feat: add sandbox provider conformance - #31
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
MANAGED_AGENT_SANDBOXvalues instead of silently executing on the hostAttachwhile preserving existing durable reference valuesProvider contract
The shared suite covers stable identity, POSIX execution, binary file round trips, path confinement, cancellation, idempotent
Create, fresh-clientAttach, workspace preservation, cross-session ownership rejection, idempotentDestroy, and explicitErrNotFoundafter deletion. Provider-specific isolation/resource tests remain separate.Scope
This is the adapter foundation, not a sandbox service and not a provider-specific public API. E2B, CubeSandbox, OpenSandbox, and other remote adapters remain follow-up PRs. Docker still uses its existing CLI transport; orphan reconciliation and optional pause/snapshot capabilities are separate work.
Verification
go test ./...go test -race ./...go vet ./...MERGEABLE yesgolangci-lintwas unavailable locally and is left to CI.