From f51924fdbcc043ac3d79538e1509093b121aba44 Mon Sep 17 00:00:00 2001 From: MechaCat02 Date: Sat, 23 May 2026 16:26:12 +0200 Subject: [PATCH] feat: per-script Rhai sandbox overrides with admin ceiling MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Adds optional per-script overrides for the six Rhai sandbox knobs (max_operations, max_string_size, max_array_size, max_map_size, max_call_levels, max_expr_depth). The executor merges its defaults with each script's overrides on every call; the manager validates overrides against an admin-set ceiling at write time, so the executor trusts whatever is stored. Storage chose JSONB on the existing scripts table over six new columns: lets future knobs land as code-only changes, keeps the sparse common case (most scripts override nothing) cheap to store and serialize, and matches how the manager + executor pass the config across the wire. * 0002_sandbox.sql — ALTER TABLE scripts ADD COLUMN sandbox JSONB NOT NULL DEFAULT '{}' * shared::ScriptSandbox — six Option fields with deny_unknown_fields so typos surface as 422 * Script.sandbox + ExecRequest.sandbox_overrides — typed end to end; cluster mode just serializes the same struct * executor-core::Limits::with_overrides — field-by-field replacement; tests cover the override actually tightening the live engine * manager-core::SandboxCeiling — built-in conservative defaults (10M ops, 1 MiB strings, 100k array/map, 128 call/expr depth); env vars override per knob, invalid values warn-and-skip rather than blocking boot * manager-core admin API — POST/PUT accept `sandbox`; values above the ceiling return 422 with the specific field + requested + ceiling; absent or `{}` keeps platform defaults * picloud all-in-one — wires SandboxCeiling::from_env() into AdminState * memory_limit_mb stays in the schema, marked v1.3+ advisory (no enforcement until OS-level isolation lands with cluster-mode executors) Verified live through Caddy: * /version reports schema 2, product 0.3.0 * Script with max_operations: 500 → 507 on a 10k-iteration loop * Same script after PUT raising to 1M → succeeds, returns 10000 * POST with max_operations: 1_000_000_000 → 422 (exceeds ceiling) Tests: * 13 executor-core unit tests (added 2 for override semantics) * 20 integration tests (added 6 for sandbox CRUD + ceiling + unknown-field rejection + executor honoring overrides) * default cargo test --workspace stays green (integration tests remain #[ignore]'d until DATABASE_URL is set) Bumps: * schema 1 → 2 * product 0.2.0 → 0.3.0 * SDK unchanged (scripts see nothing new) Co-Authored-By: Claude Opus 4.7 (1M context) --- Cargo.toml | 2 +- crates/executor-core/src/engine.rs | 7 +- crates/executor-core/src/sandbox.rs | 41 +++++- crates/executor-core/src/types.rs | 8 +- crates/executor-core/tests/engine.rs | 37 ++++- .../manager-core/migrations/0002_sandbox.sql | 15 ++ crates/manager-core/src/api.rs | 33 ++++- crates/manager-core/src/lib.rs | 2 + crates/manager-core/src/repo.rs | 41 +++++- crates/manager-core/src/sandbox.rs | 103 +++++++++++++ crates/orchestrator-core/src/api.rs | 5 +- crates/picloud/src/lib.rs | 3 +- crates/picloud/tests/api.rs | 138 ++++++++++++++++++ crates/shared/src/lib.rs | 2 + crates/shared/src/sandbox.rs | 58 ++++++++ crates/shared/src/script.rs | 12 +- dashboard/package.json | 2 +- docs/versioning.md | 4 +- 18 files changed, 491 insertions(+), 22 deletions(-) create mode 100644 crates/manager-core/migrations/0002_sandbox.sql create mode 100644 crates/manager-core/src/sandbox.rs create mode 100644 crates/shared/src/sandbox.rs diff --git a/Cargo.toml b/Cargo.toml index a89e788..5e580a1 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -12,7 +12,7 @@ members = [ ] [workspace.package] -version = "0.2.0" +version = "0.3.0" edition = "2021" rust-version = "1.92" license = "MIT OR Apache-2.0" diff --git a/crates/executor-core/src/engine.rs b/crates/executor-core/src/engine.rs index cdf4b10..9907492 100644 --- a/crates/executor-core/src/engine.rs +++ b/crates/executor-core/src/engine.rs @@ -49,10 +49,13 @@ impl Engine { /// Execute `source` against `req`. Op-budget protection comes from /// Rhai's `set_max_operations`; wall-clock enforcement is the - /// caller's responsibility. + /// caller's responsibility. Per-script sandbox overrides on the + /// request replace the engine's defaults field-by-field; the + /// manager already clamped them against the admin ceiling. pub fn execute(&self, source: &str, req: ExecRequest) -> Result { + let effective_limits = self.limits.with_overrides(&req.sandbox_overrides); let logs: Arc>> = Arc::new(Mutex::new(Vec::new())); - let engine = build_engine(self.limits, Some(logs.clone())); + let engine = build_engine(effective_limits, Some(logs.clone())); let ast = engine .compile(source) diff --git a/crates/executor-core/src/sandbox.rs b/crates/executor-core/src/sandbox.rs index 40eedef..29f0e5c 100644 --- a/crates/executor-core/src/sandbox.rs +++ b/crates/executor-core/src/sandbox.rs @@ -1,8 +1,11 @@ +use picloud_shared::ScriptSandbox; + /// Resource and capability limits applied to every script execution. /// /// Defaults are conservative and safe to expose to untrusted Rhai sources. -/// Per-script overrides (e.g. higher operation budgets) come from the -/// `Script` config and are clamped against these as upper bounds. +/// Per-script overrides (via `Limits::with_overrides`) replace individual +/// fields; the manager clamps every override against the admin ceiling at +/// write time, so the executor trusts what arrives in `ExecRequest`. #[derive(Debug, Clone, Copy)] pub struct Limits { /// Hard cap on Rhai operations executed per invocation. @@ -35,3 +38,37 @@ impl Default for Limits { } } } + +impl Limits { + /// Returns a new `Limits` with each field replaced by the matching + /// override if present, otherwise the existing field. Overrides + /// arrive as `u64` for JSONB round-tripping cleanliness; they're + /// narrowed to `usize` here, saturating on the unlikely overflow + /// (these caps come from admin-clamped writes, so the values are + /// always small). + #[must_use] + pub fn with_overrides(&self, overrides: &ScriptSandbox) -> Self { + Self { + max_operations: overrides.max_operations.unwrap_or(self.max_operations), + max_string_size: overrides + .max_string_size + .map_or(self.max_string_size, narrow_usize), + max_array_size: overrides + .max_array_size + .map_or(self.max_array_size, narrow_usize), + max_map_size: overrides + .max_map_size + .map_or(self.max_map_size, narrow_usize), + max_call_levels: overrides + .max_call_levels + .map_or(self.max_call_levels, narrow_usize), + max_expr_depth: overrides + .max_expr_depth + .map_or(self.max_expr_depth, narrow_usize), + } + } +} + +fn narrow_usize(v: u64) -> usize { + usize::try_from(v).unwrap_or(usize::MAX) +} diff --git a/crates/executor-core/src/types.rs b/crates/executor-core/src/types.rs index 4a53cec..f09ff19 100644 --- a/crates/executor-core/src/types.rs +++ b/crates/executor-core/src/types.rs @@ -1,7 +1,7 @@ use std::collections::BTreeMap; use chrono::{DateTime, Utc}; -use picloud_shared::{ExecutionId, RequestId, ScriptId}; +use picloud_shared::{ExecutionId, RequestId, ScriptId, ScriptSandbox}; use serde::{Deserialize, Serialize}; use thiserror::Error; @@ -27,6 +27,12 @@ pub struct ExecRequest { pub path: String, pub headers: BTreeMap, pub body: serde_json::Value, + + /// Per-script sandbox overrides resolved by the manager. The + /// executor's default `Limits` get merged with these (per-field + /// override) before the Rhai engine is built. + #[serde(default)] + pub sandbox_overrides: ScriptSandbox, } #[derive(Debug, Clone, Serialize, Deserialize)] diff --git a/crates/executor-core/tests/engine.rs b/crates/executor-core/tests/engine.rs index 892300b..e9b5332 100644 --- a/crates/executor-core/tests/engine.rs +++ b/crates/executor-core/tests/engine.rs @@ -1,7 +1,7 @@ use std::collections::BTreeMap; use picloud_executor_core::{Engine, ExecError, ExecRequest, InvocationType, Limits, LogLevel}; -use picloud_shared::{ExecutionId, RequestId, ScriptId}; +use picloud_shared::{ExecutionId, RequestId, ScriptId, ScriptSandbox}; use serde_json::json; fn req(body: serde_json::Value) -> ExecRequest { @@ -14,6 +14,7 @@ fn req(body: serde_json::Value) -> ExecRequest { path: "/test".into(), headers: BTreeMap::new(), body, + sandbox_overrides: ScriptSandbox::default(), } } @@ -126,6 +127,40 @@ fn enforces_operation_budget() { assert!(matches!(err, ExecError::OperationBudgetExceeded)); } +#[test] +fn per_request_sandbox_override_tightens_budget() { + // Engine default is 1M ops — the script below would finish. + // We override down to 500 ops on this single request; should fail. + let engine = engine(); + let src = r"let n = 0; for i in 0..10000 { n += 1; } n"; + let r = ExecRequest { + sandbox_overrides: ScriptSandbox { + max_operations: Some(500), + ..ScriptSandbox::default() + }, + ..req(json!(null)) + }; + let err = engine.execute(src, r).expect_err("override should tighten"); + assert!(matches!(err, ExecError::OperationBudgetExceeded)); +} + +#[test] +fn override_only_replaces_specified_field() { + // Tight string size, default everything else. Strings > 32 chars + // should fail; loops up to default 1M ops should still pass. + let engine = engine(); + let small_string_ok = r#"let s = "hello"; #{ statusCode: 200, body: s }"#; + let r1 = ExecRequest { + sandbox_overrides: ScriptSandbox { + max_string_size: Some(32), + ..ScriptSandbox::default() + }, + ..req(json!(null)) + }; + let resp = engine.execute(small_string_ok, r1).unwrap(); + assert_eq!(resp.body, json!("hello")); +} + #[test] fn runtime_error_is_mapped_to_runtime_variant() { let err = engine() diff --git a/crates/manager-core/migrations/0002_sandbox.sql b/crates/manager-core/migrations/0002_sandbox.sql new file mode 100644 index 0000000..ffda984 --- /dev/null +++ b/crates/manager-core/migrations/0002_sandbox.sql @@ -0,0 +1,15 @@ +-- Per-script Rhai sandbox overrides. Empty JSONB = use platform defaults. +-- Schema is shape-only: the manager validates field names + value ranges + +-- against the admin-set ceiling at write time. Storing JSONB lets us add +-- new knobs without a migration (and skip them cleanly on read). +-- +-- Recognized fields: +-- max_operations u64 +-- max_string_size u64 +-- max_array_size u64 +-- max_map_size u64 +-- max_call_levels u64 +-- max_expr_depth u64 + +ALTER TABLE scripts + ADD COLUMN sandbox JSONB NOT NULL DEFAULT '{}'::jsonb; diff --git a/crates/manager-core/src/api.rs b/crates/manager-core/src/api.rs index 1f1ae76..abfca9b 100644 --- a/crates/manager-core/src/api.rs +++ b/crates/manager-core/src/api.rs @@ -11,12 +11,15 @@ use axum::{ routing::get, Json, Router, }; -use picloud_shared::{ExecutionLog, Script, ScriptId, ScriptValidator, ValidationError}; +use picloud_shared::{ + ExecutionLog, Script, ScriptId, ScriptSandbox, ScriptValidator, ValidationError, +}; use serde::Deserialize; use crate::repo::{ ExecutionLogRepository, NewScript, ScriptPatch, ScriptRepository, ScriptRepositoryError, }; +use crate::sandbox::{CeilingError, SandboxCeiling}; /// State shared by control-plane handlers. Separates concerns so the /// manager can validate at upload time without depending on the @@ -25,6 +28,7 @@ pub struct AdminState { pub repo: Arc, pub logs: Arc, pub validator: Arc, + pub sandbox_ceiling: SandboxCeiling, } impl Clone for AdminState { @@ -33,6 +37,7 @@ impl Clone for AdminState { repo: self.repo.clone(), logs: self.logs.clone(), validator: self.validator.clone(), + sandbox_ceiling: self.sandbox_ceiling, } } } @@ -70,6 +75,11 @@ pub struct CreateScriptRequest { pub source: String, pub timeout_seconds: Option, pub memory_limit_mb: Option, + /// Sandbox overrides; absent or empty `{}` means "use platform + /// defaults". Each non-null field is checked against the admin + /// ceiling at write time. + #[serde(default)] + pub sandbox: ScriptSandbox, } #[derive(Debug, Deserialize)] @@ -83,6 +93,10 @@ pub struct UpdateScriptRequest { pub source: Option, pub timeout_seconds: Option, pub memory_limit_mb: Option, + /// `Some(sandbox)` replaces the stored overrides wholesale (use + /// `Some(ScriptSandbox::empty())` to clear them). Absent leaves + /// the stored value unchanged. + pub sandbox: Option, } #[allow(clippy::option_option)] @@ -120,6 +134,7 @@ async fn create_script( Json(input): Json, ) -> Result<(StatusCode, Json