Skip to content

Sandbox on Windows

This page is the Windows enforcement of the sandbox contract. It is informative for module authors and normative for agent implementers. It needs Windows 10 1809 or later.

  • Launch. Windows has no exec. oarbank-agent sandbox-exec POLICY.json -- argv is a shim, already in the attempt’s Job Object, that starts the module in an AppContainer and waits for it, passing its exit code on. It exits 70 when the container cannot be set up and 71 when the module cannot start.
  • Identity. One AppContainer profile per module, Oarbank.<module id>. Its SID is granted read and execute on the policy’s read-only roots and full access on its read-write roots.
  • Verification. The parent checks that the shim’s children run with an AppContainer token.
  • Process container. The Job Object, killed with the agent for attempts; a job memory limit and a CPU rate cap when the node’s policy turns reservations into hard limits.
Contract element Windows
read and execute the bundle, runtime and tools an inheritable allow entry for the container’s SID; system directories are readable by every AppContainer already
work, data and temporary directories an inheritable full-access entry for the container’s SID
no local IPC except the broker AppContainer object isolation: named pipes, sections and other objects outside the container are denied
net = none no network capability
net = egress-allowlist the elevated helper (a LocalSystem service) exempts the container from loopback isolation for the job, and Windows Filtering Platform filters block every loopback port but the agent’s proxy
net = egress-any the internetClient capability; loopback isolation keeps it off loopback
children children of an AppContainer process stay in it, and in the Job Object
Capability Status
filesystem, IPC, net.none, net.egress-any, no loopback, GPU enforced
net.egress-allowlist enforced where the elevated helper runs; unavailable otherwise
no link-local under egress-any unavailable
exec_writable deny unavailable: any readable binary is executable without application control
containers unavailable until the agent-owned WSL2 distribution ships

Source: spec/sandbox/backends/windows.md in the oarbank-sdk repository