Skip to content

Start only Sandbox I/O in the sandbox - #557

Merged
SaladDay merged 1 commit into
aos/cutoverfrom
aos/pr6b-provider
Oct 8, 2026
Merged

SaladDay merged 1 commit into
aos/cutoverfrom
aos/pr6b-provider

Conversation

@SaladDay

@SaladDay SaladDay commented Oct 8, 2026 •

Copy link
Copy Markdown
Collaborator

Every Provider now starts only oac-sandbox-io in a sandbox. Nothing inside the sandbox talks to Core except Sandbox I/O over the Link.

  • Core–Sandbox Provider protocol.
    • Bootstrap is {Reference, SandboxIO}, and Validate checks that SandboxIO serves the Reference's allocation.
    • RunCommand and RunCommandCompute (with ErrCommandUnconfirmed) are gone from the interface, from the operation lists and from every implementation and wire.
    • Required operations are Create, GetInfo, Renew and Kill. The checkpoint set loses RunCommandCompute.
  • Node wire. Follows the smaller Bootstrap, drops the command operations and lowers the frame limit to 1 MiB. ProtocolVersion stays 5.
  • Docker. The container's entrypoint is oac-sandbox-io --bootstrap-file …, so Sandbox I/O is PID 1. The bootstrap writes only its file. The guest env, the runtime bootstrap file and nested_sandbox are deleted, and the -home volume stays.
  • E2B.
    • managed_init.py starts only Sandbox I/O. The new receipt is {identity, status: "sandbox_io_started", sandbox_io_pid}, and provider.py checks it.
    • contractgen and both generated helper contracts are regenerated.
    • The application-managed example (init.py, launch.py, init_test.py) is deleted.
  • microsandbox tool. The bootstrap starts only Sandbox I/O (UID 1000, empty environment). The command backend is deleted.
  • Core composition. CoreURL, runtimeAPI and RuntimeAPI() are deleted.
  • Docs. sandbox-provider, node-generation-protocol, configuration, architecture, machine-api, environments (en and zh), plus the E2B and microsandbox READMEs.

Checks:

  • go build ./... and go vet ./....
  • Unit tests for sandbox/..., cmd/server, execution and deployment.
  • The touched integration tests, on a lane database.
  • Docker live tests against a freshly built sandbox image, and earlier against a Codex Runtime image too.
  • make check-e2b-provider, deploy/node tests, the microsandbox tool tests, -race on the changed packages.
  • make check-names check-docs check-ci.

View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

@SaladDay
SaladDay merged commit d9fd2f0 into aos/cutover Oct 8, 2026
@SaladDay
SaladDay deleted the aos/pr6b-provider branch October 8, 2026 11:14
Every Provider now starts oac-sandbox-io as the only process in a hosted
sandbox, and the Core-Sandbox Provider protocol shrinks to match.

- Bootstrap carries the Reference and the Sandbox I/O input only; RunCommand,
  RunCommandCompute, ErrCommandUnconfirmed and runtime_bootstrap.go go.
- The node wire, the E2B helper and the microsandbox helper lose the command
  operations and their 72 MiB input bound (now 1 MiB).
- Docker runs oac-sandbox-io as the container's entry point and writes only
  its bootstrap file; the nested_sandbox node option goes.
- E2B managed_init starts only oac-sandbox-io and records a
  sandbox_io_started receipt; the application-managed example goes.
- microsandbox's bootstrap starts only oac-sandbox-io.
- Core stops deriving a Runtime API URL for sandboxes.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant