feat(sandbox): scrub sensitive environment variables from package managers

Implements process-level environment variable protection per the spec.
When the sandbox is enabled, credential-bearing variables are removed from
the package manager child process before it is spawned, defending against
supply chain attacks that harvest secrets from the environment.

- DANGEROUS_ENV_VARS: curated default deny list of known secret names (no
  generic *_TOKEN/*_SECRET catch-alls); ScrubEnv matcher supports case-
  insensitive globs so profiles can opt into broader denies.
- EnvironmentPolicy (environment.allow / environment.deny) on sandbox
  profiles, merged under inheritance; deep-copied on resolve.
- npm/pypi profiles re-allow their own ecosystem's auth vars so package
  managers keep working; other ecosystems' and cloud creds stay scrubbed.
- New 'env' --sandbox-allow type (and overlay support via the same path):
  allow-only, value kept verbatim (not path-resolved), governed by lockdown.
- Enforced in executor.ApplySandbox as the last step before launch, after
  overlay and runtime overrides merge; scrubbed names logged for audit.

https://claude.ai/code/session_017Da1sAYLYpeEgogm6f9VYW
This commit is contained in:
Claude
2026-06-10 07:17:14 +00:00
parent 374f9f315e
commit d60a558579
15 changed files with 653 additions and 6 deletions
+31
View File
@@ -94,6 +94,37 @@ func TestParseSandboxAllowOverrides_ValidFormats(t *testing.T) {
}
}
func TestParseSandboxAllowOverrides_Env(t *testing.T) {
tests := []struct {
name string
raw string
expectedValue string
}{
{name: "exact name", raw: "env=NPM_TOKEN", expectedValue: "NPM_TOKEN"},
{name: "glob name kept verbatim", raw: "env=npm_config_*", expectedValue: "npm_config_*"},
{name: "not path resolved", raw: "env=AWS_PROFILE", expectedValue: "AWS_PROFILE"},
}
for _, tt := range tests {
t.Run(tt.name, func(t *testing.T) {
overrides, err := parseSandboxAllowOverrides([]string{tt.raw})
require.NoError(t, err)
require.Len(t, overrides, 1)
assert.Equal(t, SandboxAllowEnv, overrides[0].Type)
// Value is kept verbatim — no CWD/path resolution.
assert.Equal(t, tt.expectedValue, overrides[0].Value)
})
}
}
func TestParseSandboxAllowOverrides_EnvInvalid(t *testing.T) {
for _, raw := range []string{"env=NPM/TOKEN", "env=FOO=BAR", "env=HAS SPACE"} {
_, err := parseSandboxAllowOverrides([]string{raw})
assert.Error(t, err, "expected error for %q", raw)
}
}
func TestParseSandboxAllowOverrides_MultipleValues(t *testing.T) {
raw := []string{
"write=./.gitignore",