Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
18 changes: 7 additions & 11 deletions benchmarks/programbench/run_infer.py
Original file line number Diff line number Diff line change
Expand Up @@ -216,14 +216,10 @@ def prepare_workspace(
* ``--network none`` blocks the SDK from reaching the agent-server
because Docker port mappings need a network interface.
* ``docker network create --internal`` blocks ``-p`` port mappings.
* The robust answer is in-container egress filtering (iptables in an
init step), which needs ``CAP_NET_ADMIN`` and is **future work**.

For now we leave ``network=None`` (default bridge). The system prompt
explicitly tells the agent it has no internet, and the cleanroom image
ships with everything the task needs locally. Agents that try to call
out anyway will produce non-leaderboard-faithful runs — that limitation
is documented in the README and tracked in AGENTS.md.

The SDK's ``network_isolation="offline"`` bridge keeps the local
control port available while disabling Docker's outbound masquerading.
The cleanroom image ships with everything the task needs locally.
"""
details = self.metadata.details or {}
forward_env = get_acp_forward_env(self.metadata.agent_type, forward_env)
Expand All @@ -243,9 +239,9 @@ def prepare_workspace(
),
target=target, # type: ignore[arg-type]
forward_env=forward_env or [],
# See docstring above. Strict offline isolation is follow-up
# work; today we rely on the prompt + cleanroom image.
network=None,
# Keep the control port reachable while disabling bridge
# masquerading so the agent cannot reach the public internet.
network_isolation="offline",
)
elif self.metadata.workspace_type == "remote":
raise NotImplementedError(
Expand Down
2 changes: 1 addition & 1 deletion vendor/software-agent-sdk