fix(execd): kill the whole process group when a bash session run times out #3071
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Server Tests | |
| on: | |
| pull_request: | |
| branches: [ main ] | |
| permissions: | |
| contents: read | |
| pull-requests: read | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} | |
| cancel-in-progress: true | |
| jobs: | |
| changes: | |
| uses: ./.github/workflows/detect-changes.yml | |
| with: | |
| area: server | |
| test: | |
| needs: changes | |
| if: needs.changes.outputs.relevant == 'true' | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| os: [ubuntu-latest, windows-latest] | |
| runs-on: ${{ matrix.os }} | |
| defaults: | |
| run: | |
| shell: bash | |
| steps: | |
| - name: Checkout code | |
| uses: actions/checkout@v6 | |
| - name: Set up Python | |
| uses: actions/setup-python@v6 | |
| with: | |
| python-version: '3.10' | |
| - name: Install uv | |
| run: | | |
| pip install uv | |
| - name: Run tests | |
| run: | | |
| cd server | |
| uv sync --all-groups | |
| uv run ruff check | |
| mkdir -p reports | |
| uv run pytest \ | |
| --cov=opensandbox_server \ | |
| --cov-report=term \ | |
| --cov-report=xml:reports/coverage.xml \ | |
| --cov-fail-under=80 | |
| - name: Upload coverage report | |
| if: always() | |
| uses: actions/upload-artifact@v4 | |
| with: | |
| name: server-coverage-${{ matrix.os }} | |
| path: server/reports/coverage.xml | |
| docker-smoke: | |
| needs: changes | |
| if: needs.changes.outputs.relevant == 'true' | |
| strategy: | |
| matrix: | |
| network: [host, bridge] | |
| runs-on: ubuntu-latest | |
| env: | |
| OPENSANDBOX_INSECURE_SERVER: YES | |
| steps: | |
| - name: Checkout code | |
| uses: actions/checkout@v6 | |
| - name: Set up Python | |
| uses: actions/setup-python@v6 | |
| with: | |
| python-version: '3.10' | |
| - name: Install uv | |
| run: | | |
| pip install uv | |
| - name: Set up Docker | |
| run: | | |
| docker --version | |
| - name: Run smoke test | |
| run: | | |
| set -e | |
| cd server | |
| uv sync --all-groups | |
| # Create config file | |
| cat <<EOF > ~/.sandbox.toml | |
| [server] | |
| host = "127.0.0.1" | |
| port = 32888 | |
| api_key = "" | |
| [log] | |
| level = "INFO" | |
| [runtime] | |
| type = "docker" | |
| execd_image = "opensandbox/execd:latest" | |
| [egress] | |
| image = "opensandbox/egress:latest" | |
| [docker] | |
| network_mode = "${{ matrix.network }}" | |
| [storage] | |
| allowed_host_paths = ["/tmp/opensandbox-e2e"] | |
| EOF | |
| # Start server in background | |
| uv run python -m opensandbox_server.main > app.log 2>&1 & | |
| # Wait for server to start | |
| sleep 10 | |
| # Run smoke test | |
| chmod +x tests/smoke.sh | |
| ./tests/smoke.sh | |
| - name: Show logs | |
| if: always() | |
| run: | | |
| cat server/app.log | |
| postgresql-integration: | |
| needs: changes | |
| if: needs.changes.outputs.relevant == 'true' | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 15 | |
| services: | |
| postgres: | |
| image: postgres:16-alpine | |
| env: | |
| POSTGRES_DB: opensandbox | |
| POSTGRES_PASSWORD: postgres | |
| ports: | |
| - 5432:5432 | |
| options: >- | |
| --health-cmd "pg_isready -U postgres -d opensandbox" | |
| --health-interval 5s | |
| --health-timeout 5s | |
| --health-retries 10 | |
| env: | |
| OPENSANDBOX_TEST_POSTGRESQL_DSN: postgresql://postgres:postgres@127.0.0.1:5432/opensandbox | |
| steps: | |
| - name: Checkout code | |
| uses: actions/checkout@v6 | |
| - name: Set up Python | |
| uses: actions/setup-python@v6 | |
| with: | |
| python-version: '3.10' | |
| - name: Install uv | |
| run: pip install uv | |
| - name: Run PostgreSQL repository tests | |
| working-directory: server | |
| run: | | |
| uv sync --all-groups | |
| uv run pytest -v \ | |
| tests/test_snapshot_repository_postgresql.py \ | |
| tests/test_snapshot_migration.py \ | |
| tests/test_snapshot_ha_postgresql_kubernetes.py | |
| required: | |
| name: Server CI | |
| if: always() | |
| needs: [changes, test, docker-smoke, postgresql-integration] | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Verify required jobs | |
| env: | |
| RELEVANT: ${{ needs.changes.outputs.relevant }} | |
| CHANGES_RESULT: ${{ needs.changes.result }} | |
| TEST_RESULT: ${{ needs.test.result }} | |
| DOCKER_SMOKE_RESULT: ${{ needs.docker-smoke.result }} | |
| POSTGRESQL_RESULT: ${{ needs.postgresql-integration.result }} | |
| run: | | |
| if [[ "$CHANGES_RESULT" != "success" ]]; then | |
| echo "Change detection failed: $CHANGES_RESULT" | |
| exit 1 | |
| fi | |
| if [[ "$RELEVANT" == "true" ]]; then | |
| [[ "$TEST_RESULT" == "success" && "$DOCKER_SMOKE_RESULT" == "success" && "$POSTGRESQL_RESULT" == "success" ]] | |
| else | |
| [[ "$RELEVANT" == "false" && "$TEST_RESULT" == "skipped" && "$DOCKER_SMOKE_RESULT" == "skipped" && "$POSTGRESQL_RESULT" == "skipped" ]] | |
| fi |