Module: SBPrelude

Defined in:
lib/security_box/guest/prelude.rb

Overview

Hardening prelude — loaded before user code (defense in depth; WASI is the primary isolation boundary).

Responsibilities (in order):

1. capture the per-eval sandbox token from ENV and hand it to the guest
 protocol exactly once (main.rb), erasing every other reference;
2. scrub ENV so user code sees an empty environment;
3. neutralize the process-spawn APIs that WASI leaves as misleading stubs
 (e.g. `system` returns true without running anything) by raising
 SecurityError instead;
4. disable Kernel#open entirely (its pipe form executes processes; user
 code must use File.open/IO.read for plain files);
5. set $stdout.sync so captured output is not lost on a hard kill.

Constant Summary collapse

DENIED_MESSAGE =
"process execution is not allowed inside the sandbox"

Class Method Summary collapse

Class Method Details

.apply! ⇒ Object

Applies all hardening and returns the sandbox token (or nil). The token is removed from the prelude state; afterwards it exists only in the caller's local scope.



21
22
23
24
25
26
27
# File 'lib/security_box/guest/prelude.rb', line 21

def apply!
  capture_token
  scrub_env
  neutralize_process_apis
  sync_stdout
  take_token
end

.take_token ⇒ Object

Returns the token captured by apply! and erases the stored reference.



30
31
32
33
34
# File 'lib/security_box/guest/prelude.rb', line 30

def take_token
  token = @token
  remove_instance_variable(:@token) if instance_variable_defined?(:@token)
  token
end