* feat(sandbox): default to official Alpine sandbox image default_sandbox_image() now returns docker.io/library/alpine:3.22, a generic version-qualified official image, so a fresh install no longer depends on the community sandbox image catalog. All compute drivers (docker, podman, kubernetes, vm) inherit this fallback. Part of #3116. Signed-off-by: Akram Signed-off-by: Akram <akram.benaissi@gmail.com> * feat(deploy): default deployment configs to the official Alpine sandbox image Update the shared gateway default_image, Helm chart values, the standalone Kubernetes manifest, and the dev gateway task scripts to use docker.io/library/alpine:3.22 instead of the community base image, consistent with default_sandbox_image(). GPU e2e image-build base is left unchanged (CUDA needs a glibc base). Part of #3116. Signed-off-by: Akram Signed-off-by: Akram <akram.benaissi@gmail.com> * feat(driver): default to numeric non-root identity for USER-less images With the default sandbox image now Alpine, images that declare no OCI USER must start instead of being rejected. When the image declares no USER and the policy requests none, the Podman and Docker drivers now supply a numeric non-root identity (DEFAULT_SANDBOX_UID/GID = 1000) instead of rejecting, matching the numeric-identity behavior of the Kubernetes and VM drivers. The supervisor's resolved-identity path runs the sandbox as a synthesized non-root account without the account existing in the image. Images that declare a USER keep the OCI resolution path unchanged. Part of #3116. Signed-off-by: Akram <akram.benaissi@gmail.com> Signed-off-by: Evan Lezar <elezar@nvidia.com> * test(conformance): use Alpine workload image Signed-off-by: Evan Lezar <elezar@nvidia.com> * refactor(policy): drop community image /app path from default policy The restrictive default policy granted read-only access to /app, a directory that only existed in the community base image. A generic Alpine default has no /app, so remove it. Landlock best-effort already ignores absent paths; this just stops advertising a community-specific layout in the default. Part of #3116. Signed-off-by: Akram Signed-off-by: Akram <akram.benaissi@gmail.com> * docs(config): document Alpine default images Signed-off-by: Evan Lezar <elezar@nvidia.com> * fix(podman): report early sandbox termination Signed-off-by: Evan Lezar <elezar@nvidia.com> * fix(podman): initialize rootless workspace ownership Signed-off-by: Evan Lezar <elezar@nvidia.com> * fix(sandbox): qualify NVIDIA Ubuntu default Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(podman): initialize rootful default workspace Signed-off-by: Drew Newberry <anewberry@nvidia.com> * feat(sftp): add native sandbox adapter Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(sftp): gate runtime helper support to Linux Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(sftp): support standard OpenSSH file operations Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(sftp): harden rename and special file handling Signed-off-by: Drew Newberry <anewberry@nvidia.com> * refactor(runtime): remove community image dependencies Signed-off-by: Drew Newberry <anewberry@nvidia.com> * test(e2e): build provider readiness tool fixture Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(e2e): use a dedicated Noble fixture for Docker tests Signed-off-by: Evan Lezar <elezar@nvidia.com> --------- Signed-off-by: Akram Signed-off-by: Akram <akram.benaissi@gmail.com> Signed-off-by: Evan Lezar <elezar@nvidia.com> Signed-off-by: Drew Newberry <anewberry@nvidia.com> Co-authored-by: Evan Lezar <elezar@nvidia.com> Co-authored-by: Drew Newberry <anewberry@nvidia.com>
6.6 KiB
Gator Agent
Launch a headless sandbox agent that runs the gator-gate skill against OpenShell issues and pull requests. The default and currently only supported harness is Codex.
Prerequisites
ghis authenticated on the host and has access toNVIDIA/OpenShell.- For
--harness codex,codex loginhas created$HOME/.codex/auth.json. - For
--harness codex, local Codex auth must include an access token, refresh token, and account ID. - A local gateway and either Docker or Podman are available to build the default sandbox image.
Usage
./scripts/agents/run.sh \
--agent gator \
--gateway docker-dev \
--harness codex \
"Run gator on PR 1536 and keep watching until it closes or merges."
By default the launcher uses scripts/agents/gator/Dockerfile as the sandbox image source. It builds scripts/agents/gator/ as the image context, so gator-specific image files such as policy.yaml and bin/gh stay with the gator agent. The launcher bakes rendered prompts, skills, subagents, and shared runtime files into /etc/openshell/agent-payload, then passes the resulting image reference to openshell sandbox create.
The launcher queries the selected gateway and builds with its Docker or Podman
compute driver. If CONTAINER_ENGINE is set, it must match that driver. Other
gateway drivers cannot run this local-image launcher.
Use --harness codex to select Codex explicitly. Other harness names are rejected until their support is added to agent.yaml and scripts/agents/runtime/harnesses/<name>/. Agent directories do not carry their own harness implementations; they provide prompt templates and optional skills or subagents for the shared runtime to inject.
Use --codex-bin "$(command -v codex)" only when the host executable is compatible with the sandbox OS and architecture.
The manifest-driven launcher at scripts/agents/run.sh reads agent.yaml, which defines the versioned immutable payload, prompt template, provider profile IDs, provider credential sources, gateway settings, skills, subagents, supporting resources, sandbox defaults, runtime mode, and harness defaults. The shared sandbox entrypoint at scripts/agents/runtime/entrypoint.sh starts the in-sandbox supervisor, which invokes the selected harness adapter for bounded cycles.
The launcher:
- Scans
profile_pathsin manifest order and imports or updatesproviders/github-gator.yaml. - Creates or updates the
github-gatorprovider fromgh auth token. - Selects the requested harness and bakes the common runtime into the immutable sandbox payload.
- For
--harness codex, importsproviders/codex-gator.yaml, creates or updates thecodex-gatorprovider from$HOME/.codex/auth.json, and stores the refresh token as gateway-only refresh material. - For
--harness codex, configures gateway-managed refresh forCODEX_AUTH_ACCESS_TOKENand rotates it before launching the sandbox. - Enables
agent_policy_proposals_enabledandproposal_approval_mode=autoat gateway scope. - Uses the gator image policy copied to
/etc/openshell/policy.yaml. - Installs the gator-specific
ghwrapper fromgator/bin/ghas/usr/local/bin/ghto fail closed when same-head-SHA history cannot be checked, prevent duplicate dispositions, and require versioned review payloads. - Installs
gator/bin/review-feedback-ledgeras/usr/local/bin/review-feedback-ledgerso reviews receive tree- and patch-aware scope, prior summaries and findings, resolution state, convergence telemetry, and the three-round Warning budget. - Installs
gator/bin/resolve-gator-review-threadsso a follow-up commit that demonstrably fixes a Gator inline finding can resolve the corresponding Gator-owned GitHub review thread without touching human review threads. - Installs
gator/bin/validate-review-findingsto downgrade blockers that lack the required reachability, ownership, base-vs-head, impact, and reproducer evidence. - Keeps that normalized evidence as Gator's internal review contract, then renders validated blockers for people as a read-aloud
Summary, an actionableFix, and a deterministicVerify. Exact paths and only the additional provenance an implementation agent needs appear in collapsedAgent context; raw evidence headings such asBaseandHeadare not posted publicly. Review-process provenance, docs and E2E disposition, SHAs, and state codes appear at the end of the summary in collapsedGator metadata, while required human actions remain visible. - Bakes
scripts/agents/gator/skills/gator-gate/SKILL.mdinto/etc/openshell/agent-payload. - Bakes
.claude/agents/principal-engineer-reviewer.mdso the selected harness can run a deterministic independent reviewer execution through/etc/openshell/agent-payload/runtime/subagent.sh principal-engineer-reviewer < task.md. - For
--harness codex, optionally bakes a host Codex executable as/etc/openshell/agent-payload/runtime/harnesses/codex/codex. - Starts the selected harness without a TTY.
- Runs gator in
watchmode by default. The sandbox stays alive while the supervisor sleeps between bounded Codex cycles, so Codex is not connected during passive PR waits. The supervisor prints periodic heartbeat lines during active cycles and passive sleeps. - Makes each watch cycle compare its immutable payload version with the version published on the default branch. A stale watcher stops without GitHub writes and must be relaunched.
The GitHub provider profile allows read-only GraphQL queries on
api.github.com/graphqlsoghread paths can use GraphQL when needed. Its only GraphQL mutation is the namedResolveGatorReviewThreadoperation, restricted to theresolveReviewThreadroot field. All other writes remain REST-only and scoped to the two allowed repositories.
Set GATOR_CODEX_ACCESS_CREDENTIAL_KEY or pass --codex-access-key if the gator Codex profile uses a credential key other than CODEX_AUTH_ACCESS_TOKEN for the short-lived access token.
Use --once for a single reconciliation cycle. Use --poll-interval <seconds> to change the default 15-minute watch cadence.
The launcher preserves existing gateway-owned Codex refresh material by default so multiple gator sandboxes do not overwrite each other's refresh-token lineage from host Codex auth. If gateway rotation fails, the launcher automatically resets gateway refresh material from host Codex auth and retries once. After codex logout && codex login, you can also pass --reset-refresh to force that reset before rotation.
Tests
bash scripts/agents/gator/bin/gh_guard_test.sh
bash scripts/agents/gator/bin/review_feedback_ledger_test.sh
bash scripts/agents/gator/bin/resolve_gator_review_threads_test.sh
bash scripts/agents/runtime/harnesses/codex/exec_test.sh