mirror of
https://github.com/safedep/pmg.git
synced 2026-08-03 07:24:09 +02:00
* feat: Sandbox implementation with seatbelt * refactor: Remove concept of PM_CACHE * fix: Misc fixes * refactor: Sandbox for separation of boundaries * fix: Apply API * fix: Add support for sandbox cleanup * test: Add variable interpolation test * fix: Misc cleanup fixes * chore: Cleanup sandbox registry * chore: Cleanup sandbox policy * chore: Cleanup sandbox * fix: Misc cleanup fixes * fix: Remove violation mode * fix: Update config template * chore: Go mod cleanup * fix: Handle the case when package manager policy is explicitly disabled * fix: Sandbox executor * Apply suggestions from code review Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com> Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com> * test: Remove unused var * test: Add test for seatbelt sandbox driver * fix: Sandbox profile loader from file should use path for caching * test: Add policy test * feat: Add support for config templates * fix: Seatbelt translator handle glob * fix: Merge conflicts * fix: Fix sandbox policy generator for MacOS min permissions * fix: Sandbox path handling bugs * fix: Deny read to dangerous directories * fix: Deny read to dangerous directories * add sandbox e2e (#112) * fix: Sandbox E2E test * fix: Code review fixes * fix: Code review fixes * doc: Add sandbox debugging guide * doc: Update sandbox doc * docs: Add sandbox usage doc * fix: Use better error for sandbox without policy * fix: Add sandbox for npx * fix: Enable PTY for npm --------- Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com> Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com> Co-authored-by: Sahil Bansal <bansalsahil315@gmail.com>
53 lines
1.3 KiB
Go
53 lines
1.3 KiB
Go
//go:build darwin
|
|
// +build darwin
|
|
|
|
package platform
|
|
|
|
import (
|
|
"context"
|
|
"os/exec"
|
|
"testing"
|
|
|
|
"github.com/safedep/pmg/sandbox"
|
|
"github.com/stretchr/testify/assert"
|
|
)
|
|
|
|
func TestSeatbeltDarwin(t *testing.T) {
|
|
policy := &sandbox.SandboxPolicy{
|
|
Name: "test",
|
|
Description: "test",
|
|
PackageManagers: []string{"npm"},
|
|
Filesystem: sandbox.FilesystemPolicy{
|
|
AllowRead: []string{"/tmp"},
|
|
AllowWrite: []string{"/tmp"},
|
|
DenyRead: []string{"/private/var"},
|
|
DenyWrite: []string{"/private/var"},
|
|
},
|
|
Network: sandbox.NetworkPolicy{
|
|
AllowOutbound: []string{"*:*"},
|
|
},
|
|
Process: sandbox.ProcessPolicy{
|
|
AllowExec: []string{"/bin/sh"},
|
|
DenyExec: []string{"/bin/bash"},
|
|
},
|
|
}
|
|
|
|
sb, err := newSeatbeltSandbox()
|
|
assert.NoError(t, err)
|
|
|
|
cmd := exec.Command("npm", "install", "lodash")
|
|
npmResolvedPath := cmd.Path
|
|
|
|
result, err := sb.Execute(context.Background(), cmd, policy)
|
|
assert.NoError(t, err)
|
|
assert.True(t, result.ShouldRun(), "command should be runnable because seatbelt only patches the command")
|
|
|
|
assert.Equal(t, cmd.Path, "/usr/bin/sandbox-exec")
|
|
assert.Equal(t, cmd.Args, []string{"sandbox-exec", "-f", sb.tempProfilePath, npmResolvedPath, "install", "lodash"})
|
|
|
|
err = result.Close()
|
|
assert.NoError(t, err)
|
|
|
|
assert.NoFileExists(t, sb.tempProfilePath)
|
|
}
|