From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from atuin.qyliss.net (localhost [IPv6:::1]) by atuin.qyliss.net (Postfix) with ESMTP id EF699136E4; Thu, 04 Dec 2025 02:21:57 +0000 (UTC) Received: by atuin.qyliss.net (Postfix, from userid 993) id 7AE3713693; Thu, 04 Dec 2025 02:21:51 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-26) on atuin.qyliss.net X-Spam-Level: X-Spam-Status: No, score=-0.1 required=3.0 tests=DKIM_SIGNED,DKIM_VALID, DKIM_VALID_AU,DMARC_PASS,FREEMAIL_FROM,RCVD_IN_DNSWL_NONE, SPF_HELO_NONE autolearn=unavailable autolearn_force=no version=4.0.1 Received: from mail-yx1-xb12d.google.com (mail-yx1-xb12d.google.com [IPv6:2607:f8b0:4864:20::b12d]) by atuin.qyliss.net (Postfix) with ESMTPS id 57B821365E for ; Thu, 04 Dec 2025 02:21:50 +0000 (UTC) Received: by mail-yx1-xb12d.google.com with SMTP id 956f58d0204a3-640c9c85255so669466d50.3 for ; Wed, 03 Dec 2025 18:21:49 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1764814908; x=1765419708; darn=spectrum-os.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:from:to:cc:subject:date:message-id :reply-to; bh=fHqm3wiln8Whn9ilg1w16c3r2zD3V8zHbiCvOmPYTzU=; b=J4S2o3+sU81CxtoaftpFi5kk2ojcl/d8I4tc6eFEJNuPAr0MQ1hES29rotOrqmM2Jc wPEJbiJWuWbRq62CgQ4FZnscqzG9fDSAmpuAFSkWiP70PoIADLQVUI8vPZYtJGERyz4P KPJS5RbuBJwNBsO+5QbHEeyO/aLquC7CZv4P+pxr1Opyzxl4sSw+uliCB0fj9ESJ/L46 5jnfeKZc8hw6L47MgQPqm5J1Xa8RQbsXHyWxe2IMZgCqPnMFg4Ku3ocT+tIKRCItRCTp DrnbaVXIWFiYz4MMgIZiK+GHBhWeM5dPyZNpIkhrgJa1YAT7IiAUiyQrXX7BfKiU8NSY qWaQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1764814908; x=1765419708; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to; bh=fHqm3wiln8Whn9ilg1w16c3r2zD3V8zHbiCvOmPYTzU=; b=bMr2+02NdK2cDklWMv+YF5W/yuuc22Y0JDonKcWq++vPjhwHlMyneiC0Tpqnxwf5eH pWoHkSsKXTLqNBlEXguF72jI4MF5snha8bcM/vmDfrVoRUEWpFvx7uv0kDj9HM5jEouH haGVueFjmImmx9775lJ/yqjlr9rmPtKf0QJ6OduHBZcgrsbJgbNTpHdZxj3QeCBe+qAT XqjU8m/kk1DReLI9TmlEFdVrjTXxXMMk34BaNY/kPxIfqpI2xNFOcnF3wcNODOFx1f5a Dtq5WjdwW3hqdeQgm/n4g2tH6qDLAR3pP3/pefRGroeB7q4rQBeb5w1+JYF1k7KuRJf2 IphA== X-Gm-Message-State: AOJu0YxwDGFoA6amT3jH3StTAFr50uyv9ST35DskTlZRiiX/20abFYfO oTd/+5kaGZX0z6UrpYCsrcftMwUnA+clOZ+c1rJlxCMhS1JKncXa1EK7o6KjCg== X-Gm-Gg: ASbGncuopj/+r4Dbl1H504oTU0oWRnc4Qzhg8JZjb4DWHrovdg0ZlgElbZOXwED/H9P NwdxNLAbOSkaEr2t9NlUOHWSeQZkzGryaNdAxjBd+YxTgIlBzX+KA3E2IUHQPG2gX9OAN5Fk0qN 17cq6AsTg6RzbRGN9BOTT6h/MWLNS7ommF470+qiTWqNjxvmlOVV+QpPDusxpxShlScsFe2n/ci D1MAKw60Vib/OXLDgYdd15UsDYEcF35pftt9khNRzZZPjS33JDxnFyBitaX779AAwAaaUia40UP yBXR7wiLaudkni8oQ4HRNyOMlFXgSRUgOQsQNqfVJ0q85Km0ZyLq/3Ee9eC6jWcsDyt2meoneHJ p1M77cnEF0YyqRBPPkCOYzhJ1HYWVj2L5YxQw9X/Hs4Qo9482+A+uB5cvpDU6nf55rbjfqOIQF4 dUrc/hHn+g4SKB5Sof+J1PLYaTSI0DUfyFiaVbIEeRTntj+xqFVm2yY8pUoOj/GQEwvn/k8lyf9 brKkovPFNCQ/u9+dFDGrDFLE8gKMQ40hQKnv1XPEJydxQ== X-Google-Smtp-Source: AGHT+IELeH/OCiDxS6HTwCxunxU12wvzQSsU0GW3AvyjsZ9sXMmZp2x1wGCjm+JPYp7Ii79Z4q48wQ== X-Received: by 2002:a05:690e:1244:b0:63f:af64:ae5b with SMTP id 956f58d0204a3-6443d93b833mr1079106d50.41.1764814907682; Wed, 03 Dec 2025 18:21:47 -0800 (PST) Received: from localhost.localdomain (h96-60-249-169.cncrtn.broadband.dynamic.tds.net. [96.60.249.169]) by smtp.gmail.com with UTF8SMTPSA id 956f58d0204a3-6443f2b7da3sm170328d50.8.2025.12.03.18.21.47 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 03 Dec 2025 18:21:47 -0800 (PST) From: Demi Marie Obenour Date: Wed, 03 Dec 2025 21:20:39 -0500 Subject: [PATCH v4 2/6] host/rootfs: Sandbox router MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 7bit Message-Id: <20251203-sandbox-v4-2-71542a7dcf5c@gmail.com> References: <20251203-sandbox-v4-0-71542a7dcf5c@gmail.com> In-Reply-To: <20251203-sandbox-v4-0-71542a7dcf5c@gmail.com> To: Spectrum OS Development X-Mailer: b4 0.14.3 X-Developer-Signature: v=1; a=ed25519-sha256; t=1764814837; l=1427; i=demiobenour@gmail.com; s=20250729; h=from:subject:message-id; bh=myAwCDelD2tCReXMm7kzwbVZ/8KFLB3M5KFm3tOhtCI=; b=DNti3CKVyTAgHBLjTbXjytqeUxdkYHZmMlDSatUSZjYms3HT3QYOs1RpGEDiGuz5irokfkeJ+ zA+Ow1drLa6Bqc2d+0RObdJ61N/+QuFdIFWIZTR0dlaYxta4gyTZULU X-Developer-Key: i=demiobenour@gmail.com; a=ed25519; pk=X57Q4/YQDj9t4SBeKaDwvXYKB6quZJVx/DE2Ly2out0= Message-ID-Hash: VR64YGVEDY3UHWZUCLLLRZBTTW6KTQNV X-Message-ID-Hash: VR64YGVEDY3UHWZUCLLLRZBTTW6KTQNV X-MailFrom: demiobenour@gmail.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-devel.spectrum-os.org-0; header-match-devel.spectrum-os.org-1; header-match-devel.spectrum-os.org-2; header-match-devel.spectrum-os.org-3; header-match-devel.spectrum-os.org-4; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header CC: Demi Marie Obenour , Alyssa Ross X-Mailman-Version: 3.3.9 Precedence: list List-Id: Patches and low-level development discussion Archived-At: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: This needs very little access to the system. Signed-off-by: Demi Marie Obenour --- .../template/data/service/spectrum-router/run | 19 ++++++++++++++++--- 1 file changed, 16 insertions(+), 3 deletions(-) diff --git a/host/rootfs/image/etc/s6-linux-init/run-image/service/vm-services/template/data/service/spectrum-router/run b/host/rootfs/image/etc/s6-linux-init/run-image/service/vm-services/template/data/service/spectrum-router/run index 7b3e3db3b109ba1c8d195c7c47d50d0cfbc30bd5..ef68cd638c092b53cc714a5d65bbfa3b49585346 100755 --- a/host/rootfs/image/etc/s6-linux-init/run-image/service/vm-services/template/data/service/spectrum-router/run +++ b/host/rootfs/image/etc/s6-linux-init/run-image/service/vm-services/template/data/service/spectrum-router/run @@ -4,6 +4,19 @@ importas -i VM VM -export RUST_LOG spectrum-router=debug,info -spectrum-router --app-listen-path ${VM}/router-app.sock --driver-listen-path ${VM}/router-driver.sock - +bwrap + --unshare-all + --unshare-user + --dev-bind / / + --setenv RUST_LOG spectrum-router=debug,info + --tmpfs /tmp + --dev /dev + --tmpfs /dev/shm + --ro-bind /nix /nix + --ro-bind /etc /etc + --tmpfs /run + --ro-bind /usr /usr + --ro-bind /lib /lib + --bind $VM $VM + -- + spectrum-router --app-listen-path ${VM}/router-app.sock --driver-listen-path ${VM}/router-driver.sock -- 2.52.0