Spun off from PR #1321 (issue #1286) during post-merge disposition.
Context
#1321 makes cf, the batch worker and the server non-dumpable, so an agent command can no longer read their /proc/<pid>/environ. The agent still runs as the operator's uid, so three same-uid paths remain open:
Why it was not done in that PR
Each of these needs OS-level isolation, which a prctl flag or a regex cannot provide. It is the same prerequisite as hosted mode (#1266 / #1303).
Definition of done
- Agent-steerable subprocesses (ReAct
run_command, hooks, delegated CLIs) run under OS isolation that hides the operator's other processes' /proc and credential paths: a separate uid, a PID + mount namespace (bubblewrap/landlock), or a container.
- A test in the style of
tests/core/test_proc_environ_1286.py proves a grandparent-shell sentinel and ~/.codeframe/credentials are both unreadable.
Spun off from PR #1321 (issue #1286) during post-merge disposition.
Context
#1321 makes
cf, the batch worker and the server non-dumpable, so an agent command can no longer read their/proc/<pid>/environ. The agent still runs as the operator's uid, so three same-uid paths remain open:cfis in that shell's environ, one level above$PPID, and the shell is dumpable. The same applies to any other same-uid process on a self-hosted box, such asnext dev.workspace-write: this sandbox limits writes, not reads. A sandboxed command can read an absolute path to~/.codeframe/credentialswithout an approval request, so no denylist ever sees it (see the [P2.50] Agent subprocesses can read the parent's full environment via /proc/$PPID/environ, defeating the #721/#996 allowlist #1286 comment from [P2.42] Codex adapter lacks the zero-file false-completion guard, and its #916 dangerous-command guard is unreachable #1278 / PR fix(codex): zero-file guard + sandbox-preserving approval routing (#1278) #1318)."/proc"/"$PPID"/environ) and globs (/proc/1/en*) defeat it. The GLM review of fix(security): make cf/worker/server non-dumpable so agents cannot read /proc/$PPID/environ (#1286) #1321 noted this.Why it was not done in that PR
Each of these needs OS-level isolation, which a prctl flag or a regex cannot provide. It is the same prerequisite as hosted mode (#1266 / #1303).
Definition of done
run_command, hooks, delegated CLIs) run under OS isolation that hides the operator's other processes'/procand credential paths: a separate uid, a PID + mount namespace (bubblewrap/landlock), or a container.tests/core/test_proc_environ_1286.pyproves a grandparent-shell sentinel and~/.codeframe/credentialsare both unreadable.