chore: add sandboxec sandbox config for pi

This commit is contained in:
2026-07-31 13:52:21 -04:00
parent fb938066a4
commit b82281800d
3 changed files with 41 additions and 0 deletions
+39
View File
@@ -0,0 +1,39 @@
abi: 6
ignore-if-missing: true
unsafe-host-runtime: true
# Pi stores configuration, extensions, skills, and sessions under ~/.pi/agent.
# The current workspace is writable so agent edits remain confined to the repo
# from which Pi is launched. Network access is limited to model/API HTTPS.
fs:
- rwx:$HOME/.pi/agent/
- rwx:$HOME/.pi-lens/
- rwx:$HOME/.pi/context-mode/
- rw:$HOME/.pi/agent/settings.json
- r:$HOME/.pi/agent/AGENTS.md
- rx:$HOME/.local/share/mise/installs/npm-earendil-works-pi-coding-agent/
- rw:$PWD
- rw:/tmp
- r:/dev/random
- r:/dev/urandom
- r:/etc/hosts
- r:/etc/ld.so.cache
- r:/etc/localtime
- r:/etc/nsswitch.conf
- r:/etc/resolv.conf
- r:/etc/ssl/certs
- r:/etc/ssl/certs/ca-certificates.crt
- r:/etc/ssl/openssl.cnf
- r:/home/linuxbrew/.linuxbrew/etc/openssl@3/openssl.cnf
- r:/proc/
- r:/proc/meminfo
- r:/proc/self/cgroup
- r:/proc/self/groups
- r:/proc/self/maps
- r:/proc/stat
- r:/sys/devices/system/cpu/online
- r:/usr/lib/locale/locale-archive
- r:/usr/lib/ssl/openssl.cnf
- r:/usr/share/locale/locale.alias
- rw:/dev/null
net:
- c:443