Executor boundaries¶
Each executor provides the protection below per capability dimension. Every statement describes the case where the corresponding control was requested; whether a given Run actually installed it is decided by that Run's Bundle.
Network boundaries owns network detail (which path can be bypassed, and the VM data plane's protocol coverage); isolation design owns the mechanisms.
Overview¶
| Dimension | host (Linux) | host (macOS) | container | VM |
|---|---|---|---|---|
| Workspace writes | Staged through OverlayFS (FUSE); nothing lands before apply | Staged through OverlayFS (macFUSE) | Staged through OverlayFS | Copy-on-write workspace served over virtio-fs |
| Writes to other host paths | --filesystem sandbox: namespaces, projected root, and Landlock |
--filesystem sandbox: Seatbelt write scope |
Image user space and configured mounts | Separate guest; root writes go to a temporary upper and are discarded on exit |
| Reads | Ambient by default; under --filesystem sandbox, constrained by the projected root and Landlock |
Ambient by default; --safe requests a Seatbelt read scope, but current Run evidence still reports reads as ambient (see known limitations) |
Image contents and configured mounts | Only rootfs and declared mounts; --rootfs host exposes host content |
| Sensitive paths in the view | --access rules and the --safe preset, enforced through OverlayFS |
Same as Linux | Same as Linux | Same, applied to the root view |
| Network (selective policy) | Cooperative proxy, bypassable | Under --safe, blocks direct connections and enforces selective rules at the proxy |
Cooperative proxy, needs host networking | Non-bypassable smoltcp data plane |
| Network (deny all) | Private network namespace | Seatbelt blocks non-loopback IPs and ambient Unix sockets | --container-network none |
--overlaynet off |
| HOME and credentials | --safe: copy-on-write HOME view; credentials require an explicit --pass-env |
--safe: temporary HOME; cannot read the original home directory |
Only explicit mounts and passed variables | Rootfs-dependent; --rootfs host preserves the host HOME |
| Child processes | user/mount/PID namespaces; process-group cleanup | Process-group cleanup | Container process tree | Inside the guest kernel |
Is --safe available? |
Yes | Yes | Refuses to start (missing complete enforcement boundary) | Yes, requires auto networking |
Single-node daemon boundary¶
The table describes requested controls for native Jobs, not the daemon API. VM-only NativeRuntime embeds pVisor in detached supervisors with independent immutable guest rootfs and private writes; delegated cgroup v2 caps the supervisor/VM tree. Stage/apply and checkpoint/fork APIs are not implemented, and node sharing is not automatically acquired. OpenSandbox network-policy options are rejected; native OverlayNet outbound networking is not a deny-all claim.
Trust the host account, daemon/firmware and prepared image. Private state and same-UID IPC do not defend against hostile host-UID/root code. Other local users may reach loopback publications: use genuine service authentication and host controls. No hostile multi-user or security-audit assurance is claimed. See daemon runtime boundaries for the unsupplied/unvalidated bootstrap and real-service checks.
Reading the table¶
- A control in one dimension does not raise another. A staged file does not prove the network is isolated, and a captured model request does not prove no other connection exists.
- No executor currently claims complete subprocess enforcement. As a result,
--strict(which requires non-bypassable enforcement evidence for every requested dimension) exits withUnsupportedPolicyon host, container, and VM. Use it to verify fail-closed behavior; it is not a ready-made stronger sandbox preset. - The macOS VM is not a hostile multi-tenant boundary: the VMM still holds the calling user's host permissions.
- Descendants that actively leave the process group are outside host process-group cleanup.
Verify it in the Run Bundle¶
The Safety boundary section of pvisor status --review lists the controls and warnings actually installed for each dimension; in --json, executor_observations is the enforcement evidence, and the safety.* summary is derived from it. See capabilities, evidence, and assurance boundaries for what the levels (Unenforced, Cooperative, Enforced) mean.