fix: fail closed for service sandbox isolation - #51
zhanghanduo merged 2 commits into
Conversation
|
I found a credential path that the new fail-closed tool-user setting does not cover. The I recommend keeping the credential file outside all model-visible mounts and mounting only the project/workspace content needed for the task. Then add a runtime check that a tool-user command cannot read the credential file. I am working on a fix for this PR and will update this thread with the validation result. |
|
Fix pushed as 68b9200. The Compose agent now masks the on-disk Validation: |
|
@zhanghanduo Please approve this PR if it looks good. |
Service deployments can currently degrade to model-authored commands sharing the harness UID when the
agent-toolaccount is missing, leaving/proc/<harness-pid>/environreadable. Multi-task eval containers also inherit the local sandbox profile, which binds the outer/procrather than requiring a private PID namespace and fresh procfs.This change makes the supported Compose service fail before model commands when the tool account is unavailable and selects the service profile for the eval runner. A runtime that cannot mount the private procfs will now reject the eval instead of weakening process isolation.
Validation:
uv run --frozen --extra dev python -m pytest apodex/tests/test_deployment_config.py -q(17 passed).Governance task: https://infra-homepage.app.apodex.cc/board/vsdadwqr
Baseline and target-runtime probe: https://github.com/ApodexAI/apodex-cloud-iam/pull/323