Skip to content

feat: add local and cloud Smol microVM code executor - #7493

Open
BinSquare wants to merge 2 commits into
google:mainfrom
BinSquare:binsquare/smol-code-executor
Open

BinSquare wants to merge 2 commits into
google:mainfrom
BinSquare:binsquare/smol-code-executor

Conversation

@BinSquare

@BinSquare BinSquare commented Oct 10, 2026 •

Copy link
Copy Markdown

Link to Issue or Description of Change

Problem: ADK agents need an isolated way to run model-generated Python on a developer's own machine or on hosted capacity without giving that code the agent host's credentials or network access.

Solution: Add an opt-in SmolCodeExecutor and google-adk[smol] extra. Each code block runs in a fresh Smol Machines microVM (local by default, or Smol Cloud with target="cloud"), receives validated input files, and has a bounded timeout. Guest networking is off by default. The executor deletes the VM after each run; Cloud VMs also have an expiry if the client exits unexpectedly. Document setup, usage, and stateless behavior in the code executor guide.

Testing Plan

Unit Tests:

  • Added 16 passing cases covering local and Cloud configuration, file uploads, path validation before provisioning, token redaction, timeouts, truncation, missing optional dependency, and cleanup on both successful and failed execution.
  • PYTHONPATH=src .venv/bin/pytest -q tests/unittests/code_executors/test_smol_code_executor.py: 16 passed.
  • Ruff, isort, pyink, pyproject-fmt, and focused mypy checks passed.
  • uv build --wheel passed; verified the built wheel contains the executor and both optional-extra dependency declarations.

Manual End-to-End (E2E) Tests:

  • With smolmachines installed, run SmolCodeExecutor(target="local") and SmolCodeExecutor(target="cloud") with CodeExecutionInput(code="print('ready')"); both returned exit code 0 and ready in live VMs.
  • Uploaded a text input file on both transports; Python read its contents and returned the expected result. An uncaught Python exception produced a nonzero exit and traceback. A loop hit the configured timeout.
  • Tested both transports with a host OPENAI_API_KEY set: guest code saw no key, and an attempted outbound TCP connection failed with the default guest networking setting.

Checklist

  • Read the contributing guide and reviewed the change.
  • Added unit tests and documentation.
  • Manually validated local and Cloud VMs.
  • No unpublished dependent changes are required.

Additional context

This executor is stateless by design: it starts with a clean filesystem for every code block. Local runs require KVM or macOS Hypervisor.framework; the SDK's published wheels support Linux and macOS. Cloud runs require a Smol Cloud token or an existing Smol CLI login.

@google-cla

google-cla Bot commented Oct 10, 2026

Copy link
Copy Markdown

Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

View this failed invocation of the CLA check for more information.

For the most up to date status, view the checks section at the bottom of the pull request.

@BinSquare
BinSquare force-pushed the binsquare/smol-code-executor branch from da241f7 to 66acc8a Compare October 10, 2026 22:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants