Skip to content

fix(sandbox): classify broker faults and bound shell transport - #159

Open
akemmanuel wants to merge 1 commit into
masterfrom
fix/restricted-sandbox-execution
Open

akemmanuel wants to merge 1 commit into
masterfrom
fix/restricted-sandbox-execution

Conversation

@akemmanuel

Copy link
Copy Markdown
Owner

Summary

Refs #153. Make restricted shell failures diagnosable without weakening path grants or falling back to the native Host shell.

  • Record sanitized, machine-readable broker transport/authentication failures as tool results; present known reasons in the existing tool UI in English, German, and Spanish.
  • Distinguish pre-execution rejection from uncertain effects after dispatch. Network/deadline failures tell users to check the project before retrying, not that the command definitely did not run.
  • Use the correct HTTP/TLS transport, validate endpoints, preserve Unix sockets, support IPv6 literals, enforce a total deadline, bound response size, and handle partial/disconnected responses.
  • Release rejected-response sockets rather than draining an unbounded error body. Preserve cancellation, ordinary command exit codes (including 125), and authorization revalidation.

Verification

Parent review reproduced four additional regressions before fixing them: unbounded 400/401/500 response streams and bracketed IPv6 transport hostnames.

  • Focused client/Host/UI/projection suites: 72 passed.
  • Fresh wider Host/execution/protocol/tool/i18n suites after corrections: 190 passed across 27 files.
  • pnpm run check, pnpm run slop-check, and git diff --check: passed.
  • Tests use loopback fixture brokers and authenticated restricted accounts; verify no native execution and no endpoint/token/customer-path disclosure.

Acceptance boundary

These tests establish the client classification and authorization behavior, not production Docker/gVisor or image readiness. No production commands, deployment, or permission changes were performed. The deployed restricted-shell execution cause still requires a controlled live readiness check; #153 should remain open until that acceptance is verified.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant