Skip to content

fix(core): carry an audit source into sandbox deployment writes - #18

Merged
sunyalou merged 1 commit into
mainfrom
agent/oac-core/520be82b3151
Oct 4, 2026
Merged

sunyalou merged 1 commit into
mainfrom
agent/oac-core/520be82b3151

Conversation

@sunyalou

@sunyalou sunyalou commented Oct 4, 2026

Copy link
Copy Markdown
Owner

目标

修复 PUT /core/v1/sandbox/deployment 在提交有变化的部署选择时返回 400 invalid_request、导致 Web 控制台「编辑沙箱部署」无法保存的问题(OAC-22)。

根因

updateSandboxDeployment / initializeSandboxDeployment 两个 handler 未调用 setAdminAuditSource,请求上下文里没有 adminaudit.Source。变更路径 ExecutionOperations.Update 在 !equal(或替换凭据)时会在提交事务中 tx.RecordAudit("change", …);auditpg.RecordDeploymentMutation 要求 ctx 携带该 source,缺失即返回 adminaudit.ErrInvalidSource,被 writeDeploymentError 映射为 400 invalid_request。完全相同(no-op)的选择跳过 audit,所以仍返回 200,掩盖了故障。/core/v1 的 DeploymentAuthenticator 只校验 Core key,不注入 audit source。

改动

  • services/core/internal/api/sandbox_deployment_setup.go:在 updateSandboxDeployment 与 initializeSandboxDeployment 调用操作前补 setAdminAuditSource(r, ""),与 startSandboxReset / cancelSandboxReset 保持一致。部署级 mutation 的 ProjectID 为空,符合 adminaudit.ValidateDeploymentMutation。
  • services/core/internal/api/sandbox_deployment_audit_test.go:新增回归测试,断言 POST(initialize)与 PUT(change)传入操作的上下文都带有 adminaudit.Source,且该 source 能通过 ValidateDeploymentMutation(即真正可落 audit)。

验证

  • go test ./services/core/internal/api/ -run TestSandboxDeploymentMutationsCarryAdministratorAuditSource -count=1 → PASS。
    仅回退 handler 改动后重跑同一测试 → FAIL,initialize 与 change 两条路径都报 carried no deployment audit source,证明测试确实覆盖该回归。
  • go test ./services/core/internal/api/ -count=1 → ok(40.5s)。
  • 其余 services/core/...(排除 internal/store)与 packages/agents-client/... 全量单测 → 除下述环境项外全部 ok。
  • python3 -m unittest discover -s services/core/tests -p official_diagnostics_test.py → OK;python3 services/core/deploy/e2b/managed_init_test.py → OK。
  • python3 scripts/check-names.test.py + python3 scripts/check-names.py → 通过;gofmt -l 无输出。

已知限制 / 未运行

  • make check-core 未完整执行:本环境未配置 OAC_TEST_DATABASE_URL,check-core-store 与依赖测试库的包会跳过/无法运行。因此「PUT 返回 200 且落库(generation 递增、specification 更新)」的 DB 端到端行为、以及 Web「编辑沙箱部署」的端到端保存,需在带专用 PostgreSQL 的 CI/验证环境确认。
  • services/core/internal/nativeinstaller 的两个测试(TestBootstrapCommandDiscardsTimedOutResponse、TestBootstrapDownloadsVerifiedPlatformAcrossHTTPSRedirect)在本环境失败,原因是安装包 HTTPS 下载受代理 TLS 拦截(curl 60 证书校验失败),与本次改动无关;带直连/正确 CA 的环境应通过。
  • 本次改动不涉及协议、OpenAPI、sqlc 或迁移生成物。

The PUT and POST /core/v1/sandbox/deployment handlers never attached the
administrator audit source. A changed selection makes
ExecutionOperations.Update record a "change" audit in the committing
transaction, which requires adminaudit.Source on the context; without it
the transaction fails with adminaudit.ErrInvalidSource and the route
answers 400 invalid_request. An identical no-op selection skips the audit
and still returned 200, which hid the fault and broke Web's edit action.

Attach the source in both handlers, matching the reset routes, and cover
the change and initialize paths with a regression test.

Co-authored-by: multica-agent <github@multica.ai>
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@sunyalou
sunyalou merged commit 1519e38 into main Oct 4, 2026
18 checks passed
@sunyalou
sunyalou deleted the agent/oac-core/520be82b3151 branch October 4, 2026 10:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant