Skip to content

Use local system trust for native Harnesses - #622

Merged
SaladDay merged 1 commit into
aos/cutoverfrom
aos/use-local-system-trust-for-native-harnesses
Oct 9, 2026
Merged

SaladDay merged 1 commit into
aos/cutoverfrom
aos/use-local-system-trust-for-native-harnesses

Conversation

@SaladDay

@SaladDay SaladDay commented Oct 9, 2026 •

Copy link
Copy Markdown
Collaborator

Native HTTP client construction repeatedly read the sandbox CA bundle through remote File RPCs. The agent host now uses the image’s existing system CA bundle as the single source for its explicit gateway trust pool and a read-only mount at the same path in each view. This replaces the internal directory input; no settings, adapter fields, trust fallback, generated bundle, or cache are added. Native bundled trust stores and sandbox tool CA files remain unchanged.

A fixed no-model Codex two-request comparison removed 442 remote bundle reads. With 5 ms per File operation, first-request wait fell from 3.253 to 1.934 seconds and the next-request interval from 1.788 to 0.491 seconds. Stock image directory and bundle contain the same 150 DER roots; custom or disabled roots follow the generated system bundle. These are controlled measurements, not live latency guarantees.

Validation: focused Go tests, race, vet, cross-platform builds, hygiene, real read-only view and CLI checks, TLS trust/rejection, path conflict tests, translation checks, and fresh independent review passed. A broader MCP fixture failed its cgroup prerequisite on both baseline and candidate; that unrelated fixture was not changed. Final distribution and live qualification remain pending in the coordinated build batch.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

@SaladDay
SaladDay merged commit f129f57 into aos/cutover Oct 9, 2026
20 checks passed
@SaladDay
SaladDay deleted the aos/use-local-system-trust-for-native-harnesses branch October 9, 2026 15:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant