mirror of
https://github.com/simstudioai/sim.git
synced 2026-09-24 15:45:35 +08:00
feat(code): cli sandboxes, enterprise timeouts, secrets projections, resolver lift, workflow exec cancellations (#6247)
* feat(code): cli sandboxes, enterprise timeouts, secrets projections, resolver lift * fix(execution): harden compatibility and secret diagnostics * fix(execution): harden generated JavaScript literals * fix(execution): align timeout cleanup semantics * fix(tables): decouple stale job cleanup * fix(execution): drain stale workflow backlog * test(sandbox): make deadline assertions timing-safe * fix(execution): lock cleanup candidate batches * fix(execution): preserve cleanup failure metrics * cancel route fixes * separate out mship template and func template * fix * fix(execution): harden secret projection and block runs * fix(workflow): validate draft execution state * run from block ui disabling * feat(copilot): expose Sim sandboxes to mothership * feat(copilot): expose sandbox capability catalog in VFS * Updates * fix legacy logs showing up * fix(copilot): keep sandbox config visible * fix model provenance issues * fix lint' * more lint * more * test(files): align provenance copy query order * consolidate migrations, rollout compat * integration projections * update skills * fix * add provenance linters * fix: address review and compatibility regressions * fix: make tool boundary audit Bun 1.3 compatible --------- Co-authored-by: Siddharth Ganesan <siddharthganesan@gmail.com>
This commit is contained in:
co-authored by
Siddharth Ganesan
parent
5baa7a41ec
commit
117fe3137b
+25
-15
@@ -4,7 +4,6 @@ import {
|
||||
CORE_CONFIGURATION_KEYS,
|
||||
EMAIL_CAPABILITY,
|
||||
EnvCapabilityConfigurationError,
|
||||
hasEnvCapabilityValue,
|
||||
inspectCapability,
|
||||
inspectOAuthClientCapability,
|
||||
OAUTH_CLIENT_CAPABILITIES,
|
||||
@@ -382,25 +381,36 @@ function checkCoherence(ctx: CheckContext): Finding[] {
|
||||
})
|
||||
}
|
||||
|
||||
// NEXT_PUBLIC_SANDBOX_ENABLED is not a 1:1 twin: remote execution is available
|
||||
// under E2B_ENABLED or, when SANDBOX_PROVIDER=daytona, DAYTONA_API_KEY. Without
|
||||
// it the Function block hides its language dropdown and sandbox selector even
|
||||
// though the server would happily run Python.
|
||||
const sandboxProvider = inspectCapability(SANDBOX_CAPABILITY, sim.vars).providerId
|
||||
/**
|
||||
* Function sandbox visibility is not a 1:1 server/client twin. The selected
|
||||
* provider is ready only when its credential and immutable Function base are
|
||||
* valid, while the browser separately reads the public visibility flag.
|
||||
*/
|
||||
const sandboxInspection = inspectCapability(SANDBOX_CAPABILITY, sim.vars)
|
||||
const sandboxProvider = sandboxInspection.providerId
|
||||
const selectedSandboxProvider = sandboxInspection.providers.find(
|
||||
(provider) => provider.id === sandboxProvider
|
||||
)
|
||||
const remoteSandboxAvailable =
|
||||
sandboxProvider === 'daytona'
|
||||
? hasEnvCapabilityValue(sim.vars, 'DAYTONA_API_KEY')
|
||||
: sandboxProvider === 'e2b'
|
||||
? isTruthy(sim.vars.get('E2B_ENABLED'))
|
||||
: false
|
||||
if (remoteSandboxAvailable && !isTruthy(sim.vars.get('NEXT_PUBLIC_SANDBOX_ENABLED'))) {
|
||||
!sandboxInspection.error && selectedSandboxProvider?.state === 'ready'
|
||||
const publicSandboxEnabled = isTruthy(sim.vars.get('NEXT_PUBLIC_SANDBOXES_ENABLED'))
|
||||
if (remoteSandboxAvailable && !publicSandboxEnabled) {
|
||||
findings.push({
|
||||
group: 'coherence',
|
||||
status: 'fail',
|
||||
message:
|
||||
'remote sandboxes are configured but NEXT_PUBLIC_SANDBOX_ENABLED is unset — the Function block will hide its language and sandbox controls',
|
||||
fix: 'doctor --fix sets NEXT_PUBLIC_SANDBOX_ENABLED=true',
|
||||
autofix: () => writeEnvValues(sim.target, { NEXT_PUBLIC_SANDBOX_ENABLED: 'true' }),
|
||||
'remote sandboxes are configured but NEXT_PUBLIC_SANDBOXES_ENABLED is unset — the Function block will hide its language and sandbox controls',
|
||||
fix: 'doctor --fix sets NEXT_PUBLIC_SANDBOXES_ENABLED=true',
|
||||
autofix: () => writeEnvValues(sim.target, { NEXT_PUBLIC_SANDBOXES_ENABLED: 'true' }),
|
||||
})
|
||||
} else if (!remoteSandboxAvailable && publicSandboxEnabled) {
|
||||
findings.push({
|
||||
group: 'coherence',
|
||||
status: 'fail',
|
||||
message:
|
||||
'NEXT_PUBLIC_SANDBOXES_ENABLED is on but the selected provider lacks credentials or a valid immutable Function base — the UI exposes a runtime that will reject execution',
|
||||
fix: 'doctor --fix sets NEXT_PUBLIC_SANDBOXES_ENABLED=false; finish provider setup before enabling it',
|
||||
autofix: () => writeEnvValues(sim.target, { NEXT_PUBLIC_SANDBOXES_ENABLED: 'false' }),
|
||||
})
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user