{"id":13797137,"url":"https://github.com/hellais/buckle-up","last_synced_at":"2025-08-04T02:13:02.570Z","repository":{"id":2093546,"uuid":"3033934","full_name":"hellais/Buckle-Up","owner":"hellais","description":"Script for running Mac OS X applications in a sandbox and a collection of seatbelt profiles","archived":false,"fork":false,"pushed_at":"2012-02-05T10:38:20.000Z","size":327,"stargazers_count":89,"open_issues_count":1,"forks_count":9,"subscribers_count":12,"default_branch":"master","last_synced_at":"2025-04-30T06:36:05.664Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/hellais.png","metadata":{"files":{"readme":"Readme.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2011-12-22T13:21:09.000Z","updated_at":"2025-04-17T12:28:25.000Z","dependencies_parsed_at":"2022-08-26T13:51:06.459Z","dependency_job_id":null,"html_url":"https://github.com/hellais/Buckle-Up","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/hellais/Buckle-Up","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/hellais%2FBuckle-Up","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/hellais%2FBuckle-Up/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/hellais%2FBuckle-Up/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/hellais%2FBuckle-Up/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/hellais","download_url":"https://codeload.github.com/hellais/Buckle-Up/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/hellais%2FBuckle-Up/sbom","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":268639813,"owners_count":24282672,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","status":"online","status_checked_at":"2025-08-04T02:00:09.867Z","response_time":79,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-03T23:01:23.188Z","updated_at":"2025-08-04T02:13:02.493Z","avatar_url":"https://github.com/hellais.png","language":"Python","funding_links":[],"categories":["\u003ca id=\"8c5a692b5d26527ef346687e047c5c21\"\u003e\u003c/a\u003e收集"],"sub_categories":[],"readme":"# Buckle Up!\nThe aim of this project is raise sensibility of security on OS X\nand develop seatbelt profiles for all of the common used OSX applications.\n\n## The Buckle Up script\nBuckle Up is also a python script that assists you in patching your applications to\nrun with seatbelt profiles.\n\nHere is it's help banner:\n\n    Buckle Up!\n    -------\n    Mac OS X sandboxing helper scripts\n    by Arturo Filasto' \u003cart@fuffa.org\u003e\n\n    Usage: buckleup.py [options]\n\n    Options:\n      -h, --help            show this help message and exit\n      -l, --list            list all application profiles\n      -p APP, --patch=APP   patch the desired application\n      -a APP, --application=APP\n                            explicitly set the application location\n      -u APP, --unpatch=APP\n                        remove patch from the desired application\n      -r APP, --run=APP     run the desired application in sandbox\n\nTo list the currently available profiles run `./buckleup.py  -l`:\n\n    [-] Listing Buckle Up sandbox profiles...\n          Name: Adium default (APP: adium)\n          App Location: /Applications/Adium.app/Contents/MacOS/Adium\n\n          Name: Firefox default (APP: firefox)\n          App Location: /Applications/Firefox.app/Contents/MacOS/firefox\n\nYou can then either run the application from Buckle Up with `./buckleup.py -r adium`\nor patch it to use seatbelt every time your run it `./buckleup.py -p adium`.\n\nTo remove the patch you should run `./buckleup.py -u adium`\n\n## Manually running apps with seatbelt profiles\n\nTo run an app with sandboxing enabled all you have to do is:\n\n    sandbox-exec -f \u003csandbox_file\u003e.sb /path/to/the/app\n\nFor example to run the Adium sandbox plugin do this:\n\n    sandbox-exec -f adium.sb /Applications/Adium.app/Contents/MacOS/Adium\n\n\n## Buckle Up header\n\nSandbox profiles for Buckle Up include a special header that allows the shell script to offer a pretty output\nto the user and automagically install the application.\n\nWhen writing an application profile for Buckle up you should use this format. The header should be on the first\nline of the sandbox profile:\n\n    ;:buckleup:\u003cbuckleup version number\u003e:\u003capp short name\u003e:\u003capp long name\u003e:\u003cpath to executable\u003e:\n\n_buckleup version number_: (default 0.1) This is the Buckle Up version number for the app profile\n\n_app short name_: This is the shortname of the profile, it is what the user will provide as arugment to\nbuckle up to patch the application or run it\n\n_app long name_: This is the full name of the profile, it controls what will show in the list view\n\n_path to executable_: This is the full path of the executable that should be patched, it is generally\nsomething like /Applications/MyApp.app/Contents/MacOS/MyApp\n\n## How to write a sandbox profile\n\n\n### They easy way\n\nUse the example.sb sandbox file that contains in particular the line\n\n   (trace \"profile.sb\")\n\nThis instructs sandbox-exec to output a profile.sb file that will contain\nthe raw output of what resources are being accessed during the runtime of the\ntarget application.\n\nYou would therefore start the application with:\n\n    sandbox-exec -f example.sb /Path/To/The/Application/\n\nThen run sandbox-simplify on the profile.sb and pipe it to another file:\n\n    sandbox-simplify profile.sb \u003e simplified.sb\n\nYou can then start editing that simplified file to see what makes sense to keep,\nwhat can be compacted more and what should be changed.\n\nA useful vi macro to keep handly is this:\n\n    %s/literal \"\\/Users\\/replace_with_your_username/regex #\"^\\/Users\\/[^\\.]+/gc\n\nThis basically makes your profile work for people that don't have your same username.\n\n### Boring way\n\nYou want to start from a basic sandbox profile that contains the bare minimum necessary to start the application.\nSomething along the lines of this is a good starting point:\n\n    (version 1)\n    (debug allow)\n    (allow process*)\n    (deny default)\n\nWhat this does it it allow processes to run and it is a whitelist based profile (i.e. the default policy is\nto not allow).\n\nThe next thing that you want to do is start\n\n    tail -f /var/log/system.log\n\nAll the denied by policy lines will end up in that file. Then start your application with your sandbox profile:\n\n    sandbox-exec -f \u003csandbox_file\u003e.sb /path/to/the/app\n\nYou will then see in the `tail -f` terminal lines containing something like:\n\n    Dec 22 14:58:08 x sandboxd[12281] ([12280]): firefox-bin(12280) deny file-read-data /private/tmp\n\nThis is saying, for example, that firefox was denied \"file-read-data\" access to the file in /private/tmp.\nYou should then evaluate if you want to allow that or not and in the first case add the entry that allows\nthat in your sandbox file, like so:\n\n    (file-read-data\n        (regex \"^/private/tmp\")\n    )\n\nContinue iteratively until you reach a point where your application runs properly and all the error messages\nare thing you don't want to happen.\n\nSafe hacking and remember to fasten your seatbelt :)\n\n## Resources\n\n- Apple's Sandbox Guide - http://reverse.put.as/wp-content/uploads/2011/09/Apple-Sandbox-Guide-v1.0.pdf\n\n- Chromium sandboxing - http://www.chromium.org/developers/design-documents/sandbox/osx-sandboxing-design\n\n- http://techjournal.318.com/security/a-brief-introduction-to-mac-os-x-sandbox-technology/\n\n- Iron Suite - https://www.romab.com/ironsuite/\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fhellais%2Fbuckle-up","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fhellais%2Fbuckle-up","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fhellais%2Fbuckle-up/lists"}