feat: per-script Rhai sandbox overrides with admin ceiling
Adds optional per-script overrides for the six Rhai sandbox knobs
(max_operations, max_string_size, max_array_size, max_map_size,
max_call_levels, max_expr_depth). The executor merges its defaults
with each script's overrides on every call; the manager validates
overrides against an admin-set ceiling at write time, so the
executor trusts whatever is stored.
Storage chose JSONB on the existing scripts table over six new
columns: lets future knobs land as code-only changes, keeps the
sparse common case (most scripts override nothing) cheap to store
and serialize, and matches how the manager + executor pass the
config across the wire.
* 0002_sandbox.sql — ALTER TABLE scripts ADD COLUMN sandbox
JSONB NOT NULL DEFAULT '{}'
* shared::ScriptSandbox — six Option<u64> fields with
deny_unknown_fields so typos surface as 422
* Script.sandbox + ExecRequest.sandbox_overrides — typed end
to end; cluster mode just serializes the same struct
* executor-core::Limits::with_overrides — field-by-field
replacement; tests cover the override actually tightening
the live engine
* manager-core::SandboxCeiling — built-in conservative
defaults (10M ops, 1 MiB strings, 100k array/map, 128
call/expr depth); env vars override per knob, invalid
values warn-and-skip rather than blocking boot
* manager-core admin API — POST/PUT accept `sandbox`; values
above the ceiling return 422 with the specific field +
requested + ceiling; absent or `{}` keeps platform defaults
* picloud all-in-one — wires SandboxCeiling::from_env() into
AdminState
* memory_limit_mb stays in the schema, marked v1.3+ advisory
(no enforcement until OS-level isolation lands with
cluster-mode executors)
Verified live through Caddy:
* /version reports schema 2, product 0.3.0
* Script with max_operations: 500 → 507 on a 10k-iteration loop
* Same script after PUT raising to 1M → succeeds, returns 10000
* POST with max_operations: 1_000_000_000 → 422 (exceeds ceiling)
Tests:
* 13 executor-core unit tests (added 2 for override semantics)
* 20 integration tests (added 6 for sandbox CRUD + ceiling +
unknown-field rejection + executor honoring overrides)
* default cargo test --workspace stays green (integration tests
remain #[ignore]'d until DATABASE_URL is set)
Bumps:
* schema 1 → 2
* product 0.2.0 → 0.3.0
* SDK unchanged (scripts see nothing new)
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
use std::collections::BTreeMap;
|
||||
|
||||
use picloud_executor_core::{Engine, ExecError, ExecRequest, InvocationType, Limits, LogLevel};
|
||||
use picloud_shared::{ExecutionId, RequestId, ScriptId};
|
||||
use picloud_shared::{ExecutionId, RequestId, ScriptId, ScriptSandbox};
|
||||
use serde_json::json;
|
||||
|
||||
fn req(body: serde_json::Value) -> ExecRequest {
|
||||
@@ -14,6 +14,7 @@ fn req(body: serde_json::Value) -> ExecRequest {
|
||||
path: "/test".into(),
|
||||
headers: BTreeMap::new(),
|
||||
body,
|
||||
sandbox_overrides: ScriptSandbox::default(),
|
||||
}
|
||||
}
|
||||
|
||||
@@ -126,6 +127,40 @@ fn enforces_operation_budget() {
|
||||
assert!(matches!(err, ExecError::OperationBudgetExceeded));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn per_request_sandbox_override_tightens_budget() {
|
||||
// Engine default is 1M ops — the script below would finish.
|
||||
// We override down to 500 ops on this single request; should fail.
|
||||
let engine = engine();
|
||||
let src = r"let n = 0; for i in 0..10000 { n += 1; } n";
|
||||
let r = ExecRequest {
|
||||
sandbox_overrides: ScriptSandbox {
|
||||
max_operations: Some(500),
|
||||
..ScriptSandbox::default()
|
||||
},
|
||||
..req(json!(null))
|
||||
};
|
||||
let err = engine.execute(src, r).expect_err("override should tighten");
|
||||
assert!(matches!(err, ExecError::OperationBudgetExceeded));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn override_only_replaces_specified_field() {
|
||||
// Tight string size, default everything else. Strings > 32 chars
|
||||
// should fail; loops up to default 1M ops should still pass.
|
||||
let engine = engine();
|
||||
let small_string_ok = r#"let s = "hello"; #{ statusCode: 200, body: s }"#;
|
||||
let r1 = ExecRequest {
|
||||
sandbox_overrides: ScriptSandbox {
|
||||
max_string_size: Some(32),
|
||||
..ScriptSandbox::default()
|
||||
},
|
||||
..req(json!(null))
|
||||
};
|
||||
let resp = engine.execute(small_string_ok, r1).unwrap();
|
||||
assert_eq!(resp.body, json!("hello"));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn runtime_error_is_mapped_to_runtime_variant() {
|
||||
let err = engine()
|
||||
|
||||
Reference in New Issue
Block a user