-
Notifications
You must be signed in to change notification settings - Fork 1
Expand file tree
/
Copy pathforge-sandbox.loop
More file actions
34 lines (32 loc) · 1.58 KB
/
Copy pathforge-sandbox.loop
File metadata and controls
34 lines (32 loc) · 1.58 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
# examples/forge-sandbox.loop — how Forge's sandbox runner was built with LoopFlow.
# Forge is a ticket-driven implementation platform; this module runs agent-written
# code in isolation. Built one provable stage at a time — a failing stage halts the rest.
# The isolation this module enforces is also declared here as config (not just prose),
# so the loop that builds it runs under the same constraints, as an auditable identity.
sandbox:
no network access
allow egress to "registry.npmjs.org" only
cap cpu at 2 cores, memory at 4g, time at 10m
cannot reach the host filesystem or cloud metadata
runs as: forge-sandbox-bot
pipeline "forge sandbox runner":
stage isolate:
goal: every run gets a fresh, network-less container with CPU and memory caps
look at: the runner service and the container config, and the last failure
each cycle: plan, then act, then observe
done when "pnpm test sandbox/isolation" passes
when it fails: reflect, then plan again
after 6 tries: stop and warn "isolation thrashing"
stage execute:
goal: run agent code, capture stdout, stderr and exit code, kill on timeout
each cycle: act, then observe
done when "pnpm test sandbox/execute" passes
stage harden:
goal: no container escape, no host filesystem or cloud-metadata access
also: a security scan
done when "pnpm test sandbox/security" passes
a human approves before enabling network egress
stage integrate:
goal: a real ticket's generated code runs end to end inside the sandbox
done when "pnpm test:e2e sandbox" passes
a human reviews before stopping