Refuse a network-off run that cannot be sealed before it spends - #2036
Merged
Merged
Conversation
ppXD
force-pushed
the
fix/seal-a-network-off-run-to-its-broker
branch
from
September 26, 2026 23:54
eb9be4b to
66df2db
Compare
ppXD
force-pushed
the
fix/refuse-a-network-off-run-that-cannot-be-sealed
branch
from
September 27, 2026 00:04
c984ba6 to
fc9ebfb
Compare
ppXD
force-pushed
the
fix/seal-a-network-off-run-to-its-broker
branch
from
September 27, 2026 00:44
66df2db to
f430284
Compare
ppXD
force-pushed
the
fix/refuse-a-network-off-run-that-cannot-be-sealed
branch
from
September 27, 2026 00:53
fc9ebfb to
0230dd3
Compare
ppXD
force-pushed
the
fix/seal-a-network-off-run-to-its-broker
branch
from
September 27, 2026 01:26
f430284 to
9f4394f
Compare
ppXD
force-pushed
the
fix/refuse-a-network-off-run-that-cannot-be-sealed
branch
from
September 27, 2026 01:32
0230dd3 to
3a12635
Compare
ppXD
force-pushed
the
fix/seal-a-network-off-run-to-its-broker
branch
from
September 27, 2026 02:00
9f4394f to
f71bbf6
Compare
ppXD
force-pushed
the
fix/refuse-a-network-off-run-that-cannot-be-sealed
branch
from
September 27, 2026 02:04
3a12635 to
2792bdc
Compare
ppXD
force-pushed
the
fix/seal-a-network-off-run-to-its-broker
branch
from
September 27, 2026 02:54
f71bbf6 to
3aaa4bb
Compare
ppXD
force-pushed
the
fix/refuse-a-network-off-run-that-cannot-be-sealed
branch
from
September 27, 2026 03:01
2792bdc to
3bea2fb
Compare
ppXD
force-pushed
the
fix/seal-a-network-off-run-to-its-broker
branch
from
September 27, 2026 08:16
3aaa4bb to
0baf9a0
Compare
ppXD
force-pushed
the
fix/refuse-a-network-off-run-that-cannot-be-sealed
branch
from
September 27, 2026 08:16
3bea2fb to
1b65519
Compare
ppXD
force-pushed
the
fix/seal-a-network-off-run-to-its-broker
branch
from
September 27, 2026 09:10
0baf9a0 to
d3c6729
Compare
ppXD
force-pushed
the
fix/refuse-a-network-off-run-that-cannot-be-sealed
branch
from
September 27, 2026 09:10
1b65519 to
567b4bd
Compare
ppXD
changed the base branch from
fix/seal-a-network-off-run-to-its-broker
to
main
September 27, 2026 10:03
On a host that confines but cannot seal, a network-off brokered run was severed from its broker along with everything else. It then burned its whole timeout and the CLI's retries on failures that read like a provider outage. The runner now gains an optional admission capability. The executor asks it once the spec is final, before local acceptance is prepared, spend is admitted or a process starts. The local runner refuses such a spec under sandbox_sealed_egress_unavailable, naming the wall: missing ip/nft, no privilege to build a namespace, or a broker that could only bind loopback. The broker lease now says whether it bound where a namespace can reach it. A sealed setup that still fails at launch is retyped to the same refusal, with a remedy of its own: fix what the failed step names, since granting privileges or waiting for a re-probe cannot help a host that can already seal. The code joins the infra exit reasons with its own supervisor remedy: retry once in case another worker can seal, then ask a human. The headline lane installs iproute2 and nftables, so its brokered agents are sealed rather than refused.
ppXD
force-pushed
the
fix/refuse-a-network-off-run-that-cannot-be-sealed
branch
from
September 27, 2026 10:03
567b4bd to
76f67cf
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
AgentAutonomyPolicy.cs, the shape its network doc describes). Such a run is now refused before it spends anything, withsandbox_sealed_egress_unavailable.ISandboxEgressAdmission(Rule 7: a sibling interface, not a widerISandboxRunner). The executor calls it once the spec is final, before local acceptance is prepared, spend is admitted or a process starts.LocalProcessRunner.EnsureEgressAdmissiblerefuses only a spec that carries a broker port on a host that confines. The refusal names one of three causes:ip/nftmissing, no privilege to build a namespace, or a broker that could only bind loopback. Every other spec is admitted untouched, including unbrokered network-off runs, which have no model to reach.BrokeredModelCredential.ReachableFromNamespacerecords whether the lease took the wide bind. Its default is false, so an unknown answer fails closed.InvalidOperationException.FailureCodes.InfraExitReasonsand gets its own supervisor remedy inLlmSupervisorDecider.EndedByDeploymentSteer: retry once in case another worker can seal, thenask_human.backend-e2e.yml) is already root and privileged; it now also installsiproute2 nftables, so any brokered agent there is sealed instead of refused. It has no allowlist tests, so nothing else there changes.SealedEgressUnavailableException.SetupFailed): fix what the step names, since every launch runs the setup afresh. It is not told to grant privileges or wait for a re-probe, neither of which would help.FilteredEgressNetns.SealUnavailableReason). Because a probe failure can be transient, the remedy now says a retry on the host helps once it can build a namespace, which it re-checks at most once a minute.Test plan
SealedEgressAdmissionTests: each cause, including the admitted case.FailureTaxonomyTests: literal code, and the infra set member by member.SupervisorDeciderTests: the steer arm, byte for byte.ModelCredentialBrokerTests:ReachableFromNamespacematches whether the wide bind is tried.A_sealed_setup_that_fails_on_this_host_refuses_the_launch_typed_and_leaks_nothing. It occupies the host veth name so the plan's ownip link addfails, then checks that the durable launch refuses typed, the refusal names the failed step, and no namespace is left behind.SealedEgressAdmissionTestspins the setup-failure remedy: same code, the failed step's own error as the cause, and neither the Dockerfile nor the probe interval in the message.