[package] license = "Apache-2.0" name = "xai-grok-sandbox" version = "0.1.0" edition.workspace = true description = "OS-level sandboxing for Grok Build using kernel primitives (Landlock/Seatbelt) via nono" [dependencies] anyhow = { workspace = true } chrono = { workspace = true, features = ["serde"] } dirs = "5.0" dunce = { workspace = true } serde = { workspace = true } serde_json = { workspace = true } sha2 = { workspace = true } thiserror = { workspace = true } toml = { workspace = true } tracing = { workspace = true } url = { workspace = true } xai-grok-config = { workspace = true } [target.'cfg(unix)'.dependencies] libc = { workspace = true } # Pinned exact: the macOS Seatbelt deny precedence (see deny.rs `emit_seatbelt_deny`) # depends on nono's observed rule-emission order. A bump can silently change it and # re-open the `mv x y && cat y` bypass with `is_applied()` still true, so re-verify # `deny_paths_e2e` on real macOS (it self-skips in CI) before bumping. # # Non-optional (not gated on `enforce`): Cargo has no target-conditional features # table, so a `dep:nono` reference from the cross-platform `enforce` feature would # break feature resolution on non-unix targets (e.g. Windows builds). nono/globset # are unix-only here, so they only compile on unix anyway; the enforce *code* # stays gated on `cfg(all(feature = "enforce", unix))`. nono = { version = "=0.53.0", default-features = false } # globset validates every deny glob on BOTH platforms (so a glob is interpreted # identically or rejected identically) and matches them on Linux. Non-optional for # the same reason as nono above. globset = { workspace = true } # Linux additionally walks the tree to expand globs to existing paths (enforce+ # linux only). cfg(linux)-gated rather than enforce-gated: the cross-platform # enforce feature can't reference a linux-only optional dep without breaking macOS # feature resolution, so a `--no-default-features` Linux build pulls it unused. [target.'cfg(target_os = "linux")'.dependencies] ignore = { workspace = true } [features] default = ["enforce"] ## Enable kernel-enforced sandboxing via nono (Landlock/Seatbelt). Marker feature ## only: the backing deps (nono/globset) are non-optional unix-only deps (see ## above), and the enforce code is gated on `cfg(all(feature = "enforce", unix))`. ## On non-unix targets enabling this feature is a no-op (no kernel sandbox exists). enforce = [] [dev-dependencies] serial_test = { workspace = true } # Compiles the hand-rolled macOS deny-glob regex in tests to assert it matches # EXACTLY the set globset (the Linux backend) matches — the cross-platform parity # guard for the glob dialect. regex = { workspace = true } # The smoke-test example exercises kernel enforcement (uses enforce-only APIs # like `support_info`), so it only builds with the `enforce` feature. This keeps # `--no-default-features --all-targets` clean. [[example]] name = "sandbox_smoke_test" required-features = ["enforce"]