mkfile: install sandbox configs to ~/.config/ollie/sandbox

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
Levi Neely 2026-04-09 22:39:00 +02:00
parent 480c3c1f37
commit 7068d1832a
3 changed files with 162 additions and 1 deletions

3
mkfile
View File

@ -1,6 +1,7 @@
all:V: install
install:V:
mkdir -p $HOME/.config/ollie
mkdir -p $HOME/.config/ollie/sandbox
cp -rf agents $HOME/.config/ollie
cp -rf sandbox $HOME/.config/ollie

43
sandbox/anvilmcp.yaml Normal file
View File

@ -0,0 +1,43 @@
# Default sandbox config for anvilmcp execute_code
cwd: temp # Use temp workspace (cleaned up after execution)
filesystem:
ro:
- "/etc/alternatives"
- "/etc/ld.so.cache"
- "/etc/passwd"
- "{HOME}/.local/share/anvillm/mail"
- "/dev/urandom"
rox:
- "/usr"
- "/lib"
- "/lib64"
- "/bin"
- "{HOME}/go/bin"
- "{HOME}/bin"
- "{HOME}/.local/bin"
- "{HOME}/opt"
- "{PLAN9}/bin"
rw:
- "/dev/null"
- "/tmp"
- "{NAMESPACE}"
- "{XDG_RUNTIME_DIR}/superpowerd"
rwx:
- "{CWD}"
- "{HOME}/mnt/anvillm"
- "{HOME}/mnt/beads"
- "{HOME}/mnt/denote"
env:
- NAMESPACE
- PATH
- HOME
- PLAN9
- DISPLAY
- WAYLAND_DISPLAY
- USER
- AGENT_ID
- SUPERPOWERD_SESSION_TOKEN
- SUPERPOWERD_SOCKET_DIR
- XDG_RUNTIME_DIR
network:
unrestricted: true

117
sandbox/default.yaml Normal file
View File

@ -0,0 +1,117 @@
# Default role: combined most-permissive settings from all tasks/roles
cwd: "{CWD}"
filesystem:
ro:
- "{XDG_CONFIG_HOME}/git"
- "{HOME}/.ssh"
- "{HOME}/.netrc"
- "{HOME}/.local/share/anvillm/mail"
- "/etc/gitconfig"
- "/etc/gitattributes"
- "/etc/ssh/ssh_config"
- "/etc/ssh/ssh_known_hosts"
- "/etc/magic"
- "/var/log"
- "/run/systemd"
- "/var/log/journal"
- "/etc/systemd"
- "/proc"
- "/sys"
- "{HOME}/.jenkins"
- "{HOME}/.psqlrc"
- "{HOME}/.pgpass"
- "{HOME}/.aws"
- "{HOME}/.ansible"
- "{HOME}/.ansible.cfg"
- "{HOME}/.jira.d"
- "{HOME}/.my.cnf"
- "{HOME}/.mylogin.cnf"
- "{XDG_CONFIG_HOME}/gh"
- "{XDG_DATA_HOME}/gh/extensions"
- "/dev"
rw:
- "{HOME}/.ssh/known_hosts"
- "{HOME}/pCloudDrive"
- "{HOME}/.pcloud"
- "{HOME}/.git-credentials"
- "{XDG_CONFIG_HOME}/git/credentials"
- "{XDG_RUNTIME_DIR}/git/"
- "{HOME}/.mcpt"
- "{HOME}/doc"
- "{HOME}/.gnupg"
- "{XDG_DOCUMENTS_DIR}"
- "{XDG_CONFIG_HOME}/.jira"
- "{HOME}/.m2"
- "{HOME}/.gradle"
- "/var/run/docker.sock"
- "{HOME}/.docker"
- "{HOME}/.pnpm-store"
- "{XDG_CONFIG_HOME}/yarn"
- "{HOME}/.yarnrc.yml"
- "{HOME}/.npmrc"
- "{HOME}/.ansible/tmp"
- "{XDG_RUNTIME_DIR}"
- "{XDG_DATA_HOME}/containers"
- "{XDG_CONFIG_HOME}/containers"
- "{XDG_CONFIG_HOME}/pip"
- "{HOME}/.pip"
- "{HOME}/.cargo"
- "{HOME}/.rustup"
- "{XDG_CONFIG_HOME}/nvim"
- "{XDG_CONFIG_HOME}/vim"
- "{XDG_DATA_HOME}/nvim"
- "{XDG_STATE_HOME}/nvim"
- "{HOME}/.local/share/anvillm"
- "{HOME}/.vimrc"
- "{HOME}/.vim"
- "{HOME}/.emacs.d"
- "{HOME}/.config/emacs"
- "/etc"
- "/usr/local/etc"
- "/dev/urandom"
- "/dev/random"
- "/dev/null"
- "/dev/fuse"
rox:
- "{HOME}/go/bin"
- "{HOME}/env"
- "/proc/self/fd"
- "/proc/self/cmdline"
rwx:
- "{CWD}"
- "{PLAN9}"
- "{HOME}/bin"
- "{HOME}/mnt"
- "{HOME}/.pyenv"
- "{HOME}/.local/bin"
- "{HOME}/.sdkman"
- "{HOME}/go"
- "{HOME}/.cache/go-build"
- "{HOME}/opt"
- "{HOME}/src"
- "{HOME}/prj"
- "{HOME}/.nvm"
- "{HOME}/.please"
- "{HOME}/.npm"
- "{HOME}/.mcp-auth"
- "{HOME}/.yarn"
env:
- AGENT_SKILLS_PATH
- NAMESPACE
- HOME
- TMPDIR
- AGENT_ID
- PLAN9
- JENKINS_USER_ID
- JENKINS_API_TOKEN
- JENKINS_MCP_AUTH
- JIRA_API_TOKEN
- BITBUCKET_ACCESS_TOKEN
- BITBUCKET_TOKEN
- BITBUCKET_USERNAME
- PCLOUD_USER
- EDITOR
- GIT_SEQUENCE_EDITOR
- SUPERPOWERD_SESSION_TOKEN
network:
unrestricted: true