Skip to content

Add the oac-sandbox-io binary - #345

Merged
SaladDay merged 1 commit into
feature/agent-outside-sandboxfrom
aos/sandbox-io-binary
Oct 1, 2026
Merged

SaladDay merged 1 commit into
feature/agent-outside-sandboxfrom
aos/sandbox-io-binary

Conversation

@SaladDay

@SaladDay SaladDay commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

Adds oac-sandbox-io, the Sandbox I/O service: the one process a Sandbox Provider starts in a sandbox. It reads the bootstrap file, connects to the relay as the Link serve peer, and serves the File and Process protocols on the streams the relay binds. It is wiring only.

  • apps/sandboxio/cmd/oac-sandbox-io (Linux). Startup runs in this order:
    • processservice.Init();
    • the strict --bootstrap-file flag, its only input;
    • PR_SET_CHILD_SUBREAPER;
    • one processservice.Reap, the process's only wait;
    • sandboxio.Run under a SIGTERM/SIGINT context.
  • apps/sandboxio/internal/sandboxio, Run(ctx, path):
    • decodes the bootstrap strictly;
    • serves the File export world at / and the Process service;
    • wires Link attachment lost, restored and closed into the Process service's ownership hooks;
    • fails startup with a typed *StartupError{Step, Err}, whose message never includes the credential;
    • logs a link drop once per transition.
  • processservice.Shutdown(ctx). On SIGTERM it cancels live operations as ownership cleanup does (TERM, then KILL after the grace limit) and waits for them to end.
  • Build. make build-sandbox-io builds a static Linux binary (CGO_ENABLED=0). It is not added to an image or a Provider yet.
  • CI planner. apps/sandboxio/ is classified as backend, so sandbox PRs no longer run the full gate as "Unclassified input".
  • Docs.
    • docs/sandbox-bootstrap.md: the launch command and a "Responsibilities and readiness" section.
    • docs/process-protocol.md: Shutdown.
    • docs/development.md: the repository-map row now names the binary and links the File and Process docs.
    • docs/sandbox-link-protocol.md: the cancel/write race residual that the File and Process docs already state.

The Network service is wired by the network protocol PR.

Test: an in-process end-to-end test runs run against the test relay with a temporary bootstrap file and a temp-dir root. It covers:

  • creating and reading a file in world;
  • sh -c 'echo hi; exit 7' giving hi, Exited 7 and OutputClosed;
  • shutdown killing a running process;
  • a restart seen as InstanceChanged;
  • a refused credential failing without exposing it.

Checks:

  • go test -race over apps/sandboxio/...
  • link, relay and bootstrap tests
  • vet and gofmt
  • CI planner tests, markdown link check, check-names
  • make build-sandbox-io produced a static ELF
  • manual run: usage, bad input, SIGTERM

Part of the agent-outside-sandbox work, milestone M1, lane L3b.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

@SaladDay
SaladDay merged commit b07d15e into feature/agent-outside-sandbox Oct 1, 2026
1 check passed
@SaladDay
SaladDay deleted the aos/sandbox-io-binary branch October 1, 2026 00:40
oac-sandbox-io reads the Provider's bootstrap file, becomes a child
subreaper running the one reap loop, and serves the File service (world at
/) and the Process service as the Link serve peer, with attachment loss,
restore and close wired to the process ownership hooks. SIGTERM stops
accepting streams and cancels live operations through the new
processservice Shutdown before exiting. Startup failures exit nonzero with
a typed step and never the credential.

Adds make build-sandbox-io (static Linux), runs apps/sandboxio in
check-go, routes apps/sandboxio changes to the backend CI job, and
documents the launch, responsibilities and readiness.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant