# Real open-mission sandbox

This harness runs a real open-ended AGI mission locally while isolating it from
the host. It does not simulate external actions or provide a favorable test
fixture. The model must discover and use a genuine public route, and a real
external reply is the only valid completion evidence.

The security boundary is Docker:

- the agent is root only inside its writable container layer, so it can install
  tools autonomously; it retains only the identity/file capabilities required
  by package managers (`CHOWN`, `DAC_OVERRIDE`, `FOWNER`, `SETUID`, `SETGID`),
  with `no-new-privileges` and bounded memory/PIDs;
- its only host bind is a dedicated Pi model configuration mounted read-only;
- no host workspace, Docker socket, browser profile, cookies, mailbox, mail
  transport, address book, or communication account is mounted;
- the agent attaches only to an internal Docker network;
- a generic forward proxy is the sole internet path and rejects loopback,
  private, link-local, metadata, multicast, and other non-public addresses;
- Pi plus basic bootstrap shell tools are present; the agent can use `apt`, npm,
  or other public package sources to install the browser and tooling it chooses;
- a fresh Pi conversation can be recovered without replacing the durable goal
  or workspace if provider-incompatible content poisons the current context;
- the named workspace volume, Pi sessions, AGI state, wake records, and TUI
  scrollback persist for inspection.

Run this first:

The default command deploys and tests on the configured prod VPS:

```bash
npm run sandbox:mission -- preflight
```

For the optional local Docker path, use:

```bash
npm run sandbox:mission:local -- preflight
```

Preflight builds the images and proves public HTTPS and container-root package
installation work through the proxy, direct agent egress fails,
private/metadata targets are rejected, and no host workspace or Docker socket
is mounted. Its uniquely named containers, networks, temporary volume, and
local images are removed afterward.

A live VPS model run uses `PI_AGI_SANDBOX_AGENT_DIR` as a source and uploads
only `auth.json`, `models.json`, and `settings.json`. The local runner still
requires a dedicated directory and rejects the normal `~/.pi/agent` path. See
`agent-config/README.md` and the root README for the command sequence.

The pasted mission remains a normal user prompt. The sandbox-level `AGENTS.md`
contains environment facts only; it does not add task-specific behavioral
rules. The normal AGI scheduler handles delegation and durable waiting, while
the retained trace and workspace make the model's claimed evidence inspectable.
