feat(sandbox): add network_via_proxy_only and allow_direct_dns policy fields (#370)

* feat(sandbox): add network_via_proxy_only and allow_direct_dns policy fields

Config surface for network lockdown: network_via_proxy_only confines a
sandboxed package manager's outbound network to the PMG proxy;
allow_direct_dns is its escape hatch re-opening direct DNS. Both follow
the existing pointer-bool inheritance pattern in MergeWithParent. Lint
warns when allow_direct_dns is set without network_via_proxy_only, where
it has no effect.

The fields are declared and inherited but unread; enforcement lands with
the ExecutionContext plumbing and Seatbelt lockdown translation.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PqMU5GNBbQvQct9nxek1VS

* fix(sandbox): deep-copy new pointer flags in profile resolution

expandPolicyPaths re-points the older pointer booleans so callers cannot
corrupt the registry-cached policy; the new NetworkViaProxyOnly and
AllowDirectDNS fields need the same isolation.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PqMU5GNBbQvQct9nxek1VS

---------

Co-authored-by: Claude <noreply@anthropic.com>
This commit is contained in:
Abhisek Datta
2026-07-10 19:28:39 +05:30
committed by GitHub
co-authored by Claude Fable 5
parent e6b5157a2a
commit 22d6eabb6b
6 changed files with 196 additions and 0 deletions
+6
View File
@@ -39,6 +39,12 @@ func expandPolicyPaths(p *SandboxPolicy, opts ResolveOptions) (*SandboxPolicy, e
if p.AllowNetworkBind != nil {
out.AllowNetworkBind = utils.PtrTo(*p.AllowNetworkBind)
}
if p.NetworkViaProxyOnly != nil {
out.NetworkViaProxyOnly = utils.PtrTo(*p.NetworkViaProxyOnly)
}
if p.AllowDirectDNS != nil {
out.AllowDirectDNS = utils.PtrTo(*p.AllowDirectDNS)
}
allowRead, err := expandSlice(p.Filesystem.AllowRead, opts)
if err != nil {