Skip to content

[P2.69] Agent subprocesses can still read same-uid secrets outside CodeFRAME's own processes: ancestor shell environ, codex workspace-write reads #1322

Description

@frankbria

Spun off from PR #1321 (issue #1286) during post-merge disposition.

Context

#1321 makes cf, the batch worker and the server non-dumpable, so an agent command can no longer read their /proc/<pid>/environ. The agent still runs as the operator's uid, so three same-uid paths remain open:

Why it was not done in that PR

Each of these needs OS-level isolation, which a prctl flag or a regex cannot provide. It is the same prerequisite as hosted mode (#1266 / #1303).

Definition of done

  • Agent-steerable subprocesses (ReAct run_command, hooks, delegated CLIs) run under OS isolation that hides the operator's other processes' /proc and credential paths: a separate uid, a PID + mount namespace (bubblewrap/landlock), or a container.
  • A test in the style of tests/core/test_proc_environ_1286.py proves a grandparent-shell sentinel and ~/.codeframe/credentials are both unreadable.

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    FutureDeferred - beyond v1/v2 scope, consider for future versionsP2-medium-betaMedium priority - nice to have for betapriority:mediumsecurity

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions