bazelbuild / bazelbuild/bazel

Stronger MacOS Sandbox with FSKit

Open
#29,165 6 comments 7 reactions 0 assignees View on GitHub
help wanted P3 team-Remote-Exec type: feature request
Dominant language
Java
Stars
25.8k
Forks
4.6k
Avg merge
2d 20h
Merged PRs (30d)
72

Description

### Description of the feature request:

@thesayyn has been studying the new https://developer.apple.com/documentation/FSKit API introduced in recent versions of MacOS. We believe this could allow a sandbox implementation that's both fast and isolated, in the sense that it avoids common sandbox escaping by following symlinks.

Background:
- Current implementation is substantially slower than `local` spawn: https://github.com/bazelbuild/bazel/issues/8230 from 2019
- NodeJS tooling *always* follows symlinks, even when implemented in Go or Rust. Thus the new Go implementation of the TypeScript type-checker can't run in a Bazel sandbox, along with ESbuild, SWC, OXC, and so on. https://github.com/aspect-build/rules_js/issues?q=is%3Aissue%20state%3Aopen%20sandbox lists some of the issues
- The `docker` strategy gives a stronger isolation but is impractical since it doesn't re-use containers.
- Sahin has some experiments at https://github.com/thesayyn/sandboxfs

Alternatives:
- Replace eager symlink creation with an on-demand userland filesystem
- If cross-device hardlinks were permitted, it might help. The kernel security system might need changes.
- MacFUSE has a FSkit implementation now, but you have to reduce secure boot.
- bb-clientd uses an NFS approach but it's brittle (@jsharpe)

### Which category does this issue belong to?

Action Spawns

Contributor guide

Open the contributing guide

Research direction

Start by reading Apple’s FSKit documentation, Bazel issue #8230, and the sandboxfs experiments linked in the description. The issue names no Bazel files, tests, or implementation entry point, and does not define acceptance criteria; a contributor would first need to establish the design and measurable isolation and performance goals.

Written by the indexing model from the issue text.

Assessment

Tech stack
macos
Domain
build-system, operating-systems, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.