mirror of
https://github.com/safedep/pmg.git
synced 2026-08-03 07:24:09 +02:00
Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com> Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com>
This commit is contained in:
@@ -52,7 +52,8 @@ trusted_packages:
|
|||||||
# filesystem, network, and process execution access. This provides defense-in-depth
|
# filesystem, network, and process execution access. This provides defense-in-depth
|
||||||
# protection against malicious install scripts and supply chain attacks.
|
# protection against malicious install scripts and supply chain attacks.
|
||||||
#
|
#
|
||||||
# Policy violations will block execution (this is the only supported behavior).
|
# When sandboxing is enabled for a package manager, policy violations will block execution
|
||||||
|
# (no "warn-only" mode). Sandboxing itself can be disabled globally or per package manager.
|
||||||
#
|
#
|
||||||
# Currently supported platforms:
|
# Currently supported platforms:
|
||||||
# - macOS (using Seatbelt sandbox-exec)
|
# - macOS (using Seatbelt sandbox-exec)
|
||||||
|
|||||||
@@ -75,7 +75,7 @@ func ApplySandbox(ctx context.Context, cmd *exec.Cmd, pmName string) (*sandbox.E
|
|||||||
}
|
}
|
||||||
|
|
||||||
if !sb.IsAvailable() {
|
if !sb.IsAvailable() {
|
||||||
return nil, fmt.Errorf("sandbox %s not available, running without sandbox", sb.Name())
|
return nil, fmt.Errorf("sandbox %s is required but not available", sb.Name())
|
||||||
}
|
}
|
||||||
|
|
||||||
log.Debugf("Running %s in %s sandbox with policy %s", pmName, sb.Name(), policy.Name)
|
log.Debugf("Running %s in %s sandbox with policy %s", pmName, sb.Name(), policy.Name)
|
||||||
|
|||||||
Reference in New Issue
Block a user