Skip to content

Add Hazmat to Command-line tools - #55

Open
dredozubov wants to merge 1 commit into
smashism:masterfrom
dredozubov:add-hazmat
Open

dredozubov wants to merge 1 commit into
smashism:masterfrom
dredozubov:add-hazmat

Conversation

@dredozubov

Copy link
Copy Markdown

Adding Hazmat under Command-line tools.

Hazmat is a macOS containment CLI for AI coding agents and risky local scripts. The work runs under its own UID (not the admin's), under a Seatbelt policy applied via sandbox_init() from a small privileged helper (not sandbox-exec), with PF anchors and DNS blocklists for per-session network policy, plus backup/rollback for reversible host setup.

The design is checked in TLA+ across nine specs (~44,795 states) covering setup/rollback ordering, seatbelt credential-deny policy, backup safety, version migration, Tier 2/Tier 3 policy equivalence, session-time host permission repairs, harness lifecycle, and helper fd hygiene before sandbox_init.

https://github.com/dredozubov/hazmat

macOS containment CLI for AI coding agents and risky local scripts.
Separate UID, Seatbelt sandboxing, PF anchors, DNS blocklists,
backup/rollback. TLA+-checked design.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant