Skip to content

Set workers non-dumpable so a sibling cannot read /proc/<pid>/fd #18

Description

@flavorjones

Workers share a uid, so a compromised worker opens /proc/<sibling>/fd/N and reaches the descriptors the application passed — not only the staged files under the slot home. docs/DESIGN.md:140-145 documents the route, and names CAP_SETUID and CAP_SYS_ADMIN as the two fixes cap-drop ALL removes.

PR_SET_DUMPABLE=0 is a third one it does not name. It makes /proc/<pid> root-owned, which closes same-uid access to it, and it needs no capability. One prctl in Supervisor#become_worker.

To settle before doing it:

  • hotcell-server carries no dependencies, so this needs fiddle from stdlib.
  • Check how it sits with verify_ptrace_scope! (supervisor.rb:122), which is the other half of worker memory protection.
  • A non-dumpable process writes no core dump. Decide whether an operator wants one.

Found in an adversarial review by Codex, 2026-08-19.

Activity

  1. flavorjones commented on Sep 28, 2026

    @flavorjones
    MemberAuthor

    Working on this now.

  2. flavorjones commented on Sep 30, 2026

    @flavorjones
    MemberAuthor

    Closing as not planned. #79 tried the fix proposed here and was closed without merging.

    This library exists to reduce blast radius, so that the application cannot be taken down and secrets cannot be exfiltrated. Worker-on-worker attacks are worth addressing eventually, but they are out of scope for v1.0.

    The attack is also not well enough understood to fix properly. Making workers non-dumpable leaves the supervisor open to a similar attack, and a tool a worker execs is dumpable again. A non-dumpable process also behaves differently downstream (/proc ownership, ptrace, core dumps) in ways we haven't fully mapped.

    Anyone can open a new issue once the attack vector is better understood.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions