Repository navigation
Replies: 1 comment 4 replies
|
Thanks for reading the docs closely! This is a good question. I don't think a strict workspace-only read rule would work directly. Sandbox mode restricts writes to the workspace and On macOS, a command must read its own binary, Interpreters make this harder. A command that runs A literal workspace-only rule therefore turns sandbox mode into a mode where I think the real need here is more like "do not read my personal files", not "do not read outside the workspace". On a development machine those two rules are very different, and the second one could be achievable, I believe. We could try something like:
This would invert the risky part. Today the home directory is readable, with a deny list for known secret paths. A deny list only protects the paths that we thought of. An allow list for Maybe before you answer, I want to highlight some things for you:
For the question I think you are really asking, which is how much to trust sandbox mode, these two limits matter more than read scoping FYI. |
Uh oh!
There was an error while loading. Please reload this page.
Hi!
The documentation of sandbox mode says the following:
Would it be possible to only allow reading of files within the workspace (and $TMPDIR)? This would increase my trust for Posit Assistant.
All reactions