ren worker folder adding orig, mv new one into root

This commit is contained in:
2026-09-25 10:34:29 -04:00
parent 10f0668e32
commit 5b010039d7
1308 changed files with 44597 additions and 1511 deletions

View File

@@ -59,29 +59,6 @@ wait_for_pg() {
# Polyglot toolkit: REPO_NAME is empty (no single repo). Bring up Postgres + Redis
# (members need them; per-member DB setup is deferred to run-app/setup_repo), then done.
# Trial parity: limit DNS to the model endpoint and the toolkit's telemetry, so a session
# captured here cannot depend on network the trial agent will not have. Opt-in
# (RACCOON_DNS_JAIL=1) and best-effort. postCreate patches .bashrc, but postStart gets no
# login shell, so .env is read directly. Called on BOTH paths: the polyglot branch returns
# before the end of this script.
apply_dns_jail() {
[ -f /workspace/.devcontainer/dns-jail.sh ] || return 0
# Read the one line rather than sourcing: this runs on every boot AND every run-app, and
# with the jail off it must not execute the worker's .env as a side effect.
if [ "${RACCOON_DNS_JAIL:-0}" != "1" ] &&
! grep -qE '^[[:space:]]*(export[[:space:]]+)?RACCOON_DNS_JAIL[[:space:]]*=[[:space:]]*"?1"?[[:space:]]*(#.*)?$' \
/workspace/.env 2>/dev/null; then
return 0
fi
(
set -a
# shellcheck disable=SC1091
. /workspace/.env 2>/dev/null || true
set +a
bash /workspace/.devcontainer/dns-jail.sh
) || true
}
IS_POLYGLOT=$(node -e "try{process.stdout.write(require('/workspace/toolkit.json').polyglot?'1':'')}catch{}" 2>/dev/null || true)
if [ -n "$IS_POLYGLOT" ]; then
if ! pg_ready; then
@@ -129,7 +106,6 @@ if [ -n "$IS_POLYGLOT" ]; then
os_up || echo "warning: opensearch did not come up within 180s (see /tmp/opensearch.log)" >&2
fi
fi
apply_dns_jail
return 0 2>/dev/null || exit 0
fi
@@ -244,4 +220,3 @@ case "$REPO_NAME" in
;;
esac
apply_dns_jail