fix(eval): unblock Harbor startup with current policy and task user - #5267
Draft
Astro-Han wants to merge 3 commits into
Draft
fix(eval): unblock Harbor startup with current policy and task user#5267Astro-Han wants to merge 3 commits into
Astro-Han wants to merge 3 commits into
Conversation
Generated-by: Codex
Generated-by: Codex
Generated-by: Codex
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Harbor evaluation startup failed before model execution when the generated runtime policy was decoded as v2, when a task image used a non-root user, or when a connection relied on provider-default thinking.
Write the current v4 policy document, prepare relay logs and private environment files for the task's existing UID/GID, and allow thinkingLevel to be omitted. Explicit invalid thinking levels are rejected during configuration validation. The subject still runs as the task user; only directory and file ownership preparation uses root. Existing configurations with valid explicit thinking levels remain supported.
Verification
AI use
Tool(s) and scope: Codex investigated the startup failures, implemented these fixes, and ran regression and container checks.
Checklist
Does this PR entail a change in behavior?