Skip to content

fix(sandbox): allow identity-preserving setresuid and setresgid calls - #4104

Open
drew wants to merge 1 commit into
mainfrom
codex/fix/4102-make-identity/drew
Open

drew wants to merge 1 commit into
mainfrom
codex/fix/4102-make-identity/drew

Conversation

@drew

@drew drew commented Oct 2, 2026

Copy link
Copy Markdown
Collaborator

Summary

GNU Make fails to launch even a true recipe because the sandbox denies its identity-preserving setresuid and setresgid calls. Allow those calls only when every argument is the established workload ID or -1, so recipes run while identity changes remain denied.

Related Issue

Closes #4102

Changes

  • Capture the calling process's UID/GID before fork and reject filter preparation if real, effective, and saved IDs differ.
  • Replace the unconditional setresuid/setresgid blocks with argument checks. Other credential setters and supplementary-group changes remain blocked.
  • Add a kernel-level regression for all unchanged-ID combinations and denied changes in each credential slot.
  • Add a Docker/Podman E2E fixture with Ubuntu 24.04, GNU Make, and distinct non-root UID/GID values, covering canonical startup, piped exec, and terminal exec.
  • Document the identity-preserving exception in the published security guidance.

Testing

  • Checks appropriate to the affected code and behavior pass
    • cargo test -p openshell-isolation-interface: 54 tests passed.
    • Credential regression also passed as root in a disposable Docker container, where identity changes would otherwise be permitted by the kernel.
    • Clippy with -D warnings passed for the isolation interface, sandbox, and new E2E test; Rust formatting checks passed.
    • The repository's full pre-commit hook passed, including workspace Clippy, SDK checks, Markdown/license checks, and Helm validation.
    • mise run docs passed with zero errors and three warnings.
  • Unit tests added/updated
  • E2E tests added/updated
    • Focused Docker E2E on Linux ARM64: the stock runtime fails with make: true: Operation not permitted / Error 127; the patched runtime passes startup, piped exec, and terminal exec with UID 10001 and GID 10002.
    • Built the static sandbox runtime image with the repository's build:docker:sandbox task. The comparison uses the same gateway, CLI, supervisor image, and workload fixture for both runtime images.

Checklist

  • Follows Conventional Commits
  • Commits are signed off (DCO)
  • Published security documentation updated

The change introduces no configuration, protocol, or architecture changes. The related public skills do not describe these syscall restrictions, so they need no update.

Signed-off-by: Drew Newberry <anewberry@nvidia.com>
@drew
drew requested review from a team, derekwaynecarr, mrunalp and sjenning as code owners October 2, 2026 04:39
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

bug(sandbox): GNU Make cannot launch recipes with unchanged UID/GID

1 participant