Skip to content

Feature/file upload - #1

Merged
m-messer merged 8 commits into
mainfrom
feature/file_upload
Sep 24, 2026
Merged

m-messer merged 8 commits into
mainfrom
feature/file_upload

Conversation

@m-messer

Copy link
Copy Markdown
Member

No description provided.

m-messer and others added 8 commits August 13, 2026 10:41
Implements `params["files"]` feature to allow downloading S3 objects into a per-request working directory. Updates `evaluation.py` and security logic to enable read-only file access. Introduces `s3_files.py` for managing S3 interactions and accompanying unit tests in `s3_files_test.py`. Expands documentation in `CLAUDE.md` and adds integration tests to verify functionality.
Replaces S3 bucket-based file download logic with direct downloads via HTTPS URLs, removing AWS dependency. Updates `evaluation.py`, rewrites `s3_files.py` to handle streaming downloads securely, and adjusts tests and documentation (`CLAUDE.md`, `evaluation_test.py`, `s3_files_test.py`) to reflect the changes.
Switches from a version-specific base image to the `latest` tag for the evaluation function, ensuring up-to-date dependencies and compatibility.
…ove validation

Standardizes file specification by replacing the `filename` key with `name`. Enhances validation to handle malformed or incomplete file specifications gracefully. Adds error handling to catch unexpected exceptions and ensures temporary directories are cleaned up. Updates tests and documentation to reflect changes.
…["files"]`

Adds `_resolve_submission` to handle responses containing code and file specifications in `"code"` and `"files"` keys. Updates `evaluation.py` to normalize and prioritize file sources from the response payload over `params["files"]`. Enhances tests to validate this logic. Updates documentation to reflect the new behavior.
Reconcile the file-upload feature with main's security refactor, GCS plot
backend, and nsjail sandboxing.

- evaluation.py / preview.py: use the shared check_code_safety() from the
  new security.py; evaluation_function runs it as a pre-execution gate on
  the resolved student code (post _resolve_submission).
- security.py: keep `open` and `pathlib` allowed (main's version blocked
  them) — student code needs them to read files from params["files"] / the
  response payload; runtime _safe_open still blocks writes into the files
  dir. security_test.py updated to match.
- Dockerfile: take main's python:3.12 base (bundles shimmy + nsjail).
- CLAUDE.md: merged pipeline/env docs.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VSE4TC3eTVreuQhADdtDaj
…d submissions

Refactors `_resolve_submission` into `_unwrap_payload` and updates answer handling to support the `{"code", "files"}` structure. Adds unit tests for evaluation behavior with structured answers.
…les` handling

Replaces `_resolve_submission` and `_unwrap_payload` with `_collect_file_specs` to streamline file normalization and prioritization. Updates test suite to validate the new logic and modifies documentation to reflect the updated file specification and submission flow.
@m-messer
m-messer merged commit 580083e into main Sep 24, 2026
10 checks passed
m-messer added a commit that referenced this pull request Sep 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant