Repository navigation
rl harness: run trusted process argv and workspace probes without a login shell - #157
Conversation
…to e4src/trusted-argv-nonlogin
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 77aed817fb
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 0ed8ed6307
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
Problem
TrustedProcessHandleran three trusted executions through the pinned shell as a login shell (bash -lc):run_argv(setup / verifier argv, andProcessLease.execute)measure_repository_base_commit(git rev-parse --verify HEAD^{commit}, output limit 256)workspace_diffA login shell sources
/etc/profileand the first of~/.bash_profile,~/.bash_login,~/.profile. Those files are in policy-writable state, so a policy command could get its own code run inside the trusted executions. It could print extra output, change the exit status, or change the working state before the requested argv.This was observed in a production SWE training episode. The policy ran
cp /tmp/test_fix.py ~/.bash_profile. The next trusted base-commit probe sourced that file, overflowed its 256-byte output limit, and the episode failed closed withoutput_limit_exceeded.The Docker backend's
run_argvalready runs argv directly, and the native worker launch already uses-c("Not a login shell").Change
run_argv,measure_repository_base_commitandworkspace_diffnow use-cinstead of-lc.run_shell/run_native_toolkeep-lc, so policy commands still get the image's login environment.InstalledRuntimerejects afixed_environmentcarryingBASH_ENVorBASH_FUNC_*: every trusted launch runs the pinned shell with-c, and a non-interactive shell sources$BASH_ENVand imports exported functions before the requested argv. Test:test_runtime_authority_rejects_shell_startup_hooksfails before and passes after.Tests
test_trusted_argv_ignores_policy_written_login_profile:$HOME/.profileand$HOME/.bash_profile.HEAD,workspace_diffmust be unchanged, andexecutemust print only the requested argv's output.test_run_argv_executes_requested_command_through_pinned_shellandtest_workspace_diff_uses_nested_repository_and_types_missing_gitnow pin-c.Evidence
On the production runtime lineage (branch
e4src/trusted-argv-nonlogin-v11, the same change on the runtime-v11 source), Linux, bash,/bin/sh= dash:SandboxLaunchError: workspace base commit measurement failed.test_verifier_snapshot,test_sandbox_runtime,test_v2_service,test_production_composition_runtime,test_headless_runner, and the rest oftest_sandbox_process_integration.On
main, the argv-pinning tests fail before the fix and pass after it. In that cluster environment, the new sealed test is skipped asruntime_unsupported, because namespace/UID mapping is unavailable there.ACR
docs/contracts/policies/acr/ACR-20260930-trusted-argv-nonlogin.md(breadboard/**is a protected danger-zone glob).