Skip to content

refactor(runtime): decouple supervisor access and boundary audit validation - #4106

Draft
drew wants to merge 1 commit into
mainfrom
codex/runtime-foundations
Draft

drew wants to merge 1 commit into
mainfrom
codex/runtime-foundations

Conversation

@drew

@drew drew commented Oct 2, 2026

Copy link
Copy Markdown
Collaborator

Summary

Extract the backend-neutral runtime foundations from #4084 so they can be reviewed and merged independently of MXC. Keep the existing IsolationBackend and authenticated Sandbox Protocol; remove Unix assumptions from supervisor access and allow implementing backends to validate their own opaque audit evidence.

Related Issue

Follow-up to #1737 (RFC 0012). Prerequisite for #4084.

Changes

  • Keep gateway authentication, canonical process attachment, and forwarding independent of optional Unix SSH access.
  • Make TCP readiness portable while preserving initial acceptance, disconnect/reconnect gating, and teardown.
  • Retain local Unix signal support, including SIGQUIT, through a separate adapter to backend-neutral signals.
  • Inject a BoundaryAuditValidator into the shared runtime; strict Linux evidence validation remains the default, and asserted properties must match validated evidence.
  • Include supervisor libraries in native Windows checks/tests without adding a Windows isolation backend or executable.
  • Document the control-plane and evidence-validation seams and update Windows contributor guidance.
  • Correct one pre-existing Windows unit-fixture constructor call so the base's all-target validation can run independently.

No UI policy, explicit-proxy networking, MXC implementation, or public protobuf changes are included.

Testing

  • Native x64 workspace check: mise run --skip-tools windows:check:x64
  • 250 focused native tests passed across openshell-supervisor, openshell-supervisor-process, and openshell-sandbox-backend.
  • mise run pre-commit passes through the commit hook.
  • Unit tests added/updated; existing confirmation mismatch and invalid-evidence tests preserved.
  • Linux runtime and sandbox E2E regression validation; requires Linux CI/host.
  • Native ARM64 validation.

Windows control-plane tests are not MXC containment qualification. This PR remains draft pending cross-platform runtime validation.

Checklist

  • Follows Conventional Commits.
  • Commits are signed off (DCO).
  • Crate implementation documentation and related contributor skill guidance updated.

Stack

  1. This PR: main -> codex/runtime-foundations.
  2. feat(mxc): integrate Windows runtime on portable isolation foundations #4084: codex/runtime-foundations -> drew-mxc.

Merge this PR first. Retarget #4084 to main afterward; if the base is squash-merged, merge updated main into the child branch so its comparison stays incremental.

…dation

Signed-off-by: Drew Newberry <anewberry@nvidia.com>
@copy-pr-bot

copy-pr-bot Bot commented Oct 2, 2026

Copy link
Copy Markdown

This pull request requires additional validation before any workflows can run on NVIDIA's runners.

Pull request vetters can view their responsibilities here.

Contributors can view more details about this message here.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant