Skip to main content

weft-macos-sandbox

macOS sandbox runner plugin for Weft.

This extension adds the macos-sandbox runner via the weft.runners entry-point group. It currently supports one-shot command TaskSpecs only and uses sandbox-exec with a caller-provided profile.

Environment variables

The sandboxed child process does not inherit the full host environment. By default only a fixed baseline of session-plumbing variables is forwarded:

  • HOME
  • LANG
  • LC_ALL
  • LC_CTYPE
  • LOGNAME
  • PATH
  • SHELL
  • TERM
  • TMPDIR
  • USER

To forward additional host-derived values, opt in explicitly via spec.runner.options.env_passthrough:

{
  "runner": {
    "name": "macos-sandbox",
    "options": {
      "profile": "/path/to/sandbox.sb",
      "env_passthrough": ["MY_HOST_TOKEN"]
    }
  }
}

For fixed values (not derived from the host), set spec.env instead. spec.env always wins over both the baseline and env_passthrough, so TaskSpec-declared values cannot be shadowed by host state.

Migration note: weft-macos-sandbox releases before 0.6.0 inherited the full host environment; set env_passthrough explicitly if you depended on that.

Security model

This plugin's preflight validation only checks that spec.runner.options.profile exists on disk (not that it is a regular, non-empty file) and that the configured sandbox_binary (default sandbox-exec) is on PATH; at construction time the option only needs to be a non-empty string. It does not parse or validate the profile's contents. Isolation is exactly what the supplied Seatbelt profile grants — nothing more, nothing less. A profile that reads (allow default) grants no isolation at all; the plugin runs it without complaint. Writing a correctly restrictive profile is the caller's responsibility.

sandbox-exec is an Apple-deprecated, undocumented mechanism: Apple has marked the command deprecated for years and publishes no supported API or stability guarantee for the Seatbelt profile language it consumes. Treat this runner as a best-effort, host-specific containment tool, not a supported or guaranteed sandbox boundary — consistent with Weft's broader trust model (docs/specifications/00-Overview_and_Architecture.md, "Observability and Security"): user-level trust, not hostile multi-tenancy, with the OS/filesystem as the actual security boundary.

Release tag:

  • weft_macos_sandbox/vX.Y.Z

Release files for weft-macos-sandbox 0.6.7

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for weft-macos-sandbox 0.6.7
File Size Uploaded
weft_macos_sandbox-0.6.7.tar.gz 5.8 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for weft-macos-sandbox 0.6.7
File Interpreter ABI Platform
weft_macos_sandbox-0.6.7-py3-none-any.whl Python 3 none any Details

Total release size: 13.7 kB

Release files / weft_macos_sandbox-0.6.7.tar.gz

Download URL weft_macos_sandbox-0.6.7.tar.gz
Size 5.8 kB
Tags Source
SHA-256 checksum
How to use checksums
48f510a2f6d2a083e4205463c04f6cc42b826545bd046974d76b0d9d0dc94500
BLAKE2b-256 checksum
How to use checksums
7bbd0c041672ae0e1245b8986cae352fe297def926f2685c21f2421bbc0d8822
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.11.11 {"installer":{"name":"uv","version":"0.11.11","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release files / weft_macos_sandbox-0.6.7-py3-none-any.whl

Download URL weft_macos_sandbox-0.6.7-py3-none-any.whl
Size 7.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
c292901f1f56d9311facd22cc6d0dcf24ad7147c37957d439d30389592c5842a
BLAKE2b-256 checksum
How to use checksums
d73f96e516f4da7205462f22ac42e3e9a5f5a0684a59f1675aaabb2cfa21b163
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.11.11 {"installer":{"name":"uv","version":"0.11.11","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release history Release notifications | RSS feed

0.6.11

2 release files

0.6.10

2 release files

0.6.9

2 release files

0.6.8

2 release files

This release

0.6.7 This release

2 release files

0.6.6

2 release files

0.6.5

2 release files

0.6.4

2 release files

0.6.2

2 release files

0.6.1

2 release files

0.6.0

2 release files

0.5.4

2 release files

0.5.3

2 release files

0.5.2

2 release files

0.5.1

2 release files

0.5.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page