Skip to content

feat(security): add brokered sandbox egress - #6118

Open
RaresKeY wants to merge 2 commits into
odysseus-dev:devfrom
RaresKeY:refactor/agent-egress-broker
Open

feat(security): add brokered sandbox egress#6118
RaresKeY wants to merge 2 commits into
odysseus-dev:devfrom
RaresKeY:refactor/agent-egress-broker

Conversation

@RaresKeY

@RaresKeY RaresKeY commented Aug 19, 2026

Copy link
Copy Markdown
Member

Summary

This PR extracts the trusted HTTP(S) egress transport from #5818 into a focused, independently reviewable security slice. It adds the broker and loopback bridge, public-address and reconnect validation, bounded HTTP and CONNECT handling, proxy credential/header scrubbing, TLS/CA-preserving tunneling, concurrency and lifetime limits, and broker/bridge lifecycle tests. It intentionally excludes Docker/Compose installation, AppArmor and boot checks, application network-profile propagation, and process-execution wiring. The launch chain depends at runtime on the seccomp substrate tracked by #6114 and implemented by PR #6119.

Target branch

  • This PR targets dev, not main. All PRs land in dev; main is curated by the maintainer at each release. If your PR is on main by accident, click "Edit" on this PR and change the base.

Linked Issue

Fixes #6115

Depends on PR #6119 for the trusted seccomp substrate.

Part of #6091

Part of #5815

Related to and supersedes the corresponding egress slice of #5818.

Type of Change

  • Bug fix (non-breaking — fixes a confirmed issue)
  • New feature (non-breaking — adds new behaviour)
  • Breaking change (changes or removes existing behaviour)
  • Refactor / cleanup (behaviour unchanged)
  • Documentation only
  • CI / tooling / configuration

Checklist

  • I searched open issues and open PRs — this is not a duplicate.
  • This PR targets dev
  • My changes are limited to the scope described above — no unrelated refactors or whitespace changes mixed in.
  • I actually ran the app (docker compose up or uvicorn app:app) and verified the change works end-to-end. Type-checks and unit tests are not enough.
  • I did not run the app/runtime validation and stated that gap in How to Test. Leave this unchecked when the app-run box above is checked.

How to Test

  1. Run python3 -m pytest -q tests/test_egress_broker.py through the secretless review runner; this produced 46 passing tests covering address filtering, DNS/reconnect behavior, HTTP and CONNECT policy, redirects, TLS/CA handling, proxy-variable scrubbing, bridge lifecycle, concurrency, failure handling, and the independent Makefile trust contract for root/group defaults, absolute interpreter resolution, isolated -I shebang rewriting, and root-owned 0755 installation.
  2. Run make -C security/egress check through the secretless review runner; this passed Python compilation for both trusted helpers.
  3. Review the five changed paths as the broker/bridge transport boundary only. Docker/Compose installation, AppArmor/boot behavior, application network-profile propagation, process wiring, and full app/runtime execution were not run in this slice and remain follow-up work.

Visual / UI changes — REQUIRED if you touched anything that renders

This slice changes no UI or rendering behavior.

Anything that changes what the UI looks like — buttons, icons, padding, colors, fonts, spacing, layout, CSS, HTML, SVG, or any static/js/ module that draws to the DOM — needs all of the following. PRs that change rendering without these WILL be closed.

  • Screenshot or short clip of the change in the running app, attached below. Mobile screenshot too if the change affects mobile.
  • Style match: the change uses Odysseus's existing visual language. Specifically:
    • Reuse existing CSS variables (--red, --fg, --bg, --card, --border, etc.) — do not introduce new color values, font sizes, or spacing units.
    • Reuse existing button/input/card/border classes. Don't invent parallel styling.
    • No Unicode emoji in UI or code. Use inline SVG (matching the monochrome icon style already in static/index.html) or plain text.
    • Monospaced font (Fira Code) for primary UI text. Don't override.
    • Dark theme is the default; any light-mode work must be wired through the existing theme system, not hard-coded.
  • No new component patterns. If a similar widget already exists in the app, extend it instead of writing a parallel one.
  • I am not an LLM agent submitting a bulk PR. This coordinated multi-PR split intentionally leaves this bulk-submission attestation unchecked.

Screenshots / clips

Not applicable: this PR contains no UI or visual changes.

@github-actions

Copy link
Copy Markdown

⚠️ PR description is complete; validation evidence is still outstanding

Changed-file classification: backend/runtime.

Author-reported runtime / visual state

  • The author explicitly reports that app/runtime validation was not performed.

Checkboxes are author attestations. GitHub Actions results remain the execution evidence for CI; this check does not prove that a local command ran.


This comment updates automatically when the description or changed files change.

@RaresKeY
RaresKeY marked this pull request as ready for review August 19, 2026 10:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

needs runtime validation Runtime validation not attested — tick the app-run box after running it, or state the gap

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add a trusted sandbox HTTP(S) egress broker and bridge

1 participant