chore: import upstream snapshot with attribution
Integ / changes (push) Has been skipped
Pre-commit / pre-commit (push) Failing after 1s
CLI exit codes / changes (push) Has been skipped
Test (Install) / changes (push) Has been skipped
Test (Python) / changes (push) Has been skipped
Test (TypeScript) / changes (push) Has been skipped
CLI exit codes / cli-gate (push) Has been cancelled
Test (Install) / test-install-gate (push) Has been cancelled
Integ / integ-gate (push) Has been cancelled
Test (Python) / test-python-gate (push) Has been cancelled
Test (TypeScript) / test-typescript-gate (push) Has been cancelled
Test (Install) / python-minimal (3.12) (push) Has been cancelled
Test (Install) / python-minimal (3.11) (push) Has been cancelled
Test (Install) / python-extra (agno, mirage.agents.agno) (push) Has been cancelled
Test (Install) / python-extra (chroma, mirage.resource.chroma) (push) Has been cancelled
Test (Install) / python-extra (pdf, mirage.core.filetype.pdf) (push) Has been cancelled
Integ / integ (push) Has been cancelled
Integ / integ-database (push) Has been cancelled
Integ / integ-database-ts (push) Has been cancelled
Integ / integ-data (push) Has been cancelled
Integ / integ-ssh (push) Has been cancelled
Integ / integ-ssh-ts (push) Has been cancelled
Test (Python) / audit (push) Has been cancelled
Test (TypeScript) / test (push) Has been cancelled
Test (TypeScript) / python-fs-shim (push) Has been cancelled
CLI exit codes / Python CLI (push) Has been cancelled
CLI exit codes / TypeScript CLI (push) Has been cancelled
CLI exit codes / Cross-language snapshot interop (push) Has been cancelled
Test (Python) / test (push) Has been cancelled
Test (Python) / import-isolation (deepagents, openai, mirage.agents.openai_agents) (push) Has been cancelled
Test (Python) / import-isolation (deepagents, pydantic-ai, mirage.agents.pydantic_ai) (push) Has been cancelled
Integ / integ-ts (push) Has been cancelled
Integ / integ-fuse (push) Has been cancelled
Test (Install) / python-extra (databricks, mirage.resource.databricks_volume) (push) Has been cancelled
Test (Install) / python-extra (deepagents, mirage.agents.langchain) (push) Has been cancelled
Test (Install) / python-extra (email, mirage.resource.email) (push) Has been cancelled
Test (Install) / python-extra (fuse, mirage.fuse.mount) (push) Has been cancelled
Test (Install) / python-extra (hdf5, mirage.core.filetype.hdf5) (push) Has been cancelled
Test (Install) / python-extra (hf, mirage.resource.hf_buckets) (push) Has been cancelled
Test (Install) / python-extra (lancedb, mirage.resource.lancedb) (push) Has been cancelled
Test (Install) / python-extra (langfuse, mirage.resource.langfuse) (push) Has been cancelled
Test (Install) / python-extra (mongodb, mirage.resource.mongodb) (push) Has been cancelled
Test (Install) / python-extra (nextcloud, mirage.resource.nextcloud) (push) Has been cancelled
Test (Install) / python-extra (openai, mirage.agents.openai_agents) (push) Has been cancelled
Test (Install) / python-extra (openhands, mirage.agents.openhands, 3.12) (push) Has been cancelled
Test (Install) / python-extra (parquet, mirage.core.filetype.parquet) (push) Has been cancelled
Test (Install) / python-extra (postgres, mirage.resource.postgres) (push) Has been cancelled
Test (Install) / python-extra (pydantic-ai, mirage.agents.pydantic_ai) (push) Has been cancelled
Test (Install) / python-extra (qdrant, mirage.resource.qdrant) (push) Has been cancelled
Test (Install) / python-extra (redis, mirage.resource.redis) (push) Has been cancelled
Test (Install) / python-extra (s3, mirage.resource.s3) (push) Has been cancelled
Test (Install) / python-extra (ssh, mirage.resource.ssh) (push) Has been cancelled
Test (Install) / ts-minimal (push) Has been cancelled

This commit is contained in:
wehub-resource-sync
2026-07-13 12:30:44 +08:00
commit bcbd1bdb22
5748 changed files with 562488 additions and 0 deletions
@@ -0,0 +1,84 @@
# Microsandbox + Mirage FUSE
Run an untrusted [Microsandbox](https://microsandbox.dev) microVM that reads S3
through a host-side Mirage FUSE mount. Mirage FUSE-mounts S3 on the **host**;
Microsandbox bind-mounts that path into the microVM over virtio-fs. The guest
reads `/s3` natively, with no S3 credentials and no network of its own.
## How it works
```
microVM guest --virtio-fs /s3--> host FUSE mountpoint --> Mirage --> S3
(msb / libkrun) (fuse3)
```
1. `microsandbox_fuse.py` (host) FUSE-mounts an `S3Resource` at a temp mountpoint.
1. It boots a microVM with `Volume.bind(<mountpoint>, readonly=True)` mapped to
`/s3`, so the guest's `/s3` is backed by the host FUSE mount over virtio-fs.
1. `remote/guest.py` runs inside the microVM: it `os.listdir('/s3')` and reads
`/s3/data/example.jsonl` as if they were local files.
The microVM guest has no `/dev/fuse`, so Mirage can't run in the guest; the host
mount is shared in instead.
## Prerequisites
- **Microsandbox Python SDK**: `uv pip install microsandbox` (tested with 0.5.10).
- **`msb` runtime** (provides libkrunfw): `curl -sSfL https://get.microsandbox.dev | sh`.
On Apple Silicon this also pulls the libkrun HVF backend; x86_64 macOS is not
supported by Microsandbox.
- **Host FUSE**: Linux `fuse3` (see platform note below for macOS).
- **AWS credentials** in `.env.development` at the repo root:
`AWS_S3_BUCKET`, `AWS_ACCESS_KEY_ID`, `AWS_SECRET_ACCESS_KEY`, and optionally
`AWS_DEFAULT_REGION`.
- The bucket must contain `data/example.jsonl` (any text/JSONL file works; the
guest just counts lines containing `mirage`).
The SDK 0.5.10 embeds the runtime in-process, so there is **no separate `msb server` to start** (just run the example).
## Run
From the repo root (so `.env.development` loads):
```bash
./python/.venv/bin/python examples/python/runtimes/microsandbox/microsandbox_fuse.py
```
Expected tail:
```
=== guest output ===
--- os.listdir('/s3') ---
data
...
--- read /s3/data/example.jsonl through virtio-fs -> FUSE -> Mirage -> S3 ---
5766 lines, 5678 containing 'mirage'
Mirage served N ops, ... bytes to the sandbox
```
## Platform note: Linux only
This example runs on **Linux**. On **macOS it does not work**: libkrun's virtio-fs
cannot re-export a macFUSE-backed directory into the microVM. Booting the VM
fails at the bind-mount with:
```
failed to start "mirage-fuse": mount s3_<hash>: Operation not permitted (os error 1)
```
This is a libkrun + macFUSE interaction, not a Mirage or Microsandbox bug:
- It reproduces with both S3-backed and RAM-backed FUSE mounts (the trigger is the
macFUSE filesystem type, not the backend).
- A plain (non-FUSE) host directory bind-mounts and reads fine inside the same
microVM, so virtio-fs itself works on macOS.
- Mounting the FUSE filesystem with `allow_other` does not help; the failure is
`EPERM` (not `EACCES`), from a macOS-specific VFS operation libkrun's host-side
virtio-fs server issues during share setup that macFUSE rejects.
On macOS, use the sibling [`wasmer`](../wasmer/README.md) example instead: it maps
the same host FUSE mount into a WASIX guest with `--mapdir` and works on macOS.
Not run in CI. It needs the Microsandbox runtime, host FUSE, and live AWS
credentials.
@@ -0,0 +1,85 @@
# ========= Copyright 2026 @ Strukto.AI All Rights Reserved. =========
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
# ========= Copyright 2026 @ Strukto.AI All Rights Reserved. =========
# The microVM guest has no /dev/fuse, so Mirage FUSE-mounts S3 on the HOST and
# Microsandbox bind-mounts that path in over virtio-fs. The guest reads it
# natively, with no S3 credentials and no network of its own.
# Requires a running Microsandbox server (`msb server start`), host FUSE
# (Linux fuse3 or macOS macFUSE), and AWS creds in .env.development.
import asyncio
import os
import sys
from pathlib import Path
from dotenv import load_dotenv
from microsandbox import Sandbox, Volume
from mirage import Mount, MountMode, Workspace
from mirage.resource.s3 import S3Config, S3Resource
load_dotenv(".env.development")
REMOTE_DIR = Path(__file__).parent / "remote"
def s3_config() -> S3Config:
return S3Config(
bucket=os.environ["AWS_S3_BUCKET"],
region=os.environ.get("AWS_DEFAULT_REGION", "us-east-1"),
aws_access_key_id=os.environ["AWS_ACCESS_KEY_ID"],
aws_secret_access_key=os.environ["AWS_SECRET_ACCESS_KEY"],
)
async def main():
print("=== Mirage FUSE-mounting S3 on the host ===")
with Workspace({
"/s3/":
Mount(S3Resource(s3_config()), mode=MountMode.READ, fuse=True)
}) as ws:
host_s3 = ws.fuse_mountpoint
print(f" host mountpoint: {host_s3}")
print(
"\n=== booting microVM (S3 mount bind-mounted in, no network) ===")
async with await Sandbox.create(
"mirage-fuse",
image="python",
memory=1024,
cpus=1,
volumes={
"/s3": Volume.bind(host_s3, readonly=True),
"/prog": Volume.bind(str(REMOTE_DIR), readonly=True),
},
replace=True,
) as sandbox:
result = await sandbox.exec("python", ["/prog/guest.py"])
print("=== guest output ===")
print(result.stdout_text.rstrip())
if result.exit_code != 0:
print(result.stderr_text, file=sys.stderr)
print(f"\n=== exit code: {result.exit_code} ===",
file=sys.stderr)
sys.exit(result.exit_code)
records = ws.ops.records
total = sum(rec.bytes for rec in records)
print(
f"\nMirage served {len(records)} ops, {total} bytes to the sandbox"
)
if __name__ == "__main__":
asyncio.run(main())
@@ -0,0 +1,33 @@
# ========= Copyright 2026 @ Strukto.AI All Rights Reserved. =========
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
# ========= Copyright 2026 @ Strukto.AI All Rights Reserved. =========
# Runs inside a Microsandbox microVM (invoked by ../microsandbox_fuse.py).
# /s3 is a host directory that Mirage FUSE-mounted from S3, bind-mounted in
# via virtio-fs. No S3 credentials or network reach this guest.
import os
print("--- os.listdir('/s3') ---")
for entry in sorted(os.listdir("/s3")):
print(f" {entry}")
path = "/s3/data/example.jsonl"
print(f"\n--- read {path} through virtio-fs -> FUSE -> Mirage -> S3 ---")
with open(path) as f:
lines = f.readlines()
hits = sum(1 for line in lines if "mirage" in line)
print(f" {len(lines)} lines, {hits} containing 'mirage'")
print(" head:")
for line in lines[:3]:
print(f" {line.rstrip()}")