P6: shell.exec — agents execute code in their real hardened sandbox

- SandboxManager (tc-runtime): one container per agent, provisioned
  lazily on first use, reused for the manager's lifetime, replaced
  transparently if dead, destroyed on shutdown
- shell.exec tool: sh -lc inside the agent's sandbox; stdout/stderr/
  exit_code return to the model as the step output. No external effects
  declared — the sandbox boundary (uid 10001, no caps, seccomp
  allowlist, read-only rootfs, zero egress) is the §15 control here,
  not an approval gate
- RuntimeConfig.sandboxes (+ with_sandboxes builder); [sandbox] config
  {image, enabled}; the server connects the Docker driver at boot and
  tolerates an absent engine (shell.exec reports it per-call)
- Tests with the REAL DockerDriver: a scripted run executes two
  commands — output proves uid 10001 from inside, and /home/agent state
  written by the first call is read by the second (same sandbox); a
  deployment without a sandbox runtime records honest error steps and
  the run still completes

151 Rust tests + 27 Playwright journeys.

Co-Authored-By: Claude Fable 5 <[email protected]>
This commit is contained in:
Omar Sobh
2026-06-10 09:25:38 -05:00
co-authored by Claude Fable 5
parent 84c51168be
commit 7392ce1d08
14 changed files with 417 additions and 0 deletions
+19
View File
@@ -132,6 +132,23 @@ impl Default for SlackConfig {
}
}
#[derive(Debug, Clone, Deserialize)]
pub struct SandboxConfig {
/// Agent sandbox image (must exist locally / be preloaded in cluster).
pub image: String,
/// Disable to run without environment tools (shell.exec errors).
pub enabled: bool,
}
impl Default for SandboxConfig {
fn default() -> Self {
SandboxConfig {
image: "teamclaw/agent-base:dev".into(),
enabled: true,
}
}
}
#[derive(Debug, Clone, Default, Deserialize)]
pub struct OAuthConfig {
/// Default identity provider for directory-app OAuth connects.
@@ -157,6 +174,8 @@ pub struct AppConfig {
pub slack: SlackConfig,
#[serde(default)]
pub oauth: OAuthConfig,
#[serde(default)]
pub sandbox: SandboxConfig,
}
#[derive(Debug, thiserror::Error)]