v0.5.1 Release Notes
Released
v0.5.0 -> v0.5.1
Summary
Remove Podman container dependency and refactor to use bubblewrap sandbox with enhanced security hardening including network isolation and capability restrictions.
翻譯
移除 Podman 容器相依性,重構為使用 bubblewrap 沙箱執行,並強化安全設定包括網路隔離與權限限制。Changes
REFACTOR
- Remove entire
internal/container/package (build, container, health, operator) - Consolidate
RunBodyandRunNowBodystructs into singleRunBody - Extract
getRunBody(),getCodeMaxSize(),run(),setStream()helper functions - Remove commented-out Podman execution code from handlers
翻譯
- 移除整個
internal/container/套件(build、container、health、operator) - 合併
RunBody與RunNowBody結構為單一RunBody - 抽離
getRunBody()、getCodeMaxSize()、run()、setStream()輔助函式 - 移除 handlers 中已註解的 Podman 執行程式碼
SECURITY
- Enable network isolation with
--unshare-net(previously--share-net) - Add
--new-sessionto prevent TTY hijacking - Add
--cap-drop ALLto remove all capabilities - Remove
/binand/sbinbind mounts to reduce attack surface - Add sandbox home directory
/home/sandboxwith tmpfs - Clear sensitive environment variables (
LD_PRELOAD,LD_LIBRARY_PATH) - Set explicit locale and temp directory environment
翻譯
- 啟用網路隔離
--unshare-net(原為--share-net) - 新增
--new-session防止 TTY 劫持 - 新增
--cap-drop ALL移除所有 capabilities - 移除
/bin與/sbin綁定掛載以縮小攻擊面 - 新增沙箱家目錄
/home/sandbox使用 tmpfs - 清除敏感環境變數(
LD_PRELOAD、LD_LIBRARY_PATH) - 設定明確的語系與暫存目錄環境變數
Files Changed
| File | Status | Tag |
|---|---|---|
internal/container/build.go |
Deleted | REFACTOR |
internal/container/container.go |
Deleted | REFACTOR |
internal/container/health.go |
Deleted | REFACTOR |
internal/container/operator.go |
Deleted | REFACTOR |
internal/handler/run.go |
Modified | REFACTOR |
internal/handler/sse.go |
Modified | REFACTOR |
internal/sandbox/command.go |
Modified | SECURITY |
.gitignore |
Modified | CHORE |
package-lock.json |
Added | CHORE |
Generated by SKILL