Skip to content

Ship a zero-node Core installer with opt-in local sandboxes - #48

Merged
SaladDay merged 19 commits into
mainfrom
codex/landing-mx1-validation
Sep 23, 2026
Merged

SaladDay merged 19 commits into
mainfrom
codex/landing-mx1-validation

Conversation

@SaladDay

@SaladDay SaladDay commented Sep 23, 2026 •

Copy link
Copy Markdown
Collaborator

Install Core, the existing Web console and PostgreSQL with zero execution nodes by default. Local sandbox provisioning is explicit:

./install.sh
./install.sh --sandbox-provider true --provider microsandbox
./install.sh --sandbox-provider true --provider docker

Default Core receives no Docker socket, host devices or managed-provider configuration, and installation imports no Runtime or invokes a model. Core-only and Web-only modes remain available. Repeat installation preserves identities, secrets and data; automatic revision/provider migration is excluded.

The matched distribution contains immutable service/Runtime images, source provenance and checksums, a public landing page, and deployment/API/operations docs. A standalone server-side console proxy keeps the Core caller key out of browser assets. Optional microsandbox runs Core as a native user service to preserve compute during a Core restart. Its SDK-owned /environment disk supports workspace export and native full checkpoint recovery. The build entrypoint normalizes payload permissions for non-root services even when invoked with umask 077.

Validation

Candidate a5b4d140f5dd3ee6315baa5a90e6700882c73562, based on main e4b124c:

  • Full make check on zju with a dedicated PostgreSQL database passed, including 94/94 browser checks; 33 installer tests and 5 manifest tests passed.
  • Exact archive built, freshly extracted and checksum/provenance verified on mx1 Linux amd64/KVM. Default Core/Web/database installation passed 45 initial and 25 stop/restart checks, retaining zero Sessions/nodes and no execution authority.
  • Docker Core-only + Web-only installation/repeat/authentication checks passed. Codex, Claude Code and MiniMax Code each passed real Kimi execution, Files/Artifact byte checks, Core restart continuation and cancellation: 9/9.
  • Explicit microsandbox passed the same three-harness 9/9 real matrix, unchanged native process identity across Core restart, 73 tenant/secret checks and Artifact deduplication. Final Codex additionally passed default 300-second idle full checkpoint and real resume, preserving history/files/memory with no duplicate execution or cancelled-command replay. The preceding storage-qualified candidate also passed idle recovery for all three harnesses; those earlier results retain their separate revision.
  • Independent Astra high full-diff review and follow-up review passed. The reproduced umask issue was corrected in the shipped entrypoint. Private launcher/probe mistakes remain in acceptance evidence and did not require production workarounds.

Archive SHA256: 88172cde7f35f6cc56cdc89992e5b7b31838eb2fa5d5b73f0478af60e04c6032.

Evidence: ~/.parsar/acceptance/landing-mx1-zero/ on mx1 and the operator workstation; build and full-gate evidence under ~/.parsar/acceptance/landing-mx1-build-release/ and landing-mx1-check/ on zju. Test Sessions/Runtime resources are released through the public API; the default zero-node deployment is retained for inspection.

Boundaries

Linux amd64 is qualified. Microsandbox requires host KVM access and user-service lingering; host reboot/cold recovery and automatic upgrades/provider migration are not qualified. No Web application redesign, future node enrollment, PR #30, advanced Templates or new public protocol behavior is included. This is installer acceptance, not a claim of complete Agents API compatibility.

@SaladDay
SaladDay marked this pull request as ready for review September 23, 2026 11:09
@SaladDay
SaladDay merged commit 28ffd49 into main Sep 23, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant