fabro/lib/crates/fabro-cli/tests/it/cmd
Bryan Helmkamp ec1b3f2084
feat(sandbox): secure daytona snapshot names (#429)
## Summary

Secures Daytona custom snapshot creation by removing user-controlled
snapshot/image references and replacing them with deterministic names
Fabro computes internally. Docker image selection now uses
`image.docker`, while Daytona only accepts `image.dockerfile` for custom
snapshots and continues to use `daytona-medium` when no Dockerfile is
configured.

## Changes

- Replaces public `image.ref` config/API shape with Docker-specific
`image.docker` across Rust settings, OpenAPI, generated TypeScript
client, docs, defaults, examples, and web samples.
- Adds Daytona snapshot identity generation using HMAC-SHA256 over a
canonical manifest keyed by the Daytona API key, producing
`fabro-<uuid>` snapshot names without exposing Dockerfile text or key
material.
- Routes Daytona custom Dockerfiles, including devcontainer-generated
Dockerfiles, through the same computed identity path before calling
Daytona snapshot APIs.
- Updates sandbox initialization events and store projections so
initialized run state can show the resolved image and computed Daytona
snapshot after startup.
- Updates legacy config migration behavior so Docker image refs map to
`image.docker`, while Daytona legacy snapshot names are not preserved.

## Breaking Changes

- `image.ref` is no longer accepted in new environment config.
- Docker environments should use `image.docker` for image selection.
- Daytona environments reject `image.docker`; use `image.dockerfile` to
request a custom computed snapshot.

## Verification

- `cargo build -p fabro-api`
- `cd lib/packages/fabro-api-client && bun run generate`
- `cd lib/packages/fabro-api-client && bun run typecheck`
- `cd apps/fabro-web && bun run typecheck`
- `cargo +nightly-2026-04-14 fmt --check --all`
- `cargo +nightly-2026-04-14 clippy --workspace --all-targets -- -D
warnings`
- `ulimit -n 4096 && cargo nextest run --no-fail-fast -p fabro-cli -p
fabro-config -p fabro-sandbox -p fabro-workflow -p fabro-store -p
fabro-server -p fabro-api`
- `cargo insta pending-snapshots`

---

[![Compound
Engineering](https://img.shields.io/badge/Compound_Engineering-6366f1)](https://github.com/EveryInc/compound-engineering-plugin)
🤖 Generated with GPT-5 via [Codex](https://openai.com/codex)
2026-05-27 11:52:35 -04:00
..
approve.rs feat: Add approve/deny run controls to MCP and CLI (#400) 2026-05-25 15:49:57 -04:00
archive.rs feat: Add approve/deny run controls to MCP and CLI (#400) 2026-05-25 15:49:57 -04:00
artifact_cp.rs test(cli): trim slow integration fixture setup 2026-04-28 19:14:56 -07:00
artifact_list.rs test(cli): trim slow integration fixture setup 2026-04-28 19:14:56 -07:00
attach.rs feat(sandbox): secure daytona snapshot names (#429) 2026-05-27 11:52:35 -04:00
auth.rs test(cli): tighten env-dev-token-ignore tests 2026-05-01 16:25:13 -04:00
cli_reference.rs refactor(dev): decouple CLI reference generation 2026-05-06 12:31:02 -04:00
config.rs fix(model): retire GPT-5.2 and GPT-5.3 catalog entries (#412) 2026-05-26 00:06:50 -04:00
create.rs Replace run-scoped sandbox config with named environments (#360) 2026-05-23 13:03:21 -04:00
deny.rs feat: Add approve/deny run controls to MCP and CLI (#400) 2026-05-25 15:49:57 -04:00
diff.rs test(cli): prune slow integration outliers 2026-04-28 19:26:27 -07:00
discord.rs refactor(cli): deglobalize server and storage target flags 2026-04-05 16:06:42 -04:00
docs.rs refactor(cli): deglobalize server and storage target flags 2026-04-05 16:06:42 -04:00
doctor.rs refactor(auth): split credential sources and vault schemas (#306) 2026-05-18 11:07:42 -04:00
dump.rs Replace queued with pending/runnable and add approval flow (web + API s… (#371) 2026-05-23 15:34:33 -04:00
events.rs fix: stabilize attach JSON timing snapshot (#385) 2026-05-24 13:09:09 -04:00
exec.rs fix(agent): retry retryable mid-stream LLM failures 2026-05-22 21:00:50 -04:00
fabro.rs feat: Add approve/deny run controls to MCP and CLI (#400) 2026-05-25 15:49:57 -04:00
fork.rs refactor(runs): simplify run projection shape 2026-05-09 23:31:43 -04:00
graph.rs feat(cli): allow rendering invalid graphs 2026-05-25 10:19:32 -04:00
inspect.rs feat(sandbox): secure daytona snapshot names (#429) 2026-05-27 11:52:35 -04:00
install.rs refactor: rationalize server secret scopes (vault-only for optional int… (#401) 2026-05-25 17:26:01 -04:00
json_global.rs fix(server): persist manifest metadata names (#302) 2026-05-18 08:31:23 -04:00
logs.rs fix(cli): preserve API error details 2026-05-06 14:03:12 -04:00
mcp.rs feat: Add approve/deny run controls to MCP and CLI (#400) 2026-05-25 15:49:57 -04:00
mod.rs feat: Add approve/deny run controls to MCP and CLI (#400) 2026-05-25 15:49:57 -04:00
model.rs test(cli): stabilize model list snapshots 2026-05-25 10:20:47 -04:00
model_list.rs refactor(cli): separate local socket and storage defaults 2026-04-06 11:57:14 -04:00
model_test.rs refactor(llm): split provider identity from adapters (#280) 2026-05-16 13:13:41 -04:00
parent.rs feat(cli): wire run parent commands (#288) 2026-05-16 15:15:28 -04:00
parse.rs feat(cli): render fatal errors with miette 2026-04-24 15:35:57 -04:00
pr.rs feat(pr): support GitHub pull request associations (#270) 2026-05-16 12:47:27 -04:00
pr_close.rs refactor(pr): simplify server-side PR plumbing 2026-04-24 11:17:01 -04:00
pr_create.rs feat(pr): support GitHub pull request associations (#270) 2026-05-16 12:47:27 -04:00
pr_link.rs feat(pr): support GitHub pull request associations (#270) 2026-05-16 12:47:27 -04:00
pr_merge.rs refactor(pr): simplify server-side PR plumbing 2026-04-24 11:17:01 -04:00
pr_unlink.rs feat(pr): support GitHub pull request associations (#270) 2026-05-16 12:47:27 -04:00
pr_view.rs feat(pr): support GitHub pull request associations (#270) 2026-05-16 12:47:27 -04:00
preflight.rs Replace run-scoped sandbox config with named environments (#360) 2026-05-23 13:03:21 -04:00
provider.rs refactor(cli): deglobalize server and storage target flags 2026-04-05 16:06:42 -04:00
provider_login.rs Complete provider credential auth and scripted install 2026-04-13 09:15:45 -04:00
ps.rs fix(server): persist manifest metadata names (#302) 2026-05-18 08:31:23 -04:00
render_graph.rs fix(graph): support dotted Fabro graph attributes (#324) 2026-05-20 09:31:08 -04:00
repo.rs feat(cli): render fatal errors with miette 2026-04-24 15:35:57 -04:00
repo_deinit.rs refactor(config): move project state under .fabro 2026-04-11 12:55:46 -04:00
repo_init.rs Replace run-scoped sandbox config with named environments (#360) 2026-05-23 13:03:21 -04:00
resume.rs test(cli): prune slow integration outliers 2026-04-28 19:26:27 -07:00
rewind.rs feat(api): unify public run shape 2026-05-10 20:48:55 -04:00
rm.rs fix(cli): print full run id on rm (#315) 2026-05-20 08:24:31 -04:00
run.rs Replace queued with pending/runnable and add approval flow (web + API s… (#371) 2026-05-23 15:34:33 -04:00
runner.rs Replace run-scoped sandbox config with named environments (#360) 2026-05-23 13:03:21 -04:00
sandbox_cp.rs feat(api): unify public run shape 2026-05-10 20:48:55 -04:00
sandbox_preview.rs refactor(types): remove legacy run summary shape 2026-05-10 23:29:41 -04:00
sandbox_ssh.rs fix(cli): repair verification failures 2026-05-09 18:07:24 -04:00
secret.rs refactor(auth): split credential sources and vault schemas (#306) 2026-05-18 11:07:42 -04:00
secret_list.rs refactor(auth): split credential sources and vault schemas (#306) 2026-05-18 11:07:42 -04:00
secret_rm.rs refactor(cli): deglobalize server and storage target flags 2026-04-05 16:06:42 -04:00
secret_set.rs refactor(auth): split credential sources and vault schemas (#306) 2026-05-18 11:07:42 -04:00
send_analytics.rs refactor(cli): deglobalize server and storage target flags 2026-04-05 16:06:42 -04:00
send_panic.rs refactor(cli): deglobalize server and storage target flags 2026-04-05 16:06:42 -04:00
server_start.rs refactor: rationalize server secret scopes (vault-only for optional int… (#401) 2026-05-25 17:26:01 -04:00
server_status.rs refactor(server): unify daemon runtime metadata 2026-04-22 16:07:52 -04:00
server_stop.rs refactor(test): promote shared server-lifecycle test helpers into fabro-test 2026-04-19 16:43:26 -04:00
start.rs Replace run-scoped sandbox config with named environments (#360) 2026-05-23 13:03:21 -04:00
support.rs feat: Add approve/deny run controls to MCP and CLI (#400) 2026-05-25 15:49:57 -04:00
system.rs fix(system): expose unreadable run repair flow 2026-05-06 07:15:18 -04:00
system_df.rs fix(server): count whole storage tree in Fabro-managed bytes 2026-05-21 11:28:39 -04:00
system_events.rs refactor(cli): finish command context cleanup 2026-04-23 07:14:32 -04:00
system_info.rs refactor(cli): finish command context cleanup 2026-04-23 07:14:32 -04:00
system_prune.rs test(cli): trim slow integration fixture setup 2026-04-28 19:14:56 -07:00
system_repair.rs fix(runs): repair deletion of unreadable runs 2026-05-09 17:45:55 -04:00
test_panic.rs test: speed up slow default-profile tests and tighten nextest thresholds 2026-04-05 13:15:59 -04:00
top_level.rs feat(cli): show curated landing output for bare fabro 2026-04-17 08:59:03 -04:00
unarchive.rs feat: Add approve/deny run controls to MCP and CLI (#400) 2026-05-25 15:49:57 -04:00
uninstall.rs refactor(server): unify daemon runtime metadata 2026-04-22 16:07:52 -04:00
upgrade.rs feat(cli): render fatal errors with miette 2026-04-24 15:35:57 -04:00
validate.rs feat(template): resolve template error locations (#333) 2026-05-20 20:15:04 -04:00
version.rs feat(cli): add fabro version command 2026-04-14 16:30:53 -04:00
wait.rs fix: stabilize attach JSON timing snapshot (#385) 2026-05-24 13:09:09 -04:00
worker_auth.rs refactor: rationalize server secret scopes (vault-only for optional int… (#401) 2026-05-25 17:26:01 -04:00
workflow.rs fix(workflow): ignore deprecated project directory 2026-05-09 10:55:56 -04:00
workflow_create.rs fix(workflow): ignore deprecated project directory 2026-05-09 10:55:56 -04:00
workflow_list.rs feat(cli): render fatal errors with miette 2026-04-24 15:35:57 -04:00