✨ feat: add overlayfs sandbox mode#18
Conversation
There was a problem hiding this comment.
Stale comment
Risk: high. Cursor Bugbot is not present on this PR. Overlayfs sandbox execution is security-sensitive and exceeds the low-risk approval threshold; human review is required. No additional reviewers assigned (sole collaborator is the PR author).
Sent by Cursor Approval Agent: Pull Request Approver
There was a problem hiding this comment.
Stale comment
Risk: high. Overlayfs sandbox execution is security-sensitive and exceeds the low-risk approval threshold, so human review is required before approval. Cursor Bugbot is not present on this PR; no additional reviewers were assigned because the sole collaborator is the PR author.
Sent by Cursor Approval Agent: Pull Request Approver
There was a problem hiding this comment.
Stale comment
Risk: high. Overlayfs sandbox execution is security-sensitive and exceeds the low-risk approval threshold, so human review is required before approval. Cursor Bugbot is not present on this PR; no additional reviewers were assigned because the sole collaborator is the PR author.
Sent by Cursor Approval Agent: Pull Request Approver
There was a problem hiding this comment.
Stale comment
Risk: high. Overlayfs sandbox execution is security-sensitive and exceeds the low-risk approval threshold, so human review is required before approval. Cursor Bugbot is not present on this PR; no additional reviewers were assigned because the sole collaborator is the PR author.
Sent by Cursor Approval Agent: Pull Request Approver
There was a problem hiding this comment.
Stale comment
Risk: high. Overlayfs sandbox execution is security-sensitive and exceeds the low-risk approval threshold, so human review is required before approval. Cursor Bugbot is not present on this PR; no additional reviewers were assigned because the sole collaborator is the PR author.
Sent by Cursor Approval Agent: Pull Request Approver
There was a problem hiding this comment.
Stale comment
Risk: high. Overlayfs sandbox execution is security-sensitive and exceeds the low-risk approval threshold, so human review is required before approval. Cursor Bugbot is not present on this PR; no additional reviewers were assigned because the sole collaborator is the PR author.
Sent by Cursor Approval Agent: Pull Request Approver
There was a problem hiding this comment.
Stale comment
Risk: high. Overlayfs sandbox execution is security-sensitive and exceeds the low-risk approval threshold, so human review is required before approval. Cursor Bugbot is not present on this PR; no additional reviewers were assigned because the sole collaborator is the PR author.
Sent by Cursor Approval Agent: Pull Request Approver
There was a problem hiding this comment.
Stale comment
Risk: high. Overlayfs sandbox execution is security-sensitive and exceeds the low-risk approval threshold, so human review is required before approval. Cursor Bugbot is not present on this PR; no additional reviewers were assigned because the sole collaborator is the PR author.
Sent by Cursor Approval Agent: Pull Request Approver
There was a problem hiding this comment.
Risk: high. Overlayfs sandbox execution is security-sensitive and exceeds the low-risk approval threshold, so human review is required before approval. Cursor Bugbot is not present on this PR; no additional reviewers were assigned because the sole collaborator is the PR author.
Sent by Cursor Approval Agent: Pull Request Approver


Summary:
:run(sandbox=overlay)execution using overlayfs.sandbox.upper=tmpfsso overlay upper/work dirs live on tmpfs.Validation:
cargo fmt --checkcargo clippy --all-targets --all-features -- -D warningscargo test -p cue-daemon