Commit Graph
2 Commits
Author SHA1 Message Date
mroberts ad2b33f984 Split a multi-line AI_SBX_NETWORK correctly
A long host list is naturally written as a multi-line TOML string, but read
stops at the first newline, so only the first host was ever allowed. The rest
failed later as connection errors with nothing pointing back at the list.

Newlines and carriage returns are now flattened alongside commas before
splitting, and the test covers a multi-line value; it fails without the fix.

Also records the measured host requirements for a full Neovim configuration.
The Balanced policy already permits github, npm, pypi, crates, go, ubuntu,
nodejs, hashicorp releases, Copilot and the LLM APIs, which covers 93 lazy.nvim
plugins, both mason registries and all 55 mason packages. Only the .NET and
Terraform registries need declaring.
2026-08-03 12:37:53 -05:00
mroberts 2890b1dd98 Open the network policy for hosts a sandbox actually needs
Sandboxes default to a deny-everything-else policy, so the registry credentials
provisioned as custom secrets were unusable: npm.fontawesome.com,
proget.careevolution.com and localstack.cloud were all denied, and the request
never left the sandbox for the proxy to substitute a token into. The failure
looked like a connection error rather than a policy decision.

Provisioning a secret now allows its hosts in the same step, since a credential
for a denied host cannot be used by definition. AI_SBX_NETWORK declares any
further hosts, comma or space separated, for private registries that back no
secret.

The marketplace loop's inline policy call moves into the shared helper so the
two cannot drift.

The Balanced policy already permits github.com, codeload and the
githubusercontent hosts, registry.npmjs.org, pypi.org, files.pythonhosted.org,
crates.io and the Go proxies, so npm, pip, cargo, go and a plugin-managed
Neovim need nothing declared. Only private hosts do.
2026-08-03 10:42:56 -05:00