From 8e73b3ab442efac8e9a771feb205b6ac6e5c9ef2 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E7=9B=90=E7=B2=92=20Yanli?= Date: Wed, 3 Jun 2026 16:14:26 +0800 Subject: [PATCH 1/2] fix: update vulnerable dependencies --- docker/templates/base.dockerfile | 2 +- docker/templates/production.dockerfile | 2 +- docker/templates/test.dockerfile | 4 ++-- docker/versions.yaml | 4 ++-- go.mod | 12 ++++++------ go.sum | 16 ++++++++-------- 6 files changed, 20 insertions(+), 20 deletions(-) diff --git a/docker/templates/base.dockerfile b/docker/templates/base.dockerfile index cdc25079..5ffd3baa 100644 --- a/docker/templates/base.dockerfile +++ b/docker/templates/base.dockerfile @@ -26,6 +26,6 @@ RUN echo "deb ${DEBIAN_MIRROR}" > /etc/apt/sources.list \ && rm -rf /var/lib/apt/lists/* # Install Python dependencies -ARG PYTHON_PACKAGES="httpx==0.27.2 requests==2.32.3 jinja2==3.1.6 PySocks httpx[socks]" +ARG PYTHON_PACKAGES="httpx==0.27.2 requests==2.33.0 jinja2==3.1.6 PySocks httpx[socks]" RUN pip3 install --no-cache-dir ${PYTHON_PACKAGES} diff --git a/docker/templates/production.dockerfile b/docker/templates/production.dockerfile index 02147669..c11f7a64 100644 --- a/docker/templates/production.dockerfile +++ b/docker/templates/production.dockerfile @@ -1,7 +1,7 @@ # Production environment Dockerfile template ARG PYTHON_VERSION=dhi.io/python:3-debian13-sfw-ent-dev ARG DEBIAN_MIRROR="http://deb.debian.org/debian testing main" -ARG PYTHON_PACKAGES="httpx==0.27.2 requests==2.32.3 jinja2==3.1.6 PySocks httpx[socks]" +ARG PYTHON_PACKAGES="httpx==0.27.2 requests==2.33.0 jinja2==3.1.6 PySocks httpx[socks]" ARG NODEJS_VERSION=v20.11.1 ARG NODEJS_MIRROR="https://npmmirror.com/mirrors/node" ARG TARGETARCH diff --git a/docker/templates/test.dockerfile b/docker/templates/test.dockerfile index 2c63c249..bbaf48cf 100644 --- a/docker/templates/test.dockerfile +++ b/docker/templates/test.dockerfile @@ -1,8 +1,8 @@ # Test environment Dockerfile template -ARG GOLANG_VERSION=1.23.9 +ARG GOLANG_VERSION=1.25.0 ARG PYTHON_VERSION=docker.io/langgenius/python:3-debian13-sfw-ent-dev ARG DEBIAN_MIRROR="http://deb.debian.org/debian testing main" -ARG PYTHON_PACKAGES="httpx==0.27.2 requests==2.32.3 jinja2==3.1.6 PySocks httpx[socks]" +ARG PYTHON_PACKAGES="httpx==0.27.2 requests==2.33.0 jinja2==3.1.6 PySocks httpx[socks]" ARG NODEJS_VERSION=v20.11.1 ARG NODEJS_MIRROR="https://npmmirror.com/mirrors/node" ARG GOLANG_MIRROR="https://golang.org/dl" diff --git a/docker/versions.yaml b/docker/versions.yaml index a15ac5c8..5a7fce35 100644 --- a/docker/versions.yaml +++ b/docker/versions.yaml @@ -2,11 +2,11 @@ versions: # Base images python: "dhi.io/python:3-debian13-sfw-ent-dev" - golang: "1.24.13" + golang: "1.25.0" nodejs: "v20.20.0" # Python packages (unified configuration) - python_packages: "httpx==0.27.2 requests==2.32.3 jinja2==3.1.6 PySocks httpx[socks]" + python_packages: "httpx==0.27.2 requests==2.33.0 jinja2==3.1.6 PySocks httpx[socks]" # System packages system_packages: diff --git a/go.mod b/go.mod index 0d3bd055..8dc79979 100644 --- a/go.mod +++ b/go.mod @@ -1,11 +1,12 @@ module github.com/langgenius/dify-sandbox -go 1.24.11 +go 1.25.0 require ( github.com/gin-gonic/gin v1.10.0 github.com/google/uuid v1.6.0 github.com/seccomp/libseccomp-golang v0.11.0 + gopkg.in/natefinch/lumberjack.v2 v2.2.1 gopkg.in/yaml.v3 v3.0.1 ) @@ -29,10 +30,9 @@ require ( github.com/twitchyliquid64/golang-asm v0.15.1 // indirect github.com/ugorji/go/codec v1.2.12 // indirect golang.org/x/arch v0.17.0 // indirect - golang.org/x/crypto v0.45.0 // indirect - golang.org/x/net v0.47.0 // indirect - golang.org/x/sys v0.38.0 // indirect - golang.org/x/text v0.31.0 // indirect + golang.org/x/crypto v0.50.0 // indirect + golang.org/x/net v0.53.0 // indirect + golang.org/x/sys v0.43.0 // indirect + golang.org/x/text v0.36.0 // indirect google.golang.org/protobuf v1.36.6 // indirect - gopkg.in/natefinch/lumberjack.v2 v2.2.1 // indirect ) diff --git a/go.sum b/go.sum index 19486c7c..eb67436f 100644 --- a/go.sum +++ b/go.sum @@ -67,15 +67,15 @@ github.com/ugorji/go/codec v1.2.12 h1:9LC83zGrHhuUA9l16C9AHXAqEV/2wBQ4nkvumAE65E github.com/ugorji/go/codec v1.2.12/go.mod h1:UNopzCgEMSXjBc6AOMqYvWC1ktqTAfzJZUZgYf6w6lg= golang.org/x/arch v0.17.0 h1:4O3dfLzd+lQewptAHqjewQZQDyEdejz3VwgeYwkZneU= golang.org/x/arch v0.17.0/go.mod h1:bdwinDaKcfZUGpH09BB7ZmOfhalA8lQdzl62l8gGWsk= -golang.org/x/crypto v0.45.0 h1:jMBrvKuj23MTlT0bQEOBcAE0mjg8mK9RXFhRH6nyF3Q= -golang.org/x/crypto v0.45.0/go.mod h1:XTGrrkGJve7CYK7J8PEww4aY7gM3qMCElcJQ8n8JdX4= -golang.org/x/net v0.47.0 h1:Mx+4dIFzqraBXUugkia1OOvlD6LemFo1ALMHjrXDOhY= -golang.org/x/net v0.47.0/go.mod h1:/jNxtkgq5yWUGYkaZGqo27cfGZ1c5Nen03aYrrKpVRU= +golang.org/x/crypto v0.50.0 h1:zO47/JPrL6vsNkINmLoo/PH1gcxpls50DNogFvB5ZGI= +golang.org/x/crypto v0.50.0/go.mod h1:3muZ7vA7PBCE6xgPX7nkzzjiUq87kRItoJQM1Yo8S+Q= +golang.org/x/net v0.53.0 h1:d+qAbo5L0orcWAr0a9JweQpjXF19LMXJE8Ey7hwOdUA= +golang.org/x/net v0.53.0/go.mod h1:JvMuJH7rrdiCfbeHoo3fCQU24Lf5JJwT9W3sJFulfgs= golang.org/x/sys v0.6.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= -golang.org/x/sys v0.38.0 h1:3yZWxaJjBmCWXqhN1qh02AkOnCQ1poK6oF+a7xWL6Gc= -golang.org/x/sys v0.38.0/go.mod h1:OgkHotnGiDImocRcuBABYBEXf8A9a87e/uXjp9XT3ks= -golang.org/x/text v0.31.0 h1:aC8ghyu4JhP8VojJ2lEHBnochRno1sgL6nEi9WGFGMM= -golang.org/x/text v0.31.0/go.mod h1:tKRAlv61yKIjGGHX/4tP1LTbc13YSec1pxVEWXzfoeM= +golang.org/x/sys v0.43.0 h1:Rlag2XtaFTxp19wS8MXlJwTvoh8ArU6ezoyFsMyCTNI= +golang.org/x/sys v0.43.0/go.mod h1:4GL1E5IUh+htKOUEOaiffhrAeqysfVGipDYzABqnCmw= +golang.org/x/text v0.36.0 h1:JfKh3XmcRPqZPKevfXVpI1wXPTqbkE5f7JA92a55Yxg= +golang.org/x/text v0.36.0/go.mod h1:NIdBknypM8iqVmPiuco0Dh6P5Jcdk8lJL0CUebqK164= golang.org/x/xerrors v0.0.0-20191204190536-9bdfabe68543 h1:E7g+9GITq07hpfrRu66IVDexMakfv52eLZ2CXBWiKr4= golang.org/x/xerrors v0.0.0-20191204190536-9bdfabe68543/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0= google.golang.org/protobuf v1.36.6 h1:z1NpPI8ku2WgiWnf+t9wTPsn6eP1L7ksHUlkfLvd9xY= From d28dd583496aa52af2156ef0dc66c4e32667eb97 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E7=9B=90=E7=B2=92=20Yanli?= Date: Wed, 3 Jun 2026 16:48:50 +0800 Subject: [PATCH 2/2] fix: stabilize sandbox under Go 1.25 --- internal/core/runner/nodejs/nodejs.go | 8 +++++++- internal/core/runner/nodejs/prescript.js | 1 + internal/core/runner/python/prescript.py | 1 + internal/core/runner/python/python.go | 8 +++++++- internal/static/nodejs_syscall/syscalls_amd64.go | 1 + internal/static/nodejs_syscall/syscalls_arm64.go | 1 + internal/static/python_syscall/syscalls_amd64.go | 5 +++-- internal/static/python_syscall/syscalls_arm64.go | 5 +++-- 8 files changed, 24 insertions(+), 6 deletions(-) diff --git a/internal/core/runner/nodejs/nodejs.go b/internal/core/runner/nodejs/nodejs.go index 14729361..e6f667a4 100644 --- a/internal/core/runner/nodejs/nodejs.go +++ b/internal/core/runner/nodejs/nodejs.go @@ -84,7 +84,13 @@ func (p *NodeJsRunner) Run( // create a new process cmd := exec.Command(configuration.NodejsPath, buildCommandArgs(script_path, uid, options)...) - cmd.Env = []string{} + cmd.Env = []string{ + // The sandbox child loads a Go c-shared library to install seccomp. + // Disable Go runtime features that may issue housekeeping syscalls after + // the seccomp filter is active; the prescript removes this before running + // user code. + "GODEBUG=decoratemappings=0,containermaxprocs=0,updatemaxprocs=0", + } cmd.ExtraFiles = []*os.File{codeReader} if len(configuration.AllowedSyscalls) > 0 { diff --git a/internal/core/runner/nodejs/prescript.js b/internal/core/runner/nodejs/prescript.js index 85a1b53f..f8e7d282 100644 --- a/internal/core/runner/nodejs/prescript.js +++ b/internal/core/runner/nodejs/prescript.js @@ -11,6 +11,7 @@ const gid = parseInt(argv[3]) const options = JSON.parse(argv[4]) difySeccomp(uid, gid, options['enable_network']) +delete process.env.GODEBUG const code = fs.readFileSync(3, 'utf8') eval(code) diff --git a/internal/core/runner/python/prescript.py b/internal/core/runner/python/prescript.py index 55dbfcbd..e09773ee 100644 --- a/internal/core/runner/python/prescript.py +++ b/internal/core/runner/python/prescript.py @@ -27,6 +27,7 @@ def excepthook(type, value, tb): {{preload}} lib.DifySeccomp({{uid}}, {{gid}}, {{enable_network}}) +os.environ.pop("GODEBUG", None) with os.fdopen(3, "rb") as code_fd: code = code_fd.read().decode("utf-8") diff --git a/internal/core/runner/python/python.go b/internal/core/runner/python/python.go index 4d8e3bd1..dea3ef40 100644 --- a/internal/core/runner/python/python.go +++ b/internal/core/runner/python/python.go @@ -69,7 +69,13 @@ func (p *PythonRunner) Run( bootstrapPath, LIB_PATH, ) - cmd.Env = []string{} + cmd.Env = []string{ + // The sandbox child loads a Go c-shared library to install seccomp. + // Disable Go runtime features that may issue housekeeping syscalls after + // the seccomp filter is active; the