Skip to content

fix(guardrails): decide the root-delete chrt, runuser and chroot overblocks #4681

Description

@kyle-sexton

Problem

plugins/guardrails/hooks/block-root-delete-target.sh refuses three commands whose launcher reading differs from what the real tool does:

  • chrt -r rm -rf / exits 2. chrt with -r expects a priority before the command, so the real tool rejects this line; the guard reads rm as the command.
  • runuser -u bob rm -rf / exits 2. Reported by the fix(guardrails): unwrap runuser, taskset and the launcher family in the root-delete guard #4469 lane as rejected by the real tool; confirm on a Linux host before changing.
  • chroot /mnt rm -rf / exits 2. This one is deliberate and fail-closed: inside the chroot, / is host /mnt, so the delete removes the new root.

Evidence

Measured this pass (2026-09-27, main a6ba321): all three exit 2, JSON payload on stdin, nothing executed. That the real tools reject the first two lines is the #4469 lane's reading, not re-verified here.

Proposed approach

  1. chrt and runuser: leave as is. An overblock of a line the tool itself rejects costs one retry and never a lost file; loosening risks the misreads fix(guardrails): unwrap runuser, taskset and the launcher family in the root-delete guard #4469 guarded against. Close with a documented note in the guard header.
  2. chroot: keep refusing (recommended). Deleting a chroot's root is almost never intended from an agent session.

Decisions needed (Kyle)

  1. The chroot case was marked user-reserved by the fix(guardrails): unwrap runuser, taskset and the launcher family in the root-delete guard #4469 lane: keep refusing chroot <dir> rm -rf /, or allow it because the target is <dir>, not the host root?
  2. Accept the chrt and runuser overblocks as documented?

Acceptance criteria

  • The guard header's declared-behavior section records each decision.
  • If any case is loosened, the differential shows it is the only verdict that moved.

Constraints and gotchas

  • Guards only add refusals; any loosening is an explicit exception and needs Kyle's call.

Context

Source: local handoff item 20260925-070000-guardrails-root-delete-launcher-remainder-after-4469.md, item 2 (retired into this issue and draft 20260925-070000-a). Prior: #4468 / PR #4469.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    priority: lowNice-to-have, cosmetic, or speculative; opportunistic.work-class: scopedA briefed fix or small feature; blast radius bounded by the brief, tests exist.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions