Skip to content

feat(ext): add VettoCommandLineCodeExecutor for unprivileged sandboxed execution (#8298) - #8299

Open
Shleder (shleder) wants to merge 1 commit into
microsoft:mainfrom
shleder:feat/vetto-code-executor
Open

Shleder (shleder) wants to merge 1 commit into
microsoft:mainfrom
shleder:feat/vetto-code-executor

Conversation

@shleder

Copy link
Copy Markdown

Why are these changes needed?

In autogen-ext, code execution currently defaults to LocalCommandLineCodeExecutor when Docker is not installed or unavailable. This executes untrusted code directly on the host machine without isolation boundaries, exposing user files, environment variables, and network sockets.

This PR adds VettoCommandLineCodeExecutor to autogen-ext as an unprivileged, kernel-level sandbox executor:

  • Lightweight sandbox runtime (<4ms startup, 0MB daemon RAM) utilizing Landlock LSM (Linux), Seatbelt (macOS), and LPAC (Windows).
  • Configurable network isolation (off, allowlist, host).
  • Memory limits enforced via cgroups v2.
  • Clean process-group termination and fail-closed timeout handling (exit code 124/125).
  • Integrated into create_default_code_executor to prefer an isolated sandbox over un-sandboxed local execution when Docker is absent.

Related issue number

Closes #8298

Checks

  • I've included any doc changes needed for https://microsoft.github.io/autogen/.
  • I've added tests corresponding to the changes introduced in this PR (test_vetto_commandline_code_executor.py).
  • I've made sure all auto checks have passed.

@shleder

Copy link
Copy Markdown
Author

@microsoft-github-policy-service agree

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add unprivileged sandboxed code executor for environments without Docker

1 participant