Skip to content

Python: Bound hosted harness file memory with quotas and retention #8900

Description

Problem

The hosted claw sample persists file memory under the current sandbox's $HOME. Trusted user/sandbox namespaces isolate access, but FileMemoryProvider.file_memory_write and FileSystemAgentFileStore do not enforce per-file byte limits, file-count limits, per-scope storage quotas, a shared-filesystem budget, or expiry/garbage collection. Repeated authorized writes can therefore exhaust persistent disk capacity and cause ENOSPC failures.

This was raised in the review of #8899: #8899 (comment) . The maintainer explicitly requested deferring the change from that PR and tracking it separately; do not disable or redesign the sample's file memory as part of that integration/isolation slice.

Scope

  • python/packages/core/agent_framework/_harness/: file-memory provider and filesystem-store boundaries.
  • python/samples/02-agents/harness/build_your_own_claw/claw_step04_production_ready/hosted.py and its README.
  • Consider externally backed file stores so the guarantees are explicit rather than assumed from the backend.

Acceptance criteria

  • Define enforceable limits for individual writes, file count, per-user/sandbox storage, and shared storage capacity where applicable.
  • Enforce limits before allocating/loading oversized payloads or committing writes, including concurrent writes; do not silently discard or truncate data.
  • Provide operator-controlled retention/expiry and a server-driven garbage-collection lifecycle for abandoned scopes.
  • Preserve trusted user/sandbox isolation and avoid exposing identity values or tokens in diagnostics.
  • Surface quota/retention failures clearly and document the intended hosted behavior and required backend/operator configuration.
  • Validate boundary limits, concurrent accounting, cross-scope isolation, expiry/cleanup and failure behavior without requiring live Azure resources.

Related: #8746 and #8899. No live hosted deployment or resource provisioning has been performed for this follow-up.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

pythonUsage: [Issues, PRs], Target: Python

Type

No type

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions