nolabs-ai/nono
72.4
Strong · 30 September 2026
202.6k
lines of production code
Rust
primary language
2
measurements over time
What this system is
Nono is a Rust-based security framework that provides OS-enforced process sandboxing using Landlock on Linux and Seatbelt on macOS. It offers a capability-based API to restrict filesystem, network, and command execution for applications and their child processes, accessible via a CLI and C FFI bindings. The system includes a network proxy for traffic interception and credential management, along with features for audit logging, file attestation, and content-addressable rollback.
Features
AWS SigV4 authentication support for the MiTM proxy
The proxy now supports authenticating outbound requests to AWS services using SigV4. This feature parses \amazonaws.com\ hostnames to automatically resolve the signing region and service name (with explicit configuration fallback), manages credential providers with profile-based caching to avoid redundant STS/SSO refreshes, and re-signs requests by stripping only the specific AWS auth headers while preserving other \x-amz-\*\ metadata. It also handles service-specific signing nuances, such as double URL encoding for most services versus single encoding for S3.
crates/nono-proxy/src/aws · high confidence
Add automated AUR publishing and COPR source RPM packaging
Users on Arch Linux can now install the pre-built \nono-ai-bin\ package from the Arch User Repository, which is automatically published to the AUR on each upstream release via a new CI workflow. Additionally, Fedora users and maintainers can build source RPMs for COPR using the new \nono-cli.spec.in\ template and helper scripts, enabling reproducible builds from source with offline Cargo dependency vendoring.
packaging · high confidence
Added Linux development container and update-check test server
Developers can now use a dedicated Dockerfile for a consistent Linux development environment and a new Python script to locally simulate the update-check service, enabling easier testing of version discovery and update availability logic without relying on the live server.
tools · high confidence
Declarative OAuth2 credential capture and built-in profile consolidation
Users can now define declarative OAuth2 credential providers in their profiles to capture tokens from specific endpoints and inject them into API requests via configurable headers and formats, with validation ensuring required fields are present. Additionally, built-in profiles like claude-code and opencode are no longer embedded in the binary; they are now resolved from the policy configuration or registry packs, simplifying the built-in profile surface and centralizing profile definitions.
crates/nono-cli/src/profile · high confidence
Expanded Linux sandbox API with ABI-aware Landlock and seccomp fallbacks
The sandbox module now exposes granular control over Linux sandboxing, allowing users to detect the kernel's Landlock ABI version and choose between pure Landlock enforcement or a Landlock-with-seccomp fallback for network restrictions. New methods like \apply\_auto\, \apply\_landlock\, and \apply\_seccomp\ replace the previous single \apply\ entry point, enabling more precise configuration of network and filesystem policies. The module also re-exports low-level primitives for supervisor use, such as \PreparedLandlockSandbox\ for child-safe sandboxing and various seccomp notification helpers, while maintaining macOS Seatbelt extension support.
crates/nono/src/sandbox · high confidence
HTTP/2 support for TLS-intercepted CONNECT routes
The proxy now supports intercepting and forwarding HTTP/2 traffic over CONNECT tunnels. When a client negotiates the \h2\ ALPN protocol, the proxy probes the upstream to confirm HTTP/2 support, then establishes a dedicated HTTP/2 connection to forward requests with per-stream credential injection. This enables full visibility and credential management for gRPC and other HTTP/2 workloads that previously could not be intercepted.
_crates/nono-proxy/src/tls\intercept · high confidence
Initial C FFI bindings for capability-based sandboxing
This change introduces the C Foreign Function Interface (FFI) bindings, allowing C and C++ applications to interact with the nono sandboxing engine. The diff adds the build script and configuration for generating headers via cbindgen, resulting in the new \bindings/c/include/nono.h\ header. This header exposes core sandboxing concepts as C-compatible types, including access modes (read, write, read-write), network modes (blocked, allow-all, proxy-only), and a comprehensive set of error and diagnostic codes. It also defines capability source tags and query result structures, enabling callers to configure sandbox capabilities, execute commands, and inspect permission decisions or errors.
bindings · high confidence
Initial repository scaffolding and contributor guidance
The repository is initialized with essential project infrastructure, including a \.dockerignore\ to exclude build artifacts and IDE files from container contexts, and a \.gitattributes\ file to enforce consistent LF line endings for source and documentation files while preserving CRLF for Windows batch scripts. Additionally, comprehensive contributor documentation is added: \AGENTS.md\ defines security-critical coding standards and architecture boundaries for AI agents, \CONTRIBUTING.md\ outlines the development workflow and commit conventions, \GOVERNANCE.md\ establishes the maintainer council and decision-making processes, and \NOGENT.md\ provides a code review guide focused on security posture. The project also includes standard open-source governance files such as \CODE\_OF\_CONDUCT.md\, \CONTRIBUTORS.md\, \MAINTAINERS.md\, and the Apache 2.0 \LICENSE\.
(repo-wide) · high confidence
Introduce content-addressable undo system with Merkle integrity and exclusion filters
The \crates/nono/src/undo\ module now provides a filesystem snapshot and rollback capability. It captures baseline and incremental snapshots of tracked directories, storing file contents in a content-addressable object store that deduplicates identical files and uses APFS \clonefile()\ for efficient copy-on-write storage. To ensure data integrity, every snapshot computes a Merkle root over file paths and hashes, cryptographically committing to the captured state. The system supports configurable exclusion filters (including \.gitignore\ integration and glob patterns) to omit transient or generated files, and enforces walk budgets to prevent runaway directory traversals during snapshot creation.
crates/nono/src/undo · high confidence
Introduce file attestation and trust policy verification
The trust module now provides a complete pipeline for verifying the provenance and integrity of instruction files. Users can sign files using keyed ECDSA P-256 or keyless Sigstore bundles, and the system will automatically verify these signatures against a configurable trust policy. Policies define trusted publishers, blocklists of malicious digests, and file inclusion patterns, with enforcement modes (Deny, Warn, Audit) to control how violations are handled. The verification process checks file digests against blocklists, validates cryptographic signatures in Sigstore bundles, and matches signer identities against trusted publishers before allowing file consumption.
crates/nono/src/trust · high confidence
Introduce platform-specific tool-sandbox implementations for Linux and macOS
Added new platform-specific source files (linux.rs and macos.rs) under crates/nono-cli/src/tool-sandbox/platform to implement the core tool-sandbox runtime logic. These files provide the concrete execution environment for sandboxed commands, handling process launching, credential resolution, environment variable injection, and IPC protocol communication via Unix sockets. The Linux implementation includes specific handling for Landlock filesystem restrictions and cgroup-based lineage tracking, while the macOS implementation utilizes FFI calls to process information APIs for similar ancestry and identity tracking. This change establishes the foundational platform adapters required for the tool-sandbox feature to operate correctly on supported operating systems.
crates/nono-cli/src/tool-sandbox/platform · high confidence
Introduce structured network audit logging and approval backend routing
The proxy now records structured network audit events for every request, capturing details such as the proxy mode (CONNECT, reverse, or external), authentication mechanism, injection mode, and endpoint policy actions. This audit trail is stored in an in-memory buffer and can be exposed via diagnostics. Additionally, the proxy supports configurable approval backends, allowing endpoint-policy approvals to be routed to named handlers (with a default fallback) rather than using a single hardcoded implementation.
crates/nono-proxy/src · high confidence
Introduce supervised-mode approval backends and durable audit delivery
Users can now configure non-interactive approval backends (webhooks, chains, and platform integrations) for supervised-mode prompts, allowing automated or remote decision-making instead of relying solely on terminal interaction. Additionally, the CLI now features a durable audit delivery system that queues session audit logs to a local outbox and syncs them to a platform endpoint, ensuring audit integrity and availability even if the session ends abruptly or network connectivity is intermittent.
crates/nono-cli/src · high confidence
Introduce supervisor IPC for runtime capability expansion
Added a new supervisor module that enables sandboxed child processes to request additional capabilities (filesystem access, network access, and command execution) from an unsandboxed parent process at runtime. This change introduces a Unix domain socket-based IPC protocol with length-prefixed JSON framing and file descriptor passing via SCM\_RIGHTS, along with peer authentication (UID checks) and configurable approval backends (interactive, webhook, or policy-based) to grant or deny these requests securely.
crates/nono/src/supervisor · high confidence
Introduces core library modules for audit logging, capability manifests, and security hardening
This change adds several foundational modules to the \nono\ library crate. It introduces \audit.rs\ to record append-only, cryptographically chained NDJSON events for sessions, capabilities, and network activity. It adds \manifest.rs\ and \manifest\_convert.rs\ to define and validate capability manifests via JSON Schema and convert them into internal enforcement sets. Security is strengthened with \broker\_path.rs\, which sanitizes the PATH environment for host-side credential brokers to prevent trojan injection, and \net\_filter.rs\, which provides hostname filtering with cloud metadata protection. Additionally, \env\_glob.rs\ provides a shared glob-matching engine for environment variable patterns, \path.rs\ adds robust symlink-aware path canonicalization, and \resource/mod.rs\ defines resource limits for memory and process counts.
crates/nono/src · high confidence
Introduces the tool-sandbox command mediation runtime
Adds the core implementation for the tool-sandbox feature in \crates/nono-cli/src/tool-sandbox\, providing the runtime infrastructure for command mediation on Linux and macOS. This includes the audit context and decision vocabulary for logging, credential resolution (local sockets, raw files, proxies, and ambient credentials), and dynamic path token expansion (e.g., \@git:\*\ tokens for git config paths). The module also handles environment variable management (including \export\_env\ pass-through and proxy override), launch specification preparation, and the IPC protocol between the shim and the supervisor. It establishes the foundation for isolating and mediating specific tool commands within the sandbox.
crates/nono-cli/src/tool-sandbox · high confidence
Introduction of nono capability-based sandboxing library
The nono crate has been added to provide OS-enforced process-level sandboxing using Landlock on Linux (kernel 5.13+) and Seatbelt on macOS. It allows applications to restrict filesystem access, network access, and process execution for themselves and child processes through a CapabilitySet API. The library includes a build script that generates Rust types from a JSON Schema for capability manifests, ensuring type safety for sandbox policies.
crates/nono · high confidence
New C FFI bindings for sandbox capabilities and diagnostics
The \bindings/c\ module now provides a stable C ABI for the nono sandboxing library, enabling integration with languages like Go, Swift, and Java. Users can create and manage capability sets (allowing specific file paths or blocking network access), query permission decisions before execution, and inspect platform support details. The bindings also expose structured session diagnostics, allowing callers to retrieve JSON reports on sandbox denials and remediation advice, while ensuring memory safety by returning caller-owned strings and handling NULL pointers gracefully.
bindings/c · high confidence
New Dockerfiles for headless, musl, and cross-compilation builds
The docker directory now includes dedicated Dockerfiles for building the application in environments without a system keyring or D-Bus. The new Dockerfile-headless and Dockerfile-musl (along with Dockerfile-musl-cross for x86\_64 cross-compilation) build the CLI with the 'no-default-features' flag, removing the libdbus dependency and allowing credentials to be supplied via environment, file, or operator references instead. These images also enforce running as a non-root 'nono' user and set a /work directory, providing secure, portable options for CI runners, serverless functions, and static Linux environments.
docker · high confidence
New build, release, and diagnostic scripts for RPM packaging and integration testing
Added build scripts to generate RPM and source RPM (SRPM) packages for Linux distributions, including support for Fedora COPR via vendored Cargo dependencies. Introduced a release preparation script that validates version consistency across the workspace, calculates SemVer bumps based on conventional commits, and generates changelogs. Added diagnostic and cleanup utilities for macOS browser-opening behavior, Claude authentication state management, and integration test isolation, alongside a mock SPIFFE/SPIRE server for testing upstream workload identity authentication.
scripts · high confidence
New diagnostic footer rendering for sandboxed command failures
The CLI now displays a dedicated diagnostic footer when sandboxed commands fail, helping users identify whether the failure was due to sandbox restrictions. This new module parses command stderr output to detect path access issues, network denials, and protected file writes, then provides actionable guidance such as specific \--allow\ flags or \nono run\ suggestions. The output is structured to distinguish diagnostic information from command output and includes policy explanations for denied paths.
crates/nono-cli/src/diagnostic · high confidence
New tool sandbox examples for credential brokering and command policies
Added a new \tool-sandbox-examples\ directory containing practical demonstrations of nono's security features. These include an AWS CLI demo showing host-side SigV4 credential brokering with read-only S3 access, a GitHub CLI demo for token proxying and endpoint policy, a git-SSH demo using ssh-agent socket brokering with read-only git operations, an npm demo for env-var credential brokering, and a Docker-based prototype for nested command policies. The set also includes a local approval webhook demo for Kubernetes operations and a comprehensive README with setup instructions and safety notes for all examples.
tool-sandbox-examples · high confidence
Structured sandbox diagnostics for library and FFI clients
The \crates/nono/src/diagnostic\ module now exposes a stable, serializable diagnostic system for library and FFI consumers. This includes defined codes (e.g., \SandboxDeniedPath\, \CommandFailedLikelySandbox\), severity levels, and structured remediation actions (such as \GrantPath\ or \GrantNetwork\). The module provides \SessionDiagnosticReport\ for aggregating session denials and violations into JSON, and \SessionObservationInput\ to convert stderr heuristics into structured warnings. This change enables external clients to programmatically interpret sandbox denials and present actionable remediation steps.
crates/nono/src/diagnostic · high confidence
Removals
Removal of Claude Code sandbox diagnostic hook
The \nono-hook.sh\ script, which was automatically installed for the \claude-code\ profile to inject sandbox capability information upon tool failures, has been removed. Users relying on this specific integration will no longer receive the automated diagnostic context and permission-denied instructions previously provided by this hook.
crates/nono-cli/data/hooks · high confidence
Behavioural changes
Build script updates to embed network policy, profile schema, and authoring guide
The build process for nono-cli now embeds the network policy JSON, the profile JSON schema, and the profile authoring guide into the binary, replacing the previous logic that embedded security lists, built-in profiles, and hook scripts. Additionally, the build script now respects the NONO\_INSTALL\_SOURCE environment variable, enabling the CLI to emit install source information during update checks.
crates/nono-cli · high confidence
New Linux execution strategies: CLONE\_FILES bootstrap and environment sanitization
The CLI now introduces a new \CLONE\_FILES\ execution strategy for Linux that shares only the file descriptor table with the child process before detaching, improving isolation and performance for supervised sessions. Additionally, a dedicated environment sanitization module is added to block dangerous environment variables (such as \LD\_PRELOAD\, \PYTHONPATH\, and \NODE\_OPTIONS\) from being inherited into sandboxed children, preventing injection attacks from untrusted parent shells. These changes are part of a broader effort to harden the sandbox supervisor and execution boundaries on Linux.
_crates/nono-cli/src/exec\strategy · high confidence
Test coverage
Added SPIRE test configuration files; Added integration tests for SPIFFE/SPIRE workload identity authentication; Added tests for capability manifest schema validation and type conversion; Expanded integration test coverage for CLI, sandbox, and audit features; Expanded integration test coverage for sandbox security and execution features; New shared integration test harness for nono-cli.
Dependencies
Introduce network proxy, C FFI bindings, and upgrade to Rust 2024
This release adds a new \nono-proxy\ crate that provides a network filtering proxy with HTTP/2 support, TLS interception, credential injection, and AWS SigV4 signing. It also introduces \nono-ffi\, a new C FFI bindings crate for the sandboxing library, and a shared \nono-test-support\ crate for integration tests. Under the hood, the project has migrated to the Rust 2024 edition (requiring Rust 1.95+), centralized workspace dependencies, and updated numerous core libraries including \tokio\, \hyper\, \serde\, and \clap\.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 67 → 72 (+5.6)
- Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.
Lenses
- Code Health 80 → 79 (-0.3)
- Architecture 88 → 94 (+6.4)
- Maturity 52 → 66 (+13.5)
- Readiness 90 → 76 (-14.7)
- Security 75 → 78 (+3.2)
- Performance 86 (new)
Resolved (69)
- Documentation: contradicts the code
- Documentation: contradicts the code (docs/plans/2026-04-24-issue-594-phase-2-schema-plan.md)
- Documentation: no installation or build instructions (README.md)
- Duplicated block (10 lines × 2) (crates/nono-cli/src/command_runtime.rs)
- Duplicated block (10 lines × 2) (crates/nono-cli/src/tool-sandbox/platform/linux.rs)
- Duplicated block (10 lines × 2) (crates/nono-cli/src/tool-sandbox/platform/linux.rs)
- Duplicated block (11–13 lines × 2) (crates/nono-cli/src/tool-sandbox/platform/linux.rs)
- Duplicated block (12 lines × 2) (crates/nono-cli/src/tool-sandbox/platform/linux.rs)
- Duplicated block (12 lines × 2) (crates/nono-cli/src/tool-sandbox/platform/linux.rs)
- Duplicated block (13 lines × 2) (crates/nono-cli/src/exec_strategy.rs)
- Duplicated block (13 lines × 2) (crates/nono-cli/src/execution_runtime.rs)
- Duplicated block (13 lines × 2) (crates/nono-cli/src/tool-sandbox/platform/linux.rs)
- Duplicated block (15 lines × 2) (crates/nono-cli/src/tool-sandbox/platform/linux.rs)
- Duplicated block (15 lines × 2) (crates/nono-cli/src/tool-sandbox/platform/linux.rs)
- Duplicated block (16 lines × 2) (crates/nono-cli/src/tool-sandbox/platform/linux.rs)
- Duplicated block (18 lines × 2) (crates/nono-cli/src/tool-sandbox/platform/linux.rs)
- Duplicated block (18 lines × 2) (crates/nono-cli/src/tool-sandbox/platform/linux.rs)
- Duplicated block (19 lines × 2) (crates/nono-cli/src/tool-sandbox/platform/linux.rs)
- Duplicated block (20 lines × 2) (crates/nono-cli/src/tool-sandbox/platform/linux.rs)
- Duplicated block (21–24 lines × 2) (crates/nono-cli/src/tool-sandbox/platform/linux.rs)
- …and 49 more
New (79)
- Change coupling: app_runtime.rs ↔ cli_bootstrap.rs (crates/nono-cli/src/app_runtime.rs)
- Change coupling: main.rs ↔ snapshot.rs (crates/nono-cli/src/main.rs)
- DiagnosticFormatter::format_network_denial_guidance (cognitive 18) (crates/nono-cli/src/diagnostic/formatter.rs)
- Documentation: no project overview (README.md)
- Duplicated block (10 lines × 2) (crates/nono-cli/src/tool-sandbox/platform/linux.rs)
- Duplicated block (10 lines × 2) (crates/nono-cli/src/tool-sandbox/platform/linux.rs)
- Duplicated block (10 lines × 2) (crates/nono-cli/src/tool-sandbox/platform/linux.rs)
- Duplicated block (10 lines × 2) (tool-sandbox-examples/kubernetes-with-approval/make-proxy-kubeconfig.py)
- Duplicated block (11–13 lines × 2) (crates/nono-cli/src/tool-sandbox/platform/linux.rs)
- Duplicated block (12 lines × 2) (crates/nono-cli/src/tool-sandbox/platform/linux.rs)
- Duplicated block (13 lines × 2) (crates/nono-cli/src/command_runtime.rs)
- Duplicated block (14 lines × 2) (crates/nono-cli/src/tool-sandbox/platform/linux.rs)
- Duplicated block (15 lines × 2) (crates/nono-cli/src/tool-sandbox/platform/linux.rs)
- Duplicated block (16 lines × 2) (crates/nono-cli/src/tool-sandbox/platform/linux.rs)
- Duplicated block (16 lines × 2) (crates/nono-cli/src/tool-sandbox/platform/linux.rs)
- Duplicated block (18 lines × 2) (crates/nono-cli/src/tool-sandbox/platform/linux.rs)
- Duplicated block (19 lines × 2) (crates/nono-cli/src/tool-sandbox/platform/linux.rs)
- Duplicated block (19 lines × 2) (crates/nono-cli/src/tool-sandbox/platform/linux.rs)
- Duplicated block (20 lines × 2) (crates/nono-cli/src/tool-sandbox/platform/linux.rs)
- Duplicated block (21–24 lines × 2) (crates/nono-cli/src/tool-sandbox/platform/linux.rs)
- …and 59 more
Changes since last survey
- 63 commits — 45 feature/other, 18 fixes
By area
- crates/nono-cli — 25 commits
- (root) — 22 commits
- .github/workflows — 6 commits
- crates/nono-proxy — 3 commits
- docs/cli — 2 commits
- neps/0003-keychain-authorisation-to-cli.md — 1 commit
- neps/0004-opt-in-linux-namespace-isolation.md — 1 commit
- packaging/aur — 1 commit
- tests/integration — 1 commit
- tool-sandbox-examples/docker-tool-sandbox — 1 commit
Notable commits
- fix: fix(aur): update upstream URLs to nolabs-ai (#1979)
- fix: fix(cli): accept keyring:// URIs in custom credential_key (#1931)
- fix: fix(cli): audit approval backend decisions prior to file operations (#2010)
- fix: fix(cli): keep protected-root attempts out of actionable denial guidance (#1941)
- fix: fix(cli): show resolved session hooks in profile output (#1935)
- fix: fix(exec): keep session temp files alive against the OS reaper (#1942)
- fix: fix(keystore): refuse empty sanitized PATH for host-side brokers (#1895)
- fix: fix(linux): preserve O_PATH in musl builds (#2005)
- fix: fix(macos): recursively block sockets under denied directories (#2026)
- fix: fix(policy): allow Linux font configuration reads (#1991)
- fix: fix(policy): allow reading Linux MIME types (#2013)
- fix: fix(policy): let man/apropos/whatis work on Linux (#1953)
- fix: fix(proxy): decode chunked client-credentials token responses (#1976)
- fix: fix(proxy): preserve query string on jwt-bearer token_url (#1913)
- fix: fix(tool-sandbox): derive shim broker socket from executable path (#2002)
- fix: fix(tool-sandbox): fall back to the interpreter's directory for RPATH-less ELF dependencies (#1650)
- fix: fix(tool-sandbox): isolate network policy by effective command scope (#1981)
- fix: fix: file grants negate filesystem.deny - #1949 (#2019)
- change: Merge commit from fork
- change: Merge commit from fork
- …and 43 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
nolabs-ai/nono was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 30 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 0d3b347ddbd330ec34b3cf355330ff829483032a — the exact code this score is about.
- Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-cb25ca4feafa.