g1t/services/runner/src/guard.ts
Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 1 | /** |
| 2 | * Guardrails, as the runner applies them to a sandbox: what it may reach, | |
| 3 | * what its harness refuses, and how long and how much a run may take. | |
| 4 | * | |
| 5 | * - The network list is enforced here, outside the sandbox: a guarded | |
| 6 | * sandbox starts with no internet, and every HTTP(S) request it makes | |
| 7 | * comes to `egress` below, which forwards it or refuses it. | |
| 8 | * - Command rules and the cost cap are handed to the harness inside the | |
| 9 | * sandbox as `GUARDRAILS`, which applies them to the agent. | |
| 10 | * - The time cap is enforced twice: by the harness, and by the sandbox's | |
| 11 | * own alarm here, which stops the whole sandbox a little after. | |
| 12 | */ | |
| 13 | import type { OutboundHandlerContext } from "@cloudflare/containers"; | |
| 14 | ||
| 15 | import { type RepoPath, type RunKind, type ServiceBinding, guardrailsClient } from "@g1t/contracts"; | |
| 16 | ||
| 17 | import { type ModelHosts, type RunGuard, allows, refusal, sandboxHosts } from "./egress"; | |
| 18 | ||
| 19 | export { harnessEnv, newlyBlocked, timeCapMessage } from "./egress"; | |
| 20 | export type { RunGuard } from "./egress"; | |
| 21 | ||
| 22 | /** What the outbound handler is given: the hosts this sandbox may reach. */ | |
| 23 | export type EgressParams = { hosts: string[] }; | |
| 24 | ||
| 25 | /** The stop by the sandbox's alarm comes this long after the harness's own. */ | |
| 26 | export const ALARM_GRACE_SECONDS = 3 * 60; | |
| 27 | ||
| 28 | /** | |
| 29 | * The guardrails of a run in `repo`. Throws when they cannot be read: a | |
| 30 | * sandbox is not started without them. | |
| 31 | */ | |
| 32 | export async function guardFor(work: ServiceBinding, repo: RepoPath, kind: RunKind): Promise<RunGuard> { | |
| 33 | const found = await guardrailsClient(work).runGuardrails(repo); | |
| 34 | if (!found.ok) throw new Error(`g1t could not read this project's guardrails: ${found.error.message}`); | |
| 35 | const policy = found.value; | |
| 36 | return { policy, minutes: policy.minutes[kind] ?? 60 }; | |
| 37 | } | |
| 38 | ||
| 39 | /** Every host the sandbox may reach, for the outbound handler. */ | |
| 40 | export function egressHosts(guard: RunGuard, env: ModelHosts, sandboxEnv: Record<string, string>): string[] { | |
| 41 | return sandboxHosts(guard.policy.hosts, env, sandboxEnv); | |
| 42 | } | |
| 43 | ||
| 44 | /** | |
| 45 | * The outbound handler of a guarded sandbox: every HTTP and HTTPS request | |
| 46 | * it makes. An allowed host is fetched as asked; any other is refused, and | |
| 47 | * the sandbox told so it can say so on the run. | |
| 48 | */ | |
| 49 | export async function egress( | |
| 50 | request: Request, | |
| 51 | env: { SANDBOX: DurableObjectNamespace }, | |
| 52 | ctx: OutboundHandlerContext<EgressParams>, | |
| 53 | ): Promise<Response> { | |
| 54 | const host = new URL(request.url).host; | |
| 55 | if (allows(ctx.params?.hosts ?? [], host)) return fetch(request); | |
| 56 | try { | |
| 57 | const sandbox = env.SANDBOX.get(env.SANDBOX.idFromString(ctx.containerId)) as unknown as { | |
| 58 | noteBlocked(host: string): Promise<void>; | |
| 59 | }; | |
| 60 | await sandbox.noteBlocked(host); | |
| 61 | } catch (error) { | |
| 62 | console.log("blocked host not reported", host, String(error)); | |
| 63 | } | |
| 64 | return refusal(host); | |
| 65 | } | |
| 66 | ||
| 67 | /** Adds a step to a run, with its token. Never fails the caller. */ | |
| 68 | export async function reportRun( | |
| 69 | work: ServiceBinding, | |
| 70 | tracked: { runId: string; token: string }, | |
| 71 | report: { steps?: string[]; halt?: "budget" | "time"; error?: string }, | |
| 72 | ): Promise<void> { | |
| 73 | await work | |
| 74 | .fetch("https://service/rpc/report_run", { | |
| 75 | method: "POST", | |
| 76 | headers: { "content-type": "application/json" }, | |
| 77 | body: JSON.stringify({ runId: tracked.runId, token: tracked.token, ...report }), | |
| 78 | }) | |
| 79 | .catch((error: unknown) => console.log("run report failed", tracked.runId, String(error))); | |
| 80 | } | |
| 81 |