Skip to content

refactor(runtime): extract portable driver and isolation foundations - #4106

Draft
drew wants to merge 5 commits into
mainfrom
codex/runtime-foundations
Draft

drew wants to merge 5 commits into
mainfrom
codex/runtime-foundations

Conversation

@drew

@drew drew commented Oct 2, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Extract the driver-independent foundations from #4084 so they can be reviewed and merged separately from native MXC. Keep the existing IsolationBackend and authenticated Sandbox Protocol. This base includes portable supervisor access, generic networking and provider plumbing, CLI improvements, audit output, and Go gateway discovery. UI policy additions belong to #4084.

Related Issue

Follow-up to #1737 (RFC 0012). Prerequisite for #4084; Windows scope tracked in #2050.

Changes

  • Keep gateway authentication, canonical process attachment, forwarding, and TCP readiness independent of optional Unix SSH access. Process access consumes boundary-provided streams and signals rather than local PID/PTY machinery.
  • Inject backend-owned audit validators and raw transport connectors while retaining strict Linux evidence validation, pinned TLS, session authentication, generation checks, and reconnect handling.
  • Keep the existing policy schema without UI additions. Unknown authored controls remain rejected by schema validation, with a fail-closed prover regression test. UI schema/protobuf, capability checks, canonicalization, SDK conversion, tests, and documentation are all in feat(mxc): integrate Windows runtime on portable isolation foundations #4084.
  • Deliver the effective startup policy without persisting credentials or launch authentication in public sandbox records. Preserve provider workspace authorization and expired-credential validation.
  • Add backend-neutral authenticated CONNECT listener plumbing through private supervisor setup, not a new isolation-interface proxy hook. Keep the old host adapter until the MXC replacement lands.
  • Keep default external-resource admission secure while allowing factories to specify their admission contract explicitly.
  • Move driver-independent --env-from, portable gateway JSONL audit output, and Go gateway discovery into this base, with tests and documentation.
  • Retain tested internal identity-safe deletion. Do not expose ineffective CLI guards that cannot be carried by the current public delete request.
  • Include only the earlier constructor compatibility fix in the existing MXC driver; no new MXC implementation, native boundary crate, Windows sandbox executable, or UI fixture additions are included.

Testing

  • Fresh native x64 tests after moving UI to feat(mxc): integrate Windows runtime on portable isolation foundations #4084, across core, schema, policy, prover, and gateway server: 2,878 passed, 0 failed, 8 explicitly ignored. Includes fail-closed rejection of unknown UI and preserved generic startup-policy delivery. Earlier broader foundation run passed 4,954 tests before this ownership revision.
  • Full Go SDK go test ./... passed; changed Go files are gofmt-clean.
  • mise run --skip-tools pre-commit passed, including workspace Clippy, E2E compilation checks, formatting, protobuf, licenses, Python, Markdown, and TypeScript. Used the cached x64 Z3 library/header override to avoid the unauthenticated download failure.
  • Linux runtime and sandbox E2E regression validation; Windows-gated integration suites are not counted as coverage.
  • Native ARM64 validation for this extraction.

Windows control-plane tests are not MXC containment qualification. Keep this PR draft pending cross-platform runtime validation.

Checklist

  • Follows Conventional Commits.
  • Commits are signed off (DCO).
  • Shared implementation documentation and related skill guidance updated.

Stack

GitHub native stack #4225: main -> #4106 -> #4084.

Merge this PR first. The child branch retains its MXC history through ordinary merges. If this base is squash-merged, update the child against the merged main branch before retargeting it.

@copy-pr-bot

copy-pr-bot Bot commented Oct 2, 2026

Copy link
Copy Markdown

This pull request requires additional validation before any workflows can run on NVIDIA's runners.

Pull request vetters can view their responsibilities here.

Contributors can view more details about this message here.

@shiju-nv

shiju-nv commented Oct 4, 2026

Copy link
Copy Markdown
Collaborator

@drew I opened #4176 to pull Linux-specific setup out of shared supervisor startup. It moves client construction behind a private backend interface.

I'd suggest landing #4176 before #4106. That lets us review the setup extraction independently, then bring your changes onto that structure.

Happy to help with that and test the combined changes.

drew added 2 commits October 5, 2026 20:28
…dation

Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
@drew
drew added this pull request to stack #4225 October 6, 2026 03:35
@drew
drew force-pushed the codex/runtime-foundations branch from 8708b4b to 1eea0e0 Compare October 6, 2026 03:49
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown

Signed-off-by: Drew Newberry <anewberry@nvidia.com>
@drew drew changed the title refactor(runtime): decouple supervisor access and boundary audit validation refactor(runtime): extract portable driver and isolation foundations Oct 6, 2026
Signed-off-by: Drew Newberry <anewberry@nvidia.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants