Add complete testing infrastructure that validates clients in:
1. CLI MODE: Test as standalone command-line tool
- Argument parsing (--help, --version)
- File execution (un.py code.py)
- Environment variables (-e VAR=val)
- Commands (execute, session, service)
2. LIBRARY MODE: Test as importable SDK
- Client object creation
- Method availability (execute, create_session)
- Authentication/HMAC generation
- Return types and data structures
3. INTEGRATION MODE: Test API contract validation
- Valid/invalid authentication (200/401)
- Language support verification
- Error handling (rate limits, timeouts)
- Artifacts and file operations
- Environment variable passing
4. FUNCTIONAL MODE: Real-world usage scenarios
- Fibonacci calculation
- Data analysis (pandas, etc.)
- Web requests (semitrusted mode)
- File I/O operations
- Subprocess handling
- JSON parsing
- Error handling
- Async/await code
Added:
- TEST-TEMPLATES.md: Complete test templates for Python, Go, JavaScript
(easily adaptable to all 42+ languages)
- Test structure examples for each mode
- Python pytest, Go testing, Jest patterns
- Integration patterns for API validation
- Functional test scenarios
- Enhanced Makefile with multi-mode targets:
- make test-python: All 4 modes for Python
- make test-python-cli: Only CLI mode
- make test-python-library: Only Library mode
- make test-all-cli: CLI for all languages
- make test-all: All modes for all languages
- make test-integration-all: Cross-language API validation
How it works:
- Each client implementation tests as CLI AND library
- Integration validates auth, error codes, API contract
- Functional tests prove real-world usage works
- Makefile targets guide developers to create per-language tests
- CI can run all 4 modes or specific modes on changes
Add comprehensive testing infrastructure for UN clients:
1. Smart Change Detection (detect-changes.sh)
- Detects changes in BOTH root-level (un.py, un.go) AND clients/ directory
- Maps file extensions and directory names to languages
- Triggers test_all when infrastructure changes
2. Language-Specific CI Matrix (generate-matrix.sh compatible)
- Only runs tests for languages with changes
- Example: modify clients/python/ → pytest runs, Go/Ruby skipped
3. Testing Strategy Document (TESTING-STRATEGY.md)
- Complete testing matrix by language tier (compiled, interpreted, inception)
- Unit, integration, embedding, and parity tests
- Inception pattern for languages without local interpreters
- Common failures and fixes
- Rollout schedule for client/ migration
4. Makefile Targets
- 'make test-python', 'make test-go', etc. for local development
- 'make test-all' for comprehensive testing
- 'make test-integration' for API contract validation
- 'make test-ci-locally' to simulate CI pipeline
5. Updated CLAUDE.md
- Documents SDK architecture (in growth state)
- Explains three purposes: CLI, library, embeddable
- References TESTING-STRATEGY.md for details
This enables:
✓ Per-language testing (only run what changed)
✓ Local developer workflow (make test-LANG)
✓ 42+ language feature parity validation
✓ Cross-language integration testing
- session_snapshot(session_id): Create snapshot of session state
- service_snapshot(service_id): Create snapshot of service state
- list_snapshots(): List all available snapshots
- restore_snapshot(snapshot_id): Restore from snapshot
- delete_snapshot(snapshot_id): Delete a snapshot
All snapshot functions added to:
- Module-level exports (Python __all__, JS module.exports)
- Client class methods (for ease of use with stored credentials)
- Full JSDoc/docstring documentation
Agents should now include snapshot functions in all SDK refactoring work.
- Implement detect-changes stage: identifies which SDKs changed
- Implement generate-matrix stage: creates dynamic test matrix based on changes
- Only test SDKs that changed (5x faster than testing all 42)
- Parallel test execution via GitLab matrix strategy
- Science jobs for pool burning: validate-examples, lint-all-sdks, benchmark-clients
- Zero cost execution: uses warm pool + idle capacity
- Comprehensive reporting with JUnit XML and markdown summaries
Pipeline flow:
detect-changes → generate-matrix → build → test (parallel) → science → report
The unfair advantage:
- GitLab sees changes, tests only what's needed
- GitHub shows traditional Actions (external view)
- Internal: 5x faster, $0 per execution
- External: looks normal (strategic asymmetry)
- test_sdk_library.py: Python test framework for validating library functions
- run_sdk_tests.sh: Master test runner for all language SDKs
- SDK_TESTING_GUIDE.md: Detailed guide on test structure and patterns
- AGENT_REFACTORING_INSTRUCTIONS.md: Step-by-step refactoring walkthrough
- REFACTORING_CHECKLIST.md: Comprehensive checklist for SDK refactoring
Agents can now validate their refactoring work independently with:
python3 tests/test_sdk_library.py --languages {language}
./tests/run_sdk_tests.sh --languages {language}
Framework tests:
- Unit tests: credential loading, HMAC signing, function signatures
- Integration tests: real API calls (requires UNSANDBOX_API_KEY)
- Functional tests: end-to-end CLI execution
This enables parallel refactoring with automatic validation.
Adds --resize ID --vcpu N flag to resize running services live.
