fix(sandbox): require runner-specific spawn evidence
This commit is contained in:
@@ -1,14 +1,25 @@
|
||||
import { join } from 'node:path'
|
||||
import type { ConfinedArgv, SandboxPolicy } from '@deepseek-ai/dsh-sandbox'
|
||||
import { SandboxProvider } from '@deepseek-ai/dsh-sandbox'
|
||||
|
||||
const NOTICE = 'landlock-run: partial enforcement (older Landlock ABI)'
|
||||
const MISSING_RUNNER_ENV = 'DSH_SNAPSHOT_MISSING_SANDBOX_RUNNER'
|
||||
|
||||
/**
|
||||
* Snapshot-only provider that reproduces an older-ABI Landlock launch. Keep
|
||||
* its failure tuple aligned with `sandbox-local`'s Landlock runner rule.
|
||||
* Snapshot-only provider for deterministic runner classification. Its default
|
||||
* launch reproduces older-ABI Landlock; an explicit scenario flag selects a
|
||||
* missing executable under the valid workspace cwd.
|
||||
*/
|
||||
export default class PartialLandlockSandboxProvider extends SandboxProvider {
|
||||
confine(argv: readonly string[], _policy: SandboxPolicy): ConfinedArgv {
|
||||
confine(argv: readonly string[], policy: SandboxPolicy): ConfinedArgv {
|
||||
if (process.env[MISSING_RUNNER_ENV] === '1') {
|
||||
return {
|
||||
argv: [join(policy.workspaceRoot, '.dsh-missing-sandbox-runner'), ...argv],
|
||||
enforcement: 'full',
|
||||
denialSignatures: ['permission denied'],
|
||||
runnerFailureRules: [{ fatalSignatures: ['snapshot-runner: '] }],
|
||||
}
|
||||
}
|
||||
return {
|
||||
argv: [
|
||||
'bash',
|
||||
|
||||
Reference in New Issue
Block a user