Skip to content

fix: fail closed for service sandbox isolation - #51

Merged
zhanghanduo merged 2 commits into
ApodexAI:mainfrom
jack-yang-apodex:codex/service-sandbox-fail-closed
Sep 30, 2026
Merged

zhanghanduo merged 2 commits into
ApodexAI:mainfrom
jack-yang-apodex:codex/service-sandbox-fail-closed

Conversation

@jack-yang-apodex

Copy link
Copy Markdown
Contributor

Service deployments can currently degrade to model-authored commands sharing the harness UID when the agent-tool account is missing, leaving /proc/<harness-pid>/environ readable. Multi-task eval containers also inherit the local sandbox profile, which binds the outer /proc rather than requiring a private PID namespace and fresh procfs.

This change makes the supported Compose service fail before model commands when the tool account is unavailable and selects the service profile for the eval runner. A runtime that cannot mount the private procfs will now reject the eval instead of weakening process isolation.

Validation: uv run --frozen --extra dev python -m pytest apodex/tests/test_deployment_config.py -q (17 passed).

Governance task: https://infra-homepage.app.apodex.cc/board/vsdadwqr
Baseline and target-runtime probe: https://github.com/ApodexAI/apodex-cloud-iam/pull/323

@zhanghanduo

Copy link
Copy Markdown
Collaborator

I found a credential path that the new fail-closed tool-user setting does not cover. The agent service loads .env as an env_file and also bind-mounts the whole repository at /project. docker/run.sh sets APODEX_HOST_UID/GID, and the entrypoint remaps agent-tool to that host identity. A model-authored command running as agent-tool can therefore read /project/.env directly, including when the file is mode 0600 and owned by the invoking host user. The /proc/<harness-pid>/environ protection in this PR does not prevent that file read.

I recommend keeping the credential file outside all model-visible mounts and mounting only the project/workspace content needed for the task. Then add a runtime check that a tool-user command cannot read the credential file. I am working on a fix for this PR and will update this thread with the validation result.

@zhanghanduo

Copy link
Copy Markdown
Collaborator

Fix pushed as 68b9200. The Compose agent now masks the on-disk .env with a read-only /dev/null bind; the SGLang and Transformers overlays mask their own env files. The direct docker run example includes the same .env mask and strict tool-user setting. Custom credential files should remain outside the project mount.

Validation: uv run --frozen --extra dev python -m pytest apodex/tests/test_deployment_config.py -q (17 passed), docker compose config for the base and overlays, and a local Compose run with a fake mode-0600 credential file. The fake credential reached the harness environment while /project/.env was empty for a command running as the host-mapped tool UID.

@jack-yang-apodex

Copy link
Copy Markdown
Contributor Author

@zhanghanduo Please approve this PR if it looks good.

@zhanghanduo zhanghanduo left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@zhanghanduo
zhanghanduo merged commit 300b20b into ApodexAI:main Sep 30, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants