The Sandbox
Check that the sandbox blocks what it should and allows what you grant, on a Mac and on Linux.
You need this checkout's lnk, and on Linux bubblewrap, which apt-get install -y bubblewrap installs. It is free, and the script downloads a
few MB.
The script
cargo build
# probes, the proxy to a real host, the log, the kill switch, git, pip and an MCP server
src/tests/sandbox/run.shOn Linux it takes about 15 seconds once built. Every line says ok, and
it ends with "All passed." Its log is in target/sandbox-tests/<time>/.
On a Mac whose npx is under your home, as nvm's is, the MCP server
check says it can't run, because a sandbox never reads your home.
Check the sandbox
Run these in an empty folder:
lnk sandbox check # no LEAK
lnk sandbox check --write . --internet-host '*' # no LEAK; on Linux the one open is a new .envrcEach line is blocked or allowed, except a new .envrc on Linux, a
known gap, which is open. With the internet allowed, "reach the
internet" is allowed ... through its proxy, and asking the proxy for
this machine or its network address is blocked.
Reach the internet through the proxy
lnk sandbox run --internet-host '*' -- curl -sI https://example.com # 200 Connection established, then the site's answer
lnk sandbox run --internet-host example.org -- curl -sI https://example.com # 403 Forbidden, from the proxylnk sandbox log --refused shows the second as refused.
Find and name the programs a command runs (Linux)
lnk sandbox learn --command sh -- sh -c 'git --version; id' # git's version, then "git" and "id" to add
lnk sandbox run --command sh -- sh -c 'id' # "lnk sandbox: refused /usr/bin/id: add it to [commands] allow"Keep a project's dot files read only
Run these in an empty folder:
# a repository to try it on
git init -q demo && cd demo
lnk sandbox run --write . -- sh -c 'echo x >> .git/config' # read only: Read-only file system, or Operation not permitted
lnk sandbox run --write . --write-dot-files . -- git config user.name me # works
lnk sandbox check --write . # .git, .vscode, .idea: blocked; .envrc open on Linux
lnk sandbox check --write . --write-dot-files . # the same, allowedAfterwards ls -a shows nothing new, because the empty placeholders a
Linux run makes are gone when it ends.
Run by root (Linux)
Run these in an empty folder, first as yourself and then with sudo:
lnk sandbox check --write . --command sh # no LEAK; a memory program is blocked both ways
lnk sandbox run --command grep -- grep CapEff /proc/self/status # CapEff: 0000000000000000Run by root, the second shows no capabilities either.
An agent's sandbox (Linux)
With an agent running on Link Harness, default permissions:
lnk agent status # Network: through its proxy, from this machine
lnk agent link check # no LEAKThe kernel's probes are each blocked, which covers a user namespace,
io_uring, userfaultfd, the kernel's key store (keyctl) and tracing a
process (ptrace). So is connecting to another server on localhost, at
this machine's network address and to an abstract unix socket. The one
open is a known gap. A new .envrc can be made in the agent's files,
and direnv runs it only after direnv allow.
Reach a database by its names (Linux)
lnk sandbox run --internet-host '*.example.com' --tcp '*.example.com:5432' -- getent hosts www.example.com # 127.1.0.1 www.example.com
lnk sandbox run --internet-host '*.example.com' --tcp '*.example.com:5432' -- getent hosts example.org # nothing, exit 2
lnk sandbox log -n 4 # dns lines, the last refusedTo try it on a real database, use a MongoDB Atlas cluster of your own,
on its free tier. mongosh "mongodb+srv://<user>@cluster0.<id>.mongodb.net"
inside lnk sandbox run --internet-host '*.<id>.mongodb.net' --tcp '*.<id>.mongodb.net:27017' connects and asks for its password.
What the sandbox does is in Sandbox.
