Skip to content

feat(builtins): make, a GNU make subset run in the sandbox shell - #2551

Open
chaliy wants to merge 4 commits into
mainfrom
claude/fidelity-make
Open

chaliy wants to merge 4 commits into
mainfrom
claude/fidelity-make

Conversation

@chaliy

@chaliy chaliy commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Requested by Михайло · project thread

What changed

New make builtin: a GNU make 4.3 subset that runs entirely inside the sandbox.

  • Makefile language: all assignment flavors (=, :=, ::=, ?=, +=, !=, override, export), conditionals, define, include/-include, explicit, pattern, static-pattern and old-style suffix rules, target-specific variables, order-only prerequisites, special targets (.PHONY, .SILENT, .IGNORE, .ONESHELL, .EXPORT_ALL_VARIABLES, .DEFAULT_GOAL).
  • Functions: text, file-name, conditional, foreach, call, value, origin, flavor, error/warning/info, wildcard, shell.
  • Options: -f -C -n -k -q -s -i -B -e -j (sequential), VAR=value, MAKEFLAGS, recursive $(MAKE).
  • Recipes run as sh -c LINE through the interpreter (budget, limits, VFS). Two new driver steps: PlanStep::Capture for $(shell) and PlanStep::Emit so make's own messages stay in order with recipe output and respect redirects.
  • Messages and exit codes follow GNU (*** No rule to make target, [Makefile:3: all] Error 1, -q exit 1).

Why

Step 4 of the fidelity roadmap: agents reach for make constantly, and Bashkit answered "build tools are not available".

Before

$ printf 'all: a\n\techo all\na:\n\techo A $(shell echo hi)\n' > Makefile; make
bash: make: command not found. Compilers and build tools are not available in the sandbox.

After

$ make | cat
echo A hi
A hi
echo all
all
$ make nope; echo $?
make: *** No rule to make target 'nope'.  Stop.
2

make.test.sh: 19 spec cases, each verified identical against real GNU make 4.3.

Risk

Medium-low: new builtin, opt-in by use. Driver loop change in the interpreter is additive (two new step kinds). Amplification caps documented as TM-DOS-126 (expansion depth 200 / 4 MiB, include depth 16, target/query/glob caps, MAKELEVEL 8). Gaps documented as L-MAKE-001..003 with evidence tests: no $(eval)/$(file), no built-in or chained implicit rules, no vpath, SHELL ignored, -j sequential.

Checklist

  • Spec cases first, differential against GNU make 4.3
  • Unit tests for parser and expander, limitation evidence tests
  • cargo fmt, cargo clippy -D warnings, lib + integration suites
  • just regen-builtins, knowledge (builtins, limitations, threat model, log), public docs

https://claude.ai/code/session_019aFikmptPc91Fj4N2iDXQA


Generated by Claude Code

@chaliy chaliy self-assigned this Oct 7, 2026
@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
bashkit 5acd569 Commit Preview URL

Branch Preview URL
Oct 07 2026, 09:46 AM

@chaliy
chaliy force-pushed the claude/fidelity-make branch 4 times, most recently from 8ca2c37 to 0269c92 Compare October 7, 2026 09:24
chaliy added 4 commits October 7, 2026 09:42
Driver-based make: parses makefiles (assignments, conditionals, define,
include, explicit/pattern/static/suffix rules, target-specific vars,
special targets), expands functions incl. $(shell)/$(wildcard), and runs
recipes as sh -c in the interpreter. New PlanStep::Capture/Emit keep
$(shell) output captured and make's messages ordered with recipe output.
Gaps L-MAKE-001..003, caps TM-DOS-126.

Claude-Session: https://claude.ai/code/session_019aFikmptPc91Fj4N2iDXQA
@chaliy
chaliy force-pushed the claude/fidelity-make branch from 0269c92 to 5acd569 Compare October 7, 2026 09:45

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant