Skip to content

tests: bug-bash sandbox export stream follow-ups (#5800 final check) #5804

Description

@ThomasK33

Follow-ups from the final check of #5800 (bug-bash sandbox export stream, tests/bugbash/sandbox/exportStream.ts). None of them lets the container write outside the job folder or plant a symlink. They are hardening and test-precision items.

  1. Each refusal test checks only that the receiver refused, not why (exportStream.test.ts). A case can pass for the wrong reason. Example: without the control-character check, the "NUL byte" case still passes because openSync refuses the NUL. Fix: assert on a substring of result.error per case.
  2. Folders do not count toward a cap. 10,000 files with 31 folders each can create about 310,000 folders (about 1.2 GiB on ext4) on top of the 1 GiB data cap. Fix: count created folders against a limit in createFile.
  3. The writer throws (no end frame, host reports "evidence incomplete") when a file vanishes, turns into a symlink after the walk, or is unreadable. That fails safe, but the writer is meant to skip such files. Fix: treat ELOOP/ENOENT/EACCES as skipped files.

Owner: the #5714 sandbox stack. Trigger: fold into PR 3 of the stack (the self-test PR, which exercises the export check), or a separate small PR.

Refs #5714


Generated with xum • Model: anthropic:claude-opus-5-5 • Thinking: high

Activity

  1. self-assigned this
    on Oct 6, 2026
  2. ThomasK33 commented on Oct 6, 2026

    @ThomasK33
    MemberAuthor

    PR 3 of the #5714 sandbox stack fixes all three items. It is ready locally on branch tests/5714-sandbox-wirein and opens after #5802 merges (at most two stack PRs open at a time). Its body will say "Fixes #5804".

    1. Each refusal case now names the rule that must refuse it (expect(result.error).toContain(reason)).
    2. The receiver counts the folders it creates against a new dirs limit (10,000).
    3. The writer skips a file that is gone, became a symlink or socket, or is unreadable (ENOENT, ELOOP, ENXIO, EACCES), and still sends the end frame. A new test covers an unreadable file.

    Generated with xum • Model: anthropic:claude-opus-5-5 • Thinking: high

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

approvedTriage: passed unanimous bug screen

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions