Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -88,6 +88,12 @@ const FROZEN_PATH_COUNTS: &[FrozenPathCount] = &[
path: "crates/ironclaw_host_runtime/src/sandbox_process/credential_firewall.rs",
count: 5,
},
FrozenPathCount {
category: "dead-code",
item_kind: "method",
path: "crates/ironclaw_host_runtime/src/sandbox_process/attribution.rs",
count: 4,
},
FrozenPathCount {
category: "test-support",
item_kind: "field",
Expand Down Expand Up @@ -280,6 +286,12 @@ const FROZEN_PATH_COUNTS: &[FrozenPathCount] = &[
path: "crates/ironclaw_host_runtime/src/obligations.rs",
count: 1,
},
FrozenPathCount {
category: "test-support",
item_kind: "method",
path: "crates/ironclaw_host_runtime/src/sandbox_process/attribution.rs",
count: 1,
},
FrozenPathCount {
category: "test-support",
item_kind: "method",
Expand Down
451 changes: 416 additions & 35 deletions crates/ironclaw_filesystem/src/local.rs

Large diffs are not rendered by default.

4 changes: 2 additions & 2 deletions crates/ironclaw_host_runtime/src/lib.rs
Original file line number Diff line number Diff line change
Expand Up @@ -133,8 +133,8 @@ pub use process_port::{
pub use production::DefaultHostRuntime;
pub use sandbox_process::{
RebornSandboxConfig, RebornSandboxContainerIdentity, RebornSandboxNetworkBroker,
RebornSandboxScopeKey, RebornSandboxSecretBroker, RebornSandboxWorkspaceMode,
RebornScopedSandboxCommandTransport,
RebornSandboxScopeKey, RebornSandboxSecretBroker, RebornSandboxUserKey,
RebornSandboxWorkspaceMode, RebornScopedSandboxCommandTransport, SandboxActivityRegistry,
};
/// Scoped cleanup guard consumed by the generic extension activation
/// transaction's composition adapter. Raw obligation handoff stores remain
Expand Down
15 changes: 15 additions & 0 deletions crates/ironclaw_host_runtime/src/sandbox_process.rs
Original file line number Diff line number Diff line change
Expand Up @@ -33,14 +33,29 @@ mod broker;
mod ca;
mod container_identity;
mod credential_firewall;
mod key_codec;
mod mounts;
mod scope_key;

// `attribution`, `registry`, and `user_key` are the persistent per-user
// sandbox container model's identity/registry primitives: container naming,
// label-based identity, and Docker-network connection attribution. Their
// consumers are the exec-based transport's per-user container reuse and the
// egress proxy's credential-injection path. `user_key` is `pub`/re-exported
// for cross-crate composition wiring to construct directly; `registry` and
// `attribution` stay crate-private, with per-item `#[allow(dead_code)]`
// comments naming the future consumer where one isn't wired yet.
mod attribution;
mod registry;
mod user_key;

use mounts::RebornSandboxMountSources;

pub use broker::{RebornSandboxNetworkBroker, RebornSandboxSecretBroker};
pub use container_identity::{RebornSandboxContainerIdentity, RebornSandboxWorkspaceMode};
pub use registry::SandboxActivityRegistry;
pub use scope_key::RebornSandboxScopeKey;
pub use user_key::RebornSandboxUserKey;

const DEFAULT_IMAGE: &str = "ironclaw-worker:latest";
const DEFAULT_TIMEOUT: Duration = Duration::from_secs(120);
Expand Down
Loading
Loading