Skip to content

feat(sandbox): enforce current-process policies on Linux - #46

Merged
tumberger merged 6 commits into
mainfrom
feat/linux-current-process
Sep 1, 2026
Merged

tumberger merged 6 commits into
mainfrom
feat/linux-current-process

Conversation

@tumberger

@tumberger tumberger commented Aug 31, 2026 •

Copy link
Copy Markdown
Contributor

Stacked on #45.

Summary

  • Dispatch sandy::apply() to the native Linux preparation and enforcement transaction.
  • Preserve the existing public builder, JSON vocabulary, error kinds, and caller-policy-only contract.
  • Share ambient path resolution across macOS and Linux without adding an executable or bootstrap hook.
  • Package the Linux backend as an exact target-specific facade dependency.
  • Add sacrificial facade tests and external-consumer coverage.
  • Update dependency examples for the first Linux-capable release line.

Contract

  • apply() must be called while the Linux process is single-threaded; a live test proves multithreaded callers are rejected before enforcement.
  • The current working directory must be covered by an explicit filesystem grant.
  • Preparation failure leaves the process unchanged and maps to a preparation error.
  • Every error returned after irreversible application begins maps to EnforcementFailed; exhaustive internal matches force future phases to be classified deliberately.
  • Linux 6.12 or a vendor kernel carrying Landlock ABI 6 is the minimum security baseline.
  • Linux replaces the inherited session keyring and denies key-management syscalls as fixed native semantics.
  • allow_subprocesses controls ordinary descendant creation; it does not promise portable host-process inspection.
  • Unsupported hosts and policy combinations return ErrorKind::Unsupported; no request is approximated or weakened.
  • The public API remains platform-neutral and unchanged.

Verification

  • cargo clippy --workspace --all-targets --all-features --locked -- -D warnings
  • Linux-target Cargo check and Clippy
  • Facade live tests with hard timeouts
  • cargo test --workspace --locked
  • make package-check

The CLI remains macOS-only in this branch. The final stack branch adds its Linux runtime policy, bootstrap dispatch, and distribution.

@tumberger
tumberger force-pushed the feat/linux-current-process branch 9 times, most recently from d95449a to e86de0e Compare August 31, 2026 18:45
@tumberger
tumberger force-pushed the feat/linux-current-process branch 4 times, most recently from 8b6d2cf to 088f170 Compare September 1, 2026 05:54
@tumberger
tumberger marked this pull request as ready for review September 1, 2026 08:54
@greptile-apps

greptile-apps Bot commented Sep 1, 2026 •

Copy link
Copy Markdown

Greptile Summary

The PR exposes the native Linux sandbox backend through the platform-neutral sandy facade while preserving the existing API and error model.

  • Dispatches Linux calls through policy resolution, planning, preparation, and irreversible enforcement.
  • Publishes sandy-linux before the facade and updates release-version handling for both lockfiles.
  • Adds sacrificial Linux facade tests, package-consumer coverage, and Linux-specific documentation.

Confidence Score: 5/5

The PR appears safe to merge.

No blocking failure remains.

Important Files Changed

Filename Overview
crates/sandy/src/lib.rs Adds target-specific Linux dispatch with explicit preparation and post-transition enforcement error mappings.
crates/sandy/src/resolve.rs Wraps validated policy resolution with the canonical working directory required by the Linux backend.
crates/sandy/Cargo.toml Adds the target-specific sandy-linux facade dependency and Linux live-test target.
.github/workflows/release.yml Publishes sandy-linux before the dependent sandy-sandbox package, resolving the prior publication omission.
release-please-config.json Adds sandy-linux version selectors for the workspace and external-consumer lockfiles.
crates/sandy/tests/live_linux.rs Adds sacrificial coverage for enforcement, unsupported policies, and rejection of multithreaded callers before enforcement.

Flowchart

%%{init: {'theme': 'neutral'}}%%
flowchart LR
    Caller[Facade caller] --> Resolve[Resolve and validate policy]
    Resolve --> Plan[Linux plan]
    Plan --> Prepare[Prepare namespaces and filesystem view]
    Prepare --> Apply[Irreversible native enforcement]
    Apply --> Restricted[Restricted current process]
    Core[sandy-core package] --> Linux[sandy-linux package]
    Core --> Facade[sandy-sandbox package]
    Linux --> Facade
Loading

Reviews (4): Last reviewed commit: "docs(seatbelt): describe both enforcemen..." | Re-trigger Greptile

Comment thread crates/sandy/Cargo.toml
Comment thread tests/package-consumer/Cargo.lock
@tumberger
tumberger force-pushed the feat/linux-current-process branch from 088f170 to 2e9d75c Compare September 1, 2026 09:14
@tumberger

Copy link
Copy Markdown
Contributor Author

@greptile

@tumberger
tumberger force-pushed the feat/linux-current-process branch from 2e9d75c to 7354ea0 Compare September 1, 2026 10:23
@tumberger

Copy link
Copy Markdown
Contributor Author

@greptile

@tumberger
tumberger force-pushed the feat/linux-current-process branch 2 times, most recently from 9f88089 to 7c8d695 Compare September 1, 2026 13:21
@tumberger

Copy link
Copy Markdown
Contributor Author

@greptile

@tumberger
tumberger force-pushed the feat/linux-current-process branch from 7c8d695 to 557f601 Compare September 1, 2026 14:13
@tumberger
tumberger changed the base branch from feat/linux-policy-substrate to main September 1, 2026 14:58
@tumberger
tumberger force-pushed the feat/linux-current-process branch from 557f601 to 8aa559c Compare September 1, 2026 14:58
@tumberger
tumberger merged commit cedf9be into main Sep 1, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant