npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@rtq/sandbox

v0.1.1

Published

RTQ OS sandbox runtime: Seatbelt (macOS), bubblewrap (Linux), AppContainer+Job Object (Windows), fail-closed, with explicit enforcement reporting.

Readme

@rtq/sandbox

Real OS enforcement, not a policy suggestion. @rtq/sandbox runs a tool inside a real OS backend on every major platform — bubblewrap (Linux), Seatbelt (sandbox-exec, macOS), AppContainer+Job (Windows) — using RTQ-derived allowlists, and returns an enforcement report the gateway can prove in the audit trail (RTQ §46.21–46.22, §13).

The first principle here is §46.21 #1: RTQ will not execute a server's tool directly in-process "just this once" and hope; the tool either runs inside a real OS sandbox with an enforcement report, or RTQ records that this backend is not being enforced on this OS (explicit skip report, never a silent pass). Fail-closed, always.

What's inside

  • createSandbox(options) — returns a SandboxHandle for a runtime built on one of createDarwinSandbox (Seatbelt), createLinuxSandbox (bubblewrap), or createWindowsSandbox (AppContainer + Job object), selected from the runtime → backend mapping in SandboxRuntimeOptionsBackend / McpGatewayConfig.transportKind.
  • buildBubblewrapArgs / buildSeatbeltArgs — construct the real backend argv in a new namespace: ro/rw bind mounts from RTQ allowlists only, no shared /dev (empty mount), private /tmp (tmpfs), no --share-net by default, bubbles apart from the host. Linux no-/usr on Windows → SANDBOX_POLICY_INVALID if the allowlist can't validate fail-closed (§46.21 #11, linux.test.ts #6).
  • checkBwrapCapability / checkSeatbeltCapability — probe whether the real backend binary/sandbox-exec exists before promising enforcement (construction invariants: never a silent false-positive "enforced").
  • canonicalizePath / isPathAllowed / validateAllowlistPaths — path canonicalization + allowlist validation. A path that can't be canonicalized is denied, never guessed-as-abs (46.21 #8, #13).
  • buildBubblewrapArgs refusal is fail-closed: network allowlists that enforce only against the gateway (and not the OS) are refused at construction with SANDBOX_POLICY_INVALID, not silently downgraded (linux.test.ts "refuses network allowlists it cannot enforce").
  • Windows runner — scripts/windows-runner.ps1 shipped in-tree (no approve=true bypass — CI greps and fails if a bypass appears). The note here: the Windows AppContainer is the REAL backend, and tests/sandbox/windows.test.ts describeMaybe-skips the Linux//usr tests so the suite works when the OS doesn't ship /usr.

Security invariants (tests/sandbox/* enforce on the real OS)

The sandbox suite (§46.21 #1–#14, §46.22 #1–#8, §13) is written to FAIL the pipeline when enforcement is missing:

  • Real-OS test on each platform verifies the actual backend ran (file effects landed in a private tmpfs, not the host); skip is explicit and reported in CI (sandbox.yml uploads an explicit skip suite provenance artifact), never a silent "¥passed".
  • The shipped windows-runner.ps1 is checked to contain no approve=true secret bypass and to exist on the Windows runner (real OS measure).
  • buildBubblewrapArgs is namespace-safe by construction: it unshares user/PID/net/mount, binds only allowlisted paths, gives the process its own /dev//tmp, and — critically — never passes --share-net.

Note on platform truthfulness

Cross-platform CI (sandbox.yml) runs the enforcement suite on every OS in the matrix. The Linux bubblewrap tests skip cleanly on Windows with a reported skip (the OS deliberately can't prove /usr), so a red state means "the backend is genuinely broken on this OS," never "the test file doesn't exist for this platform."

License

Apache-2.0