Replies: 1 comment
|
这个问题的安全边界与 SandBase Harness 的 sandbox 设计一致:路径检查应在执行器前置校验阶段给出可读错误,OS/容器隔离仍是最终安全边界。 SandBase 当前有两层验证:
相关测试:
我赞同你提出的 lexical preflight:应在完成 escalation 后、dispatch 前检查 effective policy;只在 confining executor 有 workspaceRoot 且不是 danger-full-access 时生效。错误信息要同时包含输入路径和允许的 root,但不要把这项提示性校验当作真正的隔离边界。 |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Problem
In
packages/shell/tool-bash,resolveWorkdironly makes a relativeworkdirsession-workspace-relative; an absoluteworkdiris passed straight to the executor regardless of the resolvedSandboxExecutionPolicy.workspaceRoot.Under
workspace-write/read-only, an absoluteworkdiroutside that root still reaches the confining executor (bwrap/Landlock/Seatbelt/Windows ACL), which then rejects the confined spawn with an opaque runner-failure or sandbox-denial result. Real containment holds -- nothing escapes -- but the model (and the user watching the transcript) sees a late, confusing failure instead of a clear reason naming the expected workspace root. This is most likely to bite when the model has a stale or mis-guessed absolute path for the session (an oldpwdoutput, a different container mount, a copied example).Fix
Add a synchronous preflight in
dsh-tool-bash, run right after the call's effectiveSandboxExecutionPolicyis resolved (post-escalation) and before dispatch: when a confining executor makesworkspaceRootknown and the effective mode isn'tdanger-full-access, an absoluteworkdirlexically outside that root is rejected immediately with:The check is a cheap synchronous lexical prefix comparison against the already-canonical
workspaceRoot-- no stat, no symlink walk -- mirroring the fast pathdsh-fs-sandbox'sisPathUnderalso takes for ordinary spellings. The executor's own OS-level confinement remains the actual security boundary regardless of this preflight; this only turns a late, opaque denial into an early, legible one.Unaffected, by design:
workdiralready insideworkspaceRoot-- preserves the existing, tested contract that an absoluteworkdiroverrides the session cwd.workdirunderdanger-full-access-- no containment to violate.workdirwhen no confining executor is mounted (e.g.dsh-bash-local) -- no workspace root exists to check against.The
workdirparameter's own description gains one sentence stating the restriction, so the model learns the rule at the decision point rather than only from a rejected call.Where to look
I can't open a PR (per
CONTRIBUTING.mdand the repo's disabled PR setting), so here's the change on my fork instead -- one commit, 5 files (the fix, its tests, and its Agent Note):ysgao@df5080a
Testing done
packages/shell/tool-bash/tests/tools.spec.tscovering: confined+outside (rejected), confined+inside (accepted), escalated todanger-full-access(accepted), and unconfined composition (unaffected pass-through).oxlint) and scopedtsc -bon the package: clean.verify-agent-note-format,verify-translation-pairing,verify-agent-note-classification): passing.Happy to answer questions or adjust the approach if there's a preference for where this check should live instead.
All reactions