Development
Sandbox Loom is currently a Ruby modular monolith. Changes should preserve the boundaries between policy, gateway, lifecycle, brokers, backend adapters, executor, and closed-loop orchestration.
Verification
Run the complete test suite with:
for test_file in tests/unit/*_test.rb tests/integration/*_test.rb tests/security/*_test.rb; do
ruby -I src -I tests "$test_file"
done
The suite covers policy decisions, gateway behavior, security boundaries, broker contracts, executor/session lifecycle, OCI backend lifecycle, and closed-loop repair/escalation.
Where to change what
- Add authorization semantics under
src/policy_engine/. - Add agent-facing local capabilities under
src/gateway/. - Add external or host-facing mediation under
src/brokers/. - Add isolation adapters under
src/backends/. - Add sandbox identity and lifecycle behavior under
src/sandbox_manager/. - Add sandbox-side protocol behavior under
src/executor/. - Add workflow orchestration under
src/development_loop/.
Normative changes belong in specifications/ and should be reflected in tests and consumer-facing documentation.