Skip to content

Close the custom grader sandbox escape - #67475

Merged
pelikhan merged 5 commits into
mainfrom
copilot/aw-top-10-close-custom-grader-sandbox-escape
Oct 10, 2026
Merged

pelikhan merged 5 commits into
mainfrom
copilot/aw-top-10-close-custom-grader-sandbox-escape

Conversation

Copilot AI commented Oct 10, 2026 •

Copy link
Copy Markdown
Contributor

Inline JavaScript graders ran in Node’s vm context, which is not a security boundary; source-pattern blocking could not prevent sandbox escapes. This change restricts grader subprocesses and removes reliance on the blocklist.

  • Isolation: Run graders in separate Node processes with permissions enabled and no inherited environment. Reconstruct inputs inside the VM realm to avoid exposing host objects.
  • Validation: Remove source-substring restrictions; add regression tests asserting graders cannot access process or require, or execute a command.
return typeof process === "undefined" && typeof require === "undefined" ? 1 : 0;

Copilot AI linked an issue Oct 10, 2026 that may be closed by this pull request
2 tasks
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Copilot AI changed the title [WIP] Fix custom grader sandbox escape issue Close the custom grader sandbox escape Oct 10, 2026
Copilot AI requested a review from pelikhan October 10, 2026 16:51
@pelikhan
pelikhan marked this pull request as ready for review October 10, 2026 17:55
Copilot AI balanced review requested due to automatic review settings October 10, 2026 17:55

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The CLI’s unconditional --permission flag breaks grader execution with Node 20 installations.

1 open finding
What changed in this PR

Restricts custom JavaScript graders using permission-enabled Node subprocesses and VM-realm input reconstruction.

Changes:

  • Removes source-pattern blocking.
  • Adds subprocess isolation and sandbox-escape regression tests.
  • Updates grader security documentation.
File Description
pkg/​workflow/​graders_config.go Removes script blocklist validation.
pkg/​workflow/​graders_config_test.go Tests blocklist removal.
pkg/​cli/​graders_run.go Enables Node permissions and clears environment.
pkg/​cli/​graders_run.cjs Reconstructs inputs inside the VM realm.
pkg/​cli/​graders_run_test.go Adds CLI sandbox regression tests.
actions/​setup/​js/​trace_graders.cjs Restricts grader subprocess capabilities.
actions/​setup/​js/​trace_graders_worker.cjs Hardens worker context and result serialization.
actions/​setup/​js/​trace_graders.test.cjs Tests process access and command execution.
docs/​src/​content/​docs/​specs/​graders-specification.md Documents isolation requirements.
docs/​src/​content/​docs/​reference/​glossary.md Updates grader isolation description.

🧠 Review effort: Balanced


💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

Comment thread pkg/cli/graders_run.go Outdated
Merge current main, select supported Node permission flags, allow only the canonical runtime file, close the worker bootstrap constructor access, and preserve non-finite grader errors. Add compatibility and regression coverage.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@gh-aw-bot

Copy link
Copy Markdown
Collaborator

@copilot address the following outstanding work in one pass:

  1. Update this branch with the latest main using make merge-main, resolving any conflicts and preserving the intended changes.
  2. Review (pkg/cli/graders_run.go:232): runJavaScriptGrader still accepts any node found on PATH, but this