Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
55 commits
Select commit Hold shift + click to select a range
3a450d0
feat(layerstack): add baseline route observability
yifanxuaaa Jul 24, 2026
4d15cdf
feat(workspace): scope execution scratch to sessions
yifanxuaaa Jul 24, 2026
c996aa5
feat(layerstack): add portable root contract
yifanxuaaa Jul 24, 2026
cbe45de
chore(layerstack): remove stale guidance and artifacts
yifanxuaaa Jul 24, 2026
487ac4c
feat(layerstack): implement incremental publication
yifanxuaaa Jul 25, 2026
45ae438
feat(layerstack): implement candidate materialization
yifanxuaaa Jul 25, 2026
05faed4
fix(layerstack): stabilize candidate session I/O
yifanxuaaa Jul 25, 2026
a400863
perf: parallelize contiguous candidate writes
yifanxuaaa Jul 25, 2026
68c6e2b
perf: streamline candidate carrier durability
yifanxuaaa Jul 25, 2026
dd0b0cd
feat(layerstack): complete materialization GC alignment
yifanxuaaa Jul 26, 2026
4fef50e
feat(mpla-poc): freeze M0 scaffold interfaces
yifanxuaaa Jul 27, 2026
b48931a
feat(mpla-poc): implement stationary sealing core
yifanxuaaa Jul 27, 2026
2424592
feat(mpla-poc): add durable allocation ownership
yifanxuaaa Jul 27, 2026
e7b3176
feat(mpla-poc): qualify stationary overlay environment
yifanxuaaa Jul 27, 2026
35bf14a
test(mpla-poc): add physical M0 falsifiers
yifanxuaaa Jul 27, 2026
4889350
fix(mpla-poc): reap adopted process trees
yifanxuaaa Jul 27, 2026
650ef44
feat(mpla-poc): freeze M1 shared contract
yifanxuaaa Jul 27, 2026
484c119
feat(mpla-poc): add activation and resource controls
yifanxuaaa Jul 27, 2026
ff5d0ae
feat(mpla-poc): seal and verify evidence manifests
yifanxuaaa Jul 27, 2026
4a72901
feat(mpla-poc): add deterministic fixture generator
yifanxuaaa Jul 27, 2026
5b36086
Add matched current I2 controls
yifanxuaaa Jul 27, 2026
704d9b4
Implement durable locator ref recovery
yifanxuaaa Jul 27, 2026
1ce0466
Enforce locator parent preconditions
yifanxuaaa Jul 27, 2026
2cd67cd
feat(mpla-poc): add bounded semantic builder and oracle
yifanxuaaa Jul 27, 2026
9554d5f
feat(mpla-poc): add smoke lifecycle dispatcher
yifanxuaaa Jul 27, 2026
0715dc1
feat(mpla-poc): add authenticated receipt-hit sealing
yifanxuaaa Jul 27, 2026
1e6295c
Add bounded affected-path receipt scanner
yifanxuaaa Jul 27, 2026
1898576
Add measured M1 smoke campaign
yifanxuaaa Jul 27, 2026
f8f745e
Persist bound product catalog evidence
yifanxuaaa Jul 27, 2026
a5f362f
Create semantic spool parent for smoke campaign
yifanxuaaa Jul 27, 2026
759cf39
Fix smoke overlay lower layers
yifanxuaaa Jul 27, 2026
5bf0aee
Use permanent payload allocation arena in smoke suite
yifanxuaaa Jul 27, 2026
f7d6d6d
Fix M1 cgroup isolation and semantic object fanout
yifanxuaaa Jul 27, 2026
addc2d3
feat(mpla-poc): freeze M2 checkpoint
yifanxuaaa Jul 27, 2026
582f82b
feat(mpla-poc): add M2 promotion and locator replacement
yifanxuaaa Jul 27, 2026
0d6c501
feat(mpla-poc): add overload crash and evacuation coverage
yifanxuaaa Jul 27, 2026
09c2700
test(mpla-poc): add M2 heavy scale harness
yifanxuaaa Jul 27, 2026
ba89191
test(mpla-poc): add lead heavy campaign dispatch
yifanxuaaa Jul 27, 2026
d49c44b
test(mpla-poc): record M2 public runtime envelope
yifanxuaaa Jul 27, 2026
90f05f2
mpla: freeze M2R corrective interface
yifanxuaaa Jul 27, 2026
24bef8c
mpla: bind storage authority to public session
yifanxuaaa Jul 27, 2026
b75185a
mpla: package scoped storage administrator
yifanxuaaa Jul 27, 2026
7a09c46
feat(mpla): add scoped storage admin authority
yifanxuaaa Jul 27, 2026
0662341
fix(mpla): wire HV-07 durable operation edges
yifanxuaaa Jul 27, 2026
41888fb
fix(mpla): bind storage authority to public runtime
yifanxuaaa Jul 27, 2026
5d9a8c9
docs: improve SEO and GEO discovery
yifanxuaaa Jul 28, 2026
d3fd608
feat(mpla): add public lifecycle choreography
yifanxuaaa Jul 28, 2026
1b2f930
fix(mpla): select poc binary in wrapper
yifanxuaaa Jul 28, 2026
362cc54
fix(mpla): isolate M3 gateway recovery
yifanxuaaa Jul 28, 2026
a2be126
fix(mpla): prepare Docker lifecycle environment
yifanxuaaa Jul 28, 2026
20fe576
feat(runtime): bind MPLA overlay mount authority
yifanxuaaa Jul 28, 2026
3008c4f
fix(layerstack): satisfy strict materialization clippy
yifanxuaaa Jul 28, 2026
1142918
fix(mpla-poc): use conventional oracle module layout
yifanxuaaa Jul 28, 2026
ea39857
fix(xtask): map MPLA runtime package
yifanxuaaa Jul 28, 2026
82255cd
fix(xtask): align architecture policy with current tree
yifanxuaaa Jul 28, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
1 change: 1 addition & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -34,6 +34,7 @@ target-linux-container-gnu/
/e2e/**/test-reports/
/e2e/repo/eos-shared-workspace-base-cache/
.cache/
.seo-cache/
.omc/
**/.omc/
/docs/class_inventory/
Expand Down
2 changes: 0 additions & 2 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,8 +5,6 @@ rules.

## Required rules

- Always work, commit, and push directly on `main`. Do not create side branches
(including `agent/*`) or additional git worktrees.
- Rebuild the Docker sandbox gateway binary with
`bin/start-sandbox-docker-gateway --rebuild-binary`.
- Use `sandbox-manager-cli`, `sandbox-runtime-cli`, and
Expand Down
4 changes: 0 additions & 4 deletions CLAUDE.md
Original file line number Diff line number Diff line change
Expand Up @@ -34,10 +34,6 @@ compiles.
- **Parallel workers.** Other agents may be editing this repo concurrently. Only
touch what your task requires, never revert or overwrite changes you did not
make, and prefer additive, localized edits.
- **Work on `main`.** Always work, commit, and push directly on the `main`
branch. Never create side branches (including `agent/*`) or additional git
worktrees. If another checkout owns `main`, use that existing `main` checkout
instead of branching.

## Build & test

Expand Down
22 changes: 22 additions & 0 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

4 changes: 4 additions & 0 deletions Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -17,8 +17,10 @@ members = [
"crates/sandbox-runtime/workspace",
"crates/sandbox-runtime/namespace-process",
"crates/sandbox-runtime/namespace-execution",
"crates/sandbox-runtime/layerstack-core",
"crates/sandbox-runtime/layerstack",
"crates/sandbox-runtime/overlay",
"crates/sandbox-runtime/mpla-poc",
"crates/sandbox-provider-docker",
"xtask",
]
Expand Down Expand Up @@ -78,7 +80,9 @@ sandbox-operation-contract = { path = "crates/sandbox-operations/contract" }
sandbox-operation-catalog = { path = "crates/sandbox-operations/catalog", default-features = false }
sandbox-operation-client = { path = "crates/sandbox-operations/client" }
sandbox-config = { path = "crates/sandbox-config" }
sandbox-runtime-layerstack-core = { path = "crates/sandbox-runtime/layerstack-core" }
sandbox-runtime-layerstack = { path = "crates/sandbox-runtime/layerstack" }
sandbox-runtime-mpla-poc = { path = "crates/sandbox-runtime/mpla-poc" }
sandbox-runtime-namespace-process = { path = "crates/sandbox-runtime/namespace-process" }
sandbox-runtime-namespace-execution = { path = "crates/sandbox-runtime/namespace-execution" }
sandbox-runtime-overlay = { path = "crates/sandbox-runtime/overlay" }
Expand Down
65 changes: 65 additions & 0 deletions GEO-ANALYSIS.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,65 @@
# Ephemeral Sandbox GEO and SEO analysis

**Analysis date:** 2026-07-28
**Public surface reviewed:** `https://github.com/Ephemeral-AI-Lab/ephemeral-sandbox`
**Method:** static analysis of the public repository and its README, plus GitHub
repository metadata. Scores are directional heuristics, not Search Console or
AI-platform telemetry.

## Readiness: 58/100

| Platform | Score | Evidence and limitation |
|---|---:|---|
| Google Search and AI Overviews | 62 | The README is rendered server-side by GitHub and has clear product headings, but the repository has no description, homepage, topics, or standalone indexable site. |
| ChatGPT web search | 56 | The public GitHub source and documentation are discoverable, but the project lacks a root-level `llms.txt` endpoint on a domain it controls and has limited external entity signals. |
| Perplexity | 54 | The source, documentation, and Discord link provide useful primary material; no public product site, original research, or community evidence is available from this audit. |

## Findings addressed in this change

1. The README now begins with a self-contained definition of Ephemeral Sandbox.
It directly answers a likely product query and describes the product, users,
isolation model, interfaces, and supported host platforms in one extractable
passage.
2. Question-led section headings and a focused use-case section make the README
easier to retrieve for agent-sandbox and parallel-agent queries.
3. `llms.txt` supplies an authoritative map of the product, documentation,
architecture, console, terminology, and key facts for a future domain or
documentation deployment.
4. `.seo-cache/` is ignored so local analysis data remains uncommitted.

## Technical accessibility

- GitHub renders the README server-side, so the core product description is
available without a client-side JavaScript dependency.
- The browser console is a local operator UI, not a public product website; it
is therefore not an indexable acquisition page.
- GitHub owns the active `robots.txt`; this repository cannot independently
permit or deny AI crawlers on `github.com`.
- The repository now contains `llms.txt`, but GitHub does not expose it at
`https://github.com/llms.txt`. It becomes directly useful once deployed at
`https://<product-domain>/llms.txt`.

## Highest-impact follow-up actions

1. Set the GitHub repository description to: **Open-source local workspace
isolation for parallel coding agents, with Docker, CLI, MCP, and
observability.**
2. Add relevant GitHub topics: `ai-agents`, `coding-agents`, `agent-sandbox`,
`mcp`, `model-context-protocol`, `developer-tools`, `rust`, and `docker`.
3. Launch a canonical public documentation or product domain and serve the
versioned `llms.txt` at its root. Set the repository homepage to that URL.
4. Publish 2–3 source-backed technical guides that answer high-intent queries:
*how to isolate parallel coding agents*, *MCP sandbox for coding agents*,
and *reviewing agent changes before merge*.
5. Add Organization and SoftwareApplication JSON-LD, a canonical URL,
`robots.txt`, sitemap, author/reviewer dates, and `sameAs` links only on the
future product domain—not in this GitHub repository.

## Citation and authority plan

Use the architecture documentation, CLI/MCP references, reproducible benchmarks,
and release notes as primary sources. Prefer concrete claims about the isolation
model, supported interfaces, and operating systems; avoid unverified claims about
security guarantees, performance, or compatibility. Build third-party mentions
through release announcements, technical demonstrations, and user discussions
rather than synthetic backlinks.
34 changes: 26 additions & 8 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -20,12 +20,23 @@

</div>

Ephemeral Sandbox gives parallel coding agents isolated workspaces inside one
shared sandbox. Agents share the same project history, work independently, and
publish only the changes they intend to keep.

This repository contains the headless Rust core: gateway, manager, daemon,
runtime, observability, CLI, and MCP components. The browser UI and its backend
## What is Ephemeral Sandbox and how does it isolate parallel coding agents?

Ephemeral Sandbox is an open-source, local workspace-isolation system for teams
running parallel coding agents against the same codebase. Each agent receives a
private writable workspace over a stable shared project base and history, which
lets agents work concurrently without exchanging incomplete edits. The Rust core
combines a Docker gateway, sandbox manager and daemon, command-and-file runtime,
observability, separate CLI groups, and an MCP server. Before a change is
published, an operator can inspect activity and change provenance, then publish
one complete resolved change set—or publish nothing. Use Ephemeral Sandbox when
agent work needs a clear isolation boundary, reviewable execution, and deliberate
promotion to the shared project. Connect through the CLI, MCP-compatible clients,
or the separate browser console; setup guides cover Linux amd64, macOS on Apple
silicon, and Windows amd64. This keeps the shared checkout intentional,
traceable, and reviewable.

This repository contains the headless Rust core. The browser UI and its backend
live in the separate
[Ephemeral Sandbox Console](https://github.com/Ephemeral-AI-Lab/ephemeral-sandbox-console)
repository.
Expand All @@ -38,6 +49,13 @@ repository.
- **Publish with confidence.** Inspect activity and change provenance before
publishing a complete resolved change set.

## When should you use Ephemeral Sandbox?

- Give concurrent coding agents independent workspaces over one project base.
- Review an agent's commands, files, and provenance before promoting its work.
- Connect MCP-compatible clients to narrowly scoped management, runtime, or
observability tools.

## Quick start

Choose your host OS. Docker must already be installed and reachable. For full
Expand Down Expand Up @@ -90,7 +108,7 @@ repository. Start the gateway above, then point the console at:

The console serves the browser UI at `http://127.0.0.1:7880`.

## Choose an interface
## Which interfaces can agents use?

| Interface | Best for | Start with |
|---|---|---|
Expand All @@ -111,7 +129,7 @@ sandbox-mcp --set runtime
sandbox-mcp --set observability
```

## How it works
## How does Ephemeral Sandbox handle parallel work?

1. **Share a stable base.** LayerStack keeps the project history available to
every workspace session.
Expand Down
26 changes: 26 additions & 0 deletions bin/mpla-poc
Original file line number Diff line number Diff line change
@@ -0,0 +1,26 @@
#!/usr/bin/env bash
set -euo pipefail

script_dir="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
repo_root="$(cd "${script_dir}/.." && pwd)"

if [[ $# -eq 0 ]]; then
echo "usage: mpla-poc build|config|qualification|suite|test|crash|evidence-seal|evidence-verify ..." >&2
exit 64
fi

command_name="$1"
shift

case "${command_name}" in
build)
exec cargo build --manifest-path "${repo_root}/Cargo.toml" -p sandbox-runtime-mpla-poc "$@"
;;
config|qualification|suite|test|crash|evidence-seal|evidence-verify|catalog-bind|fixture-prepare|fixture-populate|lifecycle-metadata)
exec cargo run --quiet --manifest-path "${repo_root}/Cargo.toml" -p sandbox-runtime-mpla-poc --bin mpla-poc -- "${command_name}" "$@"
;;
*)
echo "unsupported mpla-poc command: ${command_name}" >&2
exit 64
;;
esac
Binary file added bin/sandbox-catalog-export
Binary file not shown.
2 changes: 2 additions & 0 deletions bin/start-sandbox-docker-gateway
Original file line number Diff line number Diff line change
Expand Up @@ -164,6 +164,8 @@ if [ "$show_help" -eq 0 ]; then
"$repo_root/Cargo.lock" \
"$repo_root/.cargo/config.toml" \
"$repo_root/crates/sandbox-daemon/Cargo.toml" \
"$repo_root/crates/sandbox-daemon/build.rs" \
"$repo_root/crates/sandbox-daemon/build" \
"$repo_root/crates/sandbox-daemon/src" \
"$repo_root/crates/sandbox-config/Cargo.toml" \
"$repo_root/crates/sandbox-config/src" \
Expand Down
1 change: 1 addition & 0 deletions config/bench.yml
Original file line number Diff line number Diff line change
Expand Up @@ -35,6 +35,7 @@ runtime:
namespace_execution:
scratch_root: /eos/namespace_execution
layerstack:
rollout_mode: legacy
remount_sweep_width: __SWEEP_WIDTH__
command:
max_active: 64
Expand Down
1 change: 1 addition & 0 deletions config/linux-amd64.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,7 @@ runtime:
namespace_execution:
scratch_root: /eos/namespace_execution
layerstack:
rollout_mode: legacy
autosquash_policies:
squash_at_n_layers: 100
command:
Expand Down
1 change: 1 addition & 0 deletions config/macos-arm64.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,7 @@ runtime:
namespace_execution:
scratch_root: /eos/namespace_execution
layerstack:
rollout_mode: legacy
autosquash_policies:
squash_at_n_layers: 100
command:
Expand Down
75 changes: 75 additions & 0 deletions config/mpla-poc-m2.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,75 @@
# Dedicated Stage 04.6 M2 physical-campaign configuration.
#
# The sandbox remains manager-owned and de-privileged. The build-heavy
# envelope selects the required four CPUs while Docker Desktop remains fixed
# at four GiB. The manager-owned workload cgroup is the storage domain; the
# physical runner sets its high watermark to 96 MiB while its manager-issued
# hard limit remains 128 MiB.
#
# Production commands hide all of /eos. This campaign needs the manager-owned
# layer-stack and workspace volumes as separate durable control/fixture mounts,
# so it hides only daemon runtime state. The config is used only by the
# explicitly leased PoC campaign.

daemon:
server:
socket_path: /eos/runtime/daemon/runtime.sock
pid_path: /eos/runtime/daemon/runtime.pid
worker_threads: 4
max_blocking_threads: 8
blocking_thread_keep_alive_s: 5
max_concurrent_connections: 64

runtime:
workspace:
layer_stack_root: /eos/layer-stack
scratch_root: /eos/workspace
setup_timeout_s: 30
exit_grace_s: 0.25
rfc1918_egress: allow
namespace_execution:
scratch_root: /eos/namespace_execution
layerstack:
rollout_mode: legacy
autosquash_policies:
squash_at_n_layers: 100
command:
max_active: 32

runner:
mount_mask:
hidden_paths:
- /eos/runtime

observability:
resource_stats:
enabled: true
sample_interval_ms: 2000
max_disk_bytes: 4194304

manager:
docker:
privileged: false
daemon_binary_path: dist/sandbox-daemon-linux-arm64
daemon_config_yaml_path: config/mpla-poc-m2.yml
platform: linux/arm64
resource_profile: build-heavy
resource_profiles:
standard:
nano_cpus: 1000000000
memory_high_bytes: 402653184
memory_max_bytes: 536870912
pids_max: 256
daemon_runtime_profile: standard
separate_workload_cgroup: true
build-heavy:
nano_cpus: 4000000000
memory_high_bytes: 134217728
memory_max_bytes: 134217729
pids_max: 1024
daemon_runtime_profile: build-heavy
separate_workload_cgroup: true
container_env:
HTTP_PROXY: http://http.docker.internal:3128
HTTPS_PROXY: http://http.docker.internal:3128
NO_PROXY: localhost,127.0.0.1,::1
Loading
Loading