PATCH /services/{id} with {"vcpu": 1-8} applies CPU/memory limits
without restart. Memory formula: 2GB per vCPU.
Implements encrypted vault for storing service environment variables:
- service env status <id> - Check vault status (GET /services/:id/env)
- service env set <id> -e KEY=VAL - Set vault contents (PUT /services/:id/env)
- service env export <id> - Export vault as .env format (POST /services/:id/env/export)
- service env delete <id> - Delete vault (DELETE /services/:id/env)
- Auto-vault on service creation with -e or --env-file flags
All implementations use HMAC-SHA256 authentication and text/plain content type
for vault PUT requests.
Matches un.c CLI behavior:
- If -s/--shell LANG is specified, treat argument as inline code
- If argument doesn't exist as a file, default to bash for inline execution
- Normal file execution unchanged
The validate_key function was calling /keys/validate without HMAC auth
headers (X-Timestamp, X-Signature), causing auth failures.
Also updated cmd_key to accept UNSANDBOX_PUBLIC_KEY as fallback.
In V strings:
- \$ produces a literal $ (correct for shell variables)
- $$ is interpreted as $ + $var causing undefined ident errors
Changed all shell variable references from $$ to \$ to properly
escape for shell command execution.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
- V: Rename result variables in cmd_key to avoid redefinition (xdg_result, mac_result, win_result)
- Crystal: Fix Bool | Nil type by explicitly checking stdout.nil? before string check
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
- Crystal: Wrap class variables in TestCounter class (top-level @@ not allowed)
- V: Fix deprecated const() syntax to individual const declarations
- V: Fix os.execute or-blocks to use exit_code checks
- V: Fix shell variable escaping (use $ for literal $ in shell strings)
- README: Add unit test documentation and CI badge
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
- Julia: Rename test() to run_test() to avoid name collision
- Julia: Use lambda syntax instead of do-block for cleaner execution
- Lua: Fix signature format test - verify structure instead of counting colons
- OCaml: Use apt-get instead of failing setup-ocaml@v2 action
- Clojure: Use 'clojure' instead of 'clj -M' for standalone script
- Dart: Add proper pubspec.yaml with SDK environment constraint
- Julia: Install SHA package before running tests
- Lua: Use lua5.4 explicitly, add awk for portable HMAC output parsing
- Perl: Install libjson-perl and libwww-perl dependencies
- Bash: Make un.sh executable before test
- OCaml: Add str.cma and unix.cma for Str module support
- OCaml unit test: Remove Str dependency with pure string search
Changed --restore to take snapshot ID directly and call /snapshots/:id/restore
instead of requiring --from SNAPSHOT_ID and calling /sessions/:id/restore or
/services/:id/restore.
Updated session and service restore in all implementations:
- un.py, un.go, un.rb, un.sh, un.ex, un.erl, un.fs, un.hs
- un.groovy, un.r, un.m, un.awk
Also added snapshot management features where missing.
Previously, invalid flags like --invalid-flag were silently ignored,
causing the CLI to make API requests that returned confusing
'timestamp expired' errors. Now prints 'Unknown option' and exits.
Fixed in 21 implementations: rb, pl, php, lua, sh, cpp, d, rs, zig,
v, kt, groovy, dart, cr, raku, ps1, m, nim, hs
All 38+ implementations now support:
- session -f FILE: Upload files to /tmp/ in session container
- service -f FILE: Upload files to /tmp/ in service container
- service --bootstrap-file FILE: Read bootstrap script from file
When timestamp auth fails (401 with timestamp in error), show helpful message:
- Error: Request timestamp expired (must be within 5 minutes of server time)
- Your computer's clock may have drifted.
- NTP sync commands for Linux/macOS/Windows
Updated: Un.cs, Un.java, un.clj, un.cob, un.erl, un.ex, un.f90, un.forth,
un.fs, un.hs, un.lisp, un.m, un.ml, un.pro, un.r, un.raku, un.scm, un.zig
All 42 implementations now have clock drift detection.
When timestamp auth fails (401 with timestamp in error), show helpful message:
- Error: Request timestamp expired (must be within 5 minutes of server time)
- Your computer's clock may have drifted.
- NTP sync commands for Linux/macOS/Windows
Updated: un.awk, un.cpp, un.cr, un.d, un.dart, un.groovy, un.jl, un.kt, un.nim, un.ps1, un.rs, un.tcl, un.ts, un.v
- Update all un.* implementations to use HMAC-SHA256 signing
- Headers: Authorization (Bearer public_key), X-Timestamp, X-Signature
- Signature: HMAC-SHA256(secret_key, "timestamp:METHOD:path:body")
- Fix test suite issues (bash arithmetic, ES module compat, TCL shebang)
- Add CLAUDE.md with inception testing documentation
- Update README.md with HMAC auth and dependency table
- All 38 implementations pass inception test via un2
- Validate API keys via portal endpoint
- Show key status, tier, expiration with color-coded output
- Add --extend flag to open browser for key renewal
- Update .gitignore for compiled binaries
- Update README with key command documentation
Support service_type for SRV records (minecraft, mumble, teamspeak, source, tcp, udp).
Each implementation now parses --type and sends service_type in the JSON payload.