Repository navigation
v0.1.0
Changelog
- 96b5f0b build: stabilize multi-arch release env setup
- 5a238ca ci: install gperf for cross libseccomp builds
- 67618dc ci: exclude privileged integration suite on hosted runners
- 8304c27 build: add multi-arch release pipeline
- c81b720 feat: finish seccomp transparent http and dns runtime
- 5998600 feat: supervise transparent payload execs
- fea2c7b feat: add seccomp notify supervisor
- eb3fb6c feat: add host dns forwarding and ip policy rules
- ad86c4a feat: add dns bridge protocol support
- fc6c698 feat: bundle seccomp launcher for transparent mode
- 7a4f943 docs: add seccomp transparent http dns plan
- 51f6de3 docs: add seccomp unotify transparent http dns design
- 20290a1 docs: update Docker bwrap guidance
- 410890b Merge branch 'refactor/internal-architecture'
- 65177bb refactor: finish internal architecture cleanup
- 0e8fd3a refactor: extract host bridge client collaborators
- 4c98b47 refactor: extract manager traffic services
- bc6ce1a refactor: extract manager registry and helper resolution
- 6df9f76 build: add agent container workflow
- 29476b6 refactor: extract helper runtime ingress and exec
- 1a2aafa refactor: narrow helper runtime bridge api
- ddc83fb refactor: extract helper runtime bridge coordination
- 7dcfbd0 fix: harden helper runtime dns tcp framing
- cfcba99 refactor: extract helper runtime leaf packages
- c5cfdb1 test: tighten seam assertions for mismatch and idempotency
- aa62683 test: lock runtime manager and client seams
- a0cb946 docs: add internal architecture refactor plan
- 119a0e6 docs: add internal architecture refactor design
- 7a03117 feat: add bbox cli and sandbox hardening
- 0c99cf3 docs: add sandbox architecture article
- 8789ed5 Merge remote-tracking branch 'origin/main'
- 731aaf3 test: make icmp restriction probes optional
- 943addb test: complete hermetic network restriction coverage
- e1f2f64 test: add proxy mode network restriction coverage
- 14b0f3a test: harden network integration helpers
- 1da27da test: add strict network integration helpers
- 541a696 docs: add network restriction suite plan
- 0fa36d1 docs: add network restriction suite design
- f049fff Merge branch 'feature/transparent-traffic-mode'
- e95adba test: stabilize https integration trust setup
- 9767975 feat: finish transparent traffic mode support
- c549274 feat: add transparent https mitm ingress
- 347be43 fix: separate proxy and transparent http ingress
- 4c61e27 feat: add transparent http ingress
- 1b40739 feat: add transparent dns responder
- 7be5780 feat: add helper traffic mode startup
- e7599a0 fix: stage NSS module dependencies
- d43ae5e fix: broaden NSS staging candidates
- 3ec8409 fix: stage transparent dns and accept traffic mode
- 79183d1 feat: stage transparent sandbox configuration
- 98c55d5 fix: tighten traffic mode handling
- e12cac7 feat: add sandbox traffic mode selection
- f971227 docs: add transparent traffic mode plan
- 3779458 docs: add transparent traffic mode design
- 5efe433 Merge branch 'access-audit-logging'
- f92388a feat: add access audit logging
- 7b03f18 fix: inherit authority port for MITM events
- 4542b43 fix: attribute MITM events to request host
- 6c89d54 feat: emit audit events for proxy requests
- e34f47a fix: normalize audit hosts and filter sandbox events
- 54f4473 fix: guard access audit state
- 179ed2a feat: add per-sandbox access audit state
- cb00793 fix: handle typed-nil access logger
- 98f0027 docs: clarify accessed domains stub
- 8b060b9 fix: share default access logger
- a461c2a feat: add access audit public api
- a3d6942 docs: add access audit logging implementation plan
- 7aa8796 docs: add access audit logging design spec
- 9d0fc47 Merge branch 'phase3-mitm'
- e41e5ce feat: add end-to-end mitm integration coverage
- 36108c9 feat: add helper http2 mitm interception
- 40d1b0a feat: add helper http1 mitm interception
- 0d56189 feat: handle decrypted mitm requests on manager
- 7322605 feat: extend helper protocol for mitm
- 849592d feat: add mitm request policy checks
- 7ef7318 feat: inject mitm ca into sandbox roots
- 73b2273 feat: add ephemeral mitm ca
- eff1e89 feat: add mitm manager options
- 2777f43 docs: add mitm implementation plan
- e04ea3a docs: add mitm design spec
- a34cf10 docs: add end-to-end sandbox example
- 0d639e9 docs: add package examples
- 22157ec docs: add public API godoc
- b178500 feat: expose sandbox proxy address
- c5c95b4 feat: configure sandbox proxy listen address
- ac600b4 test: cover connect tunnels across sandboxes
- 20636e5 feat: add host connect tunnel relay
- 2b1d20c feat: add helper runtime connect handling
- 432a3c7 feat: add connect tunnel bridge messages
- fdf0760 feat: add connect port policy rules
- ab9fdc1 docs: add phase2 connect tunnels plan
- e7a7c00 docs: add phase2 connect tunnels design
- 0a22059 Merge branch 'phase1-sandbox-library'
- 2d716fd feat: finish phase1 sandbox library
- 5a1a0ed fix: tighten sandbox cleanup and exec errors
- bab444e feat: add persistent sandbox lifecycle and run api
- ed42e96 fix: normalize helper handshake
- 8a834c7 feat: add helper protocol and helper binary
- 0d67005 fix: tighten mount validation and staging cleanup
- d8ab42b fix: stage absolute sandbox paths under root safely
- 5b2ee7e feat: add sandbox staging and mount validation
- 1e4a83e fix: reject malformed colon hosts in policy normalization
- bba3f25 fix: normalize host:port policy checks and add manager registry tests
- a7634f7 test: align Task 2 policy semantics and coverage
- 46a2a62 feat: add shared proxy manager and policy engine
- 4ae7634 fix: reject unsupported task1 policy options
- aa737b9 fix: validate proxy policy in manager constructor
- 1ae8850 refactor: turn module root into bbox library package
- 68bd4b7 chore: baseline bbox poc
- f26589a Initial commit