/** * Bubblewrap Sandbox for Terminal Sidecar * * Provides secure sandboxing using bubblewrap (bwrap) with: * - Single directory bind mount (based on ACL Control permission) * - Optional network isolation * - Process isolation via Linux namespaces * * Note: bubblewrap is Linux-only. On other platforms, falls back to unsandboxed execution. */ import { ChildProcess } from 'child_process'; export interface SandboxConfig { /** Working directory to bind mount (user must have acl:Control) */ workdir: string; /** Command to execute inside sandbox */ command: string; /** Command arguments */ args: string[]; /** Environment variables */ env: Record; /** Whether to isolate network (default: false) */ isolateNetwork?: boolean; /** Additional read-only bind mounts (e.g., /usr, /lib) */ readonlyBinds?: string[]; /** PTY columns */ cols?: number; /** PTY rows */ rows?: number; } export interface SandboxResult { process: ChildProcess; sandboxed: boolean; } export declare class BubblewrapSandbox { protected readonly logger: import("global-logger-factory").Logger; private static readonly SYSTEM_PATHS; /** * Launch a sandboxed process. * * @param config - Sandbox configuration * @returns The spawned process and whether it's sandboxed */ launch(config: SandboxConfig): SandboxResult; private launchSandboxed; private launchUnsandboxed; private buildBwrapArgs; /** * Check if bubblewrap is available on this system. */ static isAvailable(): boolean; }