mirror of
https://github.com/fabro-sh/fabro.git
synced 2026-10-01 02:04:24 +00:00
`fabro-server/src/sandbox_access.rs` is the server's own path to a run's sandbox: it connects the record's provider (the driver's Host, Docker and Daytona providers in process, a plugin executable for any other kind), keys ownership on the `petri.run` label Petri stamps on every sandbox it creates, attaches by the recorded id, and for a host record designates the recorded directory again when the id lives only in the worker's registry. The Docker client resolves its endpoint from the same variables Petri forwards to its plugin, so both meet on one daemon. The doctor's Docker check and the Daytona credential probe move here with `DaytonaCredentials`, and the `/sandboxes` inventory is rebuilt over the driver's `list`, narrowed to sandboxes that carry Petri's run label. Preflight asks the provider for its health instead of creating and deleting a throwaway sandbox in Fabro's own shape, which no run uses; the git retry policy behind the repository probe moves into run_manifest. The callers still on fabro-sandbox's reconnect read their access through a `legacy_provider_access` shim until they move. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
65 lines
1.5 KiB
Rust
65 lines
1.5 KiB
Rust
#![cfg_attr(
|
|
test,
|
|
allow(
|
|
clippy::absolute_paths,
|
|
clippy::await_holding_lock,
|
|
clippy::float_cmp,
|
|
reason = "Test-only server modules favor explicit assertions and fixture code."
|
|
)
|
|
)]
|
|
|
|
pub mod auth;
|
|
#[allow(
|
|
dead_code,
|
|
reason = "Automation materializer test hooks and helpers are only referenced by selected targets."
|
|
)]
|
|
mod automation_materializer;
|
|
mod canonical_host;
|
|
mod canonical_origin;
|
|
pub mod csp;
|
|
#[allow(
|
|
clippy::wildcard_imports,
|
|
clippy::absolute_paths,
|
|
reason = "The demo module is isolated fixture-style code."
|
|
)]
|
|
mod demo;
|
|
pub mod diagnostics;
|
|
pub mod error;
|
|
mod git_checkout;
|
|
pub mod github_webhooks;
|
|
pub mod install;
|
|
mod interp;
|
|
pub mod jwt_auth;
|
|
pub mod manifest_validation;
|
|
mod petri_check;
|
|
mod petri_runs;
|
|
mod principal_middleware;
|
|
mod request_id;
|
|
mod run_compiler;
|
|
mod run_files;
|
|
mod run_files_security;
|
|
mod run_intent;
|
|
mod run_manifest;
|
|
mod run_selector;
|
|
mod run_title_generation;
|
|
#[cfg(test)]
|
|
mod run_tool_create;
|
|
mod sandbox_access;
|
|
pub mod security_headers;
|
|
pub mod serve;
|
|
pub mod server;
|
|
mod server_secrets;
|
|
mod spawn_env;
|
|
mod startup;
|
|
pub mod static_files;
|
|
#[cfg(any(test, feature = "test-support"))]
|
|
pub mod test_support;
|
|
pub mod web_auth;
|
|
mod worker_control;
|
|
mod worker_runtime;
|
|
mod worker_token;
|
|
|
|
pub use error::{ApiError, Error, Result};
|
|
pub use run_manifest::workflow_bundle_from_manifest;
|
|
pub use server_secrets::process_env_snapshot;
|
|
pub use startup::{validate_startup, validate_startup_configuration};
|