Living Document Notice
Published 2026-10-31. The evolving architecture, revisions, and connected notes for this dispatch live in the Stax Digital Garden.

Delegating Jobs to Outrigger

Delegating Jobs to Outrigger: Deep crimson P22R ruby red vector CRT macro showing circulating queue funneling a focused vector beam into an isolated containment cell

Summary

Parsing complex third-party file formats inside a long-running daemon process invites security vulnerabilities and stability failures. Malformed PDFs, corrupted EPUBs, and hostile media files can exploit memory safety bugs in parsing libraries, leading to daemon crashes or remote code execution. The Tender daemon isolates document extraction and syntax transformations by delegating unsafe jobs to Outrigger Protocol worker processes.

Outrigger sandboxes isolate child processes using kernel namespaces, restricted seccomp-bpf filter profiles, and strict memory limits. If a parser crashes or enters an infinite loop, the main Tender daemon detects the failure, logs the incident, and continues serving vault requests without interruption.

The Hazard of In-Process Document Extraction

Personal knowledge vaults ingest varied external files: academic research PDFs, web archive snapshots, office spreadsheets, and user-generated plugins. Parsing these formats requires complex decoders written in C, C++, or unsafe code blocks.

A heap-buffer overflow in an image parser or an XML entity expansion in a document reader running inside the primary daemon threatens the entire vault:

  1. Memory Corruption: Exploitable bugs grant attackers read access to unencrypted private notes.
  2. Uncontrolled Resource Consumption: Pathological documents trigger catastrophic regex backtracking or allocation loops, exhausting workstation RAM.
  3. Process Termination: An unexpected panic or SIGSEGV terminates the daemon, halting filesystem watching across all vaults.

The Tender daemon mitigates these risks through process isolation. The daemon never parses untrusted external payloads within its primary address space.

+--------------------------------------------------------------------+
|                     Outrigger Isolation Model                      |
|                                                                    |
|    +-----------------------------+                                 |
|    |     Tender Supervisor       |                                 |
|    |  (Unprivileged Daemon)      |                                 |
|    +--------------+--------------+                                 |
|                   |                                                |
|                   | Fork & Sandbox Config                          |
|                   v                                                |
|    +----------------------------------------------------------+    |
|    |              Outrigger Sandboxed Child                   |    |
|    |                                                          |    |
|    |   +--------------------------------------------------+   |    |
|    |   | Kernel Restrictions:                             |   |    |
|    |   | - CLONE_NEWNET (Zero network egress)             |   |    |
|    |   | - CLONE_NEWNS  (Isolated pivot_root /tmp)        |   |    |
|    |   | - RLIMIT_AS    (256MB memory cap)                |   |    |
|    |   | - Seccomp-BPF  (Blocked socket, execve, ptrace)  |   |    |
|    |   +------------------------+-------------------------+   |    |
|    |                            |                             |    |
|    |                            v                             |    |
|    |              [ Unsafe Document Extractor ]               |    |
|    |              (PDF / Docx / HTML Parser)                  |    |
|    +----------------------------+-----------------------------+    |
|                                 | Read-only Pipe                   |
|                                 v                                  |
|                    [ Structured Plain Text ]                       |
+--------------------------------------------------------------------+

The Outrigger Sandboxing Runtime

Outrigger wraps untrusted workloads inside an operating system sandbox before executing transformation logic. On Linux, Outrigger provisions unprivileged user namespaces and applies seccomp-bpf syscall filters:

pub struct SandboxConfig {
    pub max_memory_bytes: u64,     // 256MB ceiling
    pub max_cpu_seconds: u64,      // 5-second wall clock limit
    pub enable_network: bool,      // Strictly false for parsers
    pub writable_paths: Vec<PathBuf>,
}
 
pub fn spawn_sandboxed_extractor(config: SandboxConfig, input_fd: RawFd) -> Result<Child, SandboxError> {
    let mut command = Command::new("outrigger");
    command
        .arg("exec")
        .arg("--profile=untrusted-parse")
        .arg(format!("--memory-limit={}", config.max_memory_bytes))
        .arg(format!("--cpu-limit={}", config.max_cpu_seconds))
        .stdin(Stdio::from(unsafe { File::from_raw_fd(input_fd) }))
        .stdout(Stdio::piped())
        .stderr(Stdio::piped());
 
    let child = command.spawn()?;
    Ok(child)
}

The worker child process receives the document payload through standard input (stdin). Because network namespaces (CLONE_NEWNET) disconnect network adapters, malicious scripts inside parsed documents cannot transmit extracted data to external IP addresses.

Resource Ceilings and Fault Containment

Outrigger enforces strict execution bounds using kernel resource limits (setrlimit):

Resource ConstraintKernel PrimitiveEnforcement LimitFailure Action
Address SpaceRLIMIT_AS256 MegabytesKernel denies allocation (ENOMEM)
Execution TimeRLIMIT_CPU5 SecondsKernel issues SIGXCPU signal
File Descriptor CeilingRLIMIT_NOFILE32 DescriptorsSyscalls return EMFILE
Network Accessseccomp-bpfDisallowedSyscall returns EPERM / SECCOMP_RET_ERRNO

When an incoming document triggers a panic or memory ceiling fault, the Outrigger process crashes. The Tender supervisor captures the exit status without panicking:

match child.wait_timeout(Duration::from_secs(5))? {
    Some(status) if status.success() => {
        let mut output = String::new();
        child.stdout.take().unwrap().read_to_string(&mut output)?;
        apply_extracted_text(vault_id, note_path, output);
    }
    Some(status) => {
        log::warn!("Outrigger parser failed with status: {:?}", status.code());
        record_extraction_failure(vault_id, note_path, "PARSER_FAULT");
    }
    None => {
        // Process exceeded timeout; issue forced termination
        child.kill()?;
        child.wait()?;
        log::error!("Outrigger task timed out; killed with SIGKILL");
    }
}

By confining parsers to ephemeral Outrigger workers, the Tender daemon maintains high uptime across continuous parsing workloads.


  • Directus Target: tender
  • Garden Source Reference: Outrigger Sandbox Harness, Unsafe File Extraction, OPS-1 Specification, MOC - Ingestion & Capture, MOC - Local-First Systems and Synchronization, MOC - Bosun PKM Tools, [OUT-1001 - Verifying Autonomous Agent Bounds with Pure Standard Library](OUT-1001 - Verifying Autonomous Agent Bounds with Pure Standard Library), MOC - Bosun PKM Engine, MOC - Outrigger Protocol