Files
ai-sandbox/tests
mroberts 16ba06cc6d Sign commits made in the sandbox
The sandbox held no signing material, so its commits arrived unverified and a
branch rule requiring signatures rejected them outright. AI_SBX_SIGNING_KEY
copies an SSH signing key into the sandbox and points both git and jj at it.

The private half genuinely lands in the sandbox, which is why this is opt-in
and documented as signing-only: an agent that can read the key can sign as
you. A signing key grants no repository access and is revocable on its own,
so the exposure is forged attestation rather than reach. Forwarding an agent
socket would avoid the copy, but a socket passed over virtiofs is visible and
unconnectable from the guest, and the TCP workaround is a worse trade.

Setup refuses a passphrase-protected key rather than letting the failure
surface on the agent's first commit, and writes an allowed_signers entry so
the sandbox can verify what it just signed. jj is configured through conf.d,
which is read after config.toml and so overrides the host key path a copied
dotfile carries.
2026-08-05 13:30:09 -05:00
..