Files
m4 5d893c1dc6
Docker / build (push) Has been cancelled
Build / build (push) Has been cancelled
Lint / ruff (push) Has been cancelled
Test / pytest (ubuntu-latest, 3.11) (push) Has been cancelled
Test / pytest (ubuntu-latest, 3.12) (push) Has been cancelled
Test / pytest (windows-latest, 3.11) (push) Has been cancelled
Test / pytest (windows-latest, 3.12) (push) Has been cancelled
[verified] fix: close 0.3.0 release security gaps
2026-09-03 10:42:46 +08:00

1.1 KiB

EvoScientist Native Sandbox Runtime

The canonical, packaged runtime assets live in:

EvoScientist/native_sandbox_runtime/package.json
EvoScientist/native_sandbox_runtime/package-lock.json
EvoScientist/native_sandbox_runtime/patch_merged_usr.py

Standalone Python installations copy those assets from the wheel into the user data directory, run the pinned npm ci --ignore-scripts --omit=dev, apply the fail-closed patch, verify the installation, and atomically promote it on first sandbox use.

Production Docker images install and patch the same assets during image build and set EVOSCIENTIST_NATIVE_SANDBOX_ROOT to the image-local runtime, so container startup never downloads dependencies.

Required platform tools:

  • macOS: Node 20.11+, npm, bash, rg, python3, pandoc, and /usr/bin/sandbox-exec
  • Linux: Node 20.11+, npm for standalone first install, bash, rg, python3, pandoc, bwrap, and socat

Run the host-specific black-box suite after installation:

EVOSCIENTIST_RUN_NATIVE_SANDBOX_TESTS=1 uv run pytest -q tests/test_native_sandbox_integration.py