sand-boxer/workplans/SAND-WP-0015-bwrap-runtime-and-private-state.md
tegwick 23d0c2b34d
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
feat: return combined bwrap runtime candidate to Glas
Answer the GLAS-WP-0015 handoff for SAND-WP-0015-T04 without activating any
production path.

Add candidate profile profile.claude-agent-dev-proof v1.1.0 (ext.bwrap,
localhost-only, default: deny, declared api.anthropic.com:443) for GLAS-WP-0012
review. The committed profile grants no egress by itself — ext.bwrap refuses it
unless owner extension config independently allowlists the destination — and a
regression test asserts that fail-closed default.

Reconcile the differing project examples in favour of the acceptance runner's
actor agt / project glas-local-proof, keeping the documented credential route
bound to that single project rather than broadening it.

Record the return contract (profile revision, host scope, consumer tuple,
runtime digest and mount paths, declared egress, value-free denial/cleanup
receipts) in docs/bwrap-runtime.md.

T04 stays wait: Claude credential lane, owner machine authentication, pinned
Claude executable and real-model acceptance remain operator gated.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HjyScPKb8MV8y2VZHGFSSV

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 716401@bnt-lap001
Assistant-Session: 0d02392b-d4a8-4fed-98e3-32333f768169
2026-09-06 20:34:51 +02:00

7.1 KiB

id type title domain repo status owner topic_slug created updated state_hub_workstream_id
SAND-WP-0015 workplan Provide a pinned bwrap rein runtime and private state infotech sand-boxer blocked codex bwrap-runtime-and-private-state 2026-09-05 2026-09-06 d3f12387-fd23-58f0-b979-9c811507614d

Provide a pinned bwrap rein runtime and private state

Implement the runtime prerequisites returned by Glas in GLAS-WP-0012 and docs/local-profile-acceptance.md. Continue owner work SAND-WP-0014-T05 and live residual GLAS-IN-0002. Runtime startup is a separate acceptance gate from credential delivery, enforced provider egress, and a real model task.

Mount an owner-selected, digest-pinned Python runtime

id: SAND-WP-0015-T01
status: done
priority: high
state_hub_task_id: "93e4aad8-ba9b-5850-93d4-b5bf78ac8978"

Add exact artifact verification to trusted extension configuration and mount the standalone runtime read-only at a fixed namespace path. Reject altered content/modes, unexpected files, escaping symlinks, special files, and source or workspace overlap. A caller cannot choose runtime paths through exec input. Provide a non-editable rein-aharness/llm-connect bundle builder with recorded source revisions and resolved dependency versions.

Completed 2026-09-05. extensions/runtime.py verifies complete artifact contents/modes before a read-only mount; the builder installed committed rein-aharness 1429db5 and llm-connect 0056094 without editable source paths. Candidate digest and source/package evidence are in docs/bwrap-runtime.md.

Keep writable runtime state outside the repository

id: SAND-WP-0015-T02
status: done
priority: high
state_hub_task_id: "c8a689f8-bdf2-57a2-8521-a1c0ca44e750"

Create private mode-0700 HOME/config/cache/state/tmp directories within the namespace, preserve them across exec requests, and remove them with teardown. Keep the command environment sanitized and disable Python user-site/bytecode writes. Fail closed on profile network/setup-credential declarations that the current bwrap implementation cannot honor.

Completed 2026-09-05. Mode-0700 namespace HOME and XDG/TMP directories sit outside the copied Git tree. Explicit runtime PATH selection remains owner controlled. Unsupported egress/default-allow and setup credentials now refuse before workspace creation; regression tests cover these boundaries.

Verify the real rein runtime and owner regression paths

id: SAND-WP-0015-T03
status: done
priority: high
state_hub_task_id: "1a3002f6-c6a8-59d0-9d38-942028419de5"

Run make check, the existing authenticated cross-request owner smoke, and a real runtime startup smoke. Verify the actual rein CLI and adapter imports, read-only runtime, private HOME, clean worktree, absent source, loopback-only network, and teardown. Keep the production Glas profile blocked.

Completed 2026-09-05. make check: lint clean, 132 tests passed. Authenticated owner API smoke 223db65b returned HTTP 200 and proved exact consumer identity, stdin delivery, absent source, loopback-only network and complete teardown. Pinned runtime smoke d4de9531 ran the actual rein CLI and imported its Claude adapter, proved read-only runtime/private HOME/clean worktree, retained private state across a second exec, and removed the workspace. No model call or credential acquisition occurred; T04 remains waiting.

Resolve Claude credentials, enforced egress, and production acceptance

id: SAND-WP-0015-T04
status: wait
priority: high
state_hub_task_id: "58817ef6-76d9-5e34-908f-c024e6c99f93"

The 2026-09-05 routing lookup found no concrete Anthropic/Claude workload lane. The generic OpenBao template is not a delegable lane; the OpenRouter AppRole belongs to another rein. Credential owner railiance-platform/OpenBao plus rein-aharness must establish a concrete Claude-compatible route and delivery/ revocation contract before values can be requested or supplied to the runtime.

Sand-boxer must then implement the matching enforced provider egress contract (including DNS/TLS and denied-destination proof) and pin/deploy the actual Claude executable. No unrestricted-network or interactive-login substitute is permitted. Review the deployed runtime/profile with Glas, run its real-rein acceptance fixture, and update only the proven profile's readiness. No production schedule is enabled by the runtime-startup smoke.

This task and SAND-WP-0014-T05 remain open until those gates pass. The detailed return contract and runtime proof are in docs/bwrap-runtime.md; the live cross-repo residual remains GLAS-IN-0002.

2026-09-05 transport implementation evidence

T04 remains waiting on owner machine authentication, protected credential delivery, pinned Claude startup and the real model proof. CCR-2026-0016 custody is confirmed by a metadata-only check of live version 2; no value was read. HTTPS egress is now implemented as an exact owner/profile allowlisted CONNECT proxy while retaining an isolated network namespace. Non-secret live smoke sandbox e290e788 verified provider TLS response, undeclared destination and direct-IP denial, and proxy/workspace teardown. See docs/bwrap-egress.md.

2026-09-05 credential transport owner return

Owner-bound exec-env transport is implemented and proved with a synthetic provider in real sandbox 0e5fb35a. Exact route/profile/project/actor/run binding, child-only key injection, pre-truncation redaction, next-exec absence and teardown pass. No real key read or production profile activation. See docs/bwrap-credentials.md. SECRETS-WP-0009 now owns native AppRole adoption for CCR-2026-0016, including a data-only consumer read policy. Its production exec refuses before OpenBao until SECRETS-WP-0007-T04 and SECRETS-WP-0008-T02/T06 deliver canonical authorization/consume and service authority. T04 remains waiting on that live owner path, the pinned Claude executable and real model acceptance.

2026-09-06 combined-runtime candidate returned to Glas

Answered the GLAS-WP-0015 handoff. Added candidate profile profile.claude-agent-dev-proof version 1.1.0 (ext.bwrap, localhost-only, default: deny with declared api.anthropic.com:443) for GLAS-WP-0012 review. The committed profile grants no egress by itself: ext.bwrap refuses it unless the owner extension config allowlists the destination, and a regression test now asserts that fail-closed default. make check: lint clean, 172 tests passed.

Resolved the differing project examples in favour of the acceptance runner's actor: agt / project: glas-local-proof, and bound the documented credential route to that single project rather than broadening it. The full return contract — profile id/revision, host scope, consumer tuple, runtime digest and mount paths, declared egress, and the value-free denial/cleanup receipts — is in docs/bwrap-runtime.md.

T04 stays wait: the concrete Claude credential lane and delivery/revocation contract, owner machine authentication, the pinned Claude executable with its own proxy startup proof, and the real-model acceptance are still operator and upstream-owner gated. Provider workspace scope and spend limit remain operator inputs. SAND-WP-0014-T05 remains open on the same gates.