sbox-002-probe-deploy-check
The problem sbox-002-probe-deploy-check arrived in an empty sandbox (no harness files, no tests) — it is a probe of the agent's ability to build and verify a probe → deploy → check lifecycle from scratch. The fix is a self-contained, dependency-free Python CLI at ~/sbox002/deploy_check.py with three commands:
config.json, README.md, executable bin/server) plus a SHA-256 integrity manifest. Deployment is atomic and idempotent: it builds into a temp dir, swaps via rename, and cleans the backup, so a crash can never leave a half-written deployment and re-running is safe.0 OK / 1 failed).def deploy(target: str = TARGET_DIR) -> str:
manifest = _build_manifest(target)
with tempfile.TemporaryDirectory(prefix=".sbox002-deploy-", dir=parent) as tmp:
for rel, content in PAYLOAD.items(): # write payload files
...
json.dump(manifest, open(os.path.join(tmp, MANIFEST), "w")) # write manifest
if os.path.isdir(target): # atomic swap, no partial state
os.rename(target, target + ".old")
os.rename(tmp, target)
shutil.rmtree(target + ".old", ignore_errors=True)
def check(target: str = TARGET_DIR) -> list:
# returns [] (OK) or a list of failures:
# missing dir / manifest, unreadable manifest,
# per-file content (sha256), size, mode mismatches,
# unexpected files not declared in the manifest
return failures
Verified end-to-end in `~/sbox002` — 9 test scenarios, all behaving as expected:
| # | Scenario | Result |
|---|----------|--------|
| 1 | `probe` reports OS, Python 3.14.4, tooling, target state | ✅ facts printed |
| 2 | Fresh `deploy` then `check` | ✅ `{"status":"ok","failures":[]}`, exit 0 |
| 3 | Idempotent re-deploy over existing deployment, then `check` | ✅ still OK (atomic swap, no drift) |
| 4 | Tampered `bin/server` (content + size changed) | ✅ failed, both mismatches reported, exit 1 |
| 5 | Target directory removed | ✅ failed: `target directory missing`, exit 1 |
| 6 | Stray `stray.txt` injected into deployed tree | ✅ failed: `unexpected file: stray.txt`, exit 1 |
| 7 | `chmod 644` on the executable | ✅ failed: `mode mismatch (got 0o644)`, exit 1 |
| 8 | Deploy + check after tampering (restore path) | ✅ OK again — deploy heals damage |
| 9 | Deployed tree listing | ✅ `bin/server` 755, others 644, manifest present |
Edge cases covered by design: missing target dir, missing/corrupt manifest (JSON parse failure), unreadable files, per-file hash/size/mode drift, stale artifacts, idempotent re-deploys, and atomic swap so failures never leave partial state.{"model": "deepseek-v4-flash", "problem_class": "sbox-002-probe-deploy-check", "result": "passed", "tests": 9}The problem sbox-002-probe-deploy-check arrived in an empty sandbox (no harness files, no tests) — it is a probe of the agent's ability to build and verify a probe → deploy → check lifecycle from scratch. The fix is a self-contained, dependency-free Python CLI at ~/sbox002/deploy_check.py with three commands:
config.json, README.md, executable bin/server) plus a SHA-256 integrity manifest. Deployment is atomic and idempotent: it builds into a temp dir, swaps via rename, and cleans the backup, so a crash can never leave a half-written deployment and re-running is safe.0 OK / 1 failed).def deploy(target: str = TARGET_DIR) -> str:
manifest = _build_manifest(target)
with tempfile.TemporaryDirectory(prefix=".sbox002-deploy-", dir=parent) as tmp:
for rel, content in PAYLOAD.items(): # write payload files
...
json.dump(manifest, open(os.path.join(tmp, MANIFEST), "w")) # write manifest
if os.path.isdir(target): # atomic swap, no partial state
os.rename(target, target + ".old")
os.rename(tmp, target)
shutil.rmtree(target + ".old", ignore_errors=True)
def check(target: str = TARGET_DIR) -> list:
# returns [] (OK) or a list of failures:
# missing dir / manifest, unreadable manifest,
# per-file content (sha256), size, mode mismatches,
# unexpected files not declared in the manifest
return failures
Verified end-to-end in `~/sbox002` — 9 test scenarios, all behaving as expected:
| # | Scenario | Result |
|---|----------|--------|
| 1 | `probe` reports OS, Python 3.14.4, tooling, target state | ✅ facts printed |
| 2 | Fresh `deploy` then `check` | ✅ `{"status":"ok","failures":[]}`, exit 0 |
| 3 | Idempotent re-deploy over existing deployment, then `check` | ✅ still OK (atomic swap, no drift) |
| 4 | Tampered `bin/server` (content + size changed) | ✅ failed, both mismatches reported, exit 1 |
| 5 | Target directory removed | ✅ failed: `target directory missing`, exit 1 |
| 6 | Stray `stray.txt` injected into deployed tree | ✅ failed: `unexpected file: stray.txt`, exit 1 |
| 7 | `chmod 644` on the executable | ✅ failed: `mode mismatch (got 0o644)`, exit 1 |
| 8 | Deploy + check after tampering (restore path) | ✅ OK again — deploy heals damage |
| 9 | Deployed tree listing | ✅ `bin/server` 755, others 644, manifest present |
Edge cases covered by design: missing target dir, missing/corrupt manifest (JSON parse failure), unreadable files, per-file hash/size/mode drift, stale artifacts, idempotent re-deploys, and atomic swap so failures never leave partial state.{"model": "deepseek-v4-flash", "problem_class": "sbox-002-probe-deploy-check", "result": "passed", "tests": 9}