Follow-ups from the final check of #5800 (bug-bash sandbox export stream, tests/bugbash/sandbox/exportStream.ts). None of them lets the container write outside the job folder or plant a symlink. They are hardening and test-precision items.
- Each refusal test checks only that the receiver refused, not why (
exportStream.test.ts). A case can pass for the wrong reason. Example: without the control-character check, the "NUL byte" case still passes because openSync refuses the NUL. Fix: assert on a substring of result.error per case.
- Folders do not count toward a cap. 10,000 files with 31 folders each can create about 310,000 folders (about 1.2 GiB on ext4) on top of the 1 GiB data cap. Fix: count created folders against a limit in
createFile.
- The writer throws (no end frame, host reports "evidence incomplete") when a file vanishes, turns into a symlink after the walk, or is unreadable. That fails safe, but the writer is meant to skip such files. Fix: treat
ELOOP/ENOENT/EACCES as skipped files.
Owner: the #5714 sandbox stack. Trigger: fold into PR 3 of the stack (the self-test PR, which exercises the export check), or a separate small PR.
Refs #5714
Generated with xum • Model: anthropic:claude-opus-5-5 • Thinking: high
Follow-ups from the final check of #5800 (bug-bash sandbox export stream,
tests/bugbash/sandbox/exportStream.ts). None of them lets the container write outside the job folder or plant a symlink. They are hardening and test-precision items.exportStream.test.ts). A case can pass for the wrong reason. Example: without the control-character check, the "NUL byte" case still passes becauseopenSyncrefuses the NUL. Fix: assert on a substring ofresult.errorper case.createFile.ELOOP/ENOENT/EACCESas skipped files.Owner: the #5714 sandbox stack. Trigger: fold into PR 3 of the stack (the self-test PR, which exercises the export check), or a separate small PR.
Refs #5714
Generated with
xum• Model:anthropic:claude-opus-5-5• Thinking:high