PQS: Post Quantum Shell Protocol 1.1.0.0a (A2)
A quantum secure secure shell protocol
pqssandbox.h
Go to the documentation of this file.
1/* 2025-2026 Quantum Resistant Cryptographic Solutions Corporation
2 * All Rights Reserved.
3 *
4 * NOTICE:
5 * This software and all accompanying materials are the exclusive property of
6 * Quantum Resistant Cryptographic Solutions Corporation (QRCS). The intellectual
7 * and technical concepts contained herein are proprietary to QRCS and are
8 * protected under applicable Canadian, U.S., and international copyright,
9 * patent, and trade secret laws.
10 *
11 * CRYPTOGRAPHIC ALGORITHMS AND IMPLEMENTATIONS:
12 * - This software includes implementations of cryptographic primitives and
13 * algorithms that are standardized or in the public domain, such as AES
14 * and SHA-3, which are not proprietary to QRCS.
15 * - This software also includes cryptographic primitives, constructions, and
16 * algorithms designed by QRCS, including but not limited to RCS, SCB, CSX, QMAC, and
17 * related components, which are proprietary to QRCS.
18 * - All source code, implementations, protocol compositions, optimizations,
19 * parameter selections, and engineering work contained in this software are
20 * original works of QRCS and are protected under this license.
21 *
22 * LICENSE AND USE RESTRICTIONS:
23 * - This software is licensed under the Quantum Resistant Cryptographic Solutions
24 * Public Research and Evaluation License (QRCS-PREL), 2025-2026.
25 * - Permission is granted solely for non-commercial evaluation, academic research,
26 * cryptographic analysis, interoperability testing, and feasibility assessment.
27 * - Commercial use, production deployment, commercial redistribution, or
28 * integration into products or services is strictly prohibited without a
29 * separate written license agreement executed with QRCS.
30 * - Licensing and authorized distribution are solely at the discretion of QRCS.
31 *
32 * EXPERIMENTAL CRYPTOGRAPHY NOTICE:
33 * Portions of this software may include experimental, novel, or evolving
34 * cryptographic designs. Use of this software is entirely at the user's risk.
35 *
36 * DISCLAIMER:
37 * THIS SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
38 * IMPLIED, INCLUDING BUT NOT LIMITED TO WARRANTIES OF MERCHANTABILITY, FITNESS
39 * FOR A PARTICULAR PURPOSE, SECURITY, OR NON-INFRINGEMENT. QRCS DISCLAIMS ALL
40 * LIABILITY FOR ANY DIRECT, INDIRECT, INCIDENTAL, OR CONSEQUENTIAL DAMAGES
41 * ARISING FROM THE USE OR MISUSE OF THIS SOFTWARE.
42 *
43 * FULL LICENSE:
44 * This software is subject to the Quantum Resistant Cryptographic Solutions
45 * Public Research and Evaluation License (QRCS-PREL), 2025-2026. The complete license terms
46 * are provided in the accompanying LICENSE file or at https://www.qrcscorp.ca.
