36 lines
1.1 KiB
Go
36 lines
1.1 KiB
Go
// Package sandbox provides Landlock-based filesystem sandboxing for tool execution.
|
|
//
|
|
// Tools run in a restricted environment where filesystem access is limited
|
|
// to explicitly allowed paths. The sandbox is configured via sandbox.yaml
|
|
// and enforced using Linux Landlock.
|
|
//
|
|
// # Configuration
|
|
//
|
|
// sandbox.yaml defines named profiles with path rules:
|
|
//
|
|
// default:
|
|
// ro:
|
|
// - /usr
|
|
// - /lib
|
|
// rw:
|
|
// - ${cwd}
|
|
// - /tmp
|
|
//
|
|
// Environment variables in paths are expanded at runtime. The special
|
|
// variable ${cwd} refers to the agent's working directory.
|
|
//
|
|
// # Enforcement
|
|
//
|
|
// On Linux, a native helper binary applies Landlock restrictions before
|
|
// exec'ing the tool. The helper receives the sandbox profile via base64-
|
|
// encoded JSON on the command line.
|
|
//
|
|
// On non-Linux platforms, sandboxing is a no-op (the tool runs unrestricted).
|
|
//
|
|
// # Bypass
|
|
//
|
|
// Tools can request bypass for operations outside the sandbox. These
|
|
// requests are routed to the bypass broker in olliesrv for policy
|
|
// evaluation and optional user approval.
|
|
package sandbox
|