# glas-harness integration glas-harness owns the agent gateway, tools, memory, and channels. sand-boxer delivers an isolated execution environment; the harness executes tools inside it. ## Example request ```bash sandboxer create \ --profile profile.agent-dev \ --input repo=/path/to/workspace \ --actor agt \ --project glas-harness \ --session-id session-123 \ --run-id run-456 ``` ## Response fields (ready state) | Field | Owner | Description | |-------|-------|-------------| | `sandbox_id` | sand-boxer | Stable instance identifier | | `reachability.ssh` | sand-boxer | SSH target for harness exec channel | | `reachability.remote_dir` | sand-boxer | Workspace root on remote host | | `state` | sand-boxer | Lifecycle state (`ready`, etc.) | ## Two execution modes Not every sandbox has an SSH hop. `ext.compose-ssh` / `ext.vm-packer` always run remote and populate `reachability.ssh` + `reachability. remote_dir`; glas-harness execs tools over that SSH channel. `ext.bwrap` (SAND-WP-0013) runs same-host and never populates `reachability.ssh` — instead it populates `reachability.pid` (the placeholder process holding the bwrap namespaces) and `reachability.workspace_dir` as evidence. These fields are not a consumer attach contract. `build_reachability_report()` returns `execution.mode: owner-mediated`; glas-harness sends an exec request to the resident sand-boxer owner service. Direct `nsenter` is unsupported. The request repeats the exact actor/project/session/run identity used at create, carries an argument vector (never a shell command string), and may carry only value-free credential catalog route references. sand-boxer refuses identity mismatch, non-ready or expired state, concurrent execution, and every extension without an owner execution implementation. It never retries against the host source checkout. For the local owner transport, retain these values from gateway resolution: | sand-boxer field | Glas source | |---|---| | `consumer.actor` | `ExecutionRequest.actor` | | `consumer.project` | `ExecutionRequest.project` | | `consumer.run_id` | resolved `request_id` | | `credential_route_refs` | exact selected `HarnessProfile.credential_route_refs` | | `timeout_seconds` | selected profile limit | Use bounded `stdin_text` with an in-sandbox writer command to create the private task file under `.git`; sand-boxer does not echo stdin in the result or lifecycle evidence. Local transport must not write the task file through host `Path` APIs. ## Ownership | Concern | Owner | |---------|-------| | Sandbox provision / teardown | sand-boxer | | In-namespace command broker, workspace cwd, timeout/output bounds | sand-boxer | | Tool call parsing and policies | glas-harness | | SSH / tunnel reachability setup | glas-harness + ops-bridge | | Agent memory and session state | glas-harness | ## Smoke test ```bash # Requires sandboxer CLI and SANDBOXER_HOST (or profile placement fallback) SANDBOXER_HOST=coulombcore ./scripts/smoke-agent-dev.sh ``` Creates `profile.agent-dev`, prints reachability (tunnel metadata + SSH one-liner), then destroys. ## Out of scope for sand-boxer - Tool schemas and approval flows - Channel bridges (Slack, email, etc.) - Subagent orchestration - Provider credential acquisition or injection (the selected rein owns it)