Skip to content

Declare the Claude agent-host view and share the view loader - #355

Merged
SaladDay merged 2 commits into
feature/agent-outside-sandboxfrom
aos/view-claude
Oct 1, 2026
Merged

SaladDay merged 2 commits into
feature/agent-outside-sandboxfrom
aos/view-claude

Conversation

@SaladDay

@SaladDay SaladDay commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

The Claude Code adapter (claudesdk) declares its agent-host view. This is lane L5-claude, built on the Runtime–Harness View declaration merged in #350. The PR also adds the shared viewloader package that every dynamic Harness binary uses. No view is launched yet: the agent-host library (L5a) and the end-to-end qualification (L7) follow.

Shared loader (apps/daemon/internal/agent/viewloader)

viewloader.For(binaries...) reads the binaries' ELF headers and returns the view fragment that loads them only from the closure:

  • the interpreter's host directory as the lib closure mount;
  • the interpreter as an Exec overlay at its PT_INTERP path;
  • empty masks over /etc/ld.so.preload and /etc/ld.so.cache;
  • the LD_LIBRARY_PATH value.

If the binaries need different interpreters, or a library outside the interpreter's directory, For returns ErrUnsupportedOperation, and the adapter declares no view. The Harness onboarding Executables rule names it. The MiniMax lane adopts it next.

Claude view declaration

  • Closure: node (Node's directory), claude-sdk (the bundle root) and, for dynamic binaries, the viewloader fragment.
  • LocalExec: node, and the SDK's native claude. The bridge's runtime check now reports the native path relative to the bundle (native_path), so the daemon does not repeat Node's module resolution.
  • Shims: bash, rg and git, with no ps.
  • Mask: /etc/claude-code.
  • ForwardEnv: CLAUDECODE and GIT_EDITOR.
  • Proxy: ViewProxyEnv.

If building the view fails, discovery logs one line and leaves View nil.

Executor in a view

  • Launch: the bridge starts through ViewSession.Launch in the request's workspace.
  • Environment: closed.
    • PATH is the shim directory.
    • HOME, TMPDIR, CLAUDE_CONFIG_DIR and XDG_RUNTIME_DIR are in the Session home.
    • It sets the C2, C3, C4, C7, C9 and C13 settings, the telemetry-off flags, LD_LIBRARY_PATH, both cases of the proxy variables, and NO_PROXY=127.0.0.1,localhost.
  • Credential: provider rendering uses ANTHROPIC_API_KEY on every path. In a view that is the gateway placeholder. ANTHROPIC_AUTH_TOKEN is never rendered.
  • MCP: only from ViewSession.MCP, as gateway HTTP endpoints without a bearer token. A stdio binding returns ErrUnsupportedOperation. The bridge requires capability_root only for skills, so HTTP MCP works without it.
  • Session home: the only home operations are creating and checking config, home, tmp and xdg, through one os.Root. A link planted in the home fails preparation without being followed.
  • Rejected in a view: installed Capabilities and skills, network access other than enabled, and allowed-domain lists.

Checks

  • Tests: TestViewExecutorLaunchesAClosedGatewayEnvironment resolves the view through the registry. It checks the closed environment, the key variables and the planted-link refusal. TestForPresentsTheHostLoader covers viewloader.
  • Go:
    • go test ./apps/daemon/internal/agent/...;
    • -race on claudesdk and viewloader;
    • go vet ./apps/daemon/...;
    • gofmt;
    • darwin and windows builds.
  • Bridge: pnpm run typecheck and pnpm test (170 passed).

L7 qualification items are recorded separately. Among them: dlopen'd NSS, locale and gconv modules; /bin/sh from Node spawns; and presenting an empty /etc/ld.so.preload when the sandbox has none.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

The Claude SDK adapter declares its agent-host View from the probed install: node, the bridge bundle and the SDK's native claude as the closure, with their shared ELF loader and library directory when they are dynamic. The view Executor builds the workspace profile per Session from the request, lays out {config,home,tmp,xdg} in the Session home through one os.Root, sets a closed environment pointed at the gateway, takes MCP only from the Session and launches through ViewSession.Launch.

The runtime check reports the native binary's bundle-relative path, and the bridge requires capability_root only for skills. Provider credentials render as ANTHROPIC_API_KEY on every path.
@SaladDay
SaladDay merged commit 1884170 into feature/agent-outside-sandbox Oct 1, 2026
1 check passed
viewloader.For reads the closure binaries' ELF headers and returns what a view adds for them: the interpreter's host directory as the lib closure mount, the interpreter overlay, empty masks over /etc/ld.so.preload and /etc/ld.so.cache, and the LD_LIBRARY_PATH value. Layouts it cannot present, and hosts other than Linux, return ErrUnsupportedOperation. The Claude SDK view now uses it.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant