Target sbx 0.37 clone mode
sbx 0.29 isolated the agent with --branch, creating a host-side Git worktree. 0.37 removed that flag and reinstated --clone, which gives the agent a private in-container clone mounted read-only and exposes its commits through a sandbox-<name> git remote on the host. Setup fails outright against 0.37 with '--branch is no longer supported'. Drops the branch name plumbing entirely, since the sandbox now owns the clone and there is no host branch to name. Documents the two host prerequisites this surfaced: membership of the kvm group, because sandboxes are microVMs, and the docker-sbx package rather than docker-sandbox-bin on Arch derivatives - the latter installs only the CLI, omitting the microVM kernel, rootfs and nerdbox shim, which makes sbx fall back to mounting filesystems on the host and fail for any non-root user.
This commit is contained in:
+9
-23
@@ -5,7 +5,6 @@ PROGRAM="ai:sbx"
|
||||
CONFIG_ROOT="${XDG_CONFIG_HOME:-$HOME/.config}/ai-sbx"
|
||||
DEFAULT_AGENT="${AI_SBX_AGENT:-codex}"
|
||||
DEFAULT_MODE="${AI_SBX_MODE:-clone}"
|
||||
DEFAULT_BRANCH="${AI_SBX_BRANCH:-ai-sbx}"
|
||||
DEFAULT_TOKEN_DAYS="${AI_SBX_TOKEN_DAYS:-30}"
|
||||
|
||||
# GitHub accepts these as query parameters on the token creation form. A write
|
||||
@@ -51,9 +50,10 @@ Setup options:
|
||||
written into the sandbox.
|
||||
--agent NAME Sandbox agent. Default: codex
|
||||
--direct Mount the host working tree read-write.
|
||||
--clone Give the agent a Git worktree on its own
|
||||
branch. This is the default.
|
||||
--branch NAME Branch used by --clone. Default: ai-sbx
|
||||
--clone Give the agent a private in-container clone
|
||||
of the repository, mounted read-only.
|
||||
Its commits reach the host through the
|
||||
sandbox-<name> git remote. This is the default.
|
||||
--replace Replace the existing sandbox.
|
||||
|
||||
Examples:
|
||||
@@ -289,7 +289,6 @@ load_config() {
|
||||
[[ -n "${CONFIG_AGENT:-}" ]] ||
|
||||
die "Agent is missing from $REPO_CONFIG_FILE"
|
||||
|
||||
CONFIG_BRANCH="${CONFIG_BRANCH:-$DEFAULT_BRANCH}"
|
||||
|
||||
declare -p CONFIG_AWS_PROFILES >/dev/null 2>&1 ||
|
||||
CONFIG_AWS_PROFILES=()
|
||||
@@ -298,8 +297,7 @@ load_config() {
|
||||
save_config() {
|
||||
local agent="$1"
|
||||
local mode="$2"
|
||||
local branch="$3"
|
||||
shift 3
|
||||
shift 2
|
||||
local -a profiles=("$@")
|
||||
|
||||
mkdir -p "$REPO_CONFIG_DIR"
|
||||
@@ -310,7 +308,6 @@ save_config() {
|
||||
printf 'CONFIG_SANDBOX=%q\n' "$SANDBOX_NAME"
|
||||
printf 'CONFIG_AGENT=%q\n' "$agent"
|
||||
printf 'CONFIG_MODE=%q\n' "$mode"
|
||||
printf 'CONFIG_BRANCH=%q\n' "$branch"
|
||||
|
||||
printf 'CONFIG_AWS_PROFILES=('
|
||||
local profile
|
||||
@@ -514,10 +511,10 @@ create_sandbox() {
|
||||
--name "$SANDBOX_NAME"
|
||||
)
|
||||
|
||||
# Clone mode gives the agent a Git worktree on its own branch, so its
|
||||
# commits never land on whatever the host has checked out.
|
||||
# Clone mode gives the agent its own in-container clone, so its commits
|
||||
# never land on whatever the host has checked out.
|
||||
if [[ "$CONFIG_MODE" == "clone" ]]; then
|
||||
create_args+=(--branch "$CONFIG_BRANCH")
|
||||
create_args+=(--clone)
|
||||
fi
|
||||
|
||||
create_args+=(
|
||||
@@ -531,7 +528,6 @@ create_sandbox() {
|
||||
setup_command() {
|
||||
local agent="$DEFAULT_AGENT"
|
||||
local mode="$DEFAULT_MODE"
|
||||
local branch="$DEFAULT_BRANCH"
|
||||
local replace=false
|
||||
local -a aws_profiles=()
|
||||
|
||||
@@ -551,11 +547,6 @@ setup_command() {
|
||||
mode="clone"
|
||||
shift
|
||||
;;
|
||||
--branch)
|
||||
(($# >= 2)) || die "--branch requires a value"
|
||||
branch="$2"
|
||||
shift 2
|
||||
;;
|
||||
--direct)
|
||||
mode="direct"
|
||||
shift
|
||||
@@ -581,7 +572,7 @@ setup_command() {
|
||||
validate_aws_profile "$profile"
|
||||
done
|
||||
|
||||
save_config "$agent" "$mode" "$branch" "${aws_profiles[@]}"
|
||||
save_config "$agent" "$mode" "${aws_profiles[@]}"
|
||||
|
||||
if sandbox_exists; then
|
||||
if [[ "$replace" == true ]]; then
|
||||
@@ -610,7 +601,6 @@ Repository: $REPOSITORY
|
||||
Sandbox: $SANDBOX_NAME
|
||||
Agent: $agent
|
||||
Mode: $mode
|
||||
Branch: $branch
|
||||
|
||||
Run it with:
|
||||
|
||||
@@ -666,10 +656,6 @@ status_command() {
|
||||
printf 'Agent: %s\n' "$CONFIG_AGENT"
|
||||
printf 'Mode: %s\n' "$CONFIG_MODE"
|
||||
|
||||
if [[ "$CONFIG_MODE" == "clone" ]]; then
|
||||
printf 'Branch: %s\n' "$CONFIG_BRANCH"
|
||||
fi
|
||||
|
||||
printf 'Token days: %s\n' "$DEFAULT_TOKEN_DAYS"
|
||||
|
||||
printf 'AWS profiles (host -> sandbox):\n'
|
||||
|
||||
Reference in New Issue
Block a user