47 *
48 * Written by: John G. Underhill
49 * Contact: contact@qrcscorp.ca
50 */
51
52#ifndef PQS_SANDBOX_H
53#define PQS_SANDBOX_H
54
55#include "pqscommon.h"
56
61
65#define PQS_SANDBOX_DEFAULT_TIMEOUT_SECONDS 120U
66
70#define PQS_SANDBOX_MIN_TIMEOUT_SECONDS 5U
71
75#define PQS_SANDBOX_MAX_TIMEOUT_SECONDS 3600U
76
80#define PQS_SANDBOX_DEFAULT_OUTPUT_BYTES 1048576U
81
85#define PQS_SANDBOX_MIN_OUTPUT_BYTES 4096U
86
90#define PQS_SANDBOX_MAX_OUTPUT_BYTES 16777216U
91
95PQS_EXPORT_API typedef struct pqs_sandbox_profile
96{
97 char working_directory[QSC_SYSTEM_MAX_PATH];
98 char run_as_user[PQS_USERNAME_MAX];
99 char run_as_group[PQS_USERNAME_MAX];
100 uint32_t command_timeout_seconds;
101 uint32_t max_output_bytes;
102 bool enabled;
103 bool clear_environment;
104 bool chroot_enabled;
105 bool allow_same_user;
107
113PQS_EXPORT_API void pqs_sandbox_profile_defaults(pqs_sandbox_profile* profile);
114
124PQS_EXPORT_API void pqs_sandbox_profile_configure(pqs_sandbox_profile* profile, bool enabled, bool clear_environment, uint32_t timeout_seconds, const char* working_directory);
125
138PQS_EXPORT_API void pqs_sandbox_profile_configure_security(pqs_sandbox_profile* profile, bool enabled, bool clear_environment, uint32_t timeout_seconds, const char* working_directory, const char* run_as_user, const char* run_as_group, bool chroot_enabled);
139
140
149
161PQS_EXPORT_API void pqs_sandbox_profile_set_allow_same_user(pqs_sandbox_profile* profile, bool allow_same_user);
162
169PQS_EXPORT_API void pqs_sandbox_profile_set_output_limit(pqs_sandbox_profile* profile, uint32_t max_output_bytes);
170
178PQS_EXPORT_API bool pqs_sandbox_working_directory_valid(const pqs_sandbox_profile* profile);
179
187PQS_EXPORT_API uint32_t pqs_sandbox_timeout_milliseconds(const pqs_sandbox_profile* profile);
188
196PQS_EXPORT_API uint32_t pqs_sandbox_output_limit_bytes(const pqs_sandbox_profile* profile);
197
198#endif
PQS_EXPORT_API void pqs_sandbox_profile_configure(pqs_sandbox_profile *profile, bool enabled, bool clear_environment, uint32_t timeout_seconds, const char *working_directory)
Configure a sandbox profile.
Definition pqssandbox.c:110
PQS_EXPORT_API bool pqs_sandbox_working_directory_valid(const pqs_sandbox_profile *profile)
Test whether a sandbox profile has a usable working directory.
Definition pqssandbox.c:193
PQS_EXPORT_API bool pqs_sandbox_profile_canonicalize_working_directory(pqs_sandbox_profile *profile)
Canonicalize the configured sandbox working directory in place.
Definition pqssandbox.c:149
PQS_EXPORT_API void pqs_sandbox_profile_defaults(pqs_sandbox_profile *profile)
Initialize a sandbox profile with safe defaults.
Definition pqssandbox.c:94
PQS_EXPORT_API uint32_t pqs_sandbox_output_limit_bytes(const pqs_sandbox_profile *profile)
Get the configured command-output byte limit.
Definition pqssandbox.c:227
PQS_EXPORT_API void pqs_sandbox_profile_set_allow_same_user(pqs_sandbox_profile *profile, bool allow_same_user)
Set the same-user execution override for a sandbox profile.
Definition pqssandbox.c:172
PQS_EXPORT_API void pqs_sandbox_profile_set_output_limit(pqs_sandbox_profile *profile, uint32_t max_output_bytes)
Set the maximum command-output byte count for a sandbox profile.
Definition pqssandbox.c:183
PQS_EXPORT_API uint32_t pqs_sandbox_timeout_milliseconds(const pqs_sandbox_profile *profile)
Get the command timeout in milliseconds.
Definition pqssandbox.c:211
PQS_EXPORT_API void pqs_sandbox_profile_configure_security(pqs_sandbox_profile *profile, bool enabled, bool clear_environment, uint32_t timeout_seconds, const char *working_directory, const char *run_as_user, const char *run_as_group, bool chroot_enabled)
Configure a sandbox profile with platform privilege-separation fields.
Definition pqssandbox.c:117
The PQS command execution sandbox profile.
Definition pqssandbox.h:96