weft-macos-sandbox
macOS sandbox runner plugin for Weft.
This extension adds the macos-sandbox runner via the weft.runners
entry-point group. It currently supports one-shot command TaskSpecs only and
uses sandbox-exec with a caller-provided profile.
Environment variables
The sandboxed child process does not inherit the full host environment. By default only a fixed baseline of session-plumbing variables is forwarded:
HOMELANGLC_ALLLC_CTYPELOGNAMEPATHSHELLTERMTMPDIRUSER
To forward additional host-derived values, opt in explicitly via
spec.runner.options.env_passthrough:
{
"runner": {
"name": "macos-sandbox",
"options": {
"profile": "/path/to/sandbox.sb",
"env_passthrough": ["MY_HOST_TOKEN"]
}
}
}
For fixed values (not derived from the host), set spec.env instead.
spec.env always wins over both the baseline and env_passthrough, so
TaskSpec-declared values cannot be shadowed by host state.
Migration note: weft-macos-sandbox releases before 0.6.0 inherited the
full host environment; set env_passthrough explicitly if you depended on
that.
Security model
This plugin's preflight validation only checks that
spec.runner.options.profile exists on disk (not that it is a regular,
non-empty file) and that the configured sandbox_binary (default
sandbox-exec) is on PATH; at construction time the option only needs to
be a non-empty string. It does not parse or validate the profile's
contents. Isolation is exactly what the supplied Seatbelt profile grants —
nothing more, nothing less. A profile that reads (allow default) grants no
isolation at all; the plugin runs it without complaint. Writing a correctly
restrictive profile is the caller's responsibility.
sandbox-exec is an Apple-deprecated, undocumented mechanism: Apple has
marked the command deprecated for years and publishes no supported API or
stability guarantee for the Seatbelt profile language it consumes. Treat
this runner as a best-effort, host-specific containment tool, not a
supported or guaranteed sandbox boundary — consistent with Weft's broader
trust model (docs/specifications/00-Overview_and_Architecture.md,
"Observability and Security"): user-level trust, not hostile
multi-tenancy, with the OS/filesystem as the actual security boundary.
Release tag:
weft_macos_sandbox/vX.Y.Z
Release files for weft-macos-sandbox 0.6.5
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| weft_macos_sandbox-0.6.5.tar.gz | 5.8 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| weft_macos_sandbox-0.6.5-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 13.6 kB
Release files / weft_macos_sandbox-0.6.5.tar.gz
| Download URL | weft_macos_sandbox-0.6.5.tar.gz |
|---|---|
| Size | 5.8 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
317b18ecb11951bb3d3433ed412419203d50684d6f5f9632e54145754a4dc8d8
|
|
BLAKE2b-256 checksum How to use checksums |
c70f801dc0165f060c1c787376beb99c0ef481e84dda64ab2c5c99b2c0a3a4fe
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.11.11 {"installer":{"name":"uv","version":"0.11.11","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Release files / weft_macos_sandbox-0.6.5-py3-none-any.whl
| Download URL | weft_macos_sandbox-0.6.5-py3-none-any.whl |
|---|---|
| Size | 7.8 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
00e6438adb576ede4d926584e2ce224b8f229bbb4c5547fbd8c5ef8c4b2a2646
|
|
BLAKE2b-256 checksum How to use checksums |
75fb5b4f3778976f8afb9745a207a9e272210bf9351bb68d5b3df1a3f0115033
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.11.11 {"installer":{"name":"uv","version":"0.11.11","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|