|
| 1 | +"""Live docker check that the sandbox venv does not shadow a task image's packages. |
| 2 | +
|
| 3 | +Gated: needs a real docker daemon and the `coder-eval-agent` base image. |
| 4 | +
|
| 5 | +This is the one thing the unit tests cannot prove. `tests/test_sandbox.py` asserts |
| 6 | +the venv is created with system site packages by reading `pyvenv.cfg`, which is a |
| 7 | +property of the flag, not of the outcome. The outcome only exists inside an image |
| 8 | +that provisions packages GLOBALLY — the shape every task image has (the framework |
| 9 | +image installs with `uv pip install --system`; skillsbench task images do |
| 10 | +`RUN pip install ...`). There, an isolated sandbox venv split the toolchain: |
| 11 | +`python` resolved to the venv and could not import the image's packages, while |
| 12 | +`pip` fell through to the image's global pip and reported them present. |
| 13 | +
|
| 14 | +Measured against this test's own scenario: |
| 15 | +
|
| 16 | + main (isolated venv) python -c "import pydantic" -> exit 1 |
| 17 | + with --system-site-packages python -c "import pydantic" -> exit 0 |
| 18 | +
|
| 19 | +`pydantic` is a coder_eval runtime dependency, so the base image already has it |
| 20 | +installed globally — no build and no network are needed to reproduce the shape. |
| 21 | +""" |
| 22 | + |
| 23 | +from __future__ import annotations |
| 24 | + |
| 25 | +import shutil |
| 26 | +import subprocess |
| 27 | +import sys |
| 28 | +import textwrap |
| 29 | +from pathlib import Path |
| 30 | + |
| 31 | +import pytest |
| 32 | + |
| 33 | + |
| 34 | +BASE_IMAGE = "coder-eval-agent:latest" |
| 35 | +REPO_SRC = Path(__file__).resolve().parent.parent / "src" |
| 36 | + |
| 37 | +pytestmark = [ |
| 38 | + pytest.mark.live, |
| 39 | + pytest.mark.skipif(sys.platform == "win32", reason="docker driver is POSIX-only"), |
| 40 | + pytest.mark.skipif(shutil.which("docker") is None, reason="docker CLI not available"), |
| 41 | +] |
| 42 | + |
| 43 | + |
| 44 | +def _docker_daemon_up() -> bool: |
| 45 | + try: |
| 46 | + return subprocess.run(["docker", "info"], capture_output=True, timeout=15).returncode == 0 |
| 47 | + except (subprocess.TimeoutExpired, FileNotFoundError): |
| 48 | + return False |
| 49 | + |
| 50 | + |
| 51 | +def _image_present(image: str) -> bool: |
| 52 | + return subprocess.run(["docker", "image", "inspect", image], capture_output=True, timeout=30).returncode == 0 |
| 53 | + |
| 54 | + |
| 55 | +PROBE = textwrap.dedent( |
| 56 | + """ |
| 57 | + from coder_eval.models import SandboxConfig |
| 58 | + from coder_eval.sandbox import Sandbox |
| 59 | +
|
| 60 | + sandbox = Sandbox(SandboxConfig(driver="tempdir"), task_id="venv_probe") |
| 61 | + try: |
| 62 | + sandbox_dir = sandbox.setup() |
| 63 | + import_rc, _, _ = sandbox.run_command('python -c "import pydantic"') |
| 64 | + _, prefix, _ = sandbox.run_command('python -c "import sys; print(sys.prefix)"') |
| 65 | + print(f"IMPORT_RC={import_rc}") |
| 66 | + print(f"PREFIX={prefix.strip()}") |
| 67 | + print(f"VENV={sandbox.venv_dir}") |
| 68 | + finally: |
| 69 | + sandbox.cleanup() |
| 70 | + """ |
| 71 | +) |
| 72 | + |
| 73 | + |
| 74 | +def test_criteria_can_import_the_images_global_packages() -> None: |
| 75 | + """A `run_command` criterion must see what the task image installed globally. |
| 76 | +
|
| 77 | + Mounts this checkout's `src/` over the image's copy so the assertion is about |
| 78 | + the code under test, not whatever coder_eval version the image was built with. |
| 79 | + """ |
| 80 | + if not _docker_daemon_up(): |
| 81 | + pytest.skip("docker daemon not running") |
| 82 | + if not _image_present(BASE_IMAGE): |
| 83 | + pytest.skip(f"{BASE_IMAGE} not built locally") |
| 84 | + |
| 85 | + proc = subprocess.run( |
| 86 | + [ |
| 87 | + "docker", |
| 88 | + "run", |
| 89 | + "--rm", |
| 90 | + "-v", |
| 91 | + f"{REPO_SRC}:/opt/coder_eval/src:ro", |
| 92 | + "--entrypoint", |
| 93 | + "python3", |
| 94 | + BASE_IMAGE, |
| 95 | + "-c", |
| 96 | + PROBE, |
| 97 | + ], |
| 98 | + capture_output=True, |
| 99 | + text=True, |
| 100 | + timeout=300, |
| 101 | + ) |
| 102 | + assert proc.returncode == 0, f"probe failed:\n{proc.stdout}\n{proc.stderr}" |
| 103 | + out = dict(line.split("=", 1) for line in proc.stdout.splitlines() if "=" in line) |
| 104 | + |
| 105 | + assert out["IMPORT_RC"] == "0", ( |
| 106 | + "a criterion could not import a package the image installed globally -- " |
| 107 | + f"the sandbox venv is shadowing the image interpreter again:\n{proc.stdout}" |
| 108 | + ) |
| 109 | + # Isolation still holds: installs land in the sandbox, not the image. |
| 110 | + assert out["PREFIX"] == out["VENV"], f"criterion did not run under the sandbox venv:\n{proc.stdout}" |
0 commit comments