-
Notifications
You must be signed in to change notification settings - Fork 3
plat 385
| Coordination | Value |
|---|---|
| State | fixed on main (multi-llm-provider-go 2c535cf, builder stopgap removed); not deployed |
| Date | 2026-10-03 |
| Owner | security-sandbox |
| Related |
8b6e85d61 (Full CLI everywhere on Linux), PLAT-374 (launcher hidden_paths / read_only_overlays), found by ai-work-0b's review |
Landlock grants whole folders and cannot carve blocked paths out of them.
Full CLI's native Bash/Write/Edit never pass the folder guard, so a workflow
chat on Linux could write planning/plan.json or db/db.sqlite directly where
the bridge would refuse. A Mac is not affected: Seatbelt denies blocked paths
inside granted folders.
A Linux chat with a blocked path inside one of its writable folders stays in
hybrid (native reads; shell and writes through the bridge, which enforces the
blocked paths). Chats without such a path (Code) keep Full CLI.
blockedInsideWriteGrant, TestBlockedInsideWriteGrant.
multi-llm-provider-go 2c535cf (clisandbox/landlock_blocked.go): when a
grant contains a blocked path, the grant is split. The containing folder is no
longer granted as a whole; each entry is granted on its own down the path to
the blocked one, which is left out. A read-blocked path is cut out of read
grants too. No mounts or namespaces (the launcher's hidden_paths /
read_only_overlays need user namespaces the agent server is not allowed to
create, and Cursor needs the shared /tmp), so every launch path is covered.
The PLAT-385 stopgap (hybrid for such chats) is removed.
The CLI's own working folder is never split (provider 71ca588): its blocked
entries are the CLI's managed instruction files (CLAUDE.md, AGENTS.md,
.mcp.json, ...), which stay bridge-guarded; splitting it would have stopped a
Code CLI creating files in its project (found by ai-work-0b).
Accepted limits (owner-facing): no new file or folder can be created directly in a split folder during that launch, for example the real workflow root next to planning/ or AGENTS.md (workflow chats run in their own folder and write outputs under runs/, code/ and so on, which stay writable); entries created after the launch are not writable natively until the next launch.
- Done:
TestSplitAroundBlocked;TestBlockedPathsUnderTheRealLauncherrun on Excellence against the installed launcher (planning/ readable not writable, db.sqlite neither, a new db.sqlite-wal refused, the rest of the workflow writable); the whole clisandbox package passes there. - Left: deploy; a live chat check on RTS after deploy.
Auto-synced from docs/ on main. Edit there, not here.