prescript removes this before running + // user code. + "GODEBUG=decoratemappings=0,containermaxprocs=0,updatemaxprocs=0", + } cmd.Dir = LIB_PATH cmd.ExtraFiles = []*os.File{codeReader} diff --git a/internal/static/nodejs_syscall/syscalls_amd64.go b/internal/static/nodejs_syscall/syscalls_amd64.go index 65aa4f11..1f284366 100644 --- a/internal/static/nodejs_syscall/syscalls_amd64.go +++ b/internal/static/nodejs_syscall/syscalls_amd64.go @@ -38,6 +38,7 @@ var ALLOW_SYSCALLS = []int{ syscall.SYS_READLINK, syscall.SYS_DUP3, + syscall.SYS_EVENTFD2, } var ALLOW_ERROR_SYSCALLS = []int{ diff --git a/internal/static/nodejs_syscall/syscalls_arm64.go b/internal/static/nodejs_syscall/syscalls_arm64.go index cf6ffce3..d41cc272 100644 --- a/internal/static/nodejs_syscall/syscalls_arm64.go +++ b/internal/static/nodejs_syscall/syscalls_arm64.go @@ -27,6 +27,7 @@ var ALLOW_SYSCALLS = []int{ // epoll syscall.SYS_EPOLL_CTL, syscall.SYS_EPOLL_PWAIT, + syscall.SYS_EVENTFD2, } var ALLOW_ERROR_SYSCALLS = []int{ diff --git a/internal/static/python_syscall/syscalls_amd64.go b/internal/static/python_syscall/syscalls_amd64.go index eb33590b..c5dd37d6 100644 --- a/internal/static/python_syscall/syscalls_amd64.go +++ b/internal/static/python_syscall/syscalls_amd64.go @@ -15,10 +15,10 @@ var ALLOW_SYSCALLS = []int{ syscall.SYS_NEWFSTATAT, syscall.SYS_FSTAT, syscall.SYS_FCNTL, syscall.SYS_IOCTL, syscall.SYS_LSEEK, syscall.SYS_GETDENTS64, syscall.SYS_WRITE, syscall.SYS_CLOSE, syscall.SYS_OPENAT, syscall.SYS_READ, // thread - syscall.SYS_FUTEX, + syscall.SYS_FUTEX, syscall.SYS_SCHED_GETAFFINITY, // memory syscall.SYS_MMAP, syscall.SYS_BRK, syscall.SYS_MPROTECT, syscall.SYS_MUNMAP, syscall.SYS_RT_SIGRETURN, - syscall.SYS_MREMAP, + syscall.SYS_MREMAP, syscall.SYS_MADVISE, // user/group syscall.SYS_SETGROUPS, syscall.SYS_SETGID, syscall.SYS_SETUID, syscall.SYS_GETUID, @@ -36,6 +36,7 @@ var ALLOW_SYSCALLS = []int{ syscall.SYS_TIME, syscall.SYS_RT_SIGPROCMASK, syscall.SYS_SIGALTSTACK, SYS_GETRANDOM, + syscall.SYS_EVENTFD2, } var ALLOW_ERROR_SYSCALLS = []int{ diff --git a/internal/static/python_syscall/syscalls_arm64.go b/internal/static/python_syscall/syscalls_arm64.go index 3cb869bf..f7d29594 100644 --- a/internal/static/python_syscall/syscalls_arm64.go +++ b/internal/static/python_syscall/syscalls_arm64.go @@ -16,11 +16,11 @@ var ALLOW_SYSCALLS = []int{ syscall.SYS_FSTAT, syscall.SYS_FCNTL, // thread - syscall.SYS_FUTEX, + syscall.SYS_FUTEX, syscall.SYS_SCHED_GETAFFINITY, // memory syscall.SYS_MMAP, syscall.SYS_BRK, syscall.SYS_MPROTECT, syscall.SYS_MUNMAP, syscall.SYS_RT_SIGRETURN, syscall.SYS_RT_SIGPROCMASK, - syscall.SYS_SIGALTSTACK, syscall.SYS_MREMAP, + syscall.SYS_SIGALTSTACK, syscall.SYS_MREMAP, syscall.SYS_MADVISE, // user/group syscall.SYS_SETGROUPS, syscall.SYS_SETGID, syscall.SYS_SETUID, syscall.SYS_GETUID, @@ -41,6 +41,7 @@ var ALLOW_SYSCALLS = []int{ // get random syscall.SYS_GETRANDOM, + syscall.SYS_EVENTFD2, } var ALLOW_ERROR_SYSCALLS = []int{