ollie/cmd/olliesrv/internal/bypass/doc.go

32 lines
1.1 KiB
Go

// Package bypass provides the sandbox bypass broker for olliesrv.
//
// When a tool needs to escape the Landlock sandbox (e.g., to access a
// path outside the allowed set), it requests bypass approval. The broker
// manages pending requests, policy evaluation, user notification, and
// resolution.
//
// # Flow
//
// 1. Tool calls bypass.Request() with command and path
// 2. Broker checks policy — auto-approve, auto-deny, or prompt user
// 3. If prompting, request goes to pending queue
// 4. Frontend reads bypass/pending and shows approval UI
// 5. User approves/denies; frontend writes bypass/resolve
// 6. Broker unblocks the waiting tool with the decision
//
// # Policy
//
// The policy file ($XDG_CONFIG_HOME/ollie/bypass-policy.conf) contains
// glob patterns for auto-approval or auto-denial. Format:
//
// allow /home/user/projects/*
// deny /etc/*
//
// Paths not matching any rule require interactive approval.
//
// # Rate Limiting
//
// The broker rate-limits requests per session to prevent runaway tools
// from flooding the user with approval prompts.
package bypass