tai42-sandbox-local
A direct/host sandbox provider for the TAI ecosystem. It implements the
tai42_contract.sandbox.Sandbox surface over plain host subprocesses and the host
filesystem: it runs a session's code directly on the host, with no container
and no isolation. Exactly one sandbox provider is active per deployment, and the
operator picks direct/host execution by installing this provider instead of a
container provider — the consumers are provider-agnostic and acquire whichever is
installed.
The TAI ecosystem
TAI is an open-source runtime for MCP tools, agents, and workflows. A Sandbox is
"where a session's code runs" — a pluggable provider the runtime acquires through
one seam. This package is one such provider (direct/host execution); any package
can back the same contract, so this repo is this provider's own full doc home, and
the documentation site covers the platform-level story:
- Sandbox concept: https://tai42.ai/concepts/sandboxes
- Deployment / operate: https://tai42.ai/operate
Its only tai-* dependencies are tai42-contract (the Sandbox ABC, the session /
stream models, SandboxPolicy, the error family, PluginItemKind.SANDBOX, and the
tai42_app.sandboxes facet) and tai42-kit (ManagedSandbox /
ManagedSandboxSession — the shared ledger, TTL/reap, orphan recovery, and the
session-create policy chokepoint — plus SandboxDispatchSettings and the
conformance suite). It pulls in no third-party runtime dependency: it drives the
host with the standard library only.
Security model
This provider gives no isolation: isolation="none" means arbitrary session
code runs on the host with the host's filesystem, network, and secrets in reach.
It is for a trusted, single-tenant box, not untrusted flows. It accepts only
what it can honestly enforce and rejects the rest loudly:
isolation="none"accepted;container/vmrejected. The operator isolation floor defaults tocontainer, so a deployment installing this provider must setTAI_MCP_SANDBOX_ISOLATION=noneor every session create rejects.network="egress"accepted;none/internalrejected.- a
cpu/memory_mbcap rejected. imageis inert — the host is the execution environment; the operator installs the runtime on the host.
For enforced isolation or network lockdown, install a container provider instead.
Configuration
The SANDBOX_LOCAL_ env group: SANDBOX_LOCAL_ROOT (the host workspace root) and
SANDBOX_LOCAL_BASE_PATH (the clean-env PATH), plus the shared dispatch knobs
(SANDBOX_LOCAL_DEFAULT_TTL_SECONDS, SANDBOX_LOCAL_REAP_INTERVAL_SECONDS,
SANDBOX_LOCAL_EXEC_DEFAULT_TIMEOUT_SECONDS). See
docs/index.mdx for the full table and
the durability model.
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file tai42_sandbox_local-1.0.1.tar.gz.
File metadata
- Download URL: tai42_sandbox_local-1.0.1.tar.gz
- Upload date:
- Size: 29.6 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
b27fc4837eb38799cc0c3eb0f0131a571d159952b2890a8d2d3a29e82f9f3f84
|
|
| MD5 |
759cf2f8feb92a3a9febcc35a99e09d5
|
|
| BLAKE2b-256 |
d1ae1d1c414bb78487241b8732757f59470a91b08a0c7ccdb9e603326ce20e41
|
File details
Details for the file tai42_sandbox_local-1.0.1-py3-none-any.whl.
File metadata
- Download URL: tai42_sandbox_local-1.0.1-py3-none-any.whl
- Upload date:
- Size: 20.9 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
bc5b5af3d0eab79b4cdbdbc936b2132fab92a7cd957f33a546365cc3aa10a91a
|
|
| MD5 |
17fb5414343a91ac71b86553f9d5407d
|
|
| BLAKE2b-256 |
6b7625a4a2d65da49e52676f32fe8da447c9fcaa084d1b1bb6d033a4857657df
|