Skip to content

feat(service,sdk): attach labels to VMs at create and expose them in list - #336

Open
tholop wants to merge 1 commit into
0.7from
feat/sdk-vm-labels
Open

tholop wants to merge 1 commit into
0.7from
feat/sdk-vm-labels

Conversation

@tholop

@tholop tholop commented Oct 7, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Adds optional key/value string labels (Option<HashMap<String, String>>) to ProvisionRequest (POST /vms/create), ForkRequest (POST /vms/{id}/fork), SandboxInfo (GET /vms/list and GET /vms/{id}/info), VmInstance, SessionCreationParams, and PersistentVmEntry.
  • Forking (ForkRequest) inherits the source VM's labels when labels is omitted/null, replaces them when a non-empty map is provided, and clears them when {} is passed.
  • Validates labels server-side via naming::validate_vm_labels:
    • Up to 64 entries (MAX_VM_LABELS).
    • Keys reuse validate_vm_name (1..=64 ASCII characters starting with [A-Za-z0-9] and containing only [A-Za-z0-9_-]).
    • Values are up to 255 UTF-8 bytes (MAX_VM_LABEL_VALUE_LEN) with no ASCII or Unicode control characters.
    • Normalizes empty maps via naming::non_empty_labels so {} is stored and serialized identically to None.
  • Regenerates openapi.json and threads labels through the Python, Rust, and TypeScript SDKs plus capsem create and capsem fork (-l / --label KEY=VALUE).

Notes for Review

@codecov-commenter

codecov-commenter commented Oct 7, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 95.81395% with 9 lines in your changes missing coverage. Please review.
⚠️ Please upload report for BASE (integration/0.7-clients-inspect@2ad7638). Learn more about missing BASE report.
✅ All tests successful. No failed tests found.

Files with missing lines Patch % Lines
build_system/builder/gate/qualifyschema.py 97.0% 3 Missing ⚠️
crates/capsem/src/main.rs 0.0% 2 Missing ⚠️
crates/capsem-service/src/vm_lifecycle.rs 75.0% 1 Missing ⚠️
crates/capsem-tui/src/sdk_actions.rs 50.0% 0 Missing and 1 partial ⚠️
crates/capsem/src/container_run.rs 0.0% 1 Missing ⚠️
crates/capsem/src/create_command.rs 50.0% 0 Missing and 1 partial ⚠️
Additional details and impacted files
@@                        Coverage Diff                         @@
##             integration/0.7-clients-inspect     #336   +/-   ##
==================================================================
  Coverage                                   ?    66.1%           
==================================================================
  Files                                      ?     1482           
  Lines                                      ?   121272           
  Branches                                   ?    86139           
==================================================================
  Hits                                       ?    80200           
  Misses                                     ?    36637           
  Partials                                   ?     4435           
Flag Coverage Δ
integration 21.9% <ø> (?)
linux-unit 71.9% <92.5%> (?)
mcp-server 94.7% <ø> (?)
python-sdk 98.9% <100.0%> (?)
typescript-sdk 98.3% <100.0%> (?)
unit 64.1% <95.4%> (?)

Flags with carried forward coverage won't be shown. Click here to find out more.

Components Coverage Δ
TypeScript SDK 98.3% <0.0%> (?)
Python SDK 98.9% <0.0%> (?)
Network 85.5% <0.0%> (?)
Security 82.8% <0.0%> (?)
Tooling 88.6% <0.0%> (?)
Monitoring 87.6% <0.0%> (?)
Virtualization 65.3% <0.0%> (?)
Confined Port Router 76.7% <0.0%> (?)
Private Network 78.9% <0.0%> (?)
Assets 84.3% <0.0%> (?)
Gateway API 96.8% <0.0%> (?)
Rust SDK 96.3% <0.0%> (?)
Configuration 87.0% <0.0%> (?)
Credentials 80.7% <0.0%> (?)
Host Foundation 76.6% <0.0%> (?)
Core Platform 55.8% <0.0%> (?)
Runtime 61.5% <0.0%> (?)
Daemon 41.6% <0.0%> (?)
Service 75.4% <0.0%> (?)
Process 49.1% <0.0%> (?)
Admin 70.0% <0.0%> (?)
CLI 47.3% <0.0%> (?)
MCP Server 94.7% <0.0%> (?)
MCP Aggregator 61.8% <0.0%> (?)
MCP Builtin 57.4% <0.0%> (?)
Gateway 80.3% <0.0%> (?)
TUI 67.7% <0.0%> (?)
System Tray 52.8% <0.0%> (?)
Guard 92.2% <0.0%> (?)
UI 84.8% <0.0%> (?)
Release Site 25.6% <0.0%> (?)
Builder 42.6% <0.0%> (?)
Mock Server 59.3% <0.0%> (?)
Bench 48.5% <0.0%> (?)
Files with missing lines Coverage Δ
build_system/builder/gate/buildschema.py 97.1% <100.0%> (ø)
crates/capsem-api/src/lifecycle.rs 86.6% <100.0%> (ø)
crates/capsem-service/src/instance.rs 100.0% <ø> (ø)
crates/capsem-service/src/main.rs 74.9% <ø> (ø)
crates/capsem-service/src/naming.rs 98.1% <100.0%> (ø)
crates/capsem-service/src/registry.rs 85.8% <ø> (ø)
crates/capsem-service/src/sandbox_info.rs 95.7% <100.0%> (ø)
crates/capsem-service/src/vm_files.rs 86.2% <100.0%> (ø)
crates/capsem-service/src/vm_files/fork.rs 88.7% <100.0%> (ø)
crates/capsem-service/src/vm_files/provision.rs 62.9% <100.0%> (ø)
... and 21 more
🚀 New features to boost your workflow:
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

…list

Allow callers to attach optional key/value string labels to VMs at
creation time, inherit or override them on fork, and return them on
every SandboxInfo entry in /vms/list and /vms/{id}/info so external
orchestrators and garbage collectors can identify their own VMs.

- capsem-api / capsem-service / OpenAPI: add optional labels
  (Option<HashMap<String, String>>) to ProvisionRequest, ForkRequest,
  SandboxInfo, VmInstance, SessionCreationParams, and PersistentVmEntry,
  validated server-side via naming::validate_vm_labels (<= 64 entries,
  keys reuse validate_vm_name: 1..=64 ASCII chars starting with
  [A-Za-z0-9] and containing only [A-Za-z0-9_-]; values <= 255 UTF-8
  bytes with no control chars) and normalized via
  naming::non_empty_labels so {} is treated identically to None.
- Fork inheritance: /vms/{id}/fork inherits the source VM's labels when
  ForkRequest.labels is omitted/null, replaces them when a non-empty map
  is provided, and clears them when {} is provided.
- List cache fingerprint: include running and inactive VM labels in
  list_response_fingerprint via append_labels_fingerprint so label
  differences invalidate cached /vms/list responses.
- SDKs (Python, Rust, TypeScript): thread optional labels through
  Hypervisor.create / CreateOptions and VM.fork / ForkOptions and
  regenerate OpenAPI models across all three SDKs.
- CLI & TUI: add repeatable -l / --label KEY=VALUE to capsem create and
  capsem fork, and display labels in the TUI session detail pane.
@tholop
tholop force-pushed the feat/sdk-vm-labels branch from bc9bdb5 to 2514565 Compare October 8, 2026 13:07
@tholop
tholop changed the base branch from integration/0.7-clients-inspect to 0.7 October 8, 2026 13:12
@tholop tholop changed the title feat(service,sdk): add persistent VM labels and server-side label filtering feat(service,sdk): attach labels to VMs at create and expose them in list Oct 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants