fix(sandbox): require runner-specific spawn evidence

This commit is contained in:
Hypatia May
2026-08-04 14:47:46 +08:00
parent 0cd1611023
commit 96ba98c99e
14 changed files with 217 additions and 39 deletions

View File

@@ -1,14 +1,25 @@
import { join } from 'node:path'
import type { ConfinedArgv, SandboxPolicy } from '@deepseek-ai/dsh-sandbox'
import { SandboxProvider } from '@deepseek-ai/dsh-sandbox'
const NOTICE = 'landlock-run: partial enforcement (older Landlock ABI)'
const MISSING_RUNNER_ENV = 'DSH_SNAPSHOT_MISSING_SANDBOX_RUNNER'
/**
* Snapshot-only provider that reproduces an older-ABI Landlock launch. Keep
* its failure tuple aligned with `sandbox-local`'s Landlock runner rule.
* Snapshot-only provider for deterministic runner classification. Its default
* launch reproduces older-ABI Landlock; an explicit scenario flag selects a
* missing executable under the valid workspace cwd.
*/
export default class PartialLandlockSandboxProvider extends SandboxProvider {
confine(argv: readonly string[], _policy: SandboxPolicy): ConfinedArgv {
confine(argv: readonly string[], policy: SandboxPolicy): ConfinedArgv {
if (process.env[MISSING_RUNNER_ENV] === '1') {
return {
argv: [join(policy.workspaceRoot, '.dsh-missing-sandbox-runner'), ...argv],
enforcement: 'full',
denialSignatures: ['permission denied'],
runnerFailureRules: [{ fatalSignatures: ['snapshot-runner: '] }],
}
}
return {
argv: [
'bash',