Skip to content

feat(agent-sandbox): add NonoSandboxProvider via nono-py bindings - #3029

Merged
Imran Siddique (imran-siddique) merged 1 commit into
microsoft:mainfrom
SequeI:addNonoIntegration
Jun 15, 2026
Merged

Imran Siddique (imran-siddique) merged 1 commit into
microsoft:mainfrom
SequeI:addNonoIntegration

Conversation

@SequeI

@SequeI Aleks (SequeI) commented Jun 15, 2026 •

Copy link
Copy Markdown
Contributor

Description

Add a fifth OS native sandbox backend for Linux and macOS using the nono-py capability sandbox (Landlock / Seatbelt). The provider implements the existing SandboxProvider session contract: policy-driven config, host-side PolicyEvaluator gating, AST pre-scan, filtering network proxy for allowlisted egress, and one-shot sandboxed_exec per invocation with persistent session output/.

  • Add nono_sandbox_provider package (config, provider, lazy exports)
  • Add optional [nono] extra (nono-py>=0.10.1) and README provider docs
  • Add design proposal and runnable quickstart example with policy YAML
  • Add hermetic unit tests and opt-in integration tests (AGT_NONO_INTEGRATION=1)

cc Luke Hinds (@lukehinds)

Type of Change

  • Bug fix (non-breaking change that fixes an issue)
  • New feature (non-breaking change that adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Documentation update
  • Maintenance (dependency updates, CI/CD, refactoring)
  • Security fix

Package(s) Affected

  • agent-os-kernel
  • agent-mesh
  • agent-runtime
  • agent-sre
  • agent-governance
  • docs / root

Checklist

  • My code follows the project style guidelines (ruff check)
  • I have added tests that prove my fix/feature works
  • All new and existing tests pass (pytest)
  • I have updated documentation as needed
  • I have signed the Microsoft CLA

Attribution & Prior Art

  • This contribution does not contain code copied or derived from other projects without attribution
  • Any external projects that inspired this design are credited in code comments or documentation
  • If this PR implements functionality similar to an existing open-source project, I have listed it below

Prior art / related projects (if any):

AI Assistance

  • I can explain every meaningful change in this PR: what it does, why, and what tradeoffs were considered
  • I have run tests and verification appropriate for this change
  • No part of this PR was autonomously submitted by an AI agent without my review
  • I have not used AI to generate review comments on others' PRs

If AI tools materially shaped this change, briefly note what was used:

IP, Patents, and Licensing

  • This contribution does not implement patent-pending or patent-encumbered techniques
  • This contribution does not require an NDA or licensing agreement to understand or use
  • Any AI tools used have terms compatible with the MIT License

Related Issues

Add a fifth OS native sandbox backend for Linux and macOS using the
nono-py capability sandbox (Landlock / Seatbelt). The provider implements
the existing SandboxProvider session contract: policy-driven config,
host-side PolicyEvaluator gating, AST pre-scan, filtering network proxy
for allowlisted egress, and one-shot sandboxed_exec per invocation with
persistent session output/.

- Add nono_sandbox_provider package (config, provider, lazy exports)
- Add optional [nono] extra (nono-py>=0.10.1) and README provider docs
- Add design proposal and runnable quickstart example with policy YAML
- Add hermetic unit tests and opt-in integration tests (AGT_NONO_INTEGRATION=1)

Signed-off-by: Aleksy Siek <aleksy@alwaysfurther.ai>
@github-actions

Copy link
Copy Markdown

Welcome to the Agent Governance Toolkit! Thanks for your first pull request.
Please ensure tests pass, code follows style (ruff check), and you have signed the CLA.
See our Contributing Guide.

@github-actions github-actions Bot added documentation Improvements or additions to documentation dependencies Pull requests that update a dependency file tests labels Jun 15, 2026
@github-actions

Copy link
Copy Markdown
🤖 AI Agent: security-scanner — View details

AI-generated review output. Treat it as untrusted analysis and verify before acting.

No security issues found.

@github-actions github-actions Bot added the size/XL Extra large PR (500+ lines) label Jun 15, 2026
@github-actions

Copy link
Copy Markdown
🤖 AI Agent: test-generator — `agent_sandbox/nono_sandbox_provider/__init__.py`

AI-generated review output. Treat it as untrusted analysis and verify before acting.

agent_sandbox/nono_sandbox_provider/__init__.py

  • test_nono_provider_initialization -- Validate initialization of NonoSandboxProvider with and without the nono-py dependency.
  • test_run_once_execution -- Test the run_once method for correct execution and output handling.
  • test_create_session_with_tool_allowlist -- Ensure create_session fails when a non-empty tool_allowlist is provided.
  • test_policy_enforcement -- Verify that policies (e.g., network_allowlist) are correctly enforced during execution.
  • test_is_available -- Confirm that is_available correctly identifies supported platforms (Linux/macOS with required kernel features).

@github-actions

Copy link
Copy Markdown
🤖 AI Agent: contributor-guide — View details

AI-generated review output. Treat it as untrusted analysis and verify before acting.

Welcome, and thank you for contributing! Great job on the detailed implementation and documentation for the new NonoSandboxProvider.

Before merging, please address the following:

  1. Ensure all new files pass linting (e.g., ruff check) and tests (pytest).
  2. Verify that the added dependency nono-py is compatible with the project's requirements and licensing.
  3. Confirm that the design proposal file NONO-SANDBOX-PROVIDER.md is included in the repository.

For guidance, refer to CONTRIBUTING.md.

