkspaceQuotaMB)
|
||||
log.Printf(" workspace root: %s", cfg.WorkspaceRoot)
|
||||
} else {
|
||||
log.Printf(" workspace root %s not writable, workspace module disabled", cfg.WorkspaceRoot)
|
||||
}
|
||||
}
|
||||
|
||||
// ── Bundled Packages ───────────────
|
||||
// Auto-install bundled .pkg archives on first run.
|
||||
|
||||
Reference in New Issue
Block a user