Add @azphalt/llm-host: install and run llm packages in a GitHub sandbox - #234
Conversation
Consent data, verified install into a private Actions sandbox (one commit, sealed secrets, setup smoke test), the github-actions-runner and openai-chat protocols, and rolling delimiters byte-compatible with the reference runner. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QwYWVPse8spRrfMMcuTJPv
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Reviewer's GuideIntroduces Sequence diagram for LLM package installation and setupsequenceDiagram
participant Host
participant GitHub
participant Sandbox
participant Runner
Host->>Host: llmConsent(manifest)
Host->>Host: verifyAzp(azp)
Host->>GitHub: ensure private repository
Host->>GitHub: commitFiles(payload, workflow)
Host->>GitHub: GET actions secrets public key
Host->>GitHub: sealedBox(input, public key)
Host->>GitHub: PUT Actions secret
Host->>GitHub: dispatch setup task
GitHub->>Sandbox: start workflow
Sandbox->>Runner: execute op setup
Runner-->>GitHub: result artifact and progress
GitHub-->>Host: setup result
Sequence diagram for bounded LLM task executionsequenceDiagram
participant Host
participant GitHub
participant Runner
participant Artifact
Host->>GitHub: dispatch workflow task
loop until run completes
Host->>GitHub: findRun(install, correlationId)
Host->>GitHub: read check-run progress
GitHub-->>Host: seq and message
end
Host->>GitHub: list run artifacts
GitHub-->>Host: azphalt-llm-result
Host->>Artifact: ghBytes(zip, MAX_ARTIFACT_BYTES)
Artifact-->>Host: result.json
Host->>Host: parseResult(raw)
Host->>Host: containsSessionTag(result, tags)
Host-->>Host: completed or failed result
Sequence diagram for direct openai-chat translationsequenceDiagram
participant Host
participant ModelEndpoint
Host->>Host: sessionTags(sessionKey, turn)
Host->>Host: translate(messages, tags)
Host->>ModelEndpoint: POST /chat/completions
ModelEndpoint-->>Host: chat response
Host->>Host: containsSessionTag(text, tags)
Host-->>Host: ChatResult or rejection
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
🚀 Deploying Preview to Cloudflare 🚀Preview Deployments by commit
|
OpenCode security review |
|
No The other red checks aren't from this PR either: Vercel (a leftover project), Workers Builds (the Cloudflare preview), and Locally, Generated by Claude Code |
There was a problem hiding this comment.
Sorry @HereLiesAz, you've used your own review budget of 250,000 diff characters for the last 7 days.
You can request another review in 1 day and 3 hours by commenting @sourcery-ai review. Upgrade to get a review now.
This is the host side of
kind: "llm". The store can list llm packages, but until now nothing could install or run one.What it does
llmConsent(manifest): everythingspec/llm.mdsays a host must show before install:installLlm, which:.azpfirst;llm/<id>/and the runner workflow to.github/workflows/azphalt-llm-<id>.ymlin one commit, so several packages share one sandbox;crypto_box_seal;op: "setup"task.runLlm: thegithub-actions-runnerprotocol:task, retrying while a just-committed workflow registers;run-name, and follows the check run's<seq>\t<message>lines, deduplicated byseq;azphalt-llm-resultwithin the reference bounds (4 MB zipped, 2 MB JSON) and inflates onlyresult.json;resumeand the same correlation id, follows an already-dispatched run after a restart.chatLlm: theopenai-chatprotocol, with the host translating the delimiters.newSessionKey,turnTag,sessionTags,wrap,scrub,translateandcontainsSessionTag. They're byte-compatible withscripts/llm-sandbox/run.py; the tests pin vectors computed from the Python implementation.New dependencies:
tweetnacl(public domain) andblakejs(MIT), which together make the sealed box GitHub requires for secrets.fflateis already used in the workspace.Docs: package readme, root README table,
ARCHITECTURE.md, and thespec/llm.mdstatus line (plus itsdocs/specsmirror). Changeset included.Verification
nacl.box.open. Consent is built from the real Kilo and Qwen registry packages. Install, run and chat are exercised against a fake GitHub: one commit, the executable bit onsetup.sh, a sealed secret that decrypts to the input, public-sandbox refusal, tamper refusal, and required inputs. Run covers progress dedupe, tag rejection, a missing artifact, andparseResultbounds and types.🤖 Generated with Claude Code
https://claude.ai/code/session_01QwYWVPse8spRrfMMcuTJPv
Generated by Claude Code
Summary by Sourcery
Add the host-side implementation for installing and running signed
kind: "llm"packages in private GitHub Actions sandboxes.New Features:
@azphalt/llm-hostpackage for consent disclosure, private GitHub Actions sandbox installation, model task execution, and direct OpenAI-compatible chat.Enhancements:
Build:
Documentation:
Tests:
Chores: