[codex] add native file-generation runtime - #64
Conversation
VPS test deployment evidence (2026-08-27)Deployed the reviewed candidate to the WowLoop test VPS after the test-credential exposure was explicitly accepted for this environment only. Revisions and runtime
Deployed first-party image IDs
Verification
Remaining gateThe exact browser Chat XLSX prompt was submitted with Run Code enabled, but the test account returned This is test deployment evidence only. Production remains NOT READY: KVM isolation is unavailable on this VPS, the manual provider-backed Chat XLSX gate is pending, human approval is still required, and existing image-security findings must be resolved or explicitly accepted through the production release process. |
What
/pkgsbundle with Python, Node.js, npm, Bun, LibreOffice, FFmpeg, Poppler, and WeasyPrint support.tar,brace-expansion, andip-address) and patched Python security baselines; remove pip's build-only vendored SBOM before runtime scanning.Why
WowLoop needs Code Interpreter to return real downloadable files rather than HTML, Markdown, JSON, or plain text renamed with native extensions.
Test
bun ci && bun run buildenv -u ANTHROPIC_AUTH_TOKEN bun run test- 370 passed, 0 failedtests/sandbox_runner_healthcheck.shtests/file_generation_runtime_static.shtests/block_root_package_delivery.shbash -n build-packages.sh docker/package-init.shpython3 -m py_compile scripts/verify-file-generation-runtime.pydocker buildx build --check -f api/Dockerfile .docker buildx build --check -f docker/Dockerfile.worker-sandbox .sandbox-runner-trueandsandbox-runner-falseafter rebasing onto297feadd885ebbfb33de87386baf2b79da73da6b705564776509ce250ef9fddfd0c126bacross restartgit diff --checkand secret-pattern scan passedRisk
Deployment
Not deployed. Keep this PR in draft until the coordinated WowLoop deployment PR and all VPS/manual gates are reviewed.
Related