From 2456356a9fd4bb3181880ec4740f8d6de2ba3786 Mon Sep 17 00:00:00 2001 From: Bryan Helmkamp Date: Thu, 20 Aug 2026 10:19:27 -0400 Subject: [PATCH] Label sandbox git execs with git_op tracing spans MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Sandbox exec logs previously required command_len fingerprinting to tell a push from a credential refresh or a checkpoint commit. The shared git helpers now instrument their futures with a git_op span, so Daytona's and Docker's `exec_command: entered` lines inherit the operation label and the log renders as `git_op{op=push}: exec_command: entered timeout_ms=...`. Ops: push (git_push_via_exec), refresh-credentials (both providers' refresh_push_credentials), checkpoint-commit (checked_git_checkpoint), fetch (fetch_source_run_ref), and metadata-push (the run-metadata snapshot write). Spans are attached with #[tracing::instrument] — attached to the future, never an entered() guard held across an await — so they follow the task across worker threads. No trait or signature changes. Plan: .ai/plans/git-push-token-resilience.md (PR 3: item 10). Co-Authored-By: Claude Fable 5 --- lib/components/fabro-sandbox/src/daytona/mod.rs | 1 + lib/components/fabro-sandbox/src/docker.rs | 1 + lib/components/fabro-sandbox/src/sandbox.rs | 2 ++ lib/components/fabro-workflow/src/run_metadata.rs | 1 + lib/components/fabro-workflow/src/sandbox_git.rs | 1 + 5 files changed, 6 insertions(+) diff --git a/lib/components/fabro-sandbox/src/daytona/mod.rs b/lib/components/fabro-sandbox/src/daytona/mod.rs index 0375a51cf..5a6da1d6c 100644 --- a/lib/components/fabro-sandbox/src/daytona/mod.rs +++ b/lib/components/fabro-sandbox/src/daytona/mod.rs @@ -1542,6 +1542,7 @@ impl Sandbox for DaytonaSandbox { Ok(Some((preview.url, headers))) } + #[tracing::instrument(name = "git_op", skip_all, fields(op = "refresh-credentials"))] async fn refresh_push_credentials(&self) -> crate::Result { if !self.repo_cloned() { return Ok(RefreshOutcome::Skipped); diff --git a/lib/components/fabro-sandbox/src/docker.rs b/lib/components/fabro-sandbox/src/docker.rs index d69dcca4a..21530cc94 100644 --- a/lib/components/fabro-sandbox/src/docker.rs +++ b/lib/components/fabro-sandbox/src/docker.rs @@ -2180,6 +2180,7 @@ impl Sandbox for DockerSandbox { self.origin_url.get().map(String::as_str) } + #[tracing::instrument(name = "git_op", skip_all, fields(op = "refresh-credentials"))] async fn refresh_push_credentials(&self) -> crate::Result { if !self.repo_cloned() { return Ok(RefreshOutcome::Skipped); diff --git a/lib/components/fabro-sandbox/src/sandbox.rs b/lib/components/fabro-sandbox/src/sandbox.rs index 31a873300..c70c13ee9 100644 --- a/lib/components/fabro-sandbox/src/sandbox.rs +++ b/lib/components/fabro-sandbox/src/sandbox.rs @@ -1465,6 +1465,7 @@ pub async fn setup_git_via_exec( }) } +#[tracing::instrument(name = "git_op", skip_all, fields(op = "fetch"))] pub(crate) async fn fetch_source_run_ref( sandbox: &dyn Sandbox, source_run_id: &str, @@ -1513,6 +1514,7 @@ pub(crate) async fn fetch_source_run_ref( /// Helper for sandbox implementations that manage git internally. /// Pushes a refspec to origin via exec_command inside the sandbox. +#[tracing::instrument(name = "git_op", skip_all, fields(op = "push"))] pub async fn git_push_via_exec(sandbox: &dyn Sandbox, refspec: &str) -> crate::Result<()> { if let Err(e) = sandbox.refresh_push_credentials().await { tracing::warn!( diff --git a/lib/components/fabro-workflow/src/run_metadata.rs b/lib/components/fabro-workflow/src/run_metadata.rs index 74be989df..39d686857 100644 --- a/lib/components/fabro-workflow/src/run_metadata.rs +++ b/lib/components/fabro-workflow/src/run_metadata.rs @@ -184,6 +184,7 @@ impl RunMetadataWriterHandle { .unwrap() } + #[tracing::instrument(name = "git_op", skip_all, fields(op = "metadata-push"))] pub(crate) async fn write_snapshot( &self, dump: &RunDump, diff --git a/lib/components/fabro-workflow/src/sandbox_git.rs b/lib/components/fabro-workflow/src/sandbox_git.rs index 914153955..c6084a977 100644 --- a/lib/components/fabro-workflow/src/sandbox_git.rs +++ b/lib/components/fabro-workflow/src/sandbox_git.rs @@ -158,6 +158,7 @@ pub async fn git_checkpoint( clippy::too_many_arguments, reason = "Checkpointing needs explicit run metadata, checkpoint settings, and author inputs." )] +#[tracing::instrument(name = "git_op", skip_all, fields(op = "checkpoint-commit"))] pub(crate) async fn checked_git_checkpoint( runtime: &SandboxGitRuntime, sandbox: &dyn Sandbox,