Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
14 changes: 13 additions & 1 deletion architecture/sandbox.md
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,19 @@ or backend-admin authority.

The compute driver provisions separate protected configurations and one
mutually authenticated gRPC connection over a private Unix socket, Kubernetes
TCP Service, or VM vsock channel. Independent bidirectional `Exchange` RPCs
TCP Service, or VM vsock channel. The sandbox listener presents a server
certificate only; the supervisor authenticates every RPC with an EdDSA session
bearer bound to the sandbox, runtime generation, and credential epoch. The
Unix socket is reachable by same-UID workload processes because Landlock does
not govern `connect()` on a filesystem socket, so the sandbox rejects peers
inside its own PID namespace that are not the sandbox or one of its ancestors
before TLS, charges a bounded control-connection slot only after the first
accepted bearer, and closes connections that present no valid bearer within a
short deadline. Unauthenticated gRPC transports have a separate bounded pool.
When it is full, a new connection closes the oldest waiting peer and holds a
handshake permit until the closed peer releases its pool permit. The same
unauthenticated deadline covers that wait. Independent
bidirectional `Exchange` RPCs
carry lifecycle, exec, TCP, and forwarding traffic, while one persistent
bidirectional `Mediate` RPC carries multiplexed DNS traffic. General application
UDP is unsupported; UDP DNS remains mediated by the supervisor.
Expand Down
7 changes: 5 additions & 2 deletions crates/openshell-driver-docker/src/lib.rs
Original file line number Diff line number Diff line change
Expand Up @@ -4389,8 +4389,11 @@ fn docker_sandbox_bundle_archive(
".openshell/channel/sandbox",
// The sandbox owns this directory so it can consume bootstrap files
// and create the control socket. The separate non-root supervisor
// needs execute-only traversal to that known socket path; mutual TLS
// authenticates the endpoint and the files beneath remain 0600.
// needs execute-only traversal to that known socket path. The socket
// presents a server certificate only; the supervisor proves itself
// with the EdDSA session bearer on each RPC, and the sandbox rejects
// same-namespace workload peers before TLS. Files beneath stay 0600
// and are consumed at startup.
0o711,
identity.uid,
identity.gid,
Expand Down
Loading
Loading