Skip to content

fix(run): say how to build a missing sandbox image when nobody can be asked - #65

Merged
radim10 merged 3 commits into
masterfrom
fix/agent-run-missing-image-hint
Oct 9, 2026
Merged

radim10 merged 3 commits into
masterfrom
fix/agent-run-missing-image-hint

Conversation

@radim10

@radim10 radim10 commented Oct 9, 2026 •

Copy link
Copy Markdown
Member

Summary

  • Without a terminal, a Docker-backend run failed with only "its image was not built". The "build it now?" prompt can't be answered in CI, with piped stdin, or from a script over SSH. The run now fails straight away with the command that builds the image, as --silent already did.
  • The hint itself was wrong for the default image. It said docker build -t <tag> <Dockerfile>, but that Dockerfile is embedded in the binary. It now names stashbase agent docker build.
  • A custom Dockerfile gets docker build -t <tag> - < <path>. That builds from the Dockerfile alone, the same way the CLI does, so it also covers a per-run --docker-dockerfile. The path is shell-quoted when it has spaces or other special characters.
  • With a terminal, the prompt still appears. Answering "no" now also names the build command instead of ending with the bare "its image was not built".
  • docs/sandboxing.md says the prompt only appears in an interactive terminal and what a run without one prints instead.

Test plan

  • Unit tests: hint for the default image and for a custom Dockerfile (plain path, path with spaces, embedded '), the prompt decision (--silent, no stdin terminal, no stderr terminal), and the error text for the non-interactive and declined cases
  • cargo fmt --check and full cargo test pass
  • Checked by hand on a Linux VM: a run with stdin from /dev/null and an unbuilt custom Dockerfile printed the build command; running it as printed and retrying the run worked
  • Quoting checked in a real shell with a path containing a space and a '

… asked

Without a terminal (stdin piped, CI, a script over SSH) the "build the
image now?" prompt can't be answered, so a Docker-backend agent run
failed with only "its image was not built". It now fails straight away
with the command that builds it, as --silent already did. The hint
itself was wrong for the default image: it said
`docker build -t <tag> <Dockerfile>`, but that Dockerfile is embedded in
the binary, so it now names `stashbase agent docker build`. A custom
Dockerfile gets `docker build -t <tag> - < <path>`, which matches how the
CLI builds it and also covers a per-run --docker-dockerfile.
A custom Dockerfile path with a space or other shell-special character
(`/repo/my image/Dockerfile`) was printed bare, so the suggested
`docker build -t <tag> - < <path>` broke when pasted. It is now
single-quoted when needed, with embedded quotes escaped.

The decision whether to prompt (not --silent, stdin and stderr are
terminals) and the error text are now small functions with tests, so a
change that brings back a blocking prompt in CI fails a test.
@radim10 radim10 self-assigned this Oct 9, 2026
Answering "no" to "build the image now?" still ended with the bare
"its image was not built". It now names the same build command as the
non-interactive path. docs/sandboxing.md says the prompt only appears in
an interactive terminal and what a run without one prints instead.
@radim10
radim10 merged commit 125f420 into master Oct 9, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant