Skip to content

Fail closed by default when the core OS sandbox can't be applied - #131

Open
kvey wants to merge 1 commit into
mainfrom
claude/sandbox-fail-open-default-8c63k6
Open

Fail closed by default when the core OS sandbox can't be applied#131
kvey wants to merge 1 commit into
mainfrom
claude/sandbox-fail-open-default-8c63k6

Conversation

@kvey

@kvey kvey commented Jul 15, 2026

Copy link
Copy Markdown
Contributor

Previously every confinement layer was best-effort: when seccomp (Linux)
or Seatbelt (macOS) failed to install, the worker logged a note to stderr
and ran the agent anyway, so a run advertised as isolated could silently
execute with only process separation. Fail-closed behavior required the
operator to opt in via CHIDORI_ISOLATE_REQUIRE_SANDBOX=1.

Reverse the default: a missing core confinement layer now refuses the run
with an actionable error (including the sandbox skip notes). Operators who
accept a degraded posture must opt in explicitly with
CHIDORI_ISOLATE_REQUIRE_SANDBOX=0, and the worker still announces the
downgrade loudly on stderr. The auxiliary layers (network namespace,
Landlock) remain best-effort. On platforms with no sandbox implementation
at all, the default stays the loud downgrade (the startup banner already
says 'no OS sandbox layer'); an explicit truthy value forces fail-closed
even there.

Also move the CHIDORI_ISOLATE_SELFTEST probes ahead of the fail-closed
gate so skip-aware tests keep their unavailability markers, add a
test-only CHIDORI_ISOLATE_TEST_FORCE_UNCONFINED hook to exercise the gate
end-to-end, and update the docs and startup banner to match.

Co-Authored-By: Claude Fable 5 noreply@anthropic.com
Claude-Session: https://claude.ai/code/session_018REuzMFXqwDZsQnnTNsYpz

Previously every confinement layer was best-effort: when seccomp (Linux)
or Seatbelt (macOS) failed to install, the worker logged a note to stderr
and ran the agent anyway, so a run advertised as isolated could silently
execute with only process separation. Fail-closed behavior required the
operator to opt in via CHIDORI_ISOLATE_REQUIRE_SANDBOX=1.

Reverse the default: a missing core confinement layer now refuses the run
with an actionable error (including the sandbox skip notes). Operators who
accept a degraded posture must opt in explicitly with
CHIDORI_ISOLATE_REQUIRE_SANDBOX=0, and the worker still announces the
downgrade loudly on stderr. The auxiliary layers (network namespace,
Landlock) remain best-effort. On platforms with no sandbox implementation
at all, the default stays the loud downgrade (the startup banner already
says 'no OS sandbox layer'); an explicit truthy value forces fail-closed
even there.

Also move the CHIDORI_ISOLATE_SELFTEST probes ahead of the fail-closed
gate so skip-aware tests keep their unavailability markers, add a
test-only CHIDORI_ISOLATE_TEST_FORCE_UNCONFINED hook to exercise the gate
end-to-end, and update the docs and startup banner to match.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018REuzMFXqwDZsQnnTNsYpz
@cursor

cursor Bot commented Jul 15, 2026

Copy link
Copy Markdown

Bugbot is not enabled for your account, so this pull request was not reviewed.

Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants