(args: LifecycleArgs)
| 90 | `; |
| 91 | try { |
| 92 | await execFileAsync('docker', ['exec', containerId, 'bun', '-e', probe, sessionId], { |
| 93 | timeout: 5_000, |
| 94 | }); |
| 95 | return true; |
| 96 | } catch { |
| 97 | return false; |
| 98 | } |
| 99 | } |
| 100 | |
| 101 | async function findOwnedSandboxes( |
| 102 | sessionId: string, |
| 103 | kiloSessionId: string | undefined, |
| 104 | knownIds: Set<string> |
| 105 | ) { |
| 106 | const candidates = sessionId.startsWith('workspace_') |
| 107 | ? await listSandboxContainers() |
| 108 | : await listSandboxesForAgentSession(sessionId); |
| 109 | const matches: SandboxContainer[] = []; |
| 110 | for (const container of candidates) { |
| 111 | if (container.isProxy || knownIds.has(container.id)) continue; |
| 112 | if (await sandboxOwnsSession(container.id, sessionId, kiloSessionId)) matches.push(container); |
| 113 | } |
| 114 | return matches; |
| 115 | } |
| 116 | |
| 117 | export async function waitForOwnedSandbox( |
| 118 | sessionId: string, |
| 119 | kiloSessionId: string, |
| 120 | knownIds: Set<string>, |
| 121 | timeoutMs: number, |
| 122 | signal?: AbortSignal |
| 123 | ): Promise<SandboxContainer | null> { |
| 124 | const deadline = Date.now() + timeoutMs; |
| 125 | while (Date.now() < deadline) { |
| 126 | // Docker discovery is not abortable mid-exec, so the signal is honoured |
| 127 | // between polls rather than during one. |
| 128 | if (signal?.aborted) return null; |
| 129 | const matches = await findOwnedSandboxes(sessionId, kiloSessionId, knownIds); |
| 130 | if (matches.length > 1) { |
| 131 | throw new Error(`Multiple containers match ${sessionId}; refusing ambiguous ownership`); |
| 132 | } |
| 133 | if (matches[0]) return matches[0]; |
| 134 | await new Promise(resolve => setTimeout(resolve, 500)); |
| 135 | } |
| 136 | return null; |
| 137 | } |
| 138 | |
| 139 | /** |
| 140 | * Single-shot owned-container discovery for the current session, used by the |
| 141 | * `sessionSandbox.currentContainer` capability. Unlike `waitForOwnedSandbox` it |
| 142 | * excludes nothing, because it observes a container that is expected to already |
| 143 | * exist; it still refuses ambiguous ownership. |
| 144 | */ |
| 145 | export async function currentOwnedSandbox( |
| 146 | sessionId: string, |
| 147 | kiloSessionId: string |
| 148 | ): Promise<SandboxContainer | null> { |
| 149 | const matches = await findOwnedSandboxes(sessionId, kiloSessionId, new Set()); |
nothing calls this directly
no test coverage detected