Project-2 baseline
This commit is contained in:
@@ -24,11 +24,11 @@ from pathlib import Path
|
||||
import atif_session
|
||||
import browser_note
|
||||
try:
|
||||
from dnsjail import apply_dns_jail
|
||||
from dnsjail import jailed
|
||||
except ImportError: # no helper shipped -> no jail, rather than no trials
|
||||
|
||||
async def apply_dns_jail(agent, environment) -> None: # type: ignore[misc]
|
||||
return None
|
||||
def jailed(run): # type: ignore[misc]
|
||||
return run
|
||||
|
||||
from harbor.agents.installed.base import CliFlag
|
||||
from harbor.agents.installed.claude_code import ClaudeCode
|
||||
@@ -208,10 +208,10 @@ class PreinstalledClaudeCode(ClaudeCode):
|
||||
def name() -> str:
|
||||
return "claude-code-reduced-toolset"
|
||||
|
||||
# Manual tasks inherit harbor's run(), so the jail has to be applied here as well as on
|
||||
# Manual tasks inherit harbor's run(), so this override needs its own @jailed as well as
|
||||
# the snapshot path — which overrides run() and never reaches this one.
|
||||
@jailed
|
||||
async def run(self, instruction, environment, context) -> None: # type: ignore[override]
|
||||
await apply_dns_jail(self, environment)
|
||||
await super().run(instruction, environment, context)
|
||||
|
||||
def __init__(self, *args, **kwargs) -> None:
|
||||
@@ -297,13 +297,36 @@ class PreinstalledClaudeCode(ClaudeCode):
|
||||
(probe.stdout or "").strip(),
|
||||
)
|
||||
return
|
||||
_log.info(
|
||||
"image bakes claude %s but %s was requested; using stock installer",
|
||||
baked,
|
||||
pinned,
|
||||
)
|
||||
_log.info("image bakes claude %s but %s was requested; installing it", baked, pinned)
|
||||
if await self._install_claude_version(environment, pinned):
|
||||
return
|
||||
await ClaudeCode.install(self, environment)
|
||||
|
||||
async def _install_claude_version(self, environment, version: str) -> bool:
|
||||
"""Install an exact claude with install.sh alone, which needs only curl. The stock
|
||||
installer apt-installs system deps first, and that fails where apt sources have rotted."""
|
||||
try:
|
||||
result = await environment.exec(
|
||||
command=(
|
||||
f"curl -fsSL https://claude.ai/install.sh | bash -s {shlex.quote(version)} >&2 && "
|
||||
'export PATH="$HOME/.local/bin:$PATH" && claude --version'
|
||||
),
|
||||
timeout_sec=300,
|
||||
)
|
||||
except Exception as exc: # noqa: BLE001 — a transport failure falls back like the probe's
|
||||
_log.warning("install.sh %s raised (%s); falling back to the stock installer", version, exc)
|
||||
return False
|
||||
installed = self.parse_version(result.stdout or "") if result.return_code == 0 else None
|
||||
if installed != version:
|
||||
_log.warning(
|
||||
"install.sh %s gave %r (rc=%s); falling back to the stock installer",
|
||||
version,
|
||||
installed,
|
||||
result.return_code,
|
||||
)
|
||||
return False
|
||||
return True
|
||||
|
||||
def build_cli_flags(self) -> str:
|
||||
"""Emit the reduced ``bash + str_replace_editor`` toolset flags: restrict
|
||||
the built-in toolset to ``--tools Bash`` and append the toolset note.
|
||||
@@ -477,6 +500,7 @@ class SnapshotClaudeCode(PreinstalledClaudeCode):
|
||||
def _is_bedrock_mode() -> bool:
|
||||
return False
|
||||
|
||||
@jailed
|
||||
async def run(self, instruction: str, environment, context) -> None:
|
||||
env = self._build_env()
|
||||
config_dir = env["CLAUDE_CONFIG_DIR"]
|
||||
@@ -561,7 +585,6 @@ class SnapshotClaudeCode(PreinstalledClaudeCode):
|
||||
"Seeded session.jsonl is empty; skipping --resume and starting fresh"
|
||||
)
|
||||
|
||||
await apply_dns_jail(self, environment)
|
||||
await self.exec_as_agent(
|
||||
environment,
|
||||
command=(
|
||||
|
||||
Reference in New Issue
Block a user