Repository navigation
feat(agent-sandbox): add NonoSandboxProvider via nono-py bindings - #3029
Conversation
Add a fifth OS native sandbox backend for Linux and macOS using the nono-py capability sandbox (Landlock / Seatbelt). The provider implements the existing SandboxProvider session contract: policy-driven config, host-side PolicyEvaluator gating, AST pre-scan, filtering network proxy for allowlisted egress, and one-shot sandboxed_exec per invocation with persistent session output/. - Add nono_sandbox_provider package (config, provider, lazy exports) - Add optional [nono] extra (nono-py>=0.10.1) and README provider docs - Add design proposal and runnable quickstart example with policy YAML - Add hermetic unit tests and opt-in integration tests (AGT_NONO_INTEGRATION=1) Signed-off-by: Aleksy Siek <aleksy@alwaysfurther.ai>
|
Welcome to the Agent Governance Toolkit! Thanks for your first pull request. |
🤖 AI Agent: security-scanner — View details
No security issues found. |
🤖 AI Agent: test-generator — `agent_sandbox/nono_sandbox_provider/__init__.py`
|
🤖 AI Agent: contributor-guide — View details
Welcome, and thank you for contributing! Great job on the detailed implementation and documentation for the new Before merging, please address the following:
For guidance, refer to CONTRIBUTING.md. |
🤖 AI Agent: code-reviewer — Action items:
TL;DR: 1 blocker, 2 warnings. The PR introduces a new
Action items:
Warnings (fine as follow-up PRs):
|
🤖 AI Agent: docs-sync-checker — Docs Sync
Docs SyncDocumentation is in sync. |
🤖 AI Agent: breaking-change-detector — API Compatibility
API Compatibility
|
PR Review Summary
Verdict: AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims. |
|
@microsoft-github-policy-service agree company="Always Further" |
Imran Siddique (imran-siddique)
left a comment
There was a problem hiding this comment.
Reviewed. Good first contribution — the fail-closed posture on tool_allowlist is the right call (refuse at session creation rather than silently ignoring), lazy import consistent with other optional providers, and the quickstart covers the important security scenarios (FS isolation, network blocking, AST scan, policy gate). Production-readiness caveat in the README is appropriately honest about nono-py Alpha status. Merging.
4ed57d1
into
microsoft:main
* fix(ci): add tzdata, pyatr, nono-py to dep-confusion allowlist All three are registered PyPI packages flagged after recent merges: - tzdata: IANA tz database (Windows tz support in agent-os) - pyatr: AGT audit trail record library (acs-atr-annotator example, PR #3025) - nono-py: OS-native sandbox bindings (agt-sandbox[nono], PR #3029) Signed-off-by: Imran Siddique <imran.siddique@opaque.co> * fix(ci): add tzdata and pyatr to cspell allowlist Signed-off-by: Imran Siddique <imran.siddique@opaque.co> --------- Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
…crosoft#3029) Add a fifth OS native sandbox backend for Linux and macOS using the nono-py capability sandbox (Landlock / Seatbelt). The provider implements the existing SandboxProvider session contract: policy-driven config, host-side PolicyEvaluator gating, AST pre-scan, filtering network proxy for allowlisted egress, and one-shot sandboxed_exec per invocation with persistent session output/. - Add nono_sandbox_provider package (config, provider, lazy exports) - Add optional [nono] extra (nono-py>=0.10.1) and README provider docs - Add design proposal and runnable quickstart example with policy YAML - Add hermetic unit tests and opt-in integration tests (AGT_NONO_INTEGRATION=1) Signed-off-by: Aleksy Siek <aleksy@alwaysfurther.ai> Signed-off-by: jlaportebot <jlaportebot@gmail.com>
…soft#3033) * fix(ci): add tzdata, pyatr, nono-py to dep-confusion allowlist All three are registered PyPI packages flagged after recent merges: - tzdata: IANA tz database (Windows tz support in agent-os) - pyatr: AGT audit trail record library (acs-atr-annotator example, PR microsoft#3025) - nono-py: OS-native sandbox bindings (agt-sandbox[nono], PR microsoft#3029) Signed-off-by: Imran Siddique <imran.siddique@opaque.co> * fix(ci): add tzdata and pyatr to cspell allowlist Signed-off-by: Imran Siddique <imran.siddique@opaque.co> --------- Signed-off-by: Imran Siddique <imran.siddique@opaque.co> Signed-off-by: jlaportebot <jlaportebot@gmail.com>
Description
Add a fifth OS native sandbox backend for Linux and macOS using the nono-py capability sandbox (Landlock / Seatbelt). The provider implements the existing SandboxProvider session contract: policy-driven config, host-side PolicyEvaluator gating, AST pre-scan, filtering network proxy for allowlisted egress, and one-shot sandboxed_exec per invocation with persistent session output/.
cc Luke Hinds (@lukehinds)
Type of Change
Package(s) Affected
Checklist
Attribution & Prior Art
Prior art / related projects (if any):
AI Assistance
If AI tools materially shaped this change, briefly note what was used:
IP, Patents, and Licensing
Related Issues