document native Landlock evolution

This commit is contained in:
Ollie Agent 2026-08-18 12:41:32 +02:00
parent 8e472a07d9
commit b7511eb089
1 changed files with 24 additions and 2 deletions

View File

@ -1801,7 +1801,29 @@ The KDE GUI's `SessionModel` gained:
- Expand/collapse arrows for agents with children
### Bug Fix: ollie-9p UNAME Fallback
`ollie-9p` previously required `$OLLIE_UNAME` when `$OLLIE_SESSION_ID` was set,
making it unusable from non-agent contexts. The fallback to `$USER` was added,
allowing normal users to read session files like `goal` and `goalstatus`.
allowing normal users to read session files like `goal` and `goalstatus`.
## Phase 32: Native Landlock and Remote Deployment Simplification (Current)
Sandbox enforcement moved from an external sandbox executable into the
`toolsrv` binary. The policy source remains the runtime `sandbox.yaml`, so
permissions can still change without recompiling or redeploying the policy.
Each restricted tool execution starts a short-lived `sandbox-exec` helper mode
inside `toolsrv`. The helper loads the policy snapshot, sets `no_new_privs`,
creates a Landlock ruleset, grants the configured filesystem permissions, and
executes the tool. Restrictions are applied to the child rather than the
long-lived toolsrv process because Landlock rules are inherited and cannot be
removed.
The external sandbox dependency was removed from local and remote execution.
Remote bootstrap now transfers only the toolsrv binary and runtime
configuration. It no longer locates, copies, or installs a separate sandbox
executable. Remote toolsrv instances enforce the same native policy on the
remote host, while `--yolo` remains the explicit way to disable enforcement.
The project was also described more precisely as a distributed, integrating AI
agent runtime: orchestration and model calls remain local while toolsrv,
tools, and external systems can be composed locally or across remote hosts.