v0.2.8 — Per-command Sandbox Profile (Issue #34)
Per-command Seatbelt/Sandbox Profile (Issue #34)
Add a per-command configurable SandboxProfile to ExecutionRequest — enables seatbelt/sandbox for the detached executor subprocess (fusion-code G2 sandbox-independence). Default-off / opt-in: None profile preserves the existing fixed profile byte-for-byte.
SandboxProfile fields
network(allow/deny, defaultdeny) —allowomits network denyfilesystem(allow/deny_write/deny, defaultdeny_write) — FS write deny controlexcluded_commands([]) — injected as seatbeltdeny process-exec, sanitizedfail_if_unavailable(false) — fail-closed whensandbox-execabsent
Python usage
from fusion_executor import FusionSandboxExecutor, SandboxProfile
result = FusionSandboxExecutor().run(
"echo hi",
sandbox=SandboxProfile(network="allow", excluded_commands=["rm", "curl"]),
)Properties
- 4-layer additive wiring (fe-sandbox → fe-core → fe-ipc → fe-pyo3/Python)
- 0 new unsafe (reuses fe-sandbox safe wrappers +
whichPATH probe) - Baseline preserved:
sandbox=Nonebyte-identical to v0.2.7 - 510 Rust + 214 Python (6 skip TCC) green, clippy/fmt/ruff clean
Closes #34.