Skip to content

Repository files navigation

edgeBox

A decentralized, user-programmable execution platform built on the AT Protocol. Each user owns a Box — a compiled WebAssembly binary that is their page. When a visitor hits /@handle, their browser downloads the Box, runs it locally with the owner's data as input, and renders the HTML it returns. The server indexes and distributes; the visitor's device executes.

Canonical data lives in each user's own Personal Data Server (PDS) as signed AT Protocol records — edgeBox is an AppView, not a data silo. Profiles that behave, not just display. Data you own, not data we hold.

Why it's interesting

  • User-owned data. Every post, layout, and link is a signed record in the user's PDS, interoperable with the wider AT Protocol / Bluesky network. edgeBox reads them through an AppView (firehose-populated cache, with a live-fetch fallback) and writes on the user's behalf — it never holds the canonical copy.
  • Pages are programs. A Box is real compiled code (Rust → wasm32-unknown-unknown) executed in the browser's WebAssembly sandbox — no DOM access, no network, no cookies, no cross-user memory reads. The isolation is structural (the Wasm linear-memory model), not policy-enforced.
  • Edge AI. Boxes can host Actors that run an LLM (Gemma 4 E2B, q4 ONNX) entirely on the visitor's device via WebGPU. No inference server.
  • A runtime-native agent. Each viewer has a personal AI agent that follows them across the platform, reads the page they're on as context, and can invoke the tools (Actors) they've equipped — with per-command autonomy governance and prompt-injection defenses.
  • P2P distribution. Actors are seeded peer-to-peer over WebRTC DataChannels; every user who installs one becomes a seeder.

How it works

Visitor requests /@alice
→ AppView resolves alice's handle → DID → PDS
→ Server sends alice's compiled .wasm Box
→ Browser instantiates it with profile data (signed PDS records, normalized)
→ Box returns HTML
→ Browser renders the page

Boxes run in WebAssembly's linear-memory sandbox with zero imports — no ambient authority. They receive data in and return HTML out; everything else (network, storage, audio, peers, inference) is requested through a versioned, additive-only Host API command surface that the runtime mediates.

AT Protocol integration

edgeBox is an AppView over atproto. The full design is in docs/atproto.md; in brief:

  • Lexicons (lexicons/com/edgebox/*) define the canonical record schemas — profile, box layout, matter (post/track/image/game), follow, actor manifest/publication, and agent permission sets.
  • server/atproto/ — handle→DID→PDS resolution, a Jetstream firehose consumer, an indexer that populates the AppView cache, lexicon loading/validation, and PDS writes on the user's behalf.
  • server/appview/ — DID-keyed record + profile cache, per-DID compile queue, feed builder, normalizer (atproto records → edgeBox schema), and a live-fetch path for environments without the firehose.
  • Bluesky interopapp.bsky.* posts, likes, reposts, and replies are hydrated through Bluesky's public AppView, so an edgeBox feed and a Bluesky feed are the same underlying data.

Quick start

Prerequisites: Node.js 18+, Rust toolchain (rustup), and wasm-opt (from binaryen).

git clone https://github.com/botBehavior/edgeBox.git
cd edgeBox
npm install
npm start
# → http://localhost:3000

To exercise the full atproto path locally, run against a development PDS:

npm run dev-pds:up # start a local PDS (Docker)
npm run dev-pds:seed # create seed accounts + records

Log in with a handle + app-password (POST /auth/login); the server resolves your PDS and reads/writes records there.

Build a Box

# Rust → wasm32-unknown-unknown → wasm-opt -Os
bash scripts/build_box.sh [box_dir] [output_wasm_path]

Edit visually

Visit /@handle/edit to open the DSLBox — a grid-based layout editor (drag-and-drop, snap-to-grid, resize, properties panel). Saving recompiles your layout into a new Box and writes the layout record to your PDS.

Key concepts

TermMeaning
BoxA compiled .wasm binary — the user's executable page. Contains Views, Micro-Actors, and Actors.
MatterInert content data (a post, track, image). Travels the network, never executes on the receiver's device.
ViewA deterministic rendering component. Stateless, fast, no side effects.
ActorA stateful computational entity (AI agent, game, chat). Communicates via commands — zero Wasm imports.
Host APIThe JSON contract passed into every Box at render time. Versioned, additive-only — the platform's capability surface.

Actors & edge AI

Actors are self-contained Wasm modules with an init/update/render lifecycle, the same zero-import sandbox as Boxes. They express intent through commands (audio.*, matter.*, peer.*, inference.*, agent.*, …) that the runtime mediates.

Inference-capable Actors request generation via the inference.* namespace; the runtime loads Gemma 4 E2B (q4 ONNX) into a Web Worker and runs it on-device via WebGPU. A mock mode echoes input when WebGPU is unavailable, so the full pipeline is testable without a GPU.

The runtime agent is a viewer-scoped service (not a per-page actor): it lives in the shared inference worker, persists to IndexedDB across navigation, reads the current page as context, and invokes equipped vs. page tools through a namespaced CALL protocol with two-axis autonomy governance (source × owner). Authored page context is treated as data, never instructions — a deliberate prompt-injection boundary.

Architecture

boxes/ Rust source for Boxes and Actors
sdk/ Box ABI (alloc/render/dealloc) + rich-rendering helpers
actor-sdk/ Actor ABI (init/update/render)
actors/ Built-in actors (incl. the runtime agent)
dslbox/ Visual layout editor
feedbox/ marketplacebox/
runner/ JavaScript runtimes (browser + Node + Deno), SPA shell, inference worker/bridge
server/ Zero-dependency Node.js HTTP server (SSR, auth, routing)
atproto/ PDS client, jetstream, indexer, lexicon loader, writes
appview/ cache, feed, normalize, compile queue, live-fetch
lexicons/com/edgebox/ Canonical AT Protocol record schemas
host-api/ Versioned Host API schema (additive-only)
scripts/ Build, test, dev-PDS tooling

Box memory interface (ABI)

Every Box exports exactly three functions: alloc(len) -> ptr, render(ptr, len) -> packed(out_ptr<<32 | out_len), and dealloc(ptr, len). Box authors write only render_page(input) -> Output — pure logic, no I/O. The SDK handles the rest.

Tech stack

  • Boxes/Actors: Rust → wasm32-unknown-unknownwasm-opt -Os (no WASI, no imports)
  • Runtime: Node.js ESM, zero runtime dependencies beyond @atproto/api
  • Server: zero-dep node:http SSR
  • Inference:@huggingface/transformers + ONNX Runtime Web + WebGPU, CDN-loaded, isolated in a Web Worker
  • Data: AT Protocol records in the user's PDS; serde with rename_all = "camelCase"

Tests

npm run test:unit # 220 unit tests (Node-only, fetch-stubbed, ~1s)
npm test# full suite incl. the wasm build pipeline

Coverage spans the build pipeline, XSS/SSR, auth + OAuth, the agent framework, the atproto client/jetstream/indexer, and every AppView module.

License

MIT

About

Decentralized, user-programmable execution platform on the AT Protocol: each page is a sandboxed WebAssembly binary, with on-device edge AI and a runtime-native agent.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages