Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a06def-6490-7033-8448-2eab2d12ed44
85 lines
3.2 KiB
Markdown
85 lines
3.2 KiB
Markdown
# glas-harness integration
|
|
|
|
glas-harness owns the agent gateway, tools, memory, and channels. sand-boxer
|
|
delivers an isolated execution environment; the harness executes tools inside it.
|
|
|
|
## Example request
|
|
|
|
```bash
|
|
sandboxer create \
|
|
--profile profile.agent-dev \
|
|
--input repo=/path/to/workspace \
|
|
--actor agt \
|
|
--project glas-harness \
|
|
--session-id session-123 \
|
|
--run-id run-456
|
|
```
|
|
|
|
## Response fields (ready state)
|
|
|
|
| Field | Owner | Description |
|
|
|-------|-------|-------------|
|
|
| `sandbox_id` | sand-boxer | Stable instance identifier |
|
|
| `reachability.ssh` | sand-boxer | SSH target for harness exec channel |
|
|
| `reachability.remote_dir` | sand-boxer | Workspace root on remote host |
|
|
| `state` | sand-boxer | Lifecycle state (`ready`, etc.) |
|
|
|
|
## Two execution modes
|
|
|
|
Not every sandbox has an SSH hop. `ext.compose-ssh` / `ext.vm-packer`
|
|
always run remote and populate `reachability.ssh` + `reachability.
|
|
remote_dir`; glas-harness execs tools over that SSH channel. `ext.bwrap`
|
|
(SAND-WP-0013) runs same-host and never populates `reachability.ssh` —
|
|
instead it populates `reachability.pid` (the placeholder process holding
|
|
the bwrap namespaces) and `reachability.workspace_dir` as evidence. These
|
|
fields are not a consumer attach contract. `build_reachability_report()`
|
|
returns `execution.mode: owner-mediated`; glas-harness sends an exec request
|
|
to the resident sand-boxer owner service. Direct `nsenter` is unsupported.
|
|
|
|
The request repeats the exact actor/project/session/run identity used at
|
|
create, carries an argument vector (never a shell command string), and may
|
|
carry only value-free credential catalog route references. sand-boxer refuses
|
|
identity mismatch, non-ready or expired state, concurrent execution, and every
|
|
extension without an owner execution implementation. It never retries against
|
|
the host source checkout.
|
|
|
|
For the local owner transport, retain these values from gateway resolution:
|
|
|
|
| sand-boxer field | Glas source |
|
|
|---|---|
|
|
| `consumer.actor` | `ExecutionRequest.actor` |
|
|
| `consumer.project` | `ExecutionRequest.project` |
|
|
| `consumer.run_id` | resolved `request_id` |
|
|
| `credential_route_refs` | exact selected `HarnessProfile.credential_route_refs` |
|
|
| `timeout_seconds` | selected profile limit |
|
|
|
|
Use bounded `stdin_text` with an in-sandbox writer command to create the private
|
|
task file under `.git`; sand-boxer does not echo stdin in the result or lifecycle
|
|
evidence. Local transport must not write the task file through host `Path` APIs.
|
|
|
|
## Ownership
|
|
|
|
| Concern | Owner |
|
|
|---------|-------|
|
|
| Sandbox provision / teardown | sand-boxer |
|
|
| In-namespace command broker, workspace cwd, timeout/output bounds | sand-boxer |
|
|
| Tool call parsing and policies | glas-harness |
|
|
| SSH / tunnel reachability setup | glas-harness + ops-bridge |
|
|
| Agent memory and session state | glas-harness |
|
|
|
|
## Smoke test
|
|
|
|
```bash
|
|
# Requires sandboxer CLI and SANDBOXER_HOST (or profile placement fallback)
|
|
SANDBOXER_HOST=coulombcore ./scripts/smoke-agent-dev.sh
|
|
```
|
|
|
|
Creates `profile.agent-dev`, prints reachability (tunnel metadata + SSH
|
|
one-liner), then destroys.
|
|
|
|
## Out of scope for sand-boxer
|
|
|
|
- Tool schemas and approval flows
|
|
- Channel bridges (Slack, email, etc.)
|
|
- Subagent orchestration
|
|
- Provider credential acquisition or injection (the selected rein owns it)
|