Skip to content

feat: make the embedded Pi sandbox loop the startup default - #8075

Open
serrrfirat wants to merge 2 commits into
nearai:feat/7903-native-loop-sandbox-spikefrom
serrrfirat:feat/pi-loop-worker
Open

serrrfirat wants to merge 2 commits into
nearai:feat/7903-native-loop-sandbox-spikefrom
serrrfirat:feat/pi-loop-worker

Conversation

@serrrfirat

@serrrfirat serrrfirat commented Sep 5, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Stacked on #7908. Base: feat/7903-native-loop-sandbox-spike. Do not merge before the base PR.

  • Add a pinned Bun/Pi agent-core worker to the sandbox image and make it the default for fresh startup, as explicitly requested for benchmark use. The default boot profile is now hosted-single-tenant-volume-sandboxed, the sandbox loop is enabled, and the default worker is Pi. Docker and a matching worker image are required.
  • Add explicit deployment selection and a Pi checkpoint schema. Bind message resolution to the current run's host, prompt materialization store, and issued message references. Rust workers remain content-blind.
  • Implement host-backed model calls, capability identity correlation, transcript updates, checkpoints, approval parking/resume, cancellation, and usage accounting. Provider credentials remain on the host.
  • Add wire-v2 authorization tests, Rust/Pi process conformance, a real-container Pi turn, and internal wire/experiment documentation.
  • Preserve explicit profile and worker overrides. Existing saved local-dev configuration remains in-process; it is not silently migrated. Benchmarks that explicitly select another profile or disable the worker still override the defaults.

Change Type

New feature; runtime/security; dependencies; documentation; Docker build.

Linked Issue

Related to #7903 and dependent on #7908.

Validation

  • Architecture suite: 315 tests passed across 42 suites.
  • Automated no-mistakes review was attempted but could not authenticate: its Claude OAuth access token has expired. Do not treat that review as passed.
  • cargo fmt --all -- --check
  • Default-switch Clippy with --all-targets --all-features -- -D warnings: configuration, turn runner, composition, and CLI. The original loop-contract/host lint also passed before the default switch.
  • Configuration tests: 114 passed. CLI unit tests: 492 passed; extension tests: 6 passed; CLI documentation tests: 2 passed.
  • CLI smoke tests: 149 of 150 passed on macOS, including fresh default startup failing closed without Docker. The remaining Railway-volume entrypoint case requires GNU readlink -m, which macOS /usr/bin/readlink does not support. The equivalent entrypoint scenario passed in a Linux container. This is not a claim that the full macOS suite passed.
  • Worker selection/driver tests: 5 passed; Rust/Pi process conformance: 6 passed. The default-executable regression failed on Rust before the change and passed on Pi afterward.
  • Bun worker tests: 8 passed. TypeScript source/test checking passed with Bun types, allowImportingTsExtensions, and skipLibCheck for dependency declarations.
  • Real-container Pi integration: passed with IRONCLAW_REQUIRE_DOCKER_TESTS=1 and ironclaw-worker:pi-smoke. It now selects the default worker kind and verifies the live Pi executable, mediated shell output, and final reply.
  • Composition size/dispatch budget and documentation publication boundary passed.

Build limitation: The full pinned Dockerfile build was attempted repeatedly. Docker Hub metadata/image pulls for the pinned Rust and Bun images timed out. The Docker smoke image uses the locally compiled Linux Pi executable on the existing sandbox image. This proves the Pi runtime path, not a clean build of the complete Dockerfile. No loop-quality benchmark or live-provider canary was run. Frontend build was skipped; this PR does not change frontend code.

Test Strategy

User behavior: a fresh startup with no profile or worker override selects Pi without benchmark-code changes. Pi can call a host model, invoke a mediated tool, park/resume, cancel, and finish a durable turn.

Risk areas: model behavior, side effects, persistence/checkpoints, permissions, and cross-component runtime behavior.

  • Unit or contract: bounded content resolution; issued-reference and role checks; wire visibility; Pi protocol, approval resume, candidate correlation, and cancellation.
  • Reborn integration: sandbox_shell_turn_runs_the_pi_loop_worker_in_a_real_container drives the production wiring and verifies the process, tool result, and final reply.
  • Recorded fixture: not applicable; deterministic scripted host replies exercise protocol behavior. No model-quality claim is made.
  • Browser E2E: not applicable; no browser surface changes.
  • Backend or runtime: Rust/Pi conformance uses actual worker processes. Docker integration requires an available daemon and image and was run without the skip path.
  • Live canary: not run; no provider credentials are needed for the scripted tests.

Security Impact

Pi is deliberately content-visible within the selected run. It receives only message references issued by that host and resolved through the same run-owned content store. Empty, guessed, foreign, and role-changed references are rejected. Rust has no content resolver. Authorization, approvals, credential mediation, execution, and outcome validation remain host-owned. The accepted pinned iron-proxy HTTP/HTTPS limitation from #7908 is unchanged.

Reborn Trust-Boundary Checklist

  • Wire requests remain untrusted; typed host boundaries authorize and execute them.
  • Message content reaches the worker through host prompt/content ports. Provider credentials do not enter the worker.
  • No new authenticity hash or trust-by-hash mechanism.
  • Startup now selects content-visible Pi by default; explicit Rust remains content-blind. Independently, omitted wire visibility still fails closed to Blind. Wire v1 and v2 are not compatible despite serde defaults.
  • Issued-reference tracking, frames, calls, and counters are bounded; counter arithmetic is checked or saturating.
  • Existing host error classes and validated exits remain in use.
  • Architecture ownership records identify LoopMessageContentPort in loop contracts. The contracts size ceiling changes from 13,608 to 13,778 for the resolved-message DTOs and optional run-owned port accessor; resolution and authorization stay outside the contracts crate.

Database Impact

No migration or backend-specific storage change. Pi uses the existing checkpoint and transcript storage ports with a distinct checkpoint schema. The new default boot profile selects its existing storage namespace and <reborn-home>/workspaces rather than the current directory. Explicitly configured old profiles retain their existing namespace and data. IRONCLAW_REBORN_WORKSPACE_ROOT remains the workspace-root override; data is not moved or deleted.

Blast Radius

Deployment selection, composition, loop contracts/host/runner, sandbox image, and shared integration fixtures. The private same-build wire changes to v2, so deploy matching host and worker builds.

Rollback Plan

Set IRONCLAW_REBORN_PROFILE=local-dev to restore in-process startup without Docker. Set IRONCLAW_REBORN_SANDBOX_LOOP_WORKER_KIND=rust for new sandbox Rust turns, or set IRONCLAW_REBORN_SANDBOX_LOOP_WORKER=false for an in-process loop while tools remain sandboxed under the sandbox profile. Retain matching Pi code/image to resume existing Pi checkpoints; Pi and Rust checkpoint payloads are not interchangeable. Do not delete stored checkpoints or transcript data. Revert the host and image together if reverting wire v2.

Review Follow-Through

Review the content-visible trust boundary, checkpoint/resume transitions, and the complete image build in an environment with working Docker Hub access. The three-lane document defines an experiment; it does not report benchmark results.

Review track: C (security/runtime).

@coderabbitai

coderabbitai Bot commented Sep 5, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

🗂️ Base branches to auto review (2)
  • staging
  • reborn-integration

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Team

Run ID: c1ef1f82-efab-47f2-a906-16999f22a96f

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added scope: sandbox Docker sandbox scope: docs Documentation size: XL 500+ changed lines risk: low Changes to docs, tests, or low-risk modules contributor: core 20+ merged PRs labels Sep 5, 2026
@serrrfirat serrrfirat changed the title feat: add embedded Pi sandbox loop worker [experiment] feat: add embedded Pi sandbox loop worker Sep 5, 2026
@serrrfirat serrrfirat changed the title [experiment] feat: add embedded Pi sandbox loop worker feat: make the embedded Pi sandbox loop the startup default Sep 5, 2026
@serrrfirat

Copy link
Copy Markdown
Collaborator Author

/benchmark pinchbench

@github-actions

github-actions Bot commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

🧪 Started pinchbench against ironclaw ac86bbbaac — watch run.

@pranavraja99

pranavraja99 commented Sep 5, 2026 •

Copy link
Copy Markdown
Contributor

🧪 nearai-bench pinchbench — run complete (no baseline)

Ironclaw ac86bbbaac on ironclaw: 59.2% pass, avg score 0.894 across 147 tasks. No baseline under baselines/pinchbench/ matches this run's framework (ironclaw) and model — add one (e.g. via the nightly refresh job) to enable regression detection. A baseline from a different framework or model is deliberately NOT used: the per-task gate would then be measuring that difference, not a regression.

🔍 browse run + per-task trajectories · download results

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: core 20+ merged PRs risk: low Changes to docs, tests, or low-risk modules scope: docs Documentation scope: sandbox Docker sandbox size: XL 500+ changed lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants