Sigroom Docs

Runtime Profiles

Room policy evaluates the explicit runtime isolation profile reported by HACP Control. UI, gateway, policy, and docs should not assume Linux-only behavior.

readyHarness operators and platform developersVerified 2026-07-22

Profiles

ProfileUse
linux.runsc.l4Linux x86_64 with gVisor runsc and required kernel controls.
macos.native.sandboxedNative macOS sandbox evidence for rooms that allow macOS native isolation.
macos.linux-vm.runscmacOS launcher with a signed Lima appliance and measured runsc systrap runtime.
windows.wsl2.runscWindows 11 x86-64 with a dedicated signed WSL2 distro and measured runsc systrap runtime.

Proof Rule

A desktop ready result proves compatibility only. A harness may satisfy L4 only when its signed release, installed tree, measured entrypoint, appliance release, sandbox profile, runtime evidence, enrollment approval, and room policy all agree.

Source Material

  • docs/deployment/runtimes/desktop-l4-runtime.md
  • docs/deployment/runtimes/macos-hacp-control-runtime.md
  • docs/deployment/runtimes/windows-wsl2/operator-guide.md
  • rust/crates/hacp-launcher/src/lib.rs