4600ab0245
fix: Sandbox policy tuning for tmp write access ( #145 )
...
* fix: Sandbox policy tuning for tmp write access
* fix: Remove numbers from test
* Update sandbox/profiles/pnpm-restrictive.yml
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com >
* fix: Sandbox E2E test to consider Linux bubblewrap tmpfs mount
* Update sandbox/profiles/pnpm-restrictive.yml
Co-authored-by: Sahil Bansal <bansalsahil315@gmail.com >
Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com >
* fix: Migrate deny rules from pnpm to npm policy
---------
Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com >
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
Co-authored-by: Sahil Bansal <bansalsahil315@gmail.com >
2026-02-01 15:20:17 +05:30
Abhisek Datta and GitHub
80a1747e3e
feat: Add support for Linux Sandbox using Bubblewrap ( #120 )
...
* feat: Add support for bubblewrap sandbox
* fix: Glob pattern expansion limit for linux
* fix: Bug in glob pattern expansion for bwrap
* fix: README on trust
* fix: Multiple bubblewrap translator fix
* test: Add E2E for linux sandbox
* fix: Refactor bwrap sandbox to use common dangerous files
* fix: Path test case
* fix: Non-existent path handling bug
* refactor: Misc cleanup
* fix: Avoid bind mount for non-existentent deny protection
* fix: Off by one bug in path depth handling
* ci: Disable AppArmor on GHA runner
* fix: Disable apparmor userns restrictions
2026-01-15 20:12:12 +05:30
9693428171
feat: Experimental Sandbox Support ( #101 )
...
* feat: Sandbox implementation with seatbelt
* refactor: Remove concept of PM_CACHE
* fix: Misc fixes
* refactor: Sandbox for separation of boundaries
* fix: Apply API
* fix: Add support for sandbox cleanup
* test: Add variable interpolation test
* fix: Misc cleanup fixes
* chore: Cleanup sandbox registry
* chore: Cleanup sandbox policy
* chore: Cleanup sandbox
* fix: Misc cleanup fixes
* fix: Remove violation mode
* fix: Update config template
* chore: Go mod cleanup
* fix: Handle the case when package manager policy is explicitly disabled
* fix: Sandbox executor
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com >
* test: Remove unused var
* test: Add test for seatbelt sandbox driver
* fix: Sandbox profile loader from file should use path for caching
* test: Add policy test
* feat: Add support for config templates
* fix: Seatbelt translator handle glob
* fix: Merge conflicts
* fix: Fix sandbox policy generator for MacOS min permissions
* fix: Sandbox path handling bugs
* fix: Deny read to dangerous directories
* fix: Deny read to dangerous directories
* add sandbox e2e (#112 )
* fix: Sandbox E2E test
* fix: Code review fixes
* fix: Code review fixes
* doc: Add sandbox debugging guide
* doc: Update sandbox doc
* docs: Add sandbox usage doc
* fix: Use better error for sandbox without policy
* fix: Add sandbox for npx
* fix: Enable PTY for npm
---------
Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com >
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
Co-authored-by: Sahil Bansal <bansalsahil315@gmail.com >
2026-01-13 14:52:02 +05:30