mirror of
https://github.com/safedep/pmg.git
synced 2026-08-03 07:24:09 +02:00
feat: Experimental Sandbox Support (#101)
* feat: Sandbox implementation with seatbelt * refactor: Remove concept of PM_CACHE * fix: Misc fixes * refactor: Sandbox for separation of boundaries * fix: Apply API * fix: Add support for sandbox cleanup * test: Add variable interpolation test * fix: Misc cleanup fixes * chore: Cleanup sandbox registry * chore: Cleanup sandbox policy * chore: Cleanup sandbox * fix: Misc cleanup fixes * fix: Remove violation mode * fix: Update config template * chore: Go mod cleanup * fix: Handle the case when package manager policy is explicitly disabled * fix: Sandbox executor * Apply suggestions from code review Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com> Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com> * test: Remove unused var * test: Add test for seatbelt sandbox driver * fix: Sandbox profile loader from file should use path for caching * test: Add policy test * feat: Add support for config templates * fix: Seatbelt translator handle glob * fix: Merge conflicts * fix: Fix sandbox policy generator for MacOS min permissions * fix: Sandbox path handling bugs * fix: Deny read to dangerous directories * fix: Deny read to dangerous directories * add sandbox e2e (#112) * fix: Sandbox E2E test * fix: Code review fixes * fix: Code review fixes * doc: Add sandbox debugging guide * doc: Update sandbox doc * docs: Add sandbox usage doc * fix: Use better error for sandbox without policy * fix: Add sandbox for npx * fix: Enable PTY for npm --------- Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com> Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com> Co-authored-by: Sahil Bansal <bansalsahil315@gmail.com>
This commit is contained in:
co-authored by
Copilot
Sahil Bansal
parent
c0122898ca
commit
9693428171
@@ -59,6 +59,41 @@ type Config struct {
|
||||
// ExperimentalProxyMode enables experimental proxy-based package interception.
|
||||
// When enabled, PMG starts a proxy server and intercepts package manager requests in real-time.
|
||||
ExperimentalProxyMode bool `mapstructure:"experimental_proxy_mode"`
|
||||
|
||||
// Sandbox enables sandboxing of package manager processes with controlled filesystem,
|
||||
// network, and process execution access. Provides defense-in-depth against supply chain attacks.
|
||||
Sandbox SandboxConfig `mapstructure:"sandbox"`
|
||||
}
|
||||
|
||||
// SandboxConfig configures the sandbox system for isolating package manager processes.
|
||||
type SandboxConfig struct {
|
||||
// Enabled enables sandbox mode (opt-in by default for backward compatibility).
|
||||
Enabled bool `mapstructure:"enabled"`
|
||||
|
||||
// Policies maps package manager names to their sandbox policy references.
|
||||
// Key is package manager name (e.g., "npm", "pip"), value is policy reference.
|
||||
Policies map[string]SandboxPolicyRef `mapstructure:"policies"`
|
||||
|
||||
// PolicyTemplates maps template names to their paths.
|
||||
PolicyTemplates map[string]SandboxPolicyTemplate `mapstructure:"policy_templates"`
|
||||
}
|
||||
|
||||
// SandboxPolicyTemplate defines a template for a sandbox policy, used to map
|
||||
// a profile name to a path.
|
||||
type SandboxPolicyTemplate struct {
|
||||
// Path is the path to the template file.
|
||||
// Relative path can be used to reference a template file in the config directory (example: ./npm-restrictive.yml)
|
||||
Path string `mapstructure:"path"`
|
||||
}
|
||||
|
||||
// SandboxPolicyRef references a sandbox policy for a specific package manager.
|
||||
type SandboxPolicyRef struct {
|
||||
// Enabled enables sandboxing for this specific package manager.
|
||||
Enabled bool `mapstructure:"enabled"`
|
||||
|
||||
// Profile is the name of a built-in profile (e.g., "npm-restrictive")
|
||||
// or an absolute path to a custom YAML policy file.
|
||||
Profile string `mapstructure:"profile"`
|
||||
}
|
||||
|
||||
// TrustedPackage is a package that is trusted by the user and will be ignored by the security guardrails.
|
||||
@@ -85,6 +120,11 @@ type RuntimeConfig struct {
|
||||
// InsecureInstallation allows bypassing install blocking on malicious packages
|
||||
InsecureInstallation bool
|
||||
|
||||
// SandboxProfileOverride is a runtime override for the sandbox policy profile.
|
||||
// When set, this profile path is used instead of the configured policy for all package managers.
|
||||
// This is a CLI-only flag (--sandbox-profile) and is not persisted to config.yml.
|
||||
SandboxProfileOverride string
|
||||
|
||||
// Internal config values computed at runtime and must be accessed via. API
|
||||
configDir string
|
||||
configFilePath string
|
||||
@@ -101,6 +141,11 @@ func (r *RuntimeConfig) EventLogDir() string {
|
||||
return r.eventLogDir
|
||||
}
|
||||
|
||||
// ConfigDir returns the path to the config directory.
|
||||
func (r *RuntimeConfig) ConfigDir() string {
|
||||
return r.configDir
|
||||
}
|
||||
|
||||
// DefaultConfig is a fail safe contract for the runtime configuration.
|
||||
// The config package return an appropriate RuntimeConfig based on the environment and the configuration.
|
||||
func DefaultConfig() RuntimeConfig {
|
||||
@@ -122,6 +167,9 @@ func DefaultConfig() RuntimeConfig {
|
||||
SkipEventLogging: false,
|
||||
ExperimentalProxyMode: false,
|
||||
TrustedPackages: []TrustedPackage{},
|
||||
Sandbox: SandboxConfig{
|
||||
Enabled: false,
|
||||
},
|
||||
},
|
||||
DryRun: false,
|
||||
InsecureInstallation: insecureInstallation,
|
||||
|
||||
Reference in New Issue
Block a user