Specific guarantees, not a magic sandbox.
Celln makes different promises for declared tools and agent-authored code. It refuses to claim a hardware property on a host that cannot provide it.
What is enforced in a KVM cell
- Declared tool code is read-only from inside the guest after stage-2 sealing.
- Execution is gated by content hash against a signed manifest.
- Tool code is not writable by the guest, including a privileged guest trying its own page tables.
- Warden enforces an authority ratchet: rights can shrink, never expand.
- Removing a mapped tool revokes it from a running cell.
Agent-authored code
celln agent creates a real sealed KVM cell. The generated program is always author=agent and runs in the agent lane: only its executable and writable workspace are loaned. Without fetch authority, pilot empties its bounding, ambient, inheritable, permitted, and effective capability sets before exec. A fetch-enabled invocation retains only CAP_SYS_RAWIO for the direct pilot-fetch PIO ABI; seccomp restricts ioperm to 0x500–0x502, denies iopl, and pilot removes legacy raw-I/O device nodes before confinement. Landlock independently rejects filesystem writes outside the workspace, and seccomp independently rejects sockets and privileged syscalls. Compiling model-written source does not promote it to tool-lane authority.
Network is brokered
A cell has no in-kernel network stack. For a named HTTPS destination, use --allow-host example.com, or in a spec [cell] allow_hosts with a tool declaring builtin = "fetch". pilot-fetch passes the bounded request over four dedicated PIO ports and the host performs the fetch; this is a narrow request protocol, not a NIC or socket transport. Private addresses and redirects that leave the declared authority are refused.
The starter web tools (https-fetch, https-post-json) take an exact host list or exactly ["*"], which means any public HTTPS host and is the configure default. Every tool request and redirect hop must be HTTPS on port 443 to a globally routable IPv4 address, pinned after resolution, with a verified certificate. Loopback, private, link-local (including cloud metadata), CGNAT, documentation, benchmarking, multicast and reserved ranges are always refused, and IPv6 is never used. A model profile’s allowInsecure affects only the operator-pinned model endpoint, never a tool.
What Celln does not claim
- It does not claim hardware isolation without Linux,
/dev/kvm, and a readable kernel image. - It does not make agent-authored code a verified host tool.
- It does not grant ambient network access, package installation, or a general-purpose Linux distribution to a cell.
- It does not remove the need to trust the host, the configured agent CLI, or the verified tool supply chain.
Verify on your own host
celln doctor celln verify make acceptance-kvm make bench-kvm
The acceptance check drives setup, generated code, its in-cell boundary, and celln ps -a using a deterministic local model stub. On a suitable host, the hardware checks include guest code that attempts forbidden operations; they are not host-side assertions alone.