Skip to content

v0.2.8 — Per-command Sandbox Profile (Issue #34)

Choose a tag to compare

@dahai80 dahai80 released this 03 Sep 07:36
· 5 commits to main since this release
55c4f15

Per-command Seatbelt/Sandbox Profile (Issue #34)

Add a per-command configurable SandboxProfile to ExecutionRequest — enables seatbelt/sandbox for the detached executor subprocess (fusion-code G2 sandbox-independence). Default-off / opt-in: None profile preserves the existing fixed profile byte-for-byte.

SandboxProfile fields

  • network (allow/deny, default deny) — allow omits network deny
  • filesystem (allow/deny_write/deny, default deny_write) — FS write deny control
  • excluded_commands ([]) — injected as seatbelt deny process-exec, sanitized
  • fail_if_unavailable (false) — fail-closed when sandbox-exec absent

Python usage

from fusion_executor import FusionSandboxExecutor, SandboxProfile

result = FusionSandboxExecutor().run(
    "echo hi",
    sandbox=SandboxProfile(network="allow", excluded_commands=["rm", "curl"]),
)

Properties

  • 4-layer additive wiring (fe-sandbox → fe-core → fe-ipc → fe-pyo3/Python)
  • 0 new unsafe (reuses fe-sandbox safe wrappers + which PATH probe)
  • Baseline preserved: sandbox=None byte-identical to v0.2.7
  • 510 Rust + 214 Python (6 skip TCC) green, clippy/fmt/ruff clean

Closes #34.