mirror of
https://github.com/windmill-labs/windmill.git
synced 2026-09-11 16:09:39 +00:00
* feat(nsjail): make tmpfs size configurable via instance setting Adds a new `nsjail_tmpfs_size_mb` instance setting that overrides the size of the `/tmp` tmpfs mount inside the nsjail sandbox across all languages. When unset, the existing per-language defaults (500MB or 800MB) continue to apply, so no behavior change for existing deployments. The setting is exposed under Settings → Jobs and is read at job execution time, so changes take effect on the next job without a restart. Fixes WIN-1963 Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * refactor(nsjail): unify default tmpfs size to 800MB Previously each executor passed its own per-language default (500MB or 800MB) to resolve_nsjail_tmpfs_size. Unify on a single DEFAULT_NSJAIL_TMPFS_SIZE_BYTES constant (800MB) so the placeholder behavior is consistent across languages. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix(nsjail): resolve tmpfs size outside ruby download closure The download.ruby config render runs inside a sync closure passed to par_install_language_dependencies_seq, so `.await` on resolve_nsjail_tmpfs_size() was a compile error under the `ruby` feature. Resolve the size once before the closure and capture the string instead. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(nsjail): rename resolver to *_bytes and clarify fallback Addresses CI review feedback: - Rename `resolve_nsjail_tmpfs_size` to `resolve_nsjail_tmpfs_size_bytes` so the returned unit is unambiguous at the call site (cubic P2). - Fix the `NSJAIL_TMPFS_SIZE_MB` doc comment that still said "per-language default" — there is no per-language fallback anymore, all unset values resolve to the unified 800MB `DEFAULT_NSJAIL_TMPFS_SIZE_BYTES` (codex/pi P2). - Expand the resolver doc to call out that `Some(0)` and negative values also fall back, since the match arm is `Some(mb) if mb > 0`. No behavior change. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
145 lines
2.0 KiB
Protocol Buffer
145 lines
2.0 KiB
Protocol Buffer
name: "ruby run script"
|
|
|
|
mode: ONCE
|
|
hostname: "ruby"
|
|
log_level: ERROR
|
|
time_limit: {TIMEOUT}
|
|
|
|
disable_rl: true
|
|
|
|
cwd: "/tmp"
|
|
|
|
clone_newnet: false
|
|
clone_newuser: {CLONE_NEWUSER}
|
|
|
|
skip_setsid: true
|
|
keep_caps: false
|
|
keep_env: true
|
|
# mount_proc: true
|
|
|
|
mount {
|
|
src: "/bin"
|
|
dst: "/bin"
|
|
is_bind: true
|
|
}
|
|
|
|
mount {
|
|
src: "/lib"
|
|
dst: "/lib"
|
|
is_bind: true
|
|
}
|
|
|
|
|
|
mount {
|
|
src: "/lib64"
|
|
dst: "/lib64"
|
|
is_bind: true
|
|
mandatory: false
|
|
}
|
|
|
|
|
|
mount {
|
|
src: "/usr"
|
|
dst: "/usr"
|
|
is_bind: true
|
|
}
|
|
|
|
mount {
|
|
src: "/dev/null"
|
|
dst: "/dev/null"
|
|
is_bind: true
|
|
rw: true
|
|
}
|
|
|
|
mount {
|
|
dst: "/tmp"
|
|
fstype: "tmpfs"
|
|
rw: true
|
|
options: "size={NSJAIL_TMPFS_SIZE}"
|
|
}
|
|
|
|
|
|
mount {
|
|
src: "{JOB_DIR}/main.rb"
|
|
dst: "/tmp/main.rb"
|
|
is_bind: true
|
|
mandatory: false
|
|
}
|
|
|
|
mount {
|
|
src: "{JOB_DIR}/args.json"
|
|
dst: "/tmp/args.json"
|
|
is_bind: true
|
|
}
|
|
|
|
mount {
|
|
src: "{JOB_DIR}/result.json"
|
|
dst: "/tmp/result.json"
|
|
rw: true
|
|
is_bind: true
|
|
}
|
|
|
|
#mount {
|
|
# src: "{CACHE_DIR}"
|
|
# dst: "{CACHE_DIR}"
|
|
# is_bind: true
|
|
# mandatory: false
|
|
# }
|
|
|
|
mount {
|
|
src: "/etc"
|
|
dst: "/etc"
|
|
is_bind: true
|
|
}
|
|
|
|
# Container runtimes bind exactly these 3 files as separate submounts over
|
|
# /etc; nsjail's ro remount of /etc is non-recursive so they stay writable.
|
|
# Load-bearing -- do not remove as redundant with the /etc bind above.
|
|
mount {
|
|
src: "/etc/resolv.conf"
|
|
dst: "/etc/resolv.conf"
|
|
is_bind: true
|
|
mandatory: false
|
|
}
|
|
|
|
mount {
|
|
src: "/etc/hosts"
|
|
dst: "/etc/hosts"
|
|
is_bind: true
|
|
mandatory: false
|
|
}
|
|
|
|
mount {
|
|
src: "/etc/hostname"
|
|
dst: "/etc/hostname"
|
|
is_bind: true
|
|
mandatory: false
|
|
}
|
|
|
|
mount {
|
|
src: "/dev/random"
|
|
dst: "/dev/random"
|
|
is_bind: true
|
|
}
|
|
|
|
mount {
|
|
src: "/dev/urandom"
|
|
dst: "/dev/urandom"
|
|
is_bind: true
|
|
}
|
|
|
|
iface_no_lo: true
|
|
|
|
{SHARED_MOUNT}
|
|
|
|
{SHARED_DEPENDENCIES}
|
|
|
|
mount {
|
|
src: "{TRACING_PROXY_CA_CERT_PATH}"
|
|
dst: "{TRACING_PROXY_CA_CERT_PATH}"
|
|
is_bind: true
|
|
mandatory: false
|
|
}
|
|
|
|
#{DEV}
|