spec/llm: openai-chat packages don't need the sandbox - #239
Conversation
§ Setup said a host that can't provide the named sandbox MUST NOT install the package. Every llm package names github-actions, so that barred even endpoint packages a host reaches directly over openai-chat, which needs neither setup nor the sandbox. Such a host may now install those and use openai-chat alone; runner-only packages (every sandbox-weights one) still need the sandbox. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019p6LTRthBQLE6CfynKmSZr
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Reviewer's guide (collapsed on small PRs)Reviewer's GuideUpdates the LLM specification so hosts without the named sandbox may install and use endpoint packages over Flow diagram for LLM package installation and execution permissionsflowchart TD
Host[Host without github-actions sandbox] --> Package{Package declares openai-chat?}
Package -->|Yes| Install[Install package]
Install --> Protocol[Use package over openai-chat]
Package -->|No| RunnerOnly[Runner-only package]
RunnerOnly --> Reject[Do not install]
Host --> Setup[Run setup or github-actions-runner]
Setup --> Deny[Not permitted]
Host --> Script[Run script on device]
Script --> Deny
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
|
None of the red checks on this PR comes from its change. The PR only edits spec Markdown.
Generated by Claude Code |
🚀 Deploying Preview to Cloudflare 🚀Preview Deployments by commit
|
OpenCode security review |
There was a problem hiding this comment.
Sorry @HereLiesAz, you've used your own review budget of 250,000 diff characters for the last 7 days.
You can request another review in 20 hours and 4 minutes by commenting @sourcery-ai review. Upgrade to get a review now.
spec/llm.md§ Setup said that a host unable to provide the named sandbox MUST NOT install the package. Everyllmpackage namesgithub-actions, so a strict reading barred even endpoint packages that a host reaches directly overopenai-chat. That protocol needs neither setup nor the sandbox (§ Protocols), and the referencechatLlmdoesn't use them either.The new wording:
github-actions-runner.openai-chatand use it over that protocol alone.sandbox-weightspackage.scripton the device.docs/specs/llm.mdwas regenerated withdocs/scripts/sync-specs.mjs. The sync also rewrotedocs/specs/repository-api.md, a drift already on main, which I left out of this change. The changeset is empty because this is spec-only.Found while wiring
kind: "llm"into Guillotine (HereLiesAz/Guillotine#358, HereLiesAz/Guillotine#359).🤖 Generated with Claude Code
https://claude.ai/code/session_019p6LTRthBQLE6CfynKmSZr
Generated by Claude Code
Summary by Sourcery
Allow sandbox-free hosts to install and use OpenAI Chat LLM endpoints while preserving restrictions on runner-only packages and device-side scripts.
Enhancements:
openai-chatprotocol while prohibiting setup, runner-only packages, and on-device scripts.Documentation:
openai-chatrequirements.