Open the network policy for hosts a sandbox actually needs

Sandboxes default to a deny-everything-else policy, so the registry credentials
provisioned as custom secrets were unusable: npm.fontawesome.com,
proget.careevolution.com and localstack.cloud were all denied, and the request
never left the sandbox for the proxy to substitute a token into. The failure
looked like a connection error rather than a policy decision.

Provisioning a secret now allows its hosts in the same step, since a credential
for a denied host cannot be used by definition. AI_SBX_NETWORK declares any
further hosts, comma or space separated, for private registries that back no
secret.

The marketplace loop's inline policy call moves into the shared helper so the
two cannot drift.

The Balanced policy already permits github.com, codeload and the
githubusercontent hosts, registry.npmjs.org, pypi.org, files.pythonhosted.org,
crates.io and the Go proxies, so npm, pip, cargo, go and a plugin-managed
Neovim need nothing declared. Only private hosts do.
This commit is contained in:
2026-08-03 10:42:56 -05:00
parent d2b7a5ef63
commit 2890b1dd98
4 changed files with 448 additions and 3 deletions
+59
View File
@@ -0,0 +1,59 @@
#!/usr/bin/env bash
set -euo pipefail
# shellcheck source-path=SCRIPTDIR
# shellcheck source=tasks/ai/sbx
source "$(dirname "${BASH_SOURCE[0]}")/../tasks/ai/sbx"
failures=0
fail() {
printf 'FAIL: %s\n' "$1" >&2
failures=$((failures + 1))
}
SANDBOX_NAME=ai-test
REPOSITORY=owner/repo
allowed=""
sbx() {
if [[ "$1 $2" == "policy allow" ]]; then
allowed+="${*: -1} "
fi
cat >/dev/null 2>&1 || true
}
allowed=""
DEFAULT_NETWORK="a.example.com,b.example.com c.example.com" install_sandbox_network >/dev/null
for host in a.example.com b.example.com c.example.com; do
[[ "$allowed" == *"$host"* ]] ||
fail "install_sandbox_network skipped $host (comma and space must both split)"
done
allowed=""
DEFAULT_NETWORK="" install_sandbox_network >/dev/null
[[ -z "${allowed// /}" ]] ||
fail "an empty AI_SBX_NETWORK should allow nothing, got: $allowed"
allowed=""
provision_secret TOKEN "reg.example.com,*.cdn.example.com" secret-value >/dev/null
[[ "$allowed" == *"reg.example.com"* ]] ||
fail "provision_secret did not allow reg.example.com"
[[ "$allowed" == *"*.cdn.example.com"* ]] ||
fail "provision_secret did not allow the wildcard host"
allowed=""
provision_secret TOKEN '*.localstack.cloud' secret-value >/dev/null
[[ "$allowed" == *'*.localstack.cloud'* ]] ||
fail "wildcard host was mangled: '$allowed'"
allowed=""
allow_sandbox_host "" >/dev/null
[[ -z "${allowed// /}" ]] || fail "an empty host should be ignored"
if ((failures)); then
printf '%d assertion(s) failed\n' "$failures" >&2
exit 1
fi
printf 'All network policy assertions passed.\n'