788a031003
Fix glob parent directory allowance for patterns with glob characters ( #331 )
...
* fix(sandbox): support pnpm workspaces and macOS cache dir in pnpm profile
pnpm in a workspace (monorepo) creates a node_modules directory inside
every workspace package to symlink direct dependencies. The profile only
allowed writes to the root node_modules, so installs failed with EPERM
on mkdir of e.g. apps/mobile/node_modules.
pnpm on macOS also writes its cache (lockfile verification, metadata)
under ~/Library/Caches/pnpm, while the base profile only covers the XDG
path ~/.cache/pnpm.
Fixes are scoped to the pnpm leaf profile, not the shared
npm-restrictive base.
Ref: https://github.com/safedep/pmg/issues/329
* fix(sandbox): emit regex parent rule for nested-glob allow patterns on Seatbelt
For allow patterns ending in /**, the translator auto-allows the parent
directory so mkdir/stat of the directory itself succeeds. The rule was
always emitted as a literal, which can never match when the parent still
contains glob characters (e.g. ${CWD}/**/node_modules from a workspace
allowance) — silently leaving the directory's own creation denied.
Emit a regex rule for glob-bearing parents instead. This stays strictly
narrower than the Linux drivers (Bubblewrap binds the prefix before the
first /** read-write; Landlock grants the glob expansion or its parent),
and deny rules are emitted after allows, so mandatory credential denies
still override.
Ref: https://github.com/safedep/pmg/issues/329
---------
Co-authored-by: Claude <noreply@anthropic.com >
2026-06-12 12:11:12 +05:30
Abhisek Datta and GitHub
c7244f921a
feat: Add support for environment protection (scrubbing) ( #327 )
...
* feat: Add support for environment variable protection for sandbox
* chore: Update dangerous env var list
* fix: Split profiles for improved environment protection
* fix: pipx sandbox profile separation
* chore: Show sandbox scrub info on error exit
* fix: Code review fixes
* test: Add e2e for sandbox environment scrubbing
2026-06-11 11:40:33 +05:30
7620097613
feat : adds pipx support to PMG ( #292 )
...
* adding the pipx support to project
Signed-off-by: DivyanshuVortex <divyanshuchandra9027@gmail.com >
* create excutors for pipx
Signed-off-by: DivyanshuVortex <divyanshuchandra9027@gmail.com >
* add pipx yml
Signed-off-by: DivyanshuVortex <divyanshuchandra9027@gmail.com >
* chores
Signed-off-by: DivyanshuVortex <divyanshuchandra9027@gmail.com >
* pipx to use standard executor pattern
Signed-off-by: DivyanshuVortex <divyanshuchandra9027@gmail.com >
* Address PR feedback for pipx support
Signed-off-by: DivyanshuVortex <divyanshuchandra9027@gmail.com >
* Update pipx flags comments
Signed-off-by: DivyanshuVortex <divyanshuchandra9027@gmail.com >
---------
Signed-off-by: DivyanshuVortex <divyanshuchandra9027@gmail.com >
Co-authored-by: Abhisek Datta <abhisek.datta@gmail.com >
Co-authored-by: Sahil Bansal <bansalsahil315@gmail.com >
2026-06-10 16:26:33 +05:30
Abhisek Datta and GitHub
b56a8e2a43
chore: Show cloud credentials store in setup info ( #236 )
...
* chore: Show cloud credentials store in setup info
* fix: pnpm sandbox policy for atomic write
2026-05-04 16:24:49 +00:00
Abhisek Datta and GitHub
0588e66131
fix: Tune pypi sandbox profile ( #178 )
2026-03-06 17:47:04 +05:30
Abhisek Datta and GitHub
3778d4d1f3
fix: Sandbox Allow network bind for npx ( #151 )
...
* feat: Add support for network bind
* chore: Add comments for bwrap sandbox
2026-02-04 15:32:47 +05:30
4600ab0245
fix: Sandbox policy tuning for tmp write access ( #145 )
...
* fix: Sandbox policy tuning for tmp write access
* fix: Remove numbers from test
* Update sandbox/profiles/pnpm-restrictive.yml
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com >
* fix: Sandbox E2E test to consider Linux bubblewrap tmpfs mount
* Update sandbox/profiles/pnpm-restrictive.yml
Co-authored-by: Sahil Bansal <bansalsahil315@gmail.com >
Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com >
* fix: Migrate deny rules from pnpm to npm policy
---------
Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com >
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
Co-authored-by: Sahil Bansal <bansalsahil315@gmail.com >
2026-02-01 15:20:17 +05:30
2e1f5b1a36
feat: Add support for policy inheritence ( #113 )
...
* feat: Add support for policy inheritence
* fix: Linter fixes
* Update docs/sandbox.md
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com >
* fix: Handle boolean inheritence
* ci: Add linter
* Update sandbox/policy_test.go
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com >
* fix: Linter fixes
* fix: Linter fixes
* fix: Sandbox rule regex format
---------
Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com >
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
2026-01-14 10:50:39 +05:30
9693428171
feat: Experimental Sandbox Support ( #101 )
...
* feat: Sandbox implementation with seatbelt
* refactor: Remove concept of PM_CACHE
* fix: Misc fixes
* refactor: Sandbox for separation of boundaries
* fix: Apply API
* fix: Add support for sandbox cleanup
* test: Add variable interpolation test
* fix: Misc cleanup fixes
* chore: Cleanup sandbox registry
* chore: Cleanup sandbox policy
* chore: Cleanup sandbox
* fix: Misc cleanup fixes
* fix: Remove violation mode
* fix: Update config template
* chore: Go mod cleanup
* fix: Handle the case when package manager policy is explicitly disabled
* fix: Sandbox executor
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com >
* test: Remove unused var
* test: Add test for seatbelt sandbox driver
* fix: Sandbox profile loader from file should use path for caching
* test: Add policy test
* feat: Add support for config templates
* fix: Seatbelt translator handle glob
* fix: Merge conflicts
* fix: Fix sandbox policy generator for MacOS min permissions
* fix: Sandbox path handling bugs
* fix: Deny read to dangerous directories
* fix: Deny read to dangerous directories
* add sandbox e2e (#112 )
* fix: Sandbox E2E test
* fix: Code review fixes
* fix: Code review fixes
* doc: Add sandbox debugging guide
* doc: Update sandbox doc
* docs: Add sandbox usage doc
* fix: Use better error for sandbox without policy
* fix: Add sandbox for npx
* fix: Enable PTY for npm
---------
Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com >
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
Co-authored-by: Sahil Bansal <bansalsahil315@gmail.com >
2026-01-13 14:52:02 +05:30