Skip to content

[code-documentation] Document the sandbox workload identity option - #247

Merged
Pedro Henrique Penna (ppenna) merged 1 commit into
devfrom
code-documentation/sandbox-workload-user-36526354851-7c8c9710a8207424
Sep 29, 2026
Merged

Pedro Henrique Penna (ppenna) merged 1 commit into
devfrom
code-documentation/sandbox-workload-user-36526354851-7c8c9710a8207424

Conversation

@ppenna

Copy link
Copy Markdown
Contributor

Summary

Documents the existing sandbox --workload-user UID:GID option in the command synopsis and option table, including its 65534:65534 default and its use by run and provision.

Evidence

The doc/usage.md ### sandbox section previously omitted this option from both the synopsis and table. scripts/nvx.py defines --workload-user as a fixed non-root workload identity, defaults it to 65534:65534, and applies it when constructing run or provision launches; python3 scripts/nvx.py sandbox --help confirms the same public CLI contract.

This does not duplicate the merged lifecycle documentation in #242 or the benchmark option documentation in #246. Searches for workload-user and sandbox identity documentation found no issue or active pull request tracking this omission. Active PRs #110 and #121 change other doc/usage.md sections; closed PR #222 concerned live virtio-fs mounts, and #229 tracks sandbox test coverage rather than this reference entry.

Scope

  • Changed doc/usage.md only.
  • Added 2 lines and deleted 0 lines (2 total changed lines).
  • Checked the changed command against scripts/nvx.py; no new path or link was added.

Validation

  • python3 scripts/nvx.py sandbox --help — passed; lists --workload-user UID:GID and default 65534:65534.
  • test -f doc/usage.md — passed.
  • grep -n -- '"--workload-user"' scripts/nvx.py — passed; found the parser definition.
  • git diff --check — passed.
  • git diff --numstat — 2 0 doc/usage.md.
  • git diff --raw — one regular Markdown file; no gitlink change.

No dependency, public API/CLI/ABI, gitlink, or OpenVMM change was made.

Generated by code-documentation · copilot · gpt56 · 105 AIC · ⌖ 13.4 AIC · ⊞ 16.3K · ◷

  • expires on Oct 13, 2026, 5:35 AM UTC

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings September 29, 2026 05:35

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The documentation accurately matches the parser default, validation, and runtime behavior.

Review effort: Balanced
Findings: None

What changed in this PR

Documents the existing sandbox workload identity option in the CLI reference.

Changes:

  • Adds --workload-user UID:GID to the sandbox synopsis.
  • Documents its default and applicable operations.
File Description
doc/​usage.md Documents the sandbox workload identity option.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@ppenna
Pedro Henrique Penna (ppenna) marked this pull request as ready for review September 29, 2026 14:27
@ppenna
Pedro Henrique Penna (ppenna) merged commit af7459c into dev Sep 29, 2026
38 checks passed
@ppenna
Pedro Henrique Penna (ppenna) deleted the code-documentation/sandbox-workload-user-36526354851-7c8c9710a8207424 branch September 29, 2026 14:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants