Documentation
¶
Index ¶
- Variables
- func ActiveSandboxBaseDir() string
- func ResetRuntimeLimitCounters(env *object.Environment)
- func RunProgramSandboxed(program any, env *object.Environment, policy *object.SecurityPolicy) object.Object
- func WithSandboxRootOverride(root string, fn func() object.Object) object.Object
- type SandboxConfig
- type SandboxVM
Constants ¶
This section is empty.
Variables ¶
var EvalProgramFn func(program any, env *object.Environment) object.Object
EvalProgramFn evaluates an AST program in the given environment. This must be set by the host package before calling RunProgramSandboxed.
var ParseBoolEnvDefaultFn func(name string, def bool) bool = func(name string, def bool) bool { v := os.Getenv(name) switch v { case "1", "true", "yes": return true case "0", "false", "no": return false default: return def } }
ParseBoolEnvDefaultFn reads a boolean from the environment with a fallback.
var WithSecurityPolicyOverrideFn func(policy *object.SecurityPolicy, fn func() (object.Object, error)) (object.Object, error)
WithSecurityPolicyOverrideFn temporarily sets a security policy and runs fn. Set by the host package.
Functions ¶
func ActiveSandboxBaseDir ¶
func ActiveSandboxBaseDir() string
ActiveSandboxBaseDir returns the currently active sandbox root directory, if any override is in effect.
func ResetRuntimeLimitCounters ¶
func ResetRuntimeLimitCounters(env *object.Environment)
ResetRuntimeLimitCounters zeroes the step/depth counters on the environment's RuntimeLimits so a fresh evaluation can run.
func RunProgramSandboxed ¶
func RunProgramSandboxed(program any, env *object.Environment, policy *object.SecurityPolicy) object.Object
RunProgramSandboxed evaluates an AST program inside the sandbox, resetting counters and applying policy/root overrides. The program parameter is typed as `any` because the ast.Program type may live in a different package; callers should pass *ast.Program.
func WithSandboxRootOverride ¶
WithSandboxRootOverride temporarily sets the sandbox root directory while running fn, then restores the previous value.
The mutex is held for the FULL DURATION of fn(), not just for the swap, so that concurrent in-process callers (e.g. the playground's per-request EvalForPlayground calls) are fully serialized and can never observe or be affected by another request's sandbox root during the overlap window.
Types ¶
type SandboxConfig ¶
type SandboxConfig struct {
Enabled bool
StrictMode bool
ProtectHost bool
AllowEnvWrite bool
MaxDepth int
MaxSteps int64
MaxHeapMB int64
MaxOutputBytes int64
MaxHTTPBodyBytes int64
MaxExecOutputBytes int64
Timeout time.Duration
BaseDir string
AllowedCapabilities []string
DeniedCapabilities []string
AllowedExecCommands []string
DeniedExecCommands []string
AllowedNetworkHosts []string
DeniedNetworkHosts []string
AllowedDBDrivers []string
DeniedDBDrivers []string
AllowedFileReadPaths []string
DeniedFileReadPaths []string
AllowedFileWritePaths []string
DeniedFileWritePaths []string
AllowedDBDSNPatterns []string
DeniedDBDSNPatterns []string
AllowedImportPaths []string
DeniedImportPaths []string
AllowedImportPackages []string
DeniedImportPackages []string
AllowedNativeModules []string
DeniedNativeModules []string
DenyDynamicImports bool
}
func DefaultExecSandboxConfig ¶
func DefaultExecSandboxConfig() SandboxConfig
DefaultExecSandboxConfig returns a SandboxConfig suitable for running scripts from the command line.
Timeout is intentionally 0 (no wall-clock deadline): trusted CLI/embedding scripts routinely run long-lived servers, schedulers, and watchers via a blocking call (listen(), schedule_run(), watch(), ...), and a fixed deadline would silently stop evaluating everything running under that script's environment once the wall clock passed it - including future request/job/event callbacks - without the process crashing or erroring visibly. Per-call step/depth/heap limits (MaxSteps/MaxDepth/MaxHeapMB) still bound any single evaluation; callers that want a hard wall-clock cap on trusted scripts should set ExecOptions.Timeout or SandboxConfig.Timeout explicitly (e.g. via --timeout on the CLI).
func DefaultReplSandboxConfig ¶
func DefaultReplSandboxConfig() SandboxConfig
DefaultReplSandboxConfig returns a SandboxConfig suitable for the interactive REPL.
type SandboxVM ¶
type SandboxVM struct {
// contains filtered or unexported fields
}
func NewSandboxVM ¶
func NewSandboxVM(args []string, sourcePath string, moduleDir string, cfg SandboxConfig) (*SandboxVM, error)
NewSandboxVM creates a new sandbox-isolated VM with the given configuration, returning a SandboxVM ready for evaluation.
func (*SandboxVM) Environment ¶
func (vm *SandboxVM) Environment() *object.Environment
Environment returns the underlying Environment.
func (*SandboxVM) Policy ¶
func (vm *SandboxVM) Policy() *object.SecurityPolicy
Policy returns the SecurityPolicy used by this sandbox, if any.