Skip to main content

vtcode_safety/sandboxing/
mod.rs

1//! Sandboxing module for VT Code
2//!
3//! This module provides sandbox policies and execution environment transformations
4//! inspired by the OpenAI Codex execution model and the AI sandbox field guide.
5//! It enables safe command execution with configurable isolation levels.
6//!
7//! ## Architecture
8//!
9//! The sandboxing system implements the field guide's three-question model:
10//! - **Boundary**: What is shared (kernel-enforced via Seatbelt/Landlock)
11//! - **Policy**: What can code touch (SandboxPolicy enum)
12//! - **Lifecycle**: What survives between runs (session-scoped approvals)
13//!
14//! Compartment topology (sandboxing-basics actor model): the broker
15//! (`SandboxManager` + `vtcode sandbox-exec` launcher) owns every grant; each
16//! sandboxed child is a leaf worker. Workers never forward capabilities to
17//! each other — there is no `SCM_RIGHTS` passing between sandboxed processes,
18//! only parent↔child pipes the broker created. File descriptors behave as
19//! capabilities except for `ioctl`s, so terminal injection (`TIOCSTI`,
20//! `TIOCSCTTY`) is denied in seccomp while general TTY ioctls stay available
21//! for PTY sessions. Privileges only ever decrease (`PR_SET_NO_NEW_PRIVS` +
22//! Landlock `restrict_self` + seccomp); namespaces are never used as the
23//! sandbox mechanism.
24//!
25//! Key components:
26//! - **SandboxPolicy**: Configurable isolation levels (ReadOnly, WorkspaceWrite, DangerFullAccess)
27//! - **SandboxManager**: Transforms command specifications into sandboxed execution environments
28//! - **SandboxPermissions**: Fine-grained permission control for individual operations
29//! - **NetworkAllowlistEntry**: Domain-based network egress control
30//! - **SensitivePath**: Credential location blocking
31//! - **ResourceLimits**: Memory, PID, disk, and CPU limits
32//!
33//! ## Usage
34//!
35//! ```rust,ignore
36//! use vtcode_core::sandboxing::{SandboxPolicy, SandboxManager, CommandSpec, ResourceLimits};
37//!
38//! let policy = SandboxPolicy::read_only();
39//! let manager = SandboxManager::new();
40//! let spec = CommandSpec {
41//!     program: "cat".to_string(),
42//!     args: vec!["file.txt".to_string()],
43//!     ..Default::default()
44//! };
45//!
46//! // Transform to sandboxed environment
47//! let exec_env = manager.transform(spec, &policy, std::path::Path::new("/tmp"), None)?;
48//! # Ok::<(), anyhow::Error>(())
49//! ```
50
51mod child_spawn;
52mod debug;
53mod exec_env;
54#[cfg(target_os = "linux")]
55mod linux;
56#[cfg(target_os = "linux")]
57mod linux_seccomp;
58mod manager;
59mod permissions;
60mod policy;
61
62pub use child_spawn::{
63    FILTERED_ENV_VARS, PRESERVED_ENV_VARS, VTCODE_SANDBOX_ACTIVE, VTCODE_SANDBOX_NETWORK_DISABLED, VTCODE_SANDBOX_TYPE,
64    VTCODE_SANDBOX_WRITABLE_ROOTS, build_sanitized_env, filter_sensitive_env, setup_parent_death_signal,
65    should_filter_env_var,
66};
67pub use debug::{
68    DebugSubcommand, SandboxDebugResult, debug_sandbox, sandbox_capabilities_summary, test_network_blocked,
69    test_path_writable,
70};
71pub use exec_env::{CommandSpec, ExecEnv, ExecExpiration, LinuxSandboxLauncher, SandboxType};
72#[cfg(target_os = "linux")]
73pub use linux::{apply_sandbox_restrictions, landlock_supported};
74pub use manager::{SandboxManager, SandboxTransformError};
75pub use permissions::{AdditionalPermissions, SandboxPermissions};
76pub use policy::{
77    BLOCKED_SYSCALLS, DEFAULT_SENSITIVE_PATHS, FILTERED_SYSCALLS, NetworkAllowlistEntry, ResourceLimits,
78    SECCOMP_PROFILE_VERSION, SandboxPolicy, SeccompProfile, SensitivePath, WritableRoot, default_sensitive_paths,
79};