STRICT default
Firecracker microVM + Guard model-only egress + srt. Demands KVM; refuses governed work without it.
somp level strict
sOMP wraps omp so every subagent the model spawns runs in a disposable AIec microVM — srt-wrapped, Guard-egress-controlled — then returns a git diff and is destroyed. Your session, skills, and MCP servers stay exactly as upstream ships them.
git clone https://github.com/fedoragobrowse-design/somp.git ~/code/somp && ~/code/somp/install.sh
One line. Idempotent. Never touches your omp setup.
level strict · runtime firecracker dispatched work: GOVERNED placement refused without KVM — fail closed
You talk to omp. The model spawns subagents. The extension throws a breaker: local spawn blocked, work re-dispatched into a box that cannot reach your host.
Paste the line. Clones the operator repo, builds the CLI, links somp + somp-omp, seeds config, verifies.
Point at your plane. Edit ~/.config/somp/config.yaml: aiec.base_url, key file, and guard.model_host (no default — inventing one would aim boxes at the wrong provider).
Run somp. Governed TUI, your normal omp. Check the status bar: sandbox 🛡️ STRICT.
Firecracker microVM + Guard model-only egress + srt. Demands KVM; refuses governed work without it.
somp level strict
Docker worker + Guard + srt. Development only — there is no microVM boundary here, and the page says so.
somp level standard
No sandboxing. dispatch and session up refuse fail-closed until you re-engage.
somp level off
SOMP_LEVEL in the environment wins over config — and says so when it does.
Numbers below are measured on the host or single-sampled — proxies, not guest evidence. The repo keeps docs/UNPROVEN.md as a standing list; this page will not claim what it hasn't measured.
| Claim | Status | Evidence |
|---|---|---|
| srt wrap median ≈ 330 ms | measured · host proxy | somp bench, 16 samples, 0 failures |
| Warm subagent start < 1 s | unproven | needs Firecracker E2E |
| Per-subagent RSS small | unproven | needs Firecracker E2E |
| JEV bash gate live | not implemented | policy pure-function only, 15/15 unit tests |
| Fail-closed on unenforceable | proven live | OFF refusal before any VM created |
One line, reversible, your omp untouched.
git clone https://github.com/fedoragobrowse-design/somp.git ~/code/somp && ~/code/somp/install.sh