Redact the driver's event ids in CLI snapshots and leave a local sandbox unnamed

The attach snapshots now carry the driver's create events, whose event
source and operation ids are minted per process and whose durations run
to the nanosecond, and the local sandbox's id is derived from a temporary
directory; the shared snapshot filters cover all three. A local sandbox's
ready event no longer names that id: the record already holds the
directory, and the id is nothing a person reads.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
Bryan Helmkamp 2026-09-11 13:55:45 -06:00
parent f568688154
commit 895735a829
No known key found for this signature in database
3 changed files with 106 additions and 4 deletions

View file

@ -1084,6 +1084,91 @@ fn attach_json_errors_without_prompting_for_human_input() {
"run_id": "[ULID]",
"ts": "[TIMESTAMP]"
},
{
"actor": {
"kind": "worker",
"run_id": "[ULID]"
},
"event": "sandbox.create.started",
"id": "[EVENT_ID]",
"properties": {
"action": "create",
"correlation_id": "[ULID]",
"id": {
"sequence": 1,
"source_id": "[HEX]"
},
"occurred_at": "[TIMESTAMP]",
"operation_id": "[HEX]",
"provider": "host",
"subject": {
"id": "host-dir-[HEX]",
"type": "sandbox"
},
"type": "operation_started"
},
"run_id": "[ULID]",
"ts": "[TIMESTAMP]"
},
{
"actor": {
"kind": "worker",
"run_id": "[ULID]"
},
"event": "sandbox.create.progress",
"id": "[EVENT_ID]",
"properties": {
"action": "create",
"correlation_id": "[ULID]",
"id": {
"sequence": 2,
"source_id": "[HEX]"
},
"occurred_at": "[TIMESTAMP]",
"operation_id": "[HEX]",
"progress": {
"code": "sandbox.provision"
},
"provider": "host",
"subject": {
"id": "host-dir-[HEX]",
"type": "sandbox"
},
"type": "operation_progress"
},
"run_id": "[ULID]",
"ts": "[TIMESTAMP]"
},
{
"actor": {
"kind": "worker",
"run_id": "[ULID]"
},
"event": "sandbox.create.completed",
"id": "[EVENT_ID]",
"properties": {
"action": "create",
"correlation_id": "[ULID]",
"duration": {
"nanos": "[NANOS]",
"secs": 0
},
"id": {
"sequence": 3,
"source_id": "[HEX]"
},
"occurred_at": "[TIMESTAMP]",
"operation_id": "[HEX]",
"provider": "host",
"subject": {
"id": "host-dir-[HEX]",
"type": "sandbox"
},
"type": "operation_completed"
},
"run_id": "[ULID]",
"ts": "[TIMESTAMP]"
},
{
"actor": {
"kind": "worker",
@ -1119,8 +1204,9 @@ fn attach_json_errors_without_prompting_for_human_input() {
"event": "sandbox.initialized",
"id": "[EVENT_ID]",
"properties": {
"id": "local:[ULID]",
"id": "host-dir-[HEX]",
"provider": "local",
"repo_cloned": false,
"working_directory": "[TEMP_DIR]"
},
"run_id": "[ULID]",

View file

@ -487,12 +487,16 @@ pub async fn initialize(
error,
));
}
// A local sandbox's id is derived from its directory, which the
// record already names; it is not a name worth showing.
let name = Some(sandbox.sandbox_info())
.filter(|name| !name.is_empty() && !sandbox.kind().is_local());
options.emitter.emit(&Event::Sandbox {
event: SandboxLifecycle::Ready {
provider: provider_name.clone(),
provider: provider_name.clone(),
duration_ms: elapsed_ms(started),
name: Some(sandbox.sandbox_info()).filter(|name| !name.is_empty()),
url: sandbox.console_url().await,
name,
url: sandbox.console_url().await,
},
});
}

View file

@ -74,6 +74,18 @@ static INSTA_FILTERS: &[(&str, &str)] = &[
"Duration: [DURATION]",
),
(r"Base: [^\n]+ \([0-9a-f]{7,40}\)", "Base: [BASE]"),
// The sandbox driver's events: per-process event source ids, operation
// ids, sub-second durations, and a local sandbox's path-derived id.
(
r#""source_id"(\s*:\s*)"[0-9a-f]{32}""#,
r#""source_id"$1"[HEX]""#,
),
(
r#""operation_id"(\s*:\s*)"[0-9a-f]{32}""#,
r#""operation_id"$1"[HEX]""#,
),
(r#""nanos"(\s*:\s*)\d+"#, r#""nanos"$1"[NANOS]""#),
(r"host-dir-[0-9a-f]+", "host-dir-[HEX]"),
(r"\\([\w\d])", "/$1"),
];