Project-2 baseline

This commit is contained in:
2026-10-04 21:19:23 -04:00
parent 0f04889edf
commit 213eb3c403
861 changed files with 1710 additions and 3363322 deletions

View File

@@ -76,7 +76,10 @@ dnsjail_apply() {
drop_ours
# cache-size=0: every lookup goes upstream, so a jailed container sees what an unjailed
# one would rather than an answer this resolver decided to keep.
dnsmasq --no-resolv --no-hosts --listen-address=127.0.0.1 --bind-interfaces \
# -u root: dnsmasq 2.80 (buster and older bases) drops to "nobody" and calls capset to
# retain CAP_NET_ADMIN, which docker's default cap set does not grant -- so it exits and
# the jail fails open on every such image.
dnsmasq -u root --no-resolv --no-hosts --listen-address=127.0.0.1 --bind-interfaces \
--cache-size=0 --pid-file="$STATE/dnsmasq.pid" --address=/#/ $srv \
>/dev/null 2>>"$STATE/dnsmasq.err" || true
fi

View File

@@ -53,6 +53,38 @@ _harness_trim() {
printf '%s' "${out:-$1}"
}
# Every env var a harness authenticates from, registry-derived so a new harness row is
# covered without touching this. ANTHROPIC_* unconditionally: it is what .env carries and
# what harbor-run hands the trial sandbox, registry or not.
_harness_credential_vars() {
local id key_env base_url_env proxy_path
printf '%s\n' ANTHROPIC_API_KEY ANTHROPIC_BASE_URL
while IFS=$'\t' read -r id key_env base_url_env proxy_path; do
if [ -n "$key_env" ]; then printf '%s\n' "$key_env"; fi
if [ -n "$base_url_env" ]; then printf '%s\n' "$base_url_env"; fi
done < <(_harness_query --authoring-credentials 2>/dev/null || true)
}
# Source .env into the CALLER's environment and trim what a harness reads its key from.
# For codex the live value is now the env var, not the auth file harness_write_auth
# cleans, so a raw `set -a; . .env` is the 401 all over again on a Windows-saved file.
harness_load_env() {
local file="${1:-${RACCOON_ENV_FILE:-/workspace/.env}}" v
if [ -f "$file" ]; then
set -a
# shellcheck disable=SC1090
. "$file" 2>/dev/null || true
set +a
fi
# Trimming twice is a no-op, so a var named by several rows needs no dedupe.
while read -r v; do
[ -n "$v" ] || continue
if [ -n "${!v:-}" ]; then
export "$v=$(_harness_trim "${!v}")"
fi
done < <(_harness_credential_vars)
}
# The proxy root: the worker's ANTHROPIC_BASE_URL minus its provider path.
_harness_proxy_root() {
local base_url

View File

@@ -0,0 +1,68 @@
import { existsSync, readFileSync, statSync } from 'fs';
const MB = 1024 * 1024;
/** At or above this the package is refused: GitHub warns at 50 MB and rejects at 100 MB. */
export const PATCH_MAX_BYTES = 49 * MB;
export const PATCH_WARN_BYTES = 10 * MB;
export const PATCH_BINARY_FILE_WARN_BYTES = 1 * MB;
export interface PatchSizeReport {
bytes: number;
errors: string[];
warnings: string[];
}
function fmt(bytes: number): string {
return `${(bytes / MB).toFixed(1)} MB`;
}
/** Binary files in a `git diff --binary` patch whose size exceeds the threshold. */
export function largeBinaryFiles(
patchText: string,
thresholdBytes = PATCH_BINARY_FILE_WARN_BYTES
): { path: string; bytes: number }[] {
const out: { path: string; bytes: number }[] = [];
const lines = patchText.split('\n');
let current = '';
for (let i = 0; i < lines.length; i++) {
const line = lines[i];
const header = /^diff --git a\/.* b\/(.*)$/.exec(line);
if (header) {
current = header[1];
continue;
}
if (line === 'GIT binary patch') {
const m = /^(?:literal|delta) (\d+)$/.exec(lines[i + 1] ?? '');
const bytes = m ? parseInt(m[1], 10) : 0;
if (bytes > thresholdBytes) out.push({ path: current, bytes });
}
}
return out;
}
export function checkWorkspacePatchSize(patchPath: string): PatchSizeReport {
const report: PatchSizeReport = { bytes: 0, errors: [], warnings: [] };
if (!existsSync(patchPath)) return report;
report.bytes = statSync(patchPath).size;
if (report.bytes >= PATCH_MAX_BYTES) {
report.errors.push(
`environment/workspace.patch is ${fmt(report.bytes)} — the limit is ${fmt(PATCH_MAX_BYTES)}. ` +
'Remove large files (model weights, datasets, archives, build output) and regenerate the patch; ' +
'use a tiny dummy fixture or a stub instead.'
);
return report;
}
if (report.bytes >= PATCH_WARN_BYTES) {
report.warnings.push(
`environment/workspace.patch is ${fmt(report.bytes)} (limit ${fmt(PATCH_MAX_BYTES)}) — ` +
'check it contains only what the task needs'
);
}
for (const f of largeBinaryFiles(readFileSync(patchPath, 'latin1'))) {
report.warnings.push(
`workspace.patch adds a ${fmt(f.bytes)} binary file: ${f.path} — ` +
'prefer a tiny dummy fixture (e.g. a small random-init checkpoint) or a stub'
);
}
return report;
}