fix(e2b): harden remote startup and teardown
This commit is contained in:
@@ -1,7 +1,31 @@
|
||||
/** Shared remote-environment scrubbing for E2B process and terminal launchers. */
|
||||
|
||||
import { Buffer } from 'node:buffer'
|
||||
import type { Sandbox } from '@deepseek-ai/dsh-e2b'
|
||||
import { SENSITIVE_ENV_PATTERN } from '@deepseek-ai/dsh-subprocess'
|
||||
|
||||
const BASE64 = /^(?:[A-Za-z0-9+/]{4})*(?:[A-Za-z0-9+/]{2}==|[A-Za-z0-9+/]{3}=)?$/
|
||||
|
||||
/**
|
||||
* Read the remote environment through ASCII base64 so SDK callback chunking cannot corrupt UTF-8.
|
||||
* @param sandbox - shared E2B execution world.
|
||||
* @param signal - optional cancellation for the control-plane request.
|
||||
* @returns the complete NUL-delimited UTF-8 environment.
|
||||
*/
|
||||
export async function readRemoteEnvironment(sandbox: Sandbox, signal?: AbortSignal): Promise<string> {
|
||||
const result = await sandbox.commands.run(
|
||||
'set -o pipefail; env -0 | base64 -w 0',
|
||||
signal === undefined ? {} : { signal },
|
||||
)
|
||||
const encoded = result.stdout.trim()
|
||||
if (!BASE64.test(encoded)) throw new Error('subprocess-e2b: remote environment transport returned invalid base64')
|
||||
try {
|
||||
return new TextDecoder('utf-8', { fatal: true }).decode(Buffer.from(encoded, 'base64'))
|
||||
} catch (error: unknown) {
|
||||
throw new Error('subprocess-e2b: remote environment is not valid UTF-8', { cause: error })
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Parse an E2B NUL-delimited environment while removing harness-private and credential-shaped names.
|
||||
* @param raw - The complete NUL-delimited remote environment.
|
||||
|
||||
Reference in New Issue
Block a user