Skip to content

feat(cli): ship Linux sandboxing - #47

Merged
tumberger merged 19 commits into
mainfrom
feat/linux-cli-release
Sep 1, 2026
Merged

tumberger merged 19 commits into
mainfrom
feat/linux-cli-release

Conversation

@tumberger

@tumberger tumberger commented Aug 31, 2026 •

Copy link
Copy Markdown
Contributor

Stack: #45 → #46 → this PR

Summary

  • Compose an explicit Linux CLI runtime baseline and launch through the existing same-executable bootstrap.
  • Support built-in and user profiles whenever the complete resolved typed policy is representable.
  • Keep deterministic planning in the parent and perform authoritative ambient preparation only in the bootstrap.
  • Infer exact scope for regular-file read and execute grants and subtree scope for directory grants.
  • Reject --read-write FILE on Linux before bootstrap with guidance to grant its containing directory.
  • Add live compatibility coverage for Node, Python, and subprocesses.
  • Document that Cargo and unqualified third-party agent distributions remain outside the initial Linux compatibility contract.
  • Document the initial private-root limitations for procfs self-links, descriptor paths, and filesystem-backed shared memory.
  • Rewrite the README around quick start, library embedding, JSON customization, and composable behavioral security.
  • Give sandy doctor actionable host-policy diagnostics without weakening the host automatically.
  • Add CI concurrency cancellation, job timeouts, strict rustdoc checks, x86-64 and arm64 Linux lanes, and packaged release verification.
  • Release Linux support starting with 0.2.

Security verification

  • Exercise positive grants and adjacent filesystem denials.
  • Prove blocked IP, pathname Unix, and abstract Unix endpoints while preserving unnamed Unix IPC.
  • Prove readable mounts remain non-executable.
  • Check named runtime devices and deny adjacent devices.
  • Verify protected configuration remains immutable while profile state remains writable.
  • Prove unsupported writable-file grants fail before the target starts.
  • Characterize intentionally absent /proc/self/exe, /proc/self/fd, /dev/fd, and /dev/shm paths.
  • Validate doctor, runtime compatibility, user-profile source denial, terminal reopening, and target exit status.
  • Give every live Linux fixture and CI job a hard timeout.

Local verification

  • Formatting, Clippy, workspace tests, and dependency checks
  • Strict workspace rustdoc
  • Cargo Clippy for native macOS and Linux x86-64 targets
  • Package and external-consumer verification
  • Workflow syntax validation

@tumberger
tumberger force-pushed the feat/linux-cli-release branch from 857d35a to e889825 Compare August 31, 2026 20:52
@tumberger
tumberger force-pushed the feat/linux-current-process branch from e86de0e to b43afe0 Compare August 31, 2026 20:52
@tumberger
tumberger force-pushed the feat/linux-cli-release branch from e889825 to 8c79065 Compare August 31, 2026 20:59
@tumberger
tumberger force-pushed the feat/linux-current-process branch from b43afe0 to 1b399e6 Compare August 31, 2026 20:59
@tumberger
tumberger force-pushed the feat/linux-cli-release branch from 8c79065 to 9bb1ea1 Compare August 31, 2026 21:02
@tumberger
tumberger force-pushed the feat/linux-current-process branch from 1b399e6 to 8b6d2cf Compare September 1, 2026 05:20
@tumberger
tumberger force-pushed the feat/linux-cli-release branch from 9bb1ea1 to b9e23d4 Compare September 1, 2026 05:20
@tumberger
tumberger force-pushed the feat/linux-current-process branch from 8b6d2cf to 088f170 Compare September 1, 2026 05:54
@tumberger
tumberger force-pushed the feat/linux-cli-release branch 3 times, most recently from c586111 to 75bd7ce Compare September 1, 2026 08:38
@tumberger
tumberger marked this pull request as ready for review September 1, 2026 08:54
@greptile-apps

greptile-apps Bot commented Sep 1, 2026 •

Copy link
Copy Markdown

Greptile Summary

The PR adds Linux support to Sandy’s CLI through the existing supervised bootstrap architecture and expands release, CI, compatibility, diagnostics, tests, and documentation accordingly.

  • Adds a Linux-specific runtime baseline and native plan/prepare/apply bootstrap path.
  • Introduces platform-aware grant scopes and rejects unsupported writable-file grants.
  • Keeps runtime-control integrations and local-host TCP exceptions macOS-only.
  • Adds Linux live compatibility coverage and Linux release artifacts for x86-64 and arm64.
  • Updates public documentation to describe the platform-specific support contract.

Confidence Score: 5/5

The PR appears safe to merge because no blocking failure remains within the eligible follow-up-review scope.

No blocking failure remains.

Important Files Changed

Filename Overview
crates/cli/src/execution/supervised.rs Adds platform-aware launch composition, Linux policy validation, grant-scope inference, and Linux bootstrap handoff behavior.
crates/cli/src/execution/bootstrap.rs Extends the same-executable bootstrap to plan, prepare, and apply the Linux backend before replacing itself with the target.
crates/cli/src/resolve/runtime/linux.rs Defines an explicit Linux runtime baseline separating executable subtrees, public runtime data, and named device access.
crates/cli/src/doctor.rs Adds a Linux enforcement probe and actionable diagnostics for unsupported host namespace or Landlock configurations.
crates/cli/src/resolve/environment.rs Adds Linux loader-variable filtering and platform-aware public CA-bundle discovery.
crates/cli/tests/live_linux.rs Provides end-to-end Linux compatibility, denial, lifecycle, and profile behavior coverage.
.github/workflows/ci.yml Adds full x86-64 and arm64 Linux validation, live enforcement tests, timeouts, and a pinned real Codex fixture.
.github/workflows/release.yml Builds and verifies Linux release archives before publishing crates and finalizing the release.

Sequence Diagram

sequenceDiagram
  participant User
  participant Parent as Sandy parent
  participant Manifest as Launch manifest
  participant Bootstrap as Sandy bootstrap
  participant Linux as Linux backend
  participant Target
  User->>Parent: sandy run [policy] -- command
  Parent->>Parent: Resolve command, profile, paths, and environment
  Parent->>Parent: Compose and validate typed policy
  Parent->>Manifest: Write bounded launch description
  Parent->>Bootstrap: Start same executable with manifest path
  Bootstrap->>Manifest: Read, validate, and remove
  Bootstrap->>Linux: Plan and prepare private sandbox
  Bootstrap->>Linux: Apply namespaces, Landlock, and seccomp
  Bootstrap->>Target: exec resolved command
  Target-->>Parent: Exit status
  Parent-->>User: Preserve exit code or map signal
Loading

Reviews (5): Last reviewed commit: "docs: add platform compatibility matrix" | Re-trigger Greptile

@tumberger
tumberger force-pushed the feat/linux-current-process branch from 088f170 to 2e9d75c Compare September 1, 2026 09:14
@tumberger
tumberger force-pushed the feat/linux-cli-release branch from 75bd7ce to 6e5a06e Compare September 1, 2026 09:14
@tumberger

Copy link
Copy Markdown
Contributor Author

@greptile

@tumberger
tumberger force-pushed the feat/linux-current-process branch from 2e9d75c to 7354ea0 Compare September 1, 2026 10:23
@tumberger
tumberger force-pushed the feat/linux-cli-release branch 5 times, most recently from 1b20f01 to e5fe187 Compare September 1, 2026 10:45
@tumberger

Copy link
Copy Markdown
Contributor Author

@greptile

@tumberger
tumberger force-pushed the feat/linux-current-process branch from 7354ea0 to 9f88089 Compare September 1, 2026 13:17
@tumberger
tumberger force-pushed the feat/linux-cli-release branch from e5fe187 to dc8bf7b Compare September 1, 2026 13:19
@tumberger
tumberger force-pushed the feat/linux-current-process branch from 9f88089 to 7c8d695 Compare September 1, 2026 13:21
@tumberger
tumberger force-pushed the feat/linux-cli-release branch from dc8bf7b to 4bae232 Compare September 1, 2026 13:21
@tumberger

Copy link
Copy Markdown
Contributor Author

@greptile

1 similar comment
@tumberger

Copy link
Copy Markdown
Contributor Author

@greptile

@tumberger
tumberger force-pushed the feat/linux-current-process branch from 7c8d695 to 557f601 Compare September 1, 2026 14:13
@tumberger
tumberger force-pushed the feat/linux-cli-release branch from dc0de87 to 37b59db Compare September 1, 2026 14:19
@tumberger
tumberger force-pushed the feat/linux-current-process branch from 557f601 to 8aa559c Compare September 1, 2026 14:58
@tumberger
tumberger changed the base branch from feat/linux-current-process to main September 1, 2026 15:04
@tumberger
tumberger force-pushed the feat/linux-cli-release branch from 3545b0e to 5ccdd94 Compare September 1, 2026 15:04
@tumberger
tumberger merged commit b6aa19b into main Sep 1, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant