Repository navigation
feat: make the embedded Pi sandbox loop the startup default - #8075
serrrfirat wants to merge 2 commits into
Conversation
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. 🗂️ Base branches to auto review (2)
Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Team Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
/benchmark pinchbench |
|
🧪 Started |
🧪 nearai-bench
|
Summary
Stacked on #7908. Base:
feat/7903-native-loop-sandbox-spike. Do not merge before the base PR.hosted-single-tenant-volume-sandboxed, the sandbox loop is enabled, and the default worker is Pi. Docker and a matching worker image are required.local-devconfiguration remains in-process; it is not silently migrated. Benchmarks that explicitly select another profile or disable the worker still override the defaults.Change Type
New feature; runtime/security; dependencies; documentation; Docker build.
Linked Issue
Related to #7903 and dependent on #7908.
Validation
no-mistakesreview was attempted but could not authenticate: its Claude OAuth access token has expired. Do not treat that review as passed.cargo fmt --all -- --check--all-targets --all-features -- -D warnings: configuration, turn runner, composition, and CLI. The original loop-contract/host lint also passed before the default switch.readlink -m, which macOS/usr/bin/readlinkdoes not support. The equivalent entrypoint scenario passed in a Linux container. This is not a claim that the full macOS suite passed.allowImportingTsExtensions, andskipLibCheckfor dependency declarations.IRONCLAW_REQUIRE_DOCKER_TESTS=1andironclaw-worker:pi-smoke. It now selects the default worker kind and verifies the live Pi executable, mediated shell output, and final reply.Build limitation: The full pinned Dockerfile build was attempted repeatedly. Docker Hub metadata/image pulls for the pinned Rust and Bun images timed out. The Docker smoke image uses the locally compiled Linux Pi executable on the existing sandbox image. This proves the Pi runtime path, not a clean build of the complete Dockerfile. No loop-quality benchmark or live-provider canary was run. Frontend build was skipped; this PR does not change frontend code.
Test Strategy
User behavior: a fresh startup with no profile or worker override selects Pi without benchmark-code changes. Pi can call a host model, invoke a mediated tool, park/resume, cancel, and finish a durable turn.
Risk areas: model behavior, side effects, persistence/checkpoints, permissions, and cross-component runtime behavior.
sandbox_shell_turn_runs_the_pi_loop_worker_in_a_real_containerdrives the production wiring and verifies the process, tool result, and final reply.Security Impact
Pi is deliberately content-visible within the selected run. It receives only message references issued by that host and resolved through the same run-owned content store. Empty, guessed, foreign, and role-changed references are rejected. Rust has no content resolver. Authorization, approvals, credential mediation, execution, and outcome validation remain host-owned. The accepted pinned iron-proxy HTTP/HTTPS limitation from #7908 is unchanged.
Reborn Trust-Boundary Checklist
LoopMessageContentPortin loop contracts. The contracts size ceiling changes from 13,608 to 13,778 for the resolved-message DTOs and optional run-owned port accessor; resolution and authorization stay outside the contracts crate.Database Impact
No migration or backend-specific storage change. Pi uses the existing checkpoint and transcript storage ports with a distinct checkpoint schema. The new default boot profile selects its existing storage namespace and
<reborn-home>/workspacesrather than the current directory. Explicitly configured old profiles retain their existing namespace and data.IRONCLAW_REBORN_WORKSPACE_ROOTremains the workspace-root override; data is not moved or deleted.Blast Radius
Deployment selection, composition, loop contracts/host/runner, sandbox image, and shared integration fixtures. The private same-build wire changes to v2, so deploy matching host and worker builds.
Rollback Plan
Set
IRONCLAW_REBORN_PROFILE=local-devto restore in-process startup without Docker. SetIRONCLAW_REBORN_SANDBOX_LOOP_WORKER_KIND=rustfor new sandbox Rust turns, or setIRONCLAW_REBORN_SANDBOX_LOOP_WORKER=falsefor an in-process loop while tools remain sandboxed under the sandbox profile. Retain matching Pi code/image to resume existing Pi checkpoints; Pi and Rust checkpoint payloads are not interchangeable. Do not delete stored checkpoints or transcript data. Revert the host and image together if reverting wire v2.Review Follow-Through
Review the content-visible trust boundary, checkpoint/resume transitions, and the complete image build in an environment with working Docker Hub access. The three-lane document defines an experiment; it does not report benchmark results.
Review track: C (security/runtime).