Repository navigation
fix(harness): bind session audits and reject unsafe loopback authority - #589
Conversation
|
CI on c9876f4: Linux failed on (a) the committed docs inventory, which had picked up an untracked local directory when regenerated on the dev Mac, and (b) ten test helpers that rebuild a policy from |
c9876f4 to
13fd26e
Compare
|
Second Linux run still hit the |
13fd26e to
df19caf
Compare
…ed loopback relay policy A second network policy, `loopback`, compiles to outbound on exactly one local TCP port (`loopback_port`, the arm's provider relay) and nothing else; SBPL's `localhost` names every address this host owns, so the pin is what makes the grant exclusive. The capability audit can now run under a session's exact policy: sentinels are placed inside the policy's own roots (caller-named homes or the last directory of each list), registered for removal one by one, reclaimed only when a well-formed owner marker names a dead process, and the retained attestation carries the profile hash and policy id the launch wrapper demands. Under `loopback` the matrix proves the pinned port is reachable, another local port is refused, and an external connect is refused outright (a hang is a failed case, never an abort). The symlink case under a session policy targets the controller's private temp tree; the report replaces hidden roots with digests. wrap_verified_command requires the case set keyed by the compiled network policy and cross-checks the attested network value. Provider bindings accept `relay_port`, the relay binds it, and admission refuses a loopback arm whose relay port differs from its pinned port. Probes never widen an arm's grants (nc or an admitted Python interpreter; printf stays the unlisted control); probe locale pinned to C. MacOSPolicy.from_canonical replaces nine hand-rolled reconstructions; roots must be printable ASCII. CLI: audit-macos --policy [--sentinel-*]; malformed input exits 2 with JSON. Successors cse-causal-study-v23 / cse-causal-study-pilot-v9; registry count -> 58. TRT-5, TRT-6, TRT-7, MON-8, CON-8, CON-5. Refs #347, #567, ADR-66 (PR7 part 2). Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EMTXwWm3ZppWcJvQQw2qbf
df19caf to
8e0dd9e
Compare
|
CI green on both platforms at 8e0dd9e (Linux 4321 passed; macOS passed). Ready for owner review (confinement class): the port-pinned loopback policy, the session-bound audit, the relay port binding, and the admission cross-check. |
|
Cross-review of head P1 — The pinned port permits a second service on another local addressLocation: The new profile allows This violates the claimed relay-only network authority (TRT-5/TRT-7): an unrelated local service at the same numeric port remains reachable. The current Merge blocker — Preserve the registrations already landed by #578
Current main already contains CSE v23, pilot v9, and BND v14 from #578, including its public-observation and model-cache bindings. Do not overwrite those historical registrations with this PR's same-number records. Reconcile against current main and append successors (currently CSE v24 / pilot v10), inherit from the latest main registrations, preserve their source coverage and pending gates, and regenerate manifests against the final combined source bytes. Update the registry count from the actual resulting set and refresh affected documentation/generated evidence. Production source files merge without textual conflicts. Check dependent PRs #590/#591 for the same version-chain collision when updating them. Validation: both existing GitHub CI checks are green on the reviewed head; the merge-conflict computation and focused live sandbox reproduction above were run during this review. I did not rerun the full test suite or change/push the author's branch. Per AGENTS.md / CON-16, these findings are posted for the Claude-authored PR to address. The final reconciled fix needs the required local gates, fresh CI, and Class C human review before merge. |
|
Addressed the review findings in 4,418 unit tests and the other completed gates passed. At the owner's explicit request for a machine restart, SIM/GRAPH was stopped after 2 passes and this commit was pushed without completing that gate. The full SIM/GRAPH gate remains outstanding. The PR description records the limitation: relay-backed confined sessions remain unavailable pending an exclusive transport. No merge performed. |
|
Review of P1 — The new registrations record a source commit that predates the confinement fixBoth Thus the recorded commit cannot reconstruct the registered source set (CON-5/TRT-1). The loopback refusal, same-port IPv4/IPv6 regression, append-only successor chain, and current source hashes otherwise looked consistent. My focused macOS run passed 258 tests across |
|
Fixed the registration provenance finding in Validation: |
PR #589 adds capability audits under a session's exact macOS policy. Review found that its proposed port-pinned
loopbackrule also admitted unrelated services on other local addresses. The final change refuses that unsupported authority and retains session-bound audits underdeny-external.Requirements: TRT-5, TRT-6, TRT-7, MON-8, CON-5, CON-8. Refs #347, #567, ADR-66.
Behavior
loopbackis rejected at profile compilation, audit startup, provider admission, and launch verification. Old passing loopback attestations cannot authorize a command. The operating-system compiler acceptslocalhost, which covers multiple host addresses, and rejects literal IP endpoint selectors. A numeric port alone cannot isolate the provider relay.provider.relay_portconfigures a listener but grants no confinement authority. Relay-backed confined sessions remain unavailable pending an exclusive transport; this PR does not attest their confinement or authorize pilot collection.Review resolution
The IPv4/IPv6 same-port defect was reproduced with the actual compiled sandbox: a separate IPv6 listener returned a synthetic canary while the IPv4 relay port was occupied. Regression tests now cover rejection of this grant, actual denial by the supported policy, rejection before audit side effects, rejection of cached attestations, and provider admission even when port numbers match. Three refusal regressions failed before the fix. All five merge conflicts were reconciled while preserving historical registrations.
The owner explicitly authorized direct fixes after the cross-review findings were posted. Class C: human review of this final change remains required before merge.
Validation