@github-actions

Copy link
Copy Markdown
🤖 AI Agent: code-reviewer — Action items:

AI-generated review output. Treat it as untrusted analysis and verify before acting.

TL;DR: 1 blocker, 2 warnings. The PR introduces a new NonoSandboxProvider for OS-native sandboxing but has a critical issue with insufficient validation of the PolicyDocument for the new provider.

# Sev Issue Where
1 Blocker Missing validation for PolicyDocument in NonoSandboxProvider, risking policy bypass. nono_sandbox_provider implementation
2 Warning nono-py dependency is marked as alpha; potential stability/security concerns. pyproject.toml
3 Warning Lack of integration tests for NonoSandboxProvider with PolicyDocument edge cases. Tests

Action items:

  1. Add robust validation for PolicyDocument in NonoSandboxProvider to ensure no policy bypasses occur.

Warnings (fine as follow-up PRs):

# Issue Where
2 Evaluate the stability and security of nono-py (alpha) before production use. pyproject.toml
3 Add integration tests for NonoSandboxProvider with edge-case PolicyDocument configurations. Tests

@github-actions

Copy link
Copy Markdown
🤖 AI Agent: docs-sync-checker — Docs Sync

AI-generated review output. Treat it as untrusted analysis and verify before acting.

Docs Sync

Documentation is in sync.

@github-actions

Copy link
Copy Markdown
🤖 AI Agent: breaking-change-detector — API Compatibility

AI-generated review output. Treat it as untrusted analysis and verify before acting.

API Compatibility

Severity Change Impact
High Added NonoSandboxProvider to the agent_sandbox package, which introduces a new sandbox backend that is only compatible with Linux and macOS. Existing users relying on the SandboxProvider interface may encounter runtime errors if they attempt to use NonoSandboxProvider on unsupported platforms or without the required nono-py dependency.
Medium NonoSandboxProvider rejects non-empty tool_allowlist configurations at session creation. This behavior differs from other providers, which may lead to unexpected errors for users attempting to use tool_allowlist with this provider.
Medium NonoSandboxProvider delegates max_cpu and max_memory_mb enforcement to the OS. Users relying on these configurations for resource caps may experience inconsistent behavior compared to other providers.

@github-actions

Copy link
Copy Markdown

PR Review Summary

Check Status Details
🔍 Code Review ⚠️ Missing No current-run comment
🛡️ Security Scan ⚠️ Missing No current-run comment
🔄 Breaking Changes ⚠️ Missing No current-run comment
📝 Docs Sync ⚠️ Missing No current-run comment
🧪 Test Coverage ⚠️ Missing No current-run comment

Verdict: ⚠️ AI review incomplete; ready for human review

AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims.

@SequeI

Copy link
Copy Markdown
Contributor Author

@microsoft-github-policy-service agree company="Always Further"

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed. Good first contribution — the fail-closed posture on tool_allowlist is the right call (refuse at session creation rather than silently ignoring), lazy import consistent with other optional providers, and the quickstart covers the important security scenarios (FS isolation, network blocking, AST scan, policy gate). Production-readiness caveat in the README is appropriately honest about nono-py Alpha status. Merging.

@imran-siddique
Imran Siddique (imran-siddique) merged commit 4ed57d1 into microsoft:main Jun 15, 2026
32 of 33 checks passed
Imran Siddique (imran-siddique) added a commit that referenced this pull request Jun 15, 2026
* fix(ci): add tzdata, pyatr, nono-py to dep-confusion allowlist

All three are registered PyPI packages flagged after recent merges:
- tzdata: IANA tz database (Windows tz support in agent-os)
- pyatr: AGT audit trail record library (acs-atr-annotator example, PR #3025)
- nono-py: OS-native sandbox bindings (agt-sandbox[nono], PR #3029)

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>

* fix(ci): add tzdata and pyatr to cspell allowlist

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>

---------

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
jlaportebot (jlaportebot) pushed a commit to jlaportebot/agent-governance-toolkit that referenced this pull request Jun 17, 2026
…crosoft#3029)

Add a fifth OS native sandbox backend for Linux and macOS using the
nono-py capability sandbox (Landlock / Seatbelt). The provider implements
the existing SandboxProvider session contract: policy-driven config,
host-side PolicyEvaluator gating, AST pre-scan, filtering network proxy
for allowlisted egress, and one-shot sandboxed_exec per invocation with
persistent session output/.

- Add nono_sandbox_provider package (config, provider, lazy exports)
- Add optional [nono] extra (nono-py>=0.10.1) and README provider docs
- Add design proposal and runnable quickstart example with policy YAML
- Add hermetic unit tests and opt-in integration tests (AGT_NONO_INTEGRATION=1)

Signed-off-by: Aleksy Siek <aleksy@alwaysfurther.ai>
Signed-off-by: jlaportebot <jlaportebot@gmail.com>
jlaportebot (jlaportebot) pushed a commit to jlaportebot/agent-governance-toolkit that referenced this pull request Jun 17, 2026
…soft#3033)

* fix(ci): add tzdata, pyatr, nono-py to dep-confusion allowlist

All three are registered PyPI packages flagged after recent merges:
- tzdata: IANA tz database (Windows tz support in agent-os)
- pyatr: AGT audit trail record library (acs-atr-annotator example, PR microsoft#3025)
- nono-py: OS-native sandbox bindings (agt-sandbox[nono], PR microsoft#3029)

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>

* fix(ci): add tzdata and pyatr to cspell allowlist

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>

---------

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
Signed-off-by: jlaportebot <jlaportebot@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file documentation Improvements or additions to documentation size/XL Extra large PR (500+ lines) tests

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants