Skip to content

🤖 tests: run the bug-bash app and browser in a container sandbox #5714

Description

@ThomasK33

Problem

The agent bug bash (make bug-bash, make test-bugbash-repros) runs the app (tests/bugbash/startApp.ts) and the e2e explorer's browser on the host, as the developer's user. A temp HOME and XUM_ROOT protect real config, but not the host filesystem.

In real-AI mode (BUGBASH_AI=auto|real, from #5711), app replies come from a real model and are untrusted text for the explorer. #5711 closes the app's direct command paths in real mode:

  • XUM_DISABLE_AGENT_TOOLS=1: the model gets no tools.
  • XUM_DISABLE_TERMINALS=1: no terminal starts and no terminal input is accepted.
  • XUM_DISABLE_PROJECT_AUTOMATION=1: no project init hooks run.

These switches close specific paths. They do not isolate the host. Settings can still add a stdio MCP server or a custom editor command, and both run host commands. Only the charter text keeps the explorer away from them. In mock mode, the Terminal tab also runs real shell commands.

Proposal

Run the bug-bash app and its browser inside a container, in both AI modes, with only the seeded temp root mounted. Then decide whether real mode can enable agent tools and terminals again.

Found by the Codex security review on #5711.


Generated with xum • Model: anthropic:claude-opus-5-5 • Thinking: high • Cost: $125.77

Activity

  1. self-assigned this
    on Oct 6, 2026
  2. ThomasK33 commented on Oct 6, 2026

    @ThomasK33
    MemberAuthor

    Maintainer decision (relayed by the issue coordinator): Option A. Design the container sandbox now. A plan-mode workspace writes the design as an HTML plan (the html-plan skill), and the maintainer approves it before any code is written.


    Generated with xum • Model: anthropic:claude-opus-5-5 • Thinking: high

  3. ThomasK33 commented on Oct 6, 2026

    @ThomasK33
    MemberAuthor

    Picked up for planning: workspace workspace-85 (plan mode).

    This workspace writes the container-sandbox design as an HTML plan (the html-plan skill). No code until the maintainer approves the plan. The plan stays consistent with the harness work in #5704, #5700 and #5716 (workspace-62).


    Generated with xum • Model: anthropic:claude-opus-5-5 • Thinking: max

  4. ThomasK33 commented on Oct 6, 2026

    @ThomasK33
    MemberAuthor

    Picked up by the issue coordinator: workspace workspace-85 (7f8c86d36c), branch tests/5714-sandbox-export (the first of five stacked PRs, in the approved plan's order).


    Generated with xum • Model: anthropic:claude-opus-5-5 • Thinking: high • Cost: $45.14

  5. 7 remaining items

  6. ThomasK33 commented on Oct 9, 2026

    @ThomasK33
    MemberAuthor

    Decision: B1 PR 4 is stopped by the user's decision. #5883 is closed unmerged (#5883 (comment)).

    • The mock-only container runner already merged and stays on main.
    • The branch tests/5714-b1-safety and its history are kept. Its open finding (a leftover process in the create's process group keeps running, and cleanup reports "unknown") is on that branch only.

    Remaining work, tracked:

    1. 🤖 tests: bug-bash runner safety work that #5883 did not land #5930: runner safety work that 🤖 tests: bug-bash sandbox safety follow-ups (create window, fd-checked staging, argument precedence) #5883 did not land. Trigger: before any CI job runs the container runner.
    2. 🤖 tests: CI job for the bug-bash container runner #5931: CI job for the runner. Trigger: after 🤖 tests: bug-bash runner safety work that #5883 did not land #5930 lands.
    3. 🤖 docs: bug-bash container runner #5932: docs for the runner. Trigger: with 🤖 tests: CI job for the bug-bash container runner #5931.

    This issue stays open for that work and for the provider proxy.


    Generated with xum • Model: anthropic:claude-opus-5-5 • Thinking: high

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

approvedTriage: passed unanimous bug screen

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions