Files
pmg/sandbox/platform/seatbelt_darwin_test.go
9693428171 feat: Experimental Sandbox Support (#101)
* feat: Sandbox implementation with seatbelt

* refactor: Remove concept of PM_CACHE

* fix: Misc fixes

* refactor: Sandbox for separation of boundaries

* fix: Apply API

* fix: Add support for sandbox cleanup

* test: Add variable interpolation test

* fix: Misc cleanup fixes

* chore: Cleanup sandbox registry

* chore: Cleanup sandbox policy

* chore: Cleanup sandbox

* fix: Misc cleanup fixes

* fix: Remove violation mode

* fix: Update config template

* chore: Go mod cleanup

* fix: Handle the case when package manager policy is explicitly disabled

* fix: Sandbox executor

* Apply suggestions from code review

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com>

* test: Remove unused var

* test: Add test for seatbelt sandbox driver

* fix: Sandbox profile loader from file should use path for caching

* test: Add policy test

* feat: Add support for config templates

* fix: Seatbelt translator handle glob

* fix: Merge conflicts

* fix: Fix sandbox policy generator for MacOS min permissions

* fix: Sandbox path handling bugs

* fix: Deny read to dangerous directories

* fix: Deny read to dangerous directories

* add sandbox e2e (#112)

* fix: Sandbox E2E test

* fix: Code review fixes

* fix: Code review fixes

* doc: Add sandbox debugging guide

* doc: Update sandbox doc

* docs: Add sandbox usage doc

* fix: Use better error for sandbox without policy

* fix: Add sandbox for npx

* fix: Enable PTY for npm

---------

Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Sahil Bansal <bansalsahil315@gmail.com>
2026-01-13 14:52:02 +05:30

53 lines
1.3 KiB
Go

//go:build darwin
// +build darwin
package platform
import (
"context"
"os/exec"
"testing"
"github.com/safedep/pmg/sandbox"
"github.com/stretchr/testify/assert"
)
func TestSeatbeltDarwin(t *testing.T) {
policy := &sandbox.SandboxPolicy{
Name: "test",
Description: "test",
PackageManagers: []string{"npm"},
Filesystem: sandbox.FilesystemPolicy{
AllowRead: []string{"/tmp"},
AllowWrite: []string{"/tmp"},
DenyRead: []string{"/private/var"},
DenyWrite: []string{"/private/var"},
},
Network: sandbox.NetworkPolicy{
AllowOutbound: []string{"*:*"},
},
Process: sandbox.ProcessPolicy{
AllowExec: []string{"/bin/sh"},
DenyExec: []string{"/bin/bash"},
},
}
sb, err := newSeatbeltSandbox()
assert.NoError(t, err)
cmd := exec.Command("npm", "install", "lodash")
npmResolvedPath := cmd.Path
result, err := sb.Execute(context.Background(), cmd, policy)
assert.NoError(t, err)
assert.True(t, result.ShouldRun(), "command should be runnable because seatbelt only patches the command")
assert.Equal(t, cmd.Path, "/usr/bin/sandbox-exec")
assert.Equal(t, cmd.Args, []string{"sandbox-exec", "-f", sb.tempProfilePath, npmResolvedPath, "install", "lodash"})
err = result.Close()
assert.NoError(t, err)
assert.NoFileExists(t, sb.tempProfilePath)
}