Repository navigation
fix(sandbox): cut executable identity hashing cost - #4221
Conversation
Reuse in-call digests and optimize sha2 in dev builds. Signed-off-by: Eric Curtin <eric.curtin@docker.com>
|
If useful, please also try https://github.com/llmmanorg/llmman, which can launch agents in an OpenShell sandbox ( |
|
@derekwaynecarr @johntmyers PTAL when you get a chance, and |
|
/ok to test 987ddb6 |
|
Label |
johntmyers
left a comment
There was a problem hiding this comment.
gator-agent
PR Review Status
No blocking findings remain. This focused change reuses executable digests within one identity lookup while retaining snapshot validation before shared-cache publication, and optimizes SHA-256 in development builds.
Thanks @ericcurtin, I checked your request to run tests against the current head and posted the full-SHA /ok to test command after verifying maintainer authority. test:e2e is applied for the sandbox runtime identity path; Branch Checks, Helm Lint, and E2E have started on the current test mirror. The E2E Label Help bot requested a rerun, which GitHub rejected while its first attempt is active. Gator will retry the authorized rerun after that attempt finishes.
Blocking findings: None.
Carried findings: None.
Non-blocking suggestions: None.
Gator metadata
- Validation: Focused sandbox binary identity performance fix for #4149; no competing implementation found.
- Docs: No direct UX or published contract change; Fern updates unnecessary.
- Checks: DCO and vouch passed; Branch Checks queued, Helm Lint and E2E running on the current head. Trivy Changes remains action_required on the fork workflow; its gate has not passed.
- E2E: test:e2e applied; full-current-head /ok to test posted. Results pending. Bot-required rerun not yet queued because the first attempt is active.
- Head SHA:
987ddb6817c2ac82e65e228e83c6f14fc770e3f6 - Base SHA:
dfef088bc3d9ecb1b21b5f43e70098eaae3e1a5c - Merge base SHA:
dfef088bc3d9ecb1b21b5f43e70098eaae3e1a5c - Patch ID:
0d66d0d59e9b9d415e342af39724d0bc92a48698 - Gator payload:
10 - Review mode:
initial - Previous reviewed SHA:
none - Review budget exhausted:
no - Maintainer decision required:
no - Next state:
gator:blocked - Blocked reason:
test_dispatch_required
@ericcurtin is it necessary to put this on every PR you have? |
|
@johntmyers No, sorry. I'll only mention it where it's relevant. |
Monitoring CompleteMonitoring is complete because this PR has merged. Final status: Gator found no blocking findings, and maintainer approval is present. The last active Gator state was The remaining active Gator metadata
|
Summary
Hash each executable once per identity lookup and optimize
sha2in dev builds, so broker tests stop timing out.Related Issue
Closes #4149
Changes
sha2toopt-level = 3in the dev profile.Testing
cargo test -p openshell-binary-identityandcargo test -p openshell-sandbox --libpass. With softwaresha2forced, one hashing test takes 2.55s onmain, 1.32s with dedupe, 0.04s with both.Checklist