What's New
✨ Features
- Retrying pool acquire policies — Kotlin/Java sandbox pools now support
RETRY_NEXT_IDLEandRETRY_NEXT_IDLE_THEN_CREATE, allowing acquire to skip stale idle candidates before failing or falling back to direct create. Existing policies keep their current behavior;maxAcquireRetriesdefaults to 3. #1347 - Sandbox create metrics —
Sandbox.createnow reports fire-and-forgetsandbox.createlatency events to the lifecycle server. Reporting never blocks callers and can be disabled withOPENSANDBOX_DISABLE_METRICS=1ordisableMetrics. #1341 - Client IP header — the SDK now best-effort detects the host intranet IPv4 and sends it as
OPEN-SANDBOX-CLIENT-IPthrough the OkHttp transport. User-provided headers are never overwritten. #1326 - Attach to isolated sessions —
isolation.attach(sessionId)lets stateless workers rebuild a handle for an existing execd isolated session while that in-memory session is still alive. #1295 - UID mode availability — isolated session responses now expose per-mode
setpriv/usernsavailability, and unavailable requested modes fail with503 NOT_SUPPORTED. #1320 - Exact snapshot name filtering — snapshot listing now supports an exact
namefilter. #1301
🐛 Bug Fixes
- Serialization runtime isolation — SDK artifacts now shade
kotlinx.serializationinto the OpenSandbox namespace and remove it from published POM/BOM dependencies, avoiding runtime ABI conflicts when applications force older serialization runtimes. #1344 - Isolated UID/GID range fix — isolated session UID/GID fields now use a wider integer type so values in the execd
uint32range deserialize and serialize correctly aboveInt32.MAX_VALUE. #1298
📦 Misc
- Kotlin code-interpreter now lives under the sandbox Kotlin Gradle build while preserving the published
com.alibaba.opensandbox:code-interpreterartifact. The sandbox BOM manages sandbox and code-interpreter artifacts together. #1293 - Bumped Kotlin/Java SDK package versions and default User-Agent strings for this release. #1384