| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
Sorry, something went wrong.
- templates/builder.ts: 8 vCPU / 8 GB Rust builder (Template SDK v2) - patches/landlock-abi2.patch: demo-only, accept Landlock ABI v2 on E2B's 6.1 kernel - scripts/build-binaries.ts: build patched openshell-sandbox + supervisor in E2B - driver/: Rust compute driver skeleton (handshake, empty list) on OpenShell v0.1.2 crates - scripts/connect.ts: private control sandbox, gateway + driver, wstunnel with traffic token + secret path + 10s heartbeat, mTLS CLI config - spikes/tunnel.ts: secure tunnel checks (token, path, throughput, idle)
…o works - driver: CreateSandbox/Delete/Get/List/Watch with NVIDIA's boundary types (boundary.rs), E2B via Node SDK helper (e2b.rs, e2b-helper.mjs) - templates/workload.ts + launch-sandbox.sh: netns (lo only) fence, PID ns, uid 1500 / zero caps / no_new_privs, policy DNS at 127.0.0.53, tmpfs for supervisor CA material - connect.ts: gateway JWT signing (ttl 3600), timeoutMs 0 for daemons, PID-file daemons, Node 24 for the helper Verified: sandbox Ready; curl GET api.github.com 200, POST 403 (read-only), unlisted host unresolvable, other binaries denied, OCSF audit entries.
…+ stopslop fixes - Cargo.toml [lints.clippy]: pedantic, nursery, unwrap_used/expect_used = deny - remove all unwrap/expect from the driver; supervisor args passed as OsStr - release the sandbox table lock before awaiting - TS: drop dotenv for node --env-file (npm scripts), timers/promises sleep - known and intentional: Stop/Start still unimplemented (antislop 'stub')
…d requests, keep record on failed delete, race-free watch, SIGTERM Findings from a gpt-6-astra review (read-only, secrets excluded): - wstunnel clients now pass --tls-verify-certificate (off by default in v11) - ValidateSandboxCreate/CreateSandbox reject other images and user namespaces - delete keeps the sandbox record until E2B confirms the kill; rollback kill failures are logged as errors - watch subscribes + snapshots under the table lock; lag ends the stream with an error instead of silently dropping events - driver shuts down on SIGTERM as well as SIGINT - comments reworded where they overstated guarantees
- templates/control.ts: openshell-control template (gateway, patched supervisor, driver, wstunnel, Node 24 + E2B SDK helper); no secrets baked in - connect.ts: reuse or create (--new) a private control box, initialise PKI, gateway config and driver credentials, start daemons, register the CLI. Cold start to connected CLI: ~12 s - scripts/demo.sh (npm run demo): create, isolation, default deny, GitHub read-only policy, GET 200 / POST 403 / wget denied, OCSF audit, delete
- media/demo.tape: waits on real output (Wait+Screen), narrated steps; renders media/demo.gif and media/demo.mp4 (1:45) - scripts/watch.ts (npm run watch): streams driver, gateway and supervisor logs from the control box, color-coded ALLOWED/DENIED
- health.rs: every 5 s check supervisor/tunnel processes, every 30 s check the E2B box exists; flip Ready=False with a reason and announce on watch - private_dir(): state dirs must be real dirs, owned by us, mode 0700; secret files opened with O_NOFOLLOW and forced to 0600; unit tests
- media/start.sh, tmux.conf, demo.bashrc, card.sh: two titled panes and chapter cards (gum); left is the stock openshell CLI on the laptop - watch.ts --compact: one short color-coded line per event; per-run marker file and remote cleanup so leftover watchers can't swallow new logs - re-recorded media/demo.mp4 + demo.gif (1080p, ~1:43)
- watch.ts: trap kills only its own jobs. 'kill 0' would kill envd, the gateway and the driver: every E2B command shares envd's process group - connect.ts: check PKI, gateway config and driver credentials separately so a half-finished init is completed; register the CLI gateway only if missing instead of swallowing errors - scripts/setup-bin.sh (npm run setup): download the openshell CLI + wstunnel
| Back | FazBrowse Home | New Git URL |
What
An external NVIDIA OpenShell compute driver that runs each agent in its own private E2B microVM.
demo.mp4Left: a laptop running the stock openshell CLI. Right: the live event feed from the E2B control plane.
How it works
laptop E2B control box (private) E2B agent box (private, one per sandbox) openshell CLI ═ tunnel 1 ═► gateway (NVIDIA) netns with loopback only (mTLS inside) ↕ unix socket openshell-sandbox (NVIDIA, patched) openshell-driver-e2b (this repo) ─E2B──► uid 1500, 0 capabilities, no_new_privs supervisor (NVIDIA) ══ tunnel 2 ════════► └ the agent policy + egress proxy → internetTry it
Verified
Review
Two rounds of external review (Codex, gpt-6-astra) plus a self-review. Fixed in this PR:
Limits (not production)