feat: Add support for Linux Sandbox using Bubblewrap (#120)

* feat: Add support for bubblewrap sandbox

* fix: Glob pattern expansion limit for linux

* fix: Bug in glob pattern expansion for bwrap

* fix: README on trust

* fix: Multiple bubblewrap translator fix

* test: Add E2E for linux sandbox

* fix: Refactor bwrap sandbox to use common dangerous files

* fix: Path test case

* fix: Non-existent path handling bug

* refactor: Misc cleanup

* fix: Avoid bind mount for non-existentent deny protection

* fix: Off by one bug in path depth handling

* ci: Disable AppArmor on GHA runner

* fix: Disable apparmor userns restrictions
This commit is contained in:
Abhisek Datta
2026-01-15 20:12:12 +05:30
committed by GitHub
parent b97a4c2ee5
commit 80a1747e3e
13 changed files with 2495 additions and 56 deletions
+7 -1
View File
@@ -57,8 +57,14 @@ trusted_packages:
#
# Currently supported platforms:
# - macOS (using Seatbelt sandbox-exec)
# - Linux (planned: Bubblewrap or seccomp-bpf)
# - Linux (using Bubblewrap with namespace isolation)
# - Windows (planned)
#
# Platform-specific limitations:
# - Linux: Filesystem permissions use coarse-grained bind mounts. Glob patterns (e.g., *.txt)
# are expanded at policy translation time, but entire directories may be mounted rather than
# individual matching files. This is less precise than macOS regex-based filtering.
# - macOS: Network filtering is limited (all-or-nothing for most policies).
sandbox:
# Enable sandbox mode (opt-in, default: false for backward compatibility)
enabled: false