ren worker folder adding orig, mv new one into root
This commit is contained in:
@@ -72,7 +72,7 @@ RUN curl -fsSL https://pgp.mongodb.com/server-8.0.asc \
|
||||
# (3.11+), and post-create runs under `set -e` — an image with only 3.10 fails container
|
||||
# creation. setup-harnesses.sh tries python3, then python3.13/3.12/3.11, so exposing the
|
||||
# newer one under its versioned name is enough and leaves the members' default untouched.
|
||||
RUN curl -fsSL https://astral.sh/uv/install.sh | env UV_INSTALL_DIR=/usr/local/bin sh \
|
||||
RUN curl -fsSL https://astral.sh/uv/0.12.10/install.sh | env UV_INSTALL_DIR=/usr/local/bin sh \
|
||||
&& uv python install 3.10 \
|
||||
&& ln -sf "$(uv python find 3.10)" /usr/local/bin/python3 \
|
||||
&& uv python install 3.11 \
|
||||
|
||||
24
worker-toolkit-potion-polyglot/explore/.devcontainer/apply-dns-jail.sh
Executable file
24
worker-toolkit-potion-polyglot/explore/.devcontainer/apply-dns-jail.sh
Executable file
@@ -0,0 +1,24 @@
|
||||
#!/bin/bash
|
||||
# Trial parity: limit DNS to the model endpoint and the toolkit's telemetry, so a session
|
||||
# captured here cannot depend on network the trial agent will not have. Opt-in, best-effort.
|
||||
#
|
||||
# Its own lifecycle step, NOT part of post-start.sh: post-create.sh calls post-start to get
|
||||
# postgres up before it installs the repo's dependencies, so a jail applied there breaks
|
||||
# `bundle install` on every fresh container. postStartCommand runs after postCreateCommand.
|
||||
set -u
|
||||
|
||||
[ -f /workspace/.devcontainer/dns-jail.sh ] || exit 0
|
||||
# Read the one line rather than sourcing: with the jail off this must not execute the
|
||||
# worker's .env as a side effect.
|
||||
if [ "${RACCOON_DNS_JAIL:-0}" != "1" ] &&
|
||||
! grep -qE '^[[:space:]]*(export[[:space:]]+)?RACCOON_DNS_JAIL[[:space:]]*=[[:space:]]*"?1"?[[:space:]]*(#.*)?$' \
|
||||
/workspace/.env 2>/dev/null; then
|
||||
exit 0
|
||||
fi
|
||||
(
|
||||
set -a
|
||||
# shellcheck disable=SC1091
|
||||
. /workspace/.env 2>/dev/null || true
|
||||
set +a
|
||||
bash /workspace/.devcontainer/dns-jail.sh
|
||||
) || true
|
||||
@@ -4,7 +4,7 @@
|
||||
"build": {
|
||||
"dockerfile": "Dockerfile",
|
||||
"args": {
|
||||
"TOOLKIT_BUILD_ID": "1788802488308-63ncdn"
|
||||
"TOOLKIT_BUILD_ID": "1789430760274-eddbpv"
|
||||
}
|
||||
},
|
||||
"appPort": [
|
||||
@@ -21,6 +21,6 @@
|
||||
"source=${localWorkspaceFolder}/repos${localEnv:EXPLORE_INSTANCE:},target=/workspace/repos,type=bind"
|
||||
],
|
||||
"postCreateCommand": "bash /workspace/.devcontainer/post-create.sh",
|
||||
"postStartCommand": "bash /workspace/.devcontainer/post-start.sh",
|
||||
"postStartCommand": "bash /workspace/.devcontainer/post-start.sh; bash /workspace/.devcontainer/apply-dns-jail.sh",
|
||||
"containerUser": "root"
|
||||
}
|
||||
|
||||
@@ -366,13 +366,25 @@ mkdir -p "$HOME/.claude"
|
||||
# SKIP_FAST_MODE_NETWORK_ERRORS: the LLM proxy doesn't forward claude's fast-mode
|
||||
# availability probe, and claude reads the failed probe as "no network" and refuses
|
||||
# /fast. The override makes /fast toggleable; fast serving stays OFF until toggled.
|
||||
node -e '
|
||||
# Names this container as the surface a proxy call came from: claude reads it from the
|
||||
# settings env below, codex from the shell (its config maps the header to this var name).
|
||||
# Only on the proxy — a provider endpoint must not carry this attribution.
|
||||
CALL_METADATA=""
|
||||
case "$(set -a; . /workspace/.env 2>/dev/null || true; set +a; printf '%s' "${ANTHROPIC_BASE_URL:-}")" in
|
||||
*/llm_proxy/*) CALL_METADATA='{"origin":"explore"}' ;;
|
||||
esac
|
||||
|
||||
CALL_METADATA="$CALL_METADATA" node -e '
|
||||
const fs = require("fs");
|
||||
const home = process.env.HOME;
|
||||
const env = {
|
||||
CLAUDE_CODE_DISABLE_AUTO_MEMORY: "1",
|
||||
CLAUDE_CODE_SKIP_FAST_MODE_NETWORK_ERRORS: "1",
|
||||
};
|
||||
if (process.env.CALL_METADATA) {
|
||||
env.ANTHROPIC_CUSTOM_HEADERS =
|
||||
`X-Surge-Client-Metadata: ${process.env.CALL_METADATA}`;
|
||||
}
|
||||
fs.writeFileSync(
|
||||
`${home}/.claude/settings.json`,
|
||||
JSON.stringify({ env }, null, 2) + "\n"
|
||||
@@ -388,6 +400,13 @@ if [ -d /workspace/data/zeta-corpus ]; then
|
||||
fi
|
||||
|
||||
# Shell setup
|
||||
# Ahead of the block below so every shell exports it, interactive or not.
|
||||
if [ -n "$CALL_METADATA" ]; then
|
||||
# A file rather than a .bashrc line alone: the launcher and refresh-harness-auth
|
||||
# read it too, so a non-login shell does not silently lose the attribution.
|
||||
printf 'export LLM_CALL_METADATA=%s\n' "'$CALL_METADATA'" > ~/.raccoon-call-origin
|
||||
printf '. "$HOME/.raccoon-call-origin"\n' >> ~/.bashrc
|
||||
fi
|
||||
cat >> ~/.bashrc <<'BASHRC'
|
||||
export PATH="$HOME/.local/bin:$PATH"
|
||||
set -a && source /workspace/.env && set +a
|
||||
@@ -407,8 +426,8 @@ bash /workspace/welcome.sh explore 2>/dev/null
|
||||
|
||||
_AK="fde503c3bdb6e5cc9c48b1f8e4c2abeb"
|
||||
_DK="e966e45af5ad1a18005f9fdb831186ea"
|
||||
_WID="w-mtriw5pe-u8me"
|
||||
_VER="2f696c53b4"
|
||||
_WID="w-mu1wvj9k-gtnk"
|
||||
_VER="037cfcf94b"
|
||||
_CT="explore"
|
||||
_RP=$(node -e "try{process.stdout.write(require('/workspace/toolkit.json').repo)}catch{}" 2>/dev/null)
|
||||
_SID="$(date +%s)-$$"
|
||||
|
||||
@@ -59,29 +59,6 @@ wait_for_pg() {
|
||||
|
||||
# Polyglot toolkit: REPO_NAME is empty (no single repo). Bring up Postgres + Redis
|
||||
# (members need them; per-member DB setup is deferred to run-app/setup_repo), then done.
|
||||
# Trial parity: limit DNS to the model endpoint and the toolkit's telemetry, so a session
|
||||
# captured here cannot depend on network the trial agent will not have. Opt-in
|
||||
# (RACCOON_DNS_JAIL=1) and best-effort. postCreate patches .bashrc, but postStart gets no
|
||||
# login shell, so .env is read directly. Called on BOTH paths: the polyglot branch returns
|
||||
# before the end of this script.
|
||||
apply_dns_jail() {
|
||||
[ -f /workspace/.devcontainer/dns-jail.sh ] || return 0
|
||||
# Read the one line rather than sourcing: this runs on every boot AND every run-app, and
|
||||
# with the jail off it must not execute the worker's .env as a side effect.
|
||||
if [ "${RACCOON_DNS_JAIL:-0}" != "1" ] &&
|
||||
! grep -qE '^[[:space:]]*(export[[:space:]]+)?RACCOON_DNS_JAIL[[:space:]]*=[[:space:]]*"?1"?[[:space:]]*(#.*)?$' \
|
||||
/workspace/.env 2>/dev/null; then
|
||||
return 0
|
||||
fi
|
||||
(
|
||||
set -a
|
||||
# shellcheck disable=SC1091
|
||||
. /workspace/.env 2>/dev/null || true
|
||||
set +a
|
||||
bash /workspace/.devcontainer/dns-jail.sh
|
||||
) || true
|
||||
}
|
||||
|
||||
IS_POLYGLOT=$(node -e "try{process.stdout.write(require('/workspace/toolkit.json').polyglot?'1':'')}catch{}" 2>/dev/null || true)
|
||||
if [ -n "$IS_POLYGLOT" ]; then
|
||||
if ! pg_ready; then
|
||||
@@ -129,7 +106,6 @@ if [ -n "$IS_POLYGLOT" ]; then
|
||||
os_up || echo "warning: opensearch did not come up within 180s (see /tmp/opensearch.log)" >&2
|
||||
fi
|
||||
fi
|
||||
apply_dns_jail
|
||||
return 0 2>/dev/null || exit 0
|
||||
fi
|
||||
|
||||
@@ -244,4 +220,3 @@ case "$REPO_NAME" in
|
||||
;;
|
||||
esac
|
||||
|
||||
apply_dns_jail
|
||||
|
||||
Reference in New Issue
Block a user