- Review the node driver
- Plan desired minimal driver that we'll use in rivet
- Add codemode example
- Add just-bash example
- Test with
- Pi
- Express
- Hono
- ???
-
Remove all
@hono/node-serverbridge integration and load it only from sandboxednode_modules.- Remove bridge module and exports (
packages/secure-exec/src/bridge/hono-node-server.ts,packages/secure-exec/src/bridge/index.ts). - Remove
@hono/node-serverspecial-cases in runtime resolution/execution (packages/secure-exec/src/index.ts,packages/secure-exec/src/shared/require-setup.ts). - Remove
honoServe/honoClosefrom adapter/types if no longer needed (packages/secure-exec/src/types.ts,packages/secure-exec/src/shared/permissions.ts,packages/secure-exec/src/node/driver.ts).
- Remove bridge module and exports (
-
Implement Node built-in HTTP server bridging (
http.createServer) without third-party module bridges.- Add server listen/close/address request-dispatch bridge hooks in runtime setup (
packages/secure-exec/src/index.ts). - Implement server-side compatibility in network bridge (
packages/secure-exec/src/bridge/network.ts). - Add Node driver implementation backed by
node:http(packages/secure-exec/src/node/driver.ts,packages/secure-exec/src/types.ts,packages/secure-exec/src/shared/permissions.ts).
- Add server listen/close/address request-dispatch bridge hooks in runtime setup (
-
Expose host-side request path to sandbox servers via
sandbox.network.fetch(...).- Provide a NodeRuntime-level network facade and document concurrent run/fetch pattern (
packages/secure-exec/src/index.ts,README.md,examples/hono/README.md). - Validate end-to-end from loader to runner (
examples/hono/loader/src/index.ts,examples/hono/runner/src/index.ts).
- Provide a NodeRuntime-level network facade and document concurrent run/fetch pattern (
-
Fix
run()ESM semantics to match docs (return module exports/default instead of evaluation result).- Fix:
runESMnow returns copied entry-module namespace exports (default + named) after evaluation. packages/secure-exec/src/index.ts,packages/secure-exec/tests/index.test.ts
- Fix:
-
Fix dynamic import execution semantics so imports are not eagerly evaluated before user code.
- Fix: precompile step now resolves/compiles only; instantiate/evaluate occur on first
import()reach. packages/secure-exec/src/index.ts,packages/secure-exec/tests/index.test.ts
- Fix: precompile step now resolves/compiles only; instantiate/evaluate occur on first
-
Remove brittle require-path hacks/monkeypatches and replace with minimal, explicit compatibility behavior.
- Current hacks include
chalk,supports-color,tty,constants,v8, andutil/url/pathpatching. packages/secure-exec/src/shared/require-setup.ts
- Current hacks include
-
Decide and enforce sandbox permission default model (allow-by-default vs deny-by-default); tighten if strict mode is desired.
- Fixed by flipping permission checks and env filtering to deny-by-default, and by exporting explicit
allowAll*helpers for opt-in access. packages/secure-exec/src/shared/permissions.ts
- Fixed by flipping permission checks and env filtering to deny-by-default, and by exporting explicit
-
Make console capture robust for circular objects (avoid
JSON.stringifythrow paths in logging).packages/secure-exec/src/index.ts
-
Reconcile
docs/node-compatability.mdxwith current runtime behavior.- Fix: completed in
codify-stdlib-support-policy(remove stale third-party bridge notes, alignhttp/https/http2sections, add support tiers).
- Fix: completed in
-
Close or explicitly codify missing
fsAPIs listed in compatibility docs.- Fix: completed in
codify-stdlib-support-policy(access/realpathdocumented as implemented; missing APIs now use deterministic unsupported errors).
- Fix: completed in
-
Decide
child_process.fork()support level.- Fix: completed in
codify-stdlib-support-policy(forkmarked unsupported with deterministicchild_process.fork is not supported in sandboxerror).
- Fix: completed in
-
Tighten crypto support policy and implementation.
- Fix: completed in
codify-stdlib-support-policy(explicit insecurity warning forgetRandomValues, deterministiccrypto.subtle.*unsupported errors, tiered policy documented).
- Fix: completed in
-
Track unimplemented core modules from compatibility docs as explicit product decisions.
- Fix: completed in
codify-stdlib-support-policy(Tier 4 Deferred vs Tier 5 Unsupported classifications with rationale and runtime policy).
