Skip to content

rl harness: run trusted process argv and workspace probes without a login shell - #157

Merged
kmccleary3301 merged 5 commits into
mainfrom
e4src/trusted-argv-nonlogin
Sep 30, 2026
Merged

kmccleary3301 merged 5 commits into
mainfrom
e4src/trusted-argv-nonlogin

Conversation

@kmccleary3301

@kmccleary3301 kmccleary3301 commented Sep 30, 2026 •

Copy link
Copy Markdown
Owner

Problem

TrustedProcessHandle ran three trusted executions through the pinned shell as a login shell (bash -lc):

  • run_argv (setup / verifier argv, and ProcessLease.execute)
  • measure_repository_base_commit (git rev-parse --verify HEAD^{commit}, output limit 256)
  • workspace_diff

A login shell sources /etc/profile and the first of ~/.bash_profile, ~/.bash_login, ~/.profile. Those files are in policy-writable state, so a policy command could get its own code run inside the trusted executions. It could print extra output, change the exit status, or change the working state before the requested argv.

This was observed in a production SWE training episode. The policy ran cp /tmp/test_fix.py ~/.bash_profile. The next trusted base-commit probe sourced that file, overflowed its 256-byte output limit, and the episode failed closed with output_limit_exceeded.

The Docker backend's run_argv already runs argv directly, and the native worker launch already uses -c ("Not a login shell").

Change

  • run_argv, measure_repository_base_commit and workspace_diff now use -c instead of -lc.
  • Policy-facing run_shell / run_native_tool keep -lc, so policy commands still get the image's login environment.
  • InstalledRuntime rejects a fixed_environment carrying BASH_ENV or BASH_FUNC_*: every trusted launch runs the pinned shell with -c, and a non-interactive shell sources $BASH_ENV and imports exported functions before the requested argv. Test: test_runtime_authority_rejects_shell_startup_hooks fails before and passes after.

Tests

  • New real-execution test test_trusted_argv_ignores_policy_written_login_profile:
    • The policy writes $HOME/.profile and $HOME/.bash_profile.
    • Sensitivity check: the policy's own login shell prints the profile marker.
    • The trusted base commit must still equal HEAD, workspace_diff must be unchanged, and execute must print only the requested argv's output.
  • test_run_argv_executes_requested_command_through_pinned_shell and test_workspace_diff_uses_nested_repository_and_types_missing_git now pin -c.

Evidence

On the production runtime lineage (branch e4src/trusted-argv-nonlogin-v11, the same change on the runtime-v11 source), Linux, bash, /bin/sh = dash:

  • Without the fix: the three tests fail. The new test fails with SandboxLaunchError: workspace base commit measurement failed.
  • With the fix: all three pass.
  • The other suites are unchanged between the two trees: test_verifier_snapshot, test_sandbox_runtime, test_v2_service, test_production_composition_runtime, test_headless_runner, and the rest of test_sandbox_process_integration.

On main, the argv-pinning tests fail before the fix and pass after it. In that cluster environment, the new sealed test is skipped as runtime_unsupported, because namespace/UID mapping is unavailable there.

ACR

docs/contracts/policies/acr/ACR-20260930-trusted-argv-nonlogin.md (breadboard/** is a protected danger-zone glob).

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 77aed817fb

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread breadboard/rl/harness/sandbox.py

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 0ed8ed6307

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread breadboard/rl/harness/sandbox.py Outdated
@kmccleary3301
kmccleary3301 merged commit 0ab0560 into main Sep 30, 2026
68 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant