Commit Graph

654 Commits

Author SHA1 Message Date
Sebastion 8374033875 fix(cli): restrict ~/.e2b/config.json permissions to owner-only (#1320)
## Summary

The CLI stores credentials (E2B access token and team API key) in
plaintext at `~/.e2b/config.json`. Today the file is created with the
process default umask, which on most Linux distributions and macOS
results in mode `0644` — readable by every other local user and by any
process running as a different UID on the same machine.

This PR routes all three write sites through a single
`writeUserConfig()` helper that creates `~/.e2b` as `0700` and
`config.json` as `0600`, matching the convention used by the AWS CLI
(`~/.aws/credentials`), `kubectl` (`~/.kube/config`), and `gh`
(`~/.config/gh/hosts.yml`).

- **CWE:** CWE-312 (Cleartext Storage of Sensitive Information) —
partial mitigation. The file remains plaintext on disk (the existing `//
TODO` in `user.ts` already acknowledges that keychain storage is the
proper long-term fix); this change reduces exposure to other local users
/ less-privileged processes, which is the standard industry mitigation
while plaintext storage remains.
- **Affected file:** `packages/cli/src/user.ts` and the three writers in
`packages/cli/src/commands/`.
- **Severity:** Moderate on shared / multi-user machines (CI runners,
dev VMs, jump boxes); low on single-user workstations.

## What's in `~/.e2b/config.json`

```ts
{
  email, accessToken,           // user access token
  teamName, teamId, teamApiKey  // team API key
}
```

`accessToken` authenticates the user against the E2B control plane;
`teamApiKey` authorizes sandbox creation against the team. Either is
sufficient to impersonate the user / spend on the team's account.

## Fix

A new helper in `packages/cli/src/user.ts`:

```ts
export function writeUserConfig(configPath: string, config: UserConfig): void {
  const dir = path.dirname(configPath)
  fs.mkdirSync(dir, { recursive: true, mode: 0o700 })
  fs.chmodSync(dir, 0o700)
  fs.writeFileSync(configPath, JSON.stringify(config, null, 2), { mode: 0o600 })
  fs.chmodSync(configPath, 0o600)
}
```

The explicit `chmodSync` calls are intentional: `mkdirSync({ mode })`
and `writeFileSync({ mode })` only set permissions when the path is
created. If the directory or file already exists with looser permissions
(the common case for users upgrading), `chmodSync` corrects them on the
next write.

Call sites updated:
- `packages/cli/src/commands/auth/login.ts`
- `packages/cli/src/commands/auth/configure.ts`
- `packages/cli/src/commands/template/buildWithProxy.ts`

`logout` uses `unlinkSync` and is unaffected. I grep'd the package for
any other writers to `USER_CONFIG_PATH` — these three are the complete
set.

Behavior on Windows: `chmodSync` only manipulates the read-only bit on
Windows, which is consistent with how the AWS/kubectl/gh CLIs behave.
ACL hardening on Windows is out of scope for this change.

## Tests

Added `packages/cli/tests/user_config_permissions.test.ts`, which writes
a config to a temporary path and asserts the resulting directory is
`0700` and file is `0600`, plus that the JSON round-trips correctly.

Manually verified before/after on Linux:

```
# before this PR
$ ls -l ~/.e2b/config.json
-rw-r--r-- 1 user user 234 ... config.json
# after
$ ls -l ~/.e2b/config.json
-rw------- 1 user user 234 ... config.json
```

## Why this is worth fixing

The exploitable scenario is a multi-tenant or shared-account host:
another local user (or a process running as `nobody`, a CI worker UID, a
sandboxed app, etc.) can `cat ~/<victim>/.e2b/config.json` and lift live
credentials. No privilege escalation, no race, no special tooling — the
file is simply world-readable today.

Before submitting, I tried to disprove the finding: I checked whether
E2B sets a restrictive umask anywhere in the CLI bootstrap (it doesn't),
whether the tokens are short-lived enough to make disclosure low-impact
(the access token isn't visibly rotated and the team API key is
long-lived), and whether the directory itself was being created
restrictively elsewhere (it wasn't — `mkdirSync` was called with default
mode). None of those mitigations are in place, so the permission
tightening is doing real work.

This doesn't close out CWE-312 — that requires moving the secrets out of
plaintext entirely, which the existing TODO acknowledges. It does close
the "any local user can read it" gap, which is the cheap, high-value
half of the mitigation.

_Submitted by Sebastion — autonomous open-source security research from
[Foundation Machines](https://foundationmachines.ai). Free for public
repos via the [Sebastion AI GitHub
App](https://github.com/marketplace/sebastion-ai)._

---------

Co-authored-by: Mish Ushakov <10400064+mishushakov@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-02 23:07:58 -07:00
github-actions[bot] dead38a396 [skip ci] Release new versions 2026-06-02 14:24:33 +00:00
Yizuki_Ame ad377962dc fix: await async callbacks in CommandHandle.wait() (#1261)
Fixes #1259

## Problem

The `CommandHandle.wait()` method fires `onStdout`, `onStderr`, and
`onPty` callbacks without `await`, so async callbacks run as
fire-and-forget microtasks. If a callback performs I/O (e.g. writing to
a file, sending over network), `wait()` can resolve before the callback
finishes, leading to lost data or race conditions.

## Fix

Add `await` before each optional-chain callback invocation:

```diff
-this.onStdout?.(stdout)
+await this.onStdout?.(stdout)
```

This is fully backwards compatible — `await`-ing a sync function's
return value is a no-op.

## Tests

3 parameterized test cases (`stdout`, `stderr`, `pty`) verify that
`wait()` does not resolve until an async callback's promise settles.

_This fix was developed with AI assistance and reviewed by a human._
2026-06-02 06:44:20 -07:00
Matt Brockman b7fa99e2b7 Silence undici fallback warning (#1375)
don't need the warning for undici

---------

Co-authored-by: Mish Ushakov <10400064+mishushakov@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-01 15:48:29 +00:00
github-actions[bot] e113618db0 [skip ci] Release new versions 2026-05-29 23:46:06 +00:00
Matt Brockman 4b9cc043dc Fix/python envd stable transport (#1368) 2026-05-29 16:39:30 -07:00
github-actions[bot] 44f07b607a [skip ci] Release new versions 2026-05-27 21:33:52 +00:00
Mish Ushakov 4a4bb36839 feat(sdk): validate E2B API key format client-side (#1356)
## Summary

- Both JS and Python SDKs now validate that the configured E2B API key
matches `e2b_` followed by 40 hex characters (mirroring the server-side
check in
[`infra/.../keys/key.go`](https://github.com/e2b-dev/infra/blob/main/packages/shared/pkg/keys/key.go#L66))
and throw `AuthenticationError` / `AuthenticationException` with an
example token (`e2b_0000…`) and a link to the API Keys dashboard tab.
- Validation runs inside `ApiClient` / `ApiClient.__init__` whenever an
API key is present, so callers get immediate, actionable feedback
instead of a generic 401 from the server.
- Added unit tests (`validateApiKey.test.ts`,
`test_validate_api_key.py`) and updated existing fixtures that used
placeholder keys like `'test-key'` / `'base-api-key'` to use the valid
format.

## Test plan

- [x] `pnpm run format`, `pnpm run lint`, `pnpm run typecheck`
- [x] `pnpm exec vitest run tests/api/validateApiKey.test.ts
tests/api/handleApiError.test.ts tests/sandbox/abortSignal.test.ts
tests/template/abortSignal.test.ts
tests/sandbox/configPropagation.test.ts tests/connectionConfig.test.ts`
- [x] `poetry run pytest tests/test_validate_api_key.py
tests/test_api_client_transport.py
tests/sync/sandbox_sync/test_config_propagation.py
tests/async/sandbox_async/test_config_propagation.py
tests/test_connection_config.py`

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
2026-05-27 21:21:19 +00:00
Mish Ushakov 2691c73d1c chore(sdk): sync OpenAPI spec from infra, regenerate clients (#1357)
## Summary
- Sync `spec/openapi.yml` from
[e2b-dev/infra@main](https://github.com/e2b-dev/infra/blob/main/spec/openapi.yml)
and re-run `make codegen`.
- Schema changes surfaced in the generated clients:
`SandboxMetric.memCache` (new required int64 — also exposed on the
public `SandboxMetrics` wrapper in both SDKs), `NodeStatus` gains
`standby`, `TeamUser.email` becomes nullable + deprecated, and `POST
/v3/templates` gains a `403` response.
- Upstream-only spec changes (not generated because the client filters
by tag): new `AuthProviderBearerAuth`/`AuthProviderTeamAuth` security
schemes, new admin endpoints for team API keys, and a `clusterID` query
param on `GET /nodes`.

## Test plan
- [x] \`pnpm run format\`, \`pnpm run lint\`, \`pnpm run typecheck\`
- [x] JS \`tests/sandbox/metrics.test.ts\` against the live API
- [x] Python sync + async \`test_metrics.py\` against the live API

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
2026-05-27 22:57:28 +02:00
Mish Ushakov a6bf71a083 fix(sdks): handle multi-source COPY/ADD in fromDockerfile (#1355)
## Summary

- Fixes #1349: `Template.fromDockerfile` (JS) and
`Template.from_dockerfile` (Python) silently dropped intermediate
sources from multi-source `COPY`/`ADD`, keeping only the first one and
producing broken images without warning.
- Both parsers now emit one `copy()` call per source to the same
destination (matching Docker semantics), preserving `--chown` across all
calls.
- Added tests in both SDKs (multi-source COPY, and multi-source COPY
with `--chown`), plus changesets for `e2b` and `@e2b/python-sdk`.

## Test plan

- [x] `pnpm run test tests/template/methods/fromDockerfile.test.ts` (JS)
- [x] `poetry run pytest
tests/{async,sync}/template_*/methods/test_from_dockerfile.py` (Python)
- [x] `pnpm run format` / `pnpm run lint`

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
2026-05-27 22:57:03 +02:00
Jakub Novak e2a660c3ee [skip ci] Release new versions 2026-05-27 12:20:55 +00:00
Jakub Novák 18a10afa87 chore(js): add max concurrency limits (#1351)
Set limit for max concurrent inflight connection, with burst traffic it
could happen that the number of connection overwhelms the underlaying
infrastructure or at least saturate it to the point each request is too
slow to succeed and blocking the rest
2026-05-27 04:17:40 -07:00
github-actions[bot] d39f17e123 [skip ci] Release new versions 2026-05-27 00:24:30 +00:00
Mish Ushakov c485bf5476 feat(sdk): add Sandbox.updateNetwork / update_network (#1337) 2026-05-26 17:12:29 -07:00
Mish Ushakov 3786f34336 feat(sdk): support structured network rules with per-host transforms (#1286) 2026-05-26 16:35:21 -07:00
Mish Ushakov ba315c0795 feat(js-sdk): support AbortSignal for Template operations (#1339)
## Summary

- Extends AbortSignal support (introduced for Sandbox in #1328) to
`Template.build`, `buildInBackground`, `getBuildStatus`, `exists`,
`assignTags`, `removeTags`, and `getTags`. Aborting the signal cancels
in-flight requests and, for `Template.build`, the status-polling loop.
- Refactors signal+timeout plumbing: `ConnectionConfig` now stores
`signal`, and `ApiClient` / `VolumeApiClient` auto-apply it (plus
`requestTimeoutMs`) to every request via a custom fetch wrapper. The 22
explicit \`signal: config.getSignal(...)\` lines across sandboxApi.ts
and volume/index.ts are dropped.
- Volume's \`FILE_TIMEOUT_MS\` overrides move one level up into the
\`VolumeConnectionConfig\` constructor. Dead
\`VolumeConnectionConfig.getSignal()\` removed.

## Test plan

- [x] \`pnpm run typecheck\` / \`lint\` / \`format\`
- [x] New \`tests/template/abortSignal.test.ts\` covering all 8 Template
entry points (MSW-based)
- [x] Existing \`tests/sandbox/abortSignal.test.ts\`,
\`tests/template/uploadFile.test.ts\`,
\`tests/connectionConfig.test.ts\` still pass

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
2026-05-26 23:21:31 +02:00
Matt Brockman 3ea4ef597b js uses the stable sandbox host url with headers (#1342)
improved h2 perf for envd execution by using stable `sandbox.e2b.app`
with headers (aside from upload/download reqs)

can change number of connections via `E2B_ENVD_RPC_CONNECTIONS` env var

| Total | SDK | Created | Executed | Exec wall | Exec p50 | Exec p90 |
Exec p95 | Exec p99 | Peak exec conns | Peak exec hosts | Errors |
|---:|---|---:|---:|---:|---:|---:|---:|---:|---:|---:|---|
| 750 | old per-sandbox host | 750/750 | 749/750 | 9.792s | 4489ms |
8682ms | 9213ms | 9631ms | 752 | 750 | 1x `fetch failed` |
| 750 | updated stable host | 750/750 | 750/750 | 0.840s | 595ms | 752ms
| 783ms | 794ms | 102 | 1 | 0 |
| 1500 | old per-sandbox host | 1500/1500 | 837/1500 | 10.783s | 5200ms
| 9633ms | 10199ms | 10603ms | 1502 | 1500 | 663x `fetch failed` |
| 1500 | updated stable host | 1500/1500 | 1500/1500 | 1.236s | 775ms |
1085ms | 1124ms | 1149ms | 102 | 1 | 0 |

---------

Co-authored-by: Jakub Novák <jakub@e2b.dev>
2026-05-26 06:48:46 -07:00
github-actions[bot] 43c4524293 [skip ci] Release new versions 2026-05-22 19:46:53 +00:00
Jakub Novák 8640378c17 feat(python-sdk): allow opting out of HTTP/2 in get_transport (#1347) 2026-05-22 12:40:00 -07:00
Mish Ushakov a9bb287fc1 fix(python-sdk): close gRPC streams on watcher/command teardown (#1346)
## Summary
- `AsyncWatchHandle.stop()` and `AsyncCommandHandle.disconnect()`
previously only cancelled the consumer task and left the underlying
server-streaming gRPC call open — the `await self._events.aclose()` was
commented out as a Python 3.8 `RuntimeError` workaround. On long-lived
sandboxes this leaks one stream per call and eventually produces
`Code.internal: error creating watcher: too many open files`.
- The SDK now pins `python = "^3.10"`, so the workaround is removed.
`stop()`/`disconnect()` cancel the consumer task, await it, then
`aclose()` the async generator. The JS SDK already aborts the underlying
request via `AbortController`, so no JS change is needed.

## Test plan
- [ ] CI: `pnpm run format`, `pnpm run lint`, `pnpm run typecheck`
(passed locally)
- [ ] CI: `tests/async/sandbox_async/files/test_watch.py` and async
command tests still pass
- [ ] Reproduce the leak: in a long-lived async sandbox, repeatedly
create+stop a watcher and confirm fd count no longer climbs

🤖 Generated with [Claude Code](https://claude.com/claude-code)
2026-05-22 20:51:21 +02:00
Mish Ushakov 6d66d159d1 fix(cli): handle missing xdg-open on headless machines during login (#1345)
## Summary
- `e2b auth login` previously crashed on headless machines (no
`xdg-open`) with an unhandled `error` event from the spawned browser
process.
- Attach an `error` listener (and `.catch`) to the `open` call; on
failure, print the login URL so the user can open it manually.
- Added a changeset for `@e2b/cli` (patch).

## Test plan
- [ ] On a headless Linux box without `xdg-open`, run `e2b auth login`
and confirm the CLI prints the manual URL instead of crashing.
- [ ] On macOS/Linux with a desktop, confirm the browser still opens
automatically and login completes.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
2026-05-22 20:37:24 +02:00
github-actions[bot] 74c42b15ee [skip ci] Release new versions 2026-05-22 15:53:30 +00:00
Jakub Novák 2680c89c3e Remove Sandbox.betaCreate / beta_create (#1344)
It didn't have any extra functionality
2026-05-22 16:36:29 +02:00
github-actions[bot] 9b0c25f8ae [skip ci] Release new versions 2026-05-22 09:48:05 +00:00
Tomas Valenta d21b936bf7 fix(sdks): make lifecycle.on_timeout and auto_pause precedence consistent (#1343)
## Summary

When `lifecycle.on_timeout` is set it wins; otherwise we fall back to
the `auto_pause` argument.

Previously the Python SDKs subscripted `lifecycle["on_timeout"]`, which
raised `KeyError` if a caller passed a `lifecycle` dict missing that key
(TypedDict is not enforced at runtime). The JS SDK silently used the
whole `lifecycle` object even when `onTimeout` was undefined. In both
cases, mixing `lifecycle` and `auto_pause` had inconsistent and
surprising behavior across the public surfaces (`create` vs
`beta_create`).

Now both SDKs use `.get`/optional chaining on `on_timeout` and only
treat `lifecycle` as authoritative when that field is actually present.

Touched files:
- `packages/python-sdk/e2b/sandbox_async/sandbox_api.py`
- `packages/python-sdk/e2b/sandbox_sync/sandbox_api.py`
- `packages/js-sdk/src/sandbox/sandboxApi.ts`

---------

Co-authored-by: Jakub Novak <jakub@e2b.dev>
2026-05-22 02:28:18 -07:00
github-actions[bot] 2eaba1a7a8 [skip ci] Release new versions 2026-05-22 00:18:05 +00:00
Matt Brockman e10958d87e Js api http2 dispatcher (#1340)
use undici for the js api calls as well where we can; improved
connection use leads to speed improvement at high concurrency
2026-05-21 12:27:42 -07:00
github-actions[bot] 71f6719bf6 [skip ci] Release new versions 2026-05-18 12:30:54 +00:00
Mish Ushakov 2ac5de2edf feat(js-sdk): support AbortSignal for request cancellation (#1328) 2026-05-15 23:24:16 +02:00
github-actions[bot] 70f0d833f5 [skip ci] Release new versions 2026-05-14 17:36:14 +00:00
Mish Ushakov eaf452a82b feat: add optional name to createSnapshot and return snapshot names (#1327)
## Summary
- Add optional `name` parameter to `createSnapshot` / `create_snapshot`
in the JS and Python SDKs so callers can name the resulting snapshot
template.
- Return the `names` field from the snapshot API on `SnapshotInfo` (both
in `createSnapshot` responses and in `listSnapshots` paginator results)
so callers can discover the namespaced snapshot names.
- Includes a changeset (`patch` for `e2b` and `@e2b/python-sdk`).

## Test plan
- [ ] `pnpm run format`, `pnpm run lint`, `pnpm run typecheck` all pass
locally
- [ ] Integration tests on a sandbox with valid credentials:
`sandbox.createSnapshot({ name: 'my-snap' })` returns non-empty `names`

Resolves https://github.com/e2b-dev/E2B/issues/1249

---------

Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
2026-05-14 17:22:31 +00:00
github-actions[bot] 9e962ae555 [skip ci] Release new versions 2026-05-11 17:38:06 +00:00
Matt Brockman b2a2786707 Bug e2b 2195 throws dynamic usage of require is not eng 4003 (#1323)
Fix the JS SDK envd HTTP/2 transport so it works in Next.js/Turbopack production builds.
2026-05-11 10:04:19 -07:00
github-actions[bot] e3092d5719 [skip ci] Release new versions 2026-05-06 00:56:25 +00:00
Matt Brockman f7a97e698e enable http2 for js sdk envd rpc/api traffic (#1311)
Enables HTTP/2 for JS SDK sandbox envd traffic in Node by routing envd
RPC/API requests through undici with an HTTP/2-enabled dispatcher.

Non-Node runtimes continue to use global fetch. Management API and
volume clients are unchanged.

Requires bumping node from >=20 to >= 20.18.1 for undici
2026-05-05 17:24:16 -07:00
Matt Brockman 20ea715252 Enable HTTP/2 for Python SDK transports for sandbox/main api calls (#1310)
switches python sdk to use http2 for calls to main api + sandboxes

doesn't add it to volumes yet - need to test those separately
2026-05-05 17:23:46 -07:00
github-actions[bot] 76f5effde6 [skip ci] Release new versions 2026-04-30 18:04:41 +00:00
Mish Ushakov ae138767ac chore(js-sdk): add patch changeset for npm-check-updates removal (#1307)
## Summary

Adds a patch changeset for the `e2b` JS SDK to cover #1306 (commit
bd99b23c1), which removed the unused `npm-check-updates` devDependency
to clear the remaining `tar@6` Dependabot security alerts.

The original PR landed without a changeset, so the next release would
skip publishing the SDK despite the `package.json` change. This file
ensures the dependency cleanup gets a proper patch bump.

## Test plan

- [x] `.changeset/drop-npm-check-updates.md` follows the repo's existing
changeset format (frontmatter + summary line)
- [ ] Changesets bot picks up the entry on the PR

Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
2026-04-30 17:40:56 +00:00
github-actions[bot] 5ed9c32ea7 [skip ci] Release new versions 2026-04-30 15:15:40 +00:00
Mish Ushakov 55e9e0eb5a chore(deps): resolve Dependabot security alerts across npm and python (#1302)
## Summary

Resolves all 31 open [Dependabot
alerts](https://github.com/e2b-dev/e2b/security/dependabot) across the
workspace.

- **npm** — added range-based `pnpm.overrides` to bump vulnerable
transitive deps to their patched versions: postcss, vite, lodash,
brace-expansion, picomatch (2.x + 4.x), yaml, @tootallnate/once,
smol-toml, flatted, and minimatch (3.x/5.x/9.x/10.x).
- **python-sdk** — bumped dev deps in `poetry.lock`: pytest 7.4 → 9.0.3
(with constraint update in `pyproject.toml`), pytest-asyncio 0.23 → 1.3
(required for pytest 9), python-dotenv 1.2.2, pygments 2.20.0, requests
2.33.1, black 26.3.1; removed 4 now-unused `# ty: ignore` directives
that pytest 9's stricter type signatures made obsolete.

## Test plan

- [x] \`pnpm run typecheck\` passes
- [x] \`pnpm run lint\` passes
- [x] \`pnpm run format\` clean
- [x] CLI tests (80/80) and js-sdk/python-sdk unit tests pass;
integration tests not run locally (need \`E2B_API_KEY\`)

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
2026-04-30 14:45:19 +00:00
github-actions[bot] 3ff25f784e [skip ci] Release new versions 2026-04-27 21:27:14 +00:00
Mish Ushakov 2c995d4494 refactor(sdk): make octet-stream file upload opt-in via useOctetStream (#1296)
## Summary

- Adds an opt-in `useOctetStream` / `use_octet_stream` flag to sandbox
file write — JS on `FilesystemWriteOpts`, Python keyword on `write` /
`write_files` (async + sync).
- Changes the default upload path to `multipart/form-data` regardless of
envd version. Callers must opt in to `application/octet-stream`
(requires envd 0.5.7 or later).

## Example

JS:

```ts
// Default — multipart/form-data
await sandbox.files.write('hello.txt', 'world')

// Opt in to application/octet-stream (envd >= 0.5.7)
await sandbox.files.writeFiles(
  [{ path: 'a.txt', data: 'a' }, { path: 'b.txt', data: 'b' }],
  { useOctetStream: true },
)
```

Python:

```python
# Default — multipart/form-data
sandbox.files.write('hello.txt', 'world')

# Opt in to application/octet-stream (envd >= 0.5.7)
await sandbox.files.write_files(
    [{'path': 'a.txt', 'data': 'a'}, {'path': 'b.txt', 'data': 'b'}],
    use_octet_stream=True,
)
```

## Test plan

- [ ] JS: `pnpm --filter e2b run lint && pnpm --filter e2b run
typecheck`
- [ ] Python: `cd packages/python-sdk && poetry run make lint && poetry
run make typecheck`
- [ ] Manual write with and without `useOctetStream` /
`use_octet_stream` against envd 0.5.7+.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
2026-04-27 21:16:33 +00:00
github-actions[bot] 557b723cc1 [skip ci] Release new versions 2026-04-24 18:35:47 +00:00
Mish Ushakov 3167e19b4f fix(sdk): buffer template upload to set Content-Length, add regression tests (#1294)
## Summary
Consolidates the fix and tests from #1285 and #1293 into a single PR.

- **js-sdk**: `uploadFile` used to pass a Node `Readable` directly to
`fetch`, causing undici to fall back to `Transfer-Encoding: chunked`. S3
presigned PUT URLs reject chunked with 501 NotImplemented. Fix buffers
the archive first so `Content-Length` is set. Includes:
- Regression test that spins up a local HTTP server and asserts
`Content-Length` is set and matches the body, and `Transfer-Encoding` is
not chunked.
- Type-fix for the CLI's typecheck (cast `Pack` →
`AsyncIterable<Buffer>`).
- Dynamic import of `node:stream/consumers` so the browser bundle
doesn't pull it in.
- **python-sdk**: Adds sync + async regression tests for `upload_file`
that guard against the same class of bug (someone swapping
`tar_buffer.getvalue()` for a stream/generator). No Python code change —
the current implementation already passes bytes to `httpx.put(...,
content=...)`.

Authorship of the original JS fix commit preserved (truffle-dev).

Closes #1243.

## Test plan
- [x] `pnpm run test tests/template/uploadFile.test.ts` — passes
- [x] `pnpm run typecheck` / `lint` clean across js-sdk and cli
- [x] `poetry run pytest tests/sync/template_sync/test_upload_file.py
tests/async/template_async/test_upload_file.py -v` — both pass
- [x] `poetry run make format` / `make lint` / `make typecheck` clean

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: truffle <truffleagent@gmail.com>
Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
2026-04-24 07:14:54 -07:00
Matt Brockman a6a1156a76 fix: cli info handles not found without showing error message (#1247)
Handles sandbox not found on cli info
2026-04-21 08:33:07 -07:00
Kagura 2f0ff5f0f7 fix(sdk): prevent shell injection in MCP config via proper escaping (#1276)
## Summary

Fixes #1154

When creating a sandbox with an `mcp` config, the JSON-serialized config
is interpolated directly into a shell command wrapped in single quotes.
Since `json.dumps()` / `JSON.stringify()` do not escape single quotes,
any MCP config value containing a single quote (e.g., API keys, tokens,
URLs) breaks out of shell quoting and allows arbitrary command execution
inside the sandbox.

## Changes

### Python SDK (`sandbox_async/main.py`, `sandbox_sync/main.py`)
- Use `shlex.quote()` to properly escape the JSON config string (4
locations)
- `shlex.quote()` is a stdlib function designed exactly for this purpose

### JS/TS SDK (`sandbox/index.ts`)
- Add a `shellQuote()` helper that escapes single quotes using the
standard `'\'''` pattern (equivalent to Python's `shlex.quote()`)
- Apply it to both MCP config interpolation sites (2 locations)

## Before / After

**Before** (vulnerable):
```
mcp-gateway --config '{"servers": {"test": {"envs": {"KEY": "it's a value"}}}}'
#                                                            ^^ breaks out
```

**After** (safe):
```
mcp-gateway --config '{"servers": {"test": {"envs": {"KEY": "it'\''s a value"}}}}'
#                                                            ^^^^ properly escaped
```

## Testing

Verified escaping behavior for both Python (`shlex.quote`) and JS
(`shellQuote`) with the PoC from the issue — single quotes in config
values are properly escaped and no longer allow shell breakout.

---------

Co-authored-by: Mish Ushakov <10400064+mishushakov@users.noreply.github.com>
Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
2026-04-21 07:30:14 -07:00
Mish Ushakov 4065ecd68c feat: allow passing template as option in Sandbox.create() (#1267)
## Summary
- Adds `template` as an optional property on `SandboxOpts` in the JS
SDK, enabling `Sandbox.create({ template: 'my-template' })` syntax
- Updates both `create` and `betaCreate` to check `opts.template` before
falling back to the default template
- Python SDK already supports `Sandbox.create(template='template')` via
named parameters, so no changes needed there

## Test plan
- [ ] Verify `Sandbox.create({ template: 'base' })` works
- [ ] Verify `Sandbox.create('base')` still works (backwards compatible)
- [ ] Verify `Sandbox.create()` still defaults to `'base'`
- [ ] Verify MCP template fallback still works when no template is
specified

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-17 13:18:11 +00:00
Berry f667f335c6 fix: correct write_files docstring about directory auto-creation (#1260)
## Summary
- Fixes the Python SDK `write_files` docstring (both sync and async)
which incorrectly stated that writing to a non-existing directory would
produce an error
- The backend actually auto-creates parent directories, consistent with
the `write()` docstring and existing tests
(`test_write_to_non_existing_directory`)

## Test plan
- [x] Verified behavior with a test script — both `write()` and
`write_files()` auto-create nested directories
- [x] Existing tests pass (`test_write_to_non_existing_directory`,
`writeFiles creates parent directories`)
2026-04-12 15:51:41 +02:00
devin-ai-integration[bot] fcb95c34e2 cli: replace sandbox.kill() with setTimeout(1s) in create command to prevent snapshot deletions (#1256)
## Summary

In the CLI's `sandbox create` command, the `connectSandbox` function's
`finally` block previously called `sandbox.kill()` when the terminal
session ended. This replaces it with `sandbox.setTimeout(1_000)` so the
sandbox expires implicitly after 1 second rather than being explicitly
killed.

The motivation is that an explicit `kill()` can trigger deletion of
historic sandbox snapshots, whereas letting the sandbox time out avoids
that side effect.

### Updates since last revision

Addressed review feedback about a race condition: `clearInterval` stops
future keep-alive ticks but cannot cancel one already in-flight. The
keep-alive callback now stores its promise in a `pendingKeepAlive`
variable, and the `finally` block awaits it (with `.catch(() => {})`)
before setting the 1s shutdown timeout. This ensures an in-flight
`setTimeout(30_000)` cannot silently override the shutdown timeout.

## Review & Testing Checklist for Human

- [ ] **Verify that `sandbox.setTimeout(1_000)` does not trigger
snapshot deletion** — this is the core assumption behind the change.
Confirm that the implicit expiry path in the backend behaves differently
from the explicit `kill()` path with respect to snapshot preservation.
- [ ] **Test `e2b sandbox create` end-to-end**: connect a terminal,
exit, and confirm the sandbox is cleaned up within a few seconds and no
snapshots are lost.
- [ ] **Review the race condition fix**: confirm that `await
pendingKeepAlive.catch(() => {})` correctly serializes against the last
in-flight keep-alive before the 1s timeout is applied. Note that the
interval callback is no longer `async` — it just assigns the promise.
- [ ] **Edge case: what happens if `setTimeout` fails?** The sandbox
would remain alive with its previous 30s keep-alive timeout. Decide if
that's acceptable or if a fallback is needed.

### Notes
- The 1-second timeout value was chosen per the request. Adjust if a
different grace period is preferred.
- The keep-alive interval (`clearInterval`) is still stopped before
awaiting the pending promise, so no new ticks will fire.

Link to Devin session:
https://app.devin.ai/sessions/68081ba06fa54be9b8127ba1d68481ae

---------

Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: ben@e2b.dev <ben@e2b.dev>
2026-04-04 01:27:28 +02:00
Mish Ushakov b5f2631141 feat: add gzip content encoding option for file operations (#1252)
## Summary

- Adds optional `gzip` parameter to sandbox file read/write operations
across JS and Python SDKs
- Uploads are gzip-compressed via `CompressionStream` (JS) /
`gzip.compress` (Python) when enabled, downloads request
`Accept-Encoding: gzip`
- Only applies to the octet-stream upload path (envd >= 0.5.7), so older
envd versions are unaffected
- Includes tests for both SDKs covering write+read with gzip, write gzip
+ read plain, multi-file writes, and byte format reads

## Test plan

- [ ] Run JS SDK content encoding tests (`contentEncoding.test.ts`)
- [ ] Run Python async/sync content encoding tests
(`test_content_encoding.py`)
- [ ] Integration test with envd backend supporting `Content-Encoding:
gzip`

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-03 10:17:53 +00:00