Skip to content

Preserve Docker image PATH during sandbox imports - #131

Merged
Dingway98 merged 2 commits into
mainfrom
fix/preserve-docker-image-path
Sep 27, 2026
Merged

Dingway98 merged 2 commits into
mainfrom
fix/preserve-docker-image-path

Conversation

@Dingway98

@Dingway98 Dingway98 commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Docker image imports discarded the image's PATH, which could make commands use the system interpreter instead of an image-provided virtualenv. Preserve that environment value when deriving sandbox image initialization metadata.

Changes

  • Retain Docker image PATH; explicit caller overrides, including an empty value, still take precedence.
  • Cover synchronous and asynchronous exact-image reuse, environment filtering, and cleanup without exporting the Docker image again. No public API change.
  • Bump the package version from 1.9.0 to 1.9.1.

Validation

  • Local SDK suite: 556 passed, 4 skipped; focused build-helper suite: 45 passed.
  • Changed-file Ruff lint and test formatting checks passed.
  • Built the 1.9.1 wheel and source distribution with Python 3.12; both passed twine check and version metadata verification.
  • Real local build-to-sandbox checks passed for Docker imports, exact-image reuse, virtualenv execution, caller overrides, and restrictive/empty PATH values, using the companion builder/receiver fixes.

The companion receiver change preserves child PATH during shell execution. These latest fixes have been validated locally end to end; production-host verification remains pending.


Note

Medium Risk
Changes how sandbox startup env is built for imported Docker images, directly affecting executable resolution; scope is narrow and covered by expanded tests.

Overview
Fixes sandbox Docker image imports dropping the image’s PATH, which could route commands to the host interpreter instead of an image virtualenv.

PATH is no longer treated as a reserved image_init env key, so _derive_auto_image_env keeps the value from the image config during exact-image reuse and other import paths. Caller image_init.env still wins via merge_image_init, including when PATH is set to a custom value or an empty string.

Tests now cover sync/async exact reuse (no docker save), env filtering for reserved keys like HOME/SANDBOX_ENABLED, and PATH override behavior. Package version is bumped to 1.9.1.

Reviewed by Cursor Bugbot for commit 00905ed. Bugbot is set up for automated code reviews on this repo. Configure here.

@Dingway98
Dingway98 marked this pull request as ready for review September 27, 2026 20:45
@Dingway98
Dingway98 merged commit c36d3d9 into main Sep 27, 2026
13 checks passed
@Dingway98
Dingway98 deleted the fix/preserve-docker-image-path branch September 27, 2026 20:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants