Skip to content

fix(sandbox): keep backups from releasing private workspaces - #2800

Merged
justinhelmer merged 1 commit into
mainfrom
codex/workspace-reclamation
Oct 6, 2026
Merged

justinhelmer merged 1 commit into
mainfrom
codex/workspace-reclamation

Conversation

@justinhelmer

Copy link
Copy Markdown
Contributor

Checkout backups return stored/unknown evidence and cannot authorize seeded teardown. Offline v1 restore refuses incomplete receipt identities before writing a restore tree.

Why: A writer can change bytes between pause samples while an upload stores an earlier checkout. Backup existence cannot prove complete custody. Independently restored bytes also cannot fill in missing receipt identity.

Where to look

  1. Backup observation Typed stored/unknown evidence replaces the boolean stop permit.
  2. Seeded retention Retains after the observation; positively unseeded containers keep their existing teardown path.
  3. Legacy receipt reader Checks identity, format, hashes and counters before creating the restore directory.

Feedback wanted: Check that no backup observation reaches either teardown path and that valid v1 archives remain readable without promoting receipt metadata into owner authority.

Risk: Seeded workspaces remain retained. Full custody capture, physical writer exclusion, original-owner archive ACK and safe reclamation remain unproved. Malformed legacy receipts now refuse before restore.

Verified: 101 named tests; root/sandbox types, lint/format, specs/hygiene/coverage/test guard. Real screenshots regenerated; all 44 PNG bytes unchanged.

Decisions (2)
  • Observation stays separate from retirement. Keep the existing legacy backup format and readers. A checkout-only stored observation is never a physical stop permit. The current unsupported quiescence path remains refused; no new cleanup controller or runtime capability is asserted.
  • Validate the complete legacy receipt. Construct the typed v1 result from checked fields before restore writes. Valid existing receipts and the byte verifier remain compatible; recorded identity still requires independent original-owner provenance before any retirement.
Validation (4 criteria)
Criterion Proof
A stale uploaded checkout with positive pause samples cannot reach SDK destroy or native kill. src/execution/sandboxCheckpoint.test.ts::checkpointIfSafe::never treats sampled pause around checkout upload as complete retirement evidence; RED against original helper, GREEN after typed observation.
Malformed or incomplete receipt identity refuses before writing a restore; valid v1 bytes still restore. src/execution/residentArchive.test.ts::resident archive harness::rejects an incomplete or malformed legacy receipt before writing a restore; actual local Python capture and independent Node restore, RED/GREEN.
Existing seeded refusal, positively unseeded teardown and passive receipts remain covered. npx vitest run src/execution/sandboxCheckpoint.test.ts src/execution/sandboxIdle.test.ts src/execution/sandboxLifecycle.test.ts src/execution/residentArchive.test.ts: 101 passed.
Generated screenshot input manifests match actual rendering without changing image bytes. npm run screenshots:gen; independent SHA-256 comparison: 44 of 44 PNGs unchanged; npm run screenshots:check: 22 surfaces current.
For agents

This is source evidence hardening. No image upload, production stop, purge, replay, new backup format, archive-pointer migration, owner/fence schema or native backend change. Complete current private checkout plus pi/OpenCode runtime custody, continuous exclusion, independent restore and original-store exact-version ACK remain a required final capability. Source tests and health do not establish that acceptance. Polylane service/feed lookup returned no mapping and issues read was unavailable; no cleared production-impact claim. Merge/release/deploy remain with the parent coordinator.

🤖 Generated with Claude Code

@justinhelmer
justinhelmer marked this pull request as ready for review October 6, 2026 02:24

@coreplane-switchboard coreplane-switchboard Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM: Fresh independent review at the frozen head: no verified major-or-higher findings in source-preservation hardening.

Note

Approved · head 0d7a934 · no findings

Full review

No verified major-or-higher findings; this source-only approval does not establish physical writer exclusion, complete runtime custody, original-store archive ACK, or safe retirement.

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto-approved: coreplane-switchboard[bot] reviewed this PR and posted an LGTM verdict (see its review). This repository opted in through its REVIEW_BOT_LOGIN and REVIEW_BOT_ID variables.

@polylane

polylane Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Warning

Polylane could not verify the production impact of this pull request.

Checked the teardown and restore changes against switchboard-sandbox (coreplane-infra, 0 errors over 72h). preserveBeforeDestroy already returned false in effect, so this is behavior-neutral hardening. The stricter restore check is an offline CLI that fails closed.

View the full analysis →

Also considered · 2 refuted
  • Refuted · Retained seeded containers accumulate and exhaust the sandbox pool · The teardown gate is identical before and after: both versions return false for every seeded/unknown container and never invoke backup/save (safeQuiescence is always false).
  • Refuted · Stricter receipt validation refuses valid legacy archives, breaking restore · No production Worker binds this function (grep across src/ and deploy/ finds only the CLI and tests).

switchboard-sandbox · requests per hour

Analysed against 7 cloud accounts and 1 repository
  • Cloud accounts: coreplane-prod, baseberry-uat, coreplane-infra, coreplane, coreplane-gtm, 251714435813, Polylane
  • Repository: coreplanelabs/switchboard

View in Polylane Disable reviews

Polylane could not find the cloud resources this repository manages, so this review looked at the entire cloud account. Connect this repository to its resources and the next review will focus on exactly what this code deploys to.

Connect resources

Polylane analysed 0d7a934 for production impact. You can ask follow-ups by mentioning @polylane in a comment.

Did this help? React 👍 or 👎 so the next review is sharper.

@justinhelmer
justinhelmer merged commit ccb3fde into main Oct 6, 2026
29 checks passed
@justinhelmer
justinhelmer deleted the codex/workspace-reclamation branch October 6, 2026 02:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant