Repository navigation
🤖 tests: run the bug-bash app and browser in a container sandbox #5714
Description
Activity
Maintainer decision (relayed by the issue coordinator): Option A. Design the container sandbox now. A plan-mode workspace writes the design as an HTML plan (the html-plan skill), and the maintainer approves it before any code is written.
Generated with
xum• Model:anthropic:claude-opus-5-5• Thinking:high- addedapprovedTriage: passed unanimous bug screenTriage: passed unanimous bug screen
on Oct 6, 2026 Picked up for planning: workspace workspace-85 (plan mode).
This workspace writes the container-sandbox design as an HTML plan (the html-plan skill). No code until the maintainer approves the plan. The plan stays consistent with the harness work in #5704, #5700 and #5716 (workspace-62).
Generated with
xum• Model:anthropic:claude-opus-5-5• Thinking:max- added a commit that references this issue
on Oct 6, 2026 Picked up by the issue coordinator: workspace workspace-85 (7f8c86d36c), branch
tests/5714-sandbox-export(the first of five stacked PRs, in the approved plan's order).
Generated with
xum• Model:anthropic:claude-opus-5-5• Thinking:high• Cost:$45.14- added 9 commits that reference this issue
on Oct 6, 2026 7 remaining items
- added 4 commits that reference this issue
on Oct 8, 2026 Decision: B1 PR 4 is stopped by the user's decision. #5883 is closed unmerged (#5883 (comment)).
- The mock-only container runner already merged and stays on main.
- The branch
tests/5714-b1-safetyand its history are kept. Its open finding (a leftover process in the create's process group keeps running, and cleanup reports "unknown") is on that branch only.
Remaining work, tracked:
- 🤖 tests: bug-bash runner safety work that #5883 did not land #5930: runner safety work that 🤖 tests: bug-bash sandbox safety follow-ups (create window, fd-checked staging, argument precedence) #5883 did not land. Trigger: before any CI job runs the container runner.
- 🤖 tests: CI job for the bug-bash container runner #5931: CI job for the runner. Trigger: after 🤖 tests: bug-bash runner safety work that #5883 did not land #5930 lands.
- 🤖 docs: bug-bash container runner #5932: docs for the runner. Trigger: with 🤖 tests: CI job for the bug-bash container runner #5931.
This issue stays open for that work and for the provider proxy.
Generated with
xum• Model:anthropic:claude-opus-5-5• Thinking:high- added 6 commits that reference this issue
on Oct 10, 2026 - added 4 commits that reference this issue
on Oct 10, 2026
Problem
The agent bug bash (
make bug-bash,make test-bugbash-repros) runs the app (tests/bugbash/startApp.ts) and the e2e explorer's browser on the host, as the developer's user. A tempHOMEandXUM_ROOTprotect real config, but not the host filesystem.In real-AI mode (
BUGBASH_AI=auto|real, from #5711), app replies come from a real model and are untrusted text for the explorer. #5711 closes the app's direct command paths in real mode:XUM_DISABLE_AGENT_TOOLS=1: the model gets no tools.XUM_DISABLE_TERMINALS=1: no terminal starts and no terminal input is accepted.XUM_DISABLE_PROJECT_AUTOMATION=1: no project init hooks run.These switches close specific paths. They do not isolate the host. Settings can still add a stdio MCP server or a custom editor command, and both run host commands. Only the charter text keeps the explorer away from them. In mock mode, the Terminal tab also runs real shell commands.
Proposal
Run the bug-bash app and its browser inside a container, in both AI modes, with only the seeded temp root mounted. Then decide whether real mode can enable agent tools and terminals again.
Found by the Codex security review on #5711.
Generated with
xum• Model:anthropic:claude-opus-5-5• Thinking:high• Cost:$125.77