- Fix: completed in
-
Filter Python
exec(..., { env })overrides throughpermissions.env.- Fix:
PyodideRuntimeDriver.exec()now applies the sharedfilterEnv(...)gate before env overrides reach the worker, and runtime-driver tests cover both denied-by-default and explicitly-allowed cases. packages/secure-exec/src/python/driver.ts,packages/secure-exec/tests/runtime-driver/python.test.ts
- Fix:
-
Bridge
crypto.getRandomValues/randomUUIDto hostnode:cryptoinstead ofMath.random().- Fix: runtime now wires host
node:cryptoreferences frompackages/secure-exec/src/index.tsinto the isolate and uses them inpackages/secure-exec/src/bridge/process.ts. - Fail-closed contract: bridge throws deterministic
crypto.getRandomValues is not supported in sandbox/crypto.randomUUID is not supported in sandboxerrors when host entropy hooks are unavailable.
- Fix: runtime now wires host
-
Add transfer size limits on base64 file I/O across the isolate boundary.
packages/secure-exec/src/index.ts(~line 1138,readFileBinaryRef/writeFileBinaryRef)- No cap currently; a large file read can OOM the host process.
-
Validate size before host-side
JSON.parsecalls.packages/secure-exec/src/index.ts(10 unvalidatedJSON.parsecalls)- Crafted large payloads from sandbox can OOM the host process.
-
Make bridge globals non-writable on
globalThis.- Fix: active-handle lifecycle globals now install via
Object.definePropertywithwritable: falseandconfigurable: false, preventing sandbox overwrite of_registerHandle/_unregisterHandle/_waitForActiveHandles. packages/secure-exec/src/bridge/active-handles.ts,packages/secure-exec/tests/index.test.ts
- Fix: active-handle lifecycle globals now install via
-
Remove default host-side console buffering; drop logs by default and expose optional streaming hook.
packages/secure-exec/src/index.ts,packages/secure-exec/src/execution.ts
-
Add global host resource budgets (output bytes, bridge-call rate, timer count, child-process count).
packages/secure-exec/src/index.ts,packages/secure-exec/src/bridge/process.ts,packages/secure-exec/src/shared/permissions.ts
-
Cap and hard-fail child-process output buffering in sync APIs.
packages/secure-exec/src/index.ts(spawnSyncRef/execSyncRef)
-
Ensure child-process sessions are always cleaned up on timeout/dispose/error paths.
packages/secure-exec/src/index.ts(sessionsmap in child-process bridge)
-
Add request/response body limits for driver HTTP paths (including decompression).
packages/secure-exec/src/node/driver.ts(httpServerListen,fetch,httpRequest)
-
Fix HTTP server lifecycle leaks when executions time out or are disposed.
packages/secure-exec/src/execution.ts,packages/secure-exec/src/index.ts,packages/secure-exec/src/node/driver.ts
-
Add
statandexistsmethods toVirtualFileSysteminterface.packages/secure-exec/src/types.ts,packages/secure-exec/src/fs-helpers.ts- Current
stat()andexists()read entire file contents; O(file size) when should be O(1). Also a DoS vector via large files.
-
Split
index.tsinto focused modules.packages/secure-exec/src/index.ts(1,956 lines and growing)- Extract:
isolate.ts,module-resolver.ts,esm-compiler.ts,bridge-setup.ts,execution.ts.
-
Replace magic O_* flag numbers with named constants.
packages/secure-exec/src/bridge/fs.ts(~line 690)- Hardcoded integers (577, 578, 1089, etc.) are Linux-specific and undocumented.
-
Fix
readDirWithTypesN+1 I/O pattern.packages/secure-exec/src/fs-helpers.ts(~line 112)- Calls
readDirper entry to check if directory; addreadDirWithTypesorstattoVirtualFileSystem.
-
Make
renameatomic or document limitation.packages/secure-exec/src/fs-helpers.ts(lines 90-92)- Currently read + write + delete; crash between steps can duplicate or lose data.
-
Make ESM module reverse-lookup O(1) to avoid O(n^2) resolver work on large import graphs.
packages/secure-exec/src/index.ts(ESM resolver / module cache lookup)
-
Add resolver memoization (positive + negative) to avoid repeated miss probes across
require()/import().packages/secure-exec/src/package-bundler.ts,packages/secure-exec/src/shared/require-setup.ts,packages/secure-exec/src/index.ts
-
Document and verify package manager support for
node_modulesloading behavior.- Cover expected resolver behavior and known caveats for npm, pnpm, yarn, and bun installs.
- Add/maintain compatibility fixtures that exercise transitive dependency loading across supported package manager layouts.
-
Cap and cache
package.jsonparsing in resolver paths.packages/secure-exec/src/package-bundler.ts
-
Reduce module-access lookup overhead (prefix index + canonicalization memoization).
packages/secure-exec/src/node/module-access.ts
-
Replace whole-file fd sync emulation with offset-based host read/write primitives.
packages/secure-exec/src/bridge/fs.ts