1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
//! Sandboxing module for VT Code
//!
//! This module provides sandbox policies and execution environment transformations
//! inspired by the OpenAI Codex execution model and the AI sandbox field guide.
//! It enables safe command execution with configurable isolation levels.
//!
//! ## Architecture
//!
//! The sandboxing system implements the field guide's three-question model:
//! - **Boundary**: What is shared (kernel-enforced via Seatbelt/Landlock)
//! - **Policy**: What can code touch (SandboxPolicy enum)
//! - **Lifecycle**: What survives between runs (session-scoped approvals)
//!
//! Compartment topology (sandboxing-basics actor model): the broker
//! (`SandboxManager` + `vtcode sandbox-exec` launcher) owns every grant; each
//! sandboxed child is a leaf worker. Workers never forward capabilities to
//! each other — there is no `SCM_RIGHTS` passing between sandboxed processes,
//! only parent↔child pipes the broker created. File descriptors behave as
//! capabilities except for `ioctl`s, so terminal injection (`TIOCSTI`,
//! `TIOCSCTTY`) is denied in seccomp while general TTY ioctls stay available
//! for PTY sessions. Privileges only ever decrease (`PR_SET_NO_NEW_PRIVS` +
//! Landlock `restrict_self` + seccomp); namespaces are never used as the
//! sandbox mechanism.
//!
//! Key components:
//! - **SandboxPolicy**: Configurable isolation levels (ReadOnly, WorkspaceWrite, DangerFullAccess)
//! - **SandboxManager**: Transforms command specifications into sandboxed execution environments
//! - **SandboxPermissions**: Fine-grained permission control for individual operations
//! - **NetworkAllowlistEntry**: Domain-based network egress control
//! - **SensitivePath**: Credential location blocking
//! - **ResourceLimits**: Memory, PID, disk, and CPU limits
//!
//! ## Usage
//!
//! ```rust,ignore
//! use vtcode_core::sandboxing::{SandboxPolicy, SandboxManager, CommandSpec, ResourceLimits};
//!
//! let policy = SandboxPolicy::read_only();
//! let manager = SandboxManager::new();
//! let spec = CommandSpec {
//! program: "cat".to_string(),
//! args: vec!["file.txt".to_string()],
//! ..Default::default()
//! };
//!
//! // Transform to sandboxed environment
//! let exec_env = manager.transform(spec, &policy, std::path::Path::new("/tmp"), None)?;
//! # Ok::<(), anyhow::Error>(())
//! ```
pub use ;
pub use ;
pub use ;
pub use ;
pub use ;
pub use ;
pub use ;