Revival qualification: Qualify sandboxed containers and interactive browser workflows
Nobody has claimed this yet.
- Dominant language
- Python
- Stars
- 101
- Forks
- 27
- Avg merge
- 6m
- Merged PRs (30d)
- 1
Description
Delivered in PR6, merged main commit a3839bd1315b83e09b828625ec38f827600fdb7b. Exact reviewed head2b04e57faeaeb06b62e60b9315e02fdfe5780155 passed Validate and package run34542459279 and MetaHarness and Autogenous run34542462102.
The delivered supported scope is inert snapshot extraction, not general browser automation. Public IPv4 addresses are resolved once and pinned into HTTPS; exact operator origin allowlist, no redirects,1MiB HTML limit,10second fetch worker and15second extraction process-group deadline. Chromium sandbox defaults enabled, scripts/network/service workers disabled. CLI and4MCP tools include opt-in fixed validation/benchmark commands. README/header/table/usage/ADR/CI artifacts, real generated MetaHarness hosts/session/field-memory adapter and pinned Autogenous gate are committed.
Validation:6domain tests including actual Chromium extraction and SDK stdio, pinned Node lookup contract regression;7generated harness tests;6Rust tests; audits0. Local Chromium152 used explicit unsandboxed test mode. Final Ubuntu22.04 CI passed with the default Chromium sandbox enabled. Ubuntu latest initially failed due AppArmor user namespace policy; we changed the supported runner without disabling Chromium sandbox.
Remaining qualification: unprivileged Docker container launch, live public HTTPS success and adversarial slow-drip fixture, authenticated/dynamic websites or disclosure actions under a separate threat model, deployment field-memory identity/storage. No credential injection or live production automation is enabled. Earlier prototype expectations do not constitute validation of these remaining features. Keep issue open for those gates.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the remaining qualification list in the issue and review the delivered PR6 scope, README, ADR, CI artifacts, and existing Validate, package, MetaHarness, and Autogenous runs. Qualification is complete when unprivileged Docker launch, live public HTTPS, adversarial slow-drip handling, and the stated deployment identity/storage gates are validated without enabling production automation.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- docker, python
- Domain
- cli, devops, security, testing
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100