Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 0 additions & 6 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion FEATURE_PARITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -747,7 +747,7 @@ CLAUDE.md for the full mapping + gap catalog.
| SSRF IPv6 transition bypass block | ✅ | ❌ | Block IPv4-mapped IPv6 bypasses |
| Cron webhook SSRF guard | ✅ | ❌ | SSRF checks on webhook delivery |
| Loopback-first | ✅ | 🚧 | HTTP binds 0.0.0.0 |
| Docker sandbox | ✅ | ✅ | Orchestrator/worker containers; opt-in `sandbox.docker.gpus` passthrough; Reborn process sandbox MVP adds typed `SandboxProcessPlan`, backend-neutral `ProcessSandboxBackend`, hardened Docker command construction, fail-closed unenforced network hosts, explicit timeout/cancel cleanup, loop-to-host `SandboxProcessPlan` validation/spawn dispatch, and a host-runtime approval/lease spawn path for `system.process_sandbox.run`; production MITM broker/product wiring still partial |
| Docker sandbox | ✅ | ❌ | Orchestrator/worker containers; opt-in `sandbox.docker.gpus` passthrough; Reborn defines a typed `SandboxProcessPlan` contract (`ironclaw_process_sandbox`) with plan validation only — no production execution backend is wired for it yet |
| Podman support | ✅ | ❌ | `--container` accepts both Docker + Podman |
| WASM sandbox | ❌ | ✅ | IronClaw innovation |
| Sandbox env sanitization | ✅ | 🚧 | Shell tool scrubs env vars (secret detection); Reborn process sandbox rejects sensitive raw env values in plans and uses placeholders for brokered credentials, but production secure-capture and MITM transport wiring remain partial |
Expand Down
2 changes: 1 addition & 1 deletion crates/AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -114,7 +114,7 @@ Boundary rule: if you need an upstream crate in a low-level crate, stop and chec
| `ironclaw_wasm` | `ironclaw_wasm/AGENTS.md`, `ironclaw_wasm/CLAUDE.md`, `docs/reborn/contracts/wasm.md`, `wit/tool.wit` | WASM runtime lane, component/WIT bindings, folded `wasm_sandbox_core` primitives, store, host adapters, runtime config. | Privileged host effects outside mediated APIs; copied secrets/network/resource logic; product/runtime-specific dependencies inside `wasm_sandbox_core`. |
| `ironclaw_wasm_limiter` | `Cargo.toml`, `src/lib.rs` | Shared `wasmtime::ResourceLimiter` for WASM tool and hook runtimes. | Product adapter workflow, policy decisions, or runtime-specific side effects beyond limiter accounting. |
| `ironclaw_extensions` | `ironclaw_extensions/AGENTS.md`, `ironclaw_extensions/CLAUDE.md` | Declarative extension manifests (v2), capability descriptors, side-effect-free in-memory registry, installation records. | Execution of any kind (WASM/MCP/process), secrets, trust decisions. |
| `ironclaw_process_sandbox` | `ironclaw_process_sandbox/CLAUDE.md` | Docker process-sandbox backend behind `ironclaw_processes::ProcessExecutor`: typed sandbox plans, install/credentialed-run phase separation, mount roots. | Process lifecycle/stores (`ironclaw_processes`); raw Docker flags for extensions. |
| `ironclaw_process_sandbox` | `ironclaw_process_sandbox/CLAUDE.md` | Typed `SandboxProcessPlan` contract and validation only: install/credentialed-run phase separation in plan types. No production execution backend is wired for this capability today. | Process lifecycle/stores (`ironclaw_processes`); raw Docker flags for extensions; adding an execution backend here. |

### Turns, threads, loops, engine

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -304,12 +304,6 @@ const FROZEN_PATH_COUNTS: &[FrozenPathCount] = &[
path: "crates/ironclaw_operator/src/operator_service_lifecycle.rs",
count: 5,
},
FrozenPathCount {
category: "test-support",
item_kind: "method",
path: "crates/ironclaw_process_sandbox/src/docker.rs",
count: 1,
},
FrozenPathCount {
category: "test-support",
item_kind: "method",
Expand Down
10 changes: 5 additions & 5 deletions crates/ironclaw_process_sandbox/CLAUDE.md
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
# ironclaw_process_sandbox guardrails

- Own the Reborn process sandbox compatibility lane for arbitrary commands, generated code, repo-local code, and user-installed CLIs.
- Own the typed `SandboxProcessPlan` contract only: plan types and validation (`ValidatedSandboxProcessPlan`) for arbitrary commands, generated code, repo-local code, and user-installed CLIs.
- Accept only typed `SandboxProcessPlan` input. Do not accept raw Docker flags, raw host paths, host environment inheritance, or raw secret material from plan JSON.
- Keep physical Docker mount roots in trusted executor configuration, never in `ProcessExecutionRequest.input`.
- Treat install and credentialed run phases separately: install may write scoped tool/cache state with no secrets; credentialed run uses brokered secrets and read-only tool/cache state.
- Secret values must stay inside broker/lease seams and redaction helpers. Docker args, process output, errors, and debug data must not contain secret material.
- Do not stretch `ironclaw_scripts`; this crate is for dynamic sandbox process execution behind `ProcessExecutor`.
- There is no production backend wired for this capability today — see `ironclaw_host_runtime`'s `process_executor` for the dispatch seam this crate's plans feed into. Do not add Docker mount-root or executor configuration here; that lives with whatever crate eventually wires a real backend.
- Treat install and credentialed run phases separately in the plan types: install may declare scoped tool/cache state with no secrets; credentialed run declares brokered secrets and read-only tool/cache state.
- Secret values must stay inside broker/lease seams and redaction helpers. Plan JSON, validation errors, and debug data must not contain secret material.
- Do not stretch `ironclaw_scripts`; this crate is plan-validation-only and does not itself execute anything.
9 changes: 0 additions & 9 deletions crates/ironclaw_process_sandbox/Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -8,15 +8,6 @@ publish = false
layer = "runtimes"

[dependencies]
async-trait = "0.1"
ironclaw_host_api = { path = "../ironclaw_host_api" }
ironclaw_processes = { path = "../ironclaw_processes" }
secrecy = "0.10"
serde = { version = "1", features = ["derive"] }
serde_json = "1"
thiserror = "2"
tokio = { version = "1", features = ["io-util", "macros", "process", "time"] }

[dev-dependencies]
tempfile = "3"
tokio = { version = "1", features = ["macros", "rt", "time"] }
120 changes: 0 additions & 120 deletions crates/ironclaw_process_sandbox/src/approval.rs

This file was deleted.

159 changes: 0 additions & 159 deletions crates/ironclaw_process_sandbox/src/backend.rs

This file was deleted.

Loading
Loading