feat: runtime sandbox for untrusted registry handlers (0.3.0) - #19
Merged
Merged
Conversation
…process (0.3.0) Registry-installed handler/seed code is never imported in the host process — at add, load, or call time. It runs in a subprocess with network/subprocess/exec/ ctypes/file-writes neutered before any untrusted import, plus CPU/memory limits. The parent owns state + entropy, so a sandboxed mock is byte-identical to a trusted one. Closes the RCE surface from the static-only safety gate.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes the real security gap in the public registry: until now,
mockworld addscanned handler code with a bypassable regex and then ran it in-process. This adds process-level isolation for untrusted (registry-installed) mocks.Threat model — untrusted code executed at three moments, all now closed
mockworld add: previously calledvalidate_mock, which imported the module to check signatures — executing untrusted code in the host before install. Now validation is static-only (import_handlers=False); nothing is imported.handlers.py/seed.pyare no longer imported in the host process at all (loaderinfers trust from the install path).mockworld._sandbox_worker).The sandbox
Before any untrusted import, the worker neuters
socket,subprocess,os.system/exec*/fork,ctypes, and file writes, and sets CPU/memory rlimits. The parent keeps ownership of state and entropy: it derives the per-call keys, ships the state slice, and applies returned mutations to its own copy-on-write overlay — so a sandboxed mock is byte-identical to a trusted one and isolation stays parent-side. Locally-authored mocks stay trusted (unchanged).Honest scope: defense-in-depth, not a formal guarantee (in-process Python can't be made perfectly escape-proof). It removes the easy paths — exfiltration, spawning processes, trashing files — and contains crashes/hangs to a disposable child holding none of the host's state. Documented: for hard isolation, run mockworld in a container.
Tests (92 total, +6)
Sandboxed mock stays byte-identical to trusted; malicious
net/proc/writehandlers all blocked with no side effect;adddoesn't execute top-level code;validate --staticdoesn't import; session isolation preserved. Bumped to 0.3.0 (new security capability);twine checkpasses.