Label sandbox git execs with git_op tracing spans

Sandbox exec logs previously required command_len fingerprinting to tell a
push from a credential refresh or a checkpoint commit. The shared git
helpers now instrument their futures with a git_op span, so Daytona's and
Docker's `exec_command: entered` lines inherit the operation label and the
log renders as `git_op{op=push}: exec_command: entered timeout_ms=...`.

Ops: push (git_push_via_exec), refresh-credentials (both providers'
refresh_push_credentials), checkpoint-commit (checked_git_checkpoint),
fetch (fetch_source_run_ref), and metadata-push (the run-metadata snapshot
write). Spans are attached with #[tracing::instrument] — attached to the
future, never an entered() guard held across an await — so they follow the
task across worker threads. No trait or signature changes.

Plan: .ai/plans/git-push-token-resilience.md (PR 3: item 10).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Bryan Helmkamp 2026-08-20 10:19:27 -04:00
parent 7987fda25d
commit 2456356a9f
No known key found for this signature in database
5 changed files with 6 additions and 0 deletions

View file

@ -1542,6 +1542,7 @@ impl Sandbox for DaytonaSandbox {
Ok(Some((preview.url, headers)))
}
#[tracing::instrument(name = "git_op", skip_all, fields(op = "refresh-credentials"))]
async fn refresh_push_credentials(&self) -> crate::Result<RefreshOutcome> {
if !self.repo_cloned() {
return Ok(RefreshOutcome::Skipped);

View file

@ -2180,6 +2180,7 @@ impl Sandbox for DockerSandbox {
self.origin_url.get().map(String::as_str)
}
#[tracing::instrument(name = "git_op", skip_all, fields(op = "refresh-credentials"))]
async fn refresh_push_credentials(&self) -> crate::Result<RefreshOutcome> {
if !self.repo_cloned() {
return Ok(RefreshOutcome::Skipped);

View file

@ -1465,6 +1465,7 @@ pub async fn setup_git_via_exec(
})
}
#[tracing::instrument(name = "git_op", skip_all, fields(op = "fetch"))]
pub(crate) async fn fetch_source_run_ref(
sandbox: &dyn Sandbox,
source_run_id: &str,
@ -1513,6 +1514,7 @@ pub(crate) async fn fetch_source_run_ref(
/// Helper for sandbox implementations that manage git internally.
/// Pushes a refspec to origin via exec_command inside the sandbox.
#[tracing::instrument(name = "git_op", skip_all, fields(op = "push"))]
pub async fn git_push_via_exec(sandbox: &dyn Sandbox, refspec: &str) -> crate::Result<()> {
if let Err(e) = sandbox.refresh_push_credentials().await {
tracing::warn!(

View file

@ -184,6 +184,7 @@ impl RunMetadataWriterHandle {
.unwrap()
}
#[tracing::instrument(name = "git_op", skip_all, fields(op = "metadata-push"))]
pub(crate) async fn write_snapshot(
&self,
dump: &RunDump,

View file

@ -158,6 +158,7 @@ pub async fn git_checkpoint(
clippy::too_many_arguments,
reason = "Checkpointing needs explicit run metadata, checkpoint settings, and author inputs."
)]
#[tracing::instrument(name = "git_op", skip_all, fields(op = "checkpoint-commit"))]
pub(crate) async fn checked_git_checkpoint(
runtime: &SandboxGitRuntime,
sandbox: &dyn Sandbox,