feat(machine): separated agent contexts on Linux nodes, dormant behind assistant:machine-contexts (0.60.0) - #1764
Merged
Merged
Conversation
added 9 commits
October 4, 2026 05:06
… activity; typed MCP tool outcomes (M1.1)
…olation # Conflicts: # backend/src/routes.rs
…hority and durable revocation (M1.2)
…xt users, workspaces and browsers, dormant behind assistant:machine-contexts (M1.3) Merges origin/main (0.58.0). Owner-card opt-in only; existing assignments stay shared_legacy and old nodes never receive separated authority. Per-context never-reused UIDs with private 0700 workspace/home/tmp, signed context binding with generation quarantine, Landlock ABI 6 for commands and files, separate secure/dev browser users, profiles and displays, and context-bound saved-login fills. Never described as isolated: residuals are documented in docs/MACHINE_AGENT_ISOLATION.md.
# Conflicts: # cli/src/wizard/bundle-meta/index.hash
📊 Code coverage
Gate: line coverage must stay at or above the threshold. Ratchet plan (W21): Backend → 55%, CLI → 50%, Frontend → 30% by quarter end. |
added 2 commits
October 5, 2026 02:33
# Conflicts: # Cargo.lock # backend/Cargo.toml # cli/Cargo.toml # cli/src/wizard/bundle-meta/index.hash # frontend/package-lock.json # frontend/package.json
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
M1.3 backend/runtime milestone: separated agent contexts on Linux machine nodes, dormant behind
assistant:machine-contexts(default off). This mode is never described as "isolated"; full isolation still requires a separate machine container or VM.nyxid__machine_capabilities(selection.mode) with an owner action card. The human Grants PUT refusesmode. Existing assignments stayshared_legacy. Separated authority is issued only to nodes that advertiseseparated.available, so old nodes never receive it.close_range(CLOEXEC).root:<agent gid>0770, so context UIDs cannot traverse them. This is fail-closed: only roots owned by the NyxID agent user are touched.separated.reasonexplains why, and there is never a silent shared fallback./dev/shmnamespace (distinct UIDs and 0600 protect contents), network not restricted, browsers without a filesystem Landlock ruleset. Details are indocs/MACHINE_AGENT_ISOLATION.mdanddocs/MACHINE_CONTEXT_SPIKE.md.Backward compatibility
Selection.mode,MachineReceipt.context_mode,MachineProfile.separated. The advertisedcontext::Supportaccepts unknown fields; node-local journals stay strict.O_PATHfor ancestors. The developer-browser user is still resolved lazily at launch.request_agent_skillsschema is byte-identical to main.separated_context_unavailableand 12421 forcontext_quarantine_pending.Follow-up (M1.3b, before owner rollout)
Graphical opt-in, the human desktop API/context selector, and native separate-users VM browser validation.
Validation
RUST_MIN_STACK=1572864:-D warnings;modeschema, a stale main merge, adeny_unknown_fieldsfield on the advertised wire type, eager dev-identity resolution, and the error-code documentation.