Skip to main content

tibet-airlock

Zero-trust sandbox with TIBET provenance. Python operator/client surface for the hardened Rust execution kernel.

Naming discipline (since v0.3.0): tibet-airlock is the Python operator surface (this package — bindings, monitoring, posture enforcement). The hardened Rust execution kernel lives as the separate crate tibet-airlock-kernel (previously published as tibet-airlock on crates.io, v0.1.0 yanked).

Install

pip install tibet-airlock
cargo install tibet-airlock-kernel   # the Rust execution kernel

Or as part of the TIBET security bundle:

pip install tibet[security]

Airlock-runtime posture enforcement (since 0.3.0)

tibet-airlock is the operator-side enforcer of the tibet-pol → snaft → cap-bus → tibet-airlock immune-switch pipeline. When a verdict has been installed, execute() refuses to even open a connection if the flow is forbidden by the active posture:

import asyncio
from tibet_airlock import Airlock, AirlockPostureDenied
from snaft.posture import consume_verdict   # snaft >= 1.4.0

# Receive a verdict.v1 record from tibet-pol via cap-bus:
verdict = {...}  # airlock_runtime_verdict.v1 record
decision = consume_verdict(verdict)

airlock = Airlock()
airlock.set_posture(decision)

try:
    asyncio.run(
        airlock.execute("code:execute", "untrusted_payload", origin="external_ai")
    )
except AirlockPostureDenied as e:
    print(f"refused: {e}")
    # In python_fallback mode: "deny_external_ai_inbound ON (intent=code:execute)"
    # No socket was opened. Operator/local diagnostics still pass through.

The invariant — "Als de bolle airlock-runtime wegvalt, mag extern AI-verkeer niet meer binnen" (Jasper 2026-05-29) — is honored at this layer: when the posture has deny_external_ai_inbound=True, drop_external_traffic=True, or isolate_session=True, no network I/O is attempted for matching origins. Local diagnostics + operator-approved repair flows still pass through.

Reference: Codex policy 2026-05-29 (immune-switch ladder).

Use with airlock kernel (full isolation)

# Terminal 1: start the airlock kernel
cargo install tibet-airlock-kernel
tibet-airlock-kernel

# Terminal 2: Python
from tibet_airlock import Airlock

result = Airlock.run("code:execute", "print('hello world')")
print(result.status)        # 200
print(result.safe)          # True
print(result.roundtrip_ms)  # 0.6
print(result.token)         # TIBET provenance token

Use SNAFT directly (no binary needed)

from tibet_airlock import SnaftMonitor

# Monitor syscalls for an intent
monitor = SnaftMonitor("code:execute")
monitor.log_syscall("sys_write")    # OK
monitor.log_syscall("sys_socket")   # VIOLATION - network access!

decision = monitor.triage()
print(decision.is_safe)     # False
print(decision.violations)  # ['sys_socket (blocked: dangerous syscall for any intent)']

# Or scan a payload string
monitor = SnaftMonitor("code:execute")
detected = monitor.scan_payload("import os; os.system('curl evil.com')")
decision = monitor.triage()
print(decision.is_kill)     # True

How it works

Intent -> Snapshot Wake (<0.01ms) -> SNAFT Monitor -> Triage -> TIBET Token
  1. Intent routing — each intent maps to a pre-warmed microVM snapshot
  2. SNAFT monitoring — every syscall checked against intent-specific allowlist
  3. Triage — violations = instant kill, clean = graceful shutdown
  4. TIBET token — cryptographic proof of what happened (the 4 dimensions: erin, eraan, eromheen, erachter)

Blocked syscalls (always dangerous)

sys_ptrace, sys_socket, sys_connect, sys_dlopen, sys_fork, sys_clone, sys_mount, sys_reboot, sys_kexec_load

Part of TIBET

Built by Humotica for the AInternet.

License

MIT

Credits

Designed by Jasper van de Meent. Built by Jasper and Root AI as part of HumoticaOS.


Stack-positie: Groep agentic · Bootstrap = OSAPI-handshake naar tibet + jis (fail → snaft-rule + tibet-pol-rapport) · ← tibet-phantom · See STACK.md · See demo/golden-path/ for the spine end-to-end.

Enterprise

For private hub hosting, SLA support, custom integrations, or compliance guidance:

Enterprise enterprise@humotica.com
Support support@humotica.com
Security security@humotica.com

See ENTERPRISE.md for details.

Release files for tibet-airlock 0.3.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for tibet-airlock 0.3.1
File Size Uploaded
tibet_airlock-0.3.1.tar.gz 15.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for tibet-airlock 0.3.1
File Interpreter ABI Platform
tibet_airlock-0.3.1-py3-none-any.whl Python 3 none any Details

Total release size: 26.5 kB

Release files / tibet_airlock-0.3.1.tar.gz

Download URL tibet_airlock-0.3.1.tar.gz
Size 15.4 kB
Tags Source
SHA-256 checksum
How to use checksums
f444f76ed3398c2f376efc8e63569e8988afb8233ee7fcc8b89917d618dc6d6c
BLAKE2b-256 checksum
How to use checksums
8e9008cc92e2c81d8772f259f14f63a2471b13217b04791a52ab1977ff0c9e7f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.13.5

Release files / tibet_airlock-0.3.1-py3-none-any.whl

Download URL tibet_airlock-0.3.1-py3-none-any.whl
Size 11.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
7c24a99714726081d99407ecb453cfa402fb834dcad6ca643a4fd23452e94dc6
BLAKE2b-256 checksum
How to use checksums
e03af870fb2612571b3e2393fea11fa1a7dcd5e6cdd118ffe62968f5fb892458
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.13.5

Release history Release notifications | RSS feed

This release

0.3.1 This release

2 release files

0.3.0

2 release files

0.2.0

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page