Something went wrong. Try again.
This repository has no description
Something went wrong. Try again.
TypeScript
123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116import * as Effect from "effect/Effect";import { getSandbox, Sandbox as NativeSandbox } from "@cloudflare/sandbox";import { SHELL_MAX_MS } from "../shared/shell";import type { Env } from "./personal-agent";import { AgentFailure, agentCall, runAgent } from "./agent-io";
/** One-use execution boundary in the native container's own DO lifetime. */export class Sandbox extends NativeSandbox<Env> { private revoked = false; private claimed = false; private launching = false; private deadline?: ReturnType<typeof setTimeout>;
execTemporary(command: string, expiresAt: number, id: string) { return runAgent( Effect.gen({ self: this }, function* () { if (!this.ctx.id.equals(this.env.Sandbox.idFromName(id))) return yield* Effect.fail( new AgentFailure({ message: "Shell identity mismatch" }), ); if ( !Number.isFinite(expiresAt) || expiresAt <= Date.now() || expiresAt > Date.now() + SHELL_MAX_MS ) return yield* Effect.fail( new AgentFailure({ message: "Shell lifetime expired" }), ); if (this.claimed) return yield* Effect.fail( new AgentFailure({ message: "Shell workspace already used" }), ); this.claimed = true; // Destroy removes container files, not this durable one-use gate. if ( this.revoked || (yield* agentCall(() => this.ctx.storage.get("flarebot:invocation"))) ) return yield* Effect.fail( new AgentFailure({ message: "Shell workspace already used" }), ); yield* agentCall(() => this.ctx.storage.put("flarebot:invocation", "started"), ); if (this.revoked) return yield* Effect.fail( new AgentFailure({ message: "Shell workspace closed" }), ); this.deadline = setTimeout( () => this.ctx.waitUntil(this.closeTemporary().catch(() => {})), Math.max(0, expiresAt - Date.now()), ); this.launching = true; const launch = runAgent( Effect.gen({ self: this }, function* () { const stream = yield* agentCall( () => getSandbox(this.env.Sandbox, id, { enableDefaultSession: false, }).execStream(command, { cwd: "/workspace", timeout: Math.max(1, expiresAt - Date.now()), }), "Shell execution unavailable", ); this.launching = false; if (this.revoked || Date.now() >= expiresAt) { yield* agentCall(() => stream.cancel()).pipe( Effect.catchTag("AgentFailure", () => Effect.void), ); return yield* Effect.fail( new AgentFailure({ message: "Shell workspace closed" }), ); } return stream; }).pipe( Effect.catchTag("AgentFailure", () => Effect.gen({ self: this }, function* () { this.launching = false; yield* this.close(); return yield* Effect.fail( new AgentFailure({ message: "Shell execution unavailable" }), ); }), ), ), ); this.ctx.waitUntil( launch.then( () => {}, () => {}, ), ); return yield* agentCall(() => launch, "Shell execution unavailable"); }), ); }
private close() { const destroy = () => super.destroy(); return Effect.gen({ self: this }, function* () { this.revoked = true; clearTimeout(this.deadline ?? null); yield* agentCall(() => this.ctx.storage.put("flarebot:invocation", "closed"), ); const launchPending = this.launching; yield* agentCall(destroy, "Shell cleanup unavailable"); return !launchPending && !this.launching; }); } closeTemporary() { return runAgent(this.close()); }}