Skip to content

Reuse the process codec for the trampoline - #451

Merged
SaladDay merged 1 commit into
feature/agent-outside-sandboxfrom
aos/b4-sandbox-side
Oct 6, 2026
Merged

SaladDay merged 1 commit into
feature/agent-outside-sandboxfrom
aos/b4-sandbox-side

Conversation

@SaladDay

@SaladDay SaladDay commented Oct 6, 2026 •

Copy link
Copy Markdown
Collaborator

B4 simplicity audit, lane L2: the sandbox side. Net −96 production lines.

  • The trampoline reuses the Process codec. It receives the operation's encoded StartRequest and decodes it with sandboxprocess.Decode. Exec argv, env, TERM and PATH are derived at the child boundary. This removes the private launch format (encodeLaunch and decodeLaunch) and the second copy of PATH. The request is read with io.ReadAll on an owned *os.File. The trampoline, the child-side umask, descriptor protection and the exec-status pipe are unchanged.
  • Startup errors are plain wrapped errors. StartupError and Step had no reader, so they become fmt.Errorf("<step>: %w", err). The message still names the step and never carries the credential, and a new table test asserts both.

Testing:

  • apps/sandboxio tests;
  • the process tests with -race -count=20;
  • the processbroker suite (unprivileged and privileged), which drives the trampoline through processserve;
  • gofmt and vet.

View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

The trampoline now receives the operation's encoded StartRequest and
decodes it with sandboxprocess.Decode, deriving argv, environment, TERM
and PATH at the child boundary, so its private launch format and the
second copy of PATH go. It reads the request with io.ReadAll on an owned
*os.File.

Startup failures wrap their cause with fmt.Errorf naming the step;
StartupError and Step had no reader.
@SaladDay
SaladDay merged commit a001bb5 into feature/agent-outside-sandbox Oct 6, 2026
19 checks passed
@SaladDay
SaladDay deleted the aos/b4-sandbox-side branch October 6, 2026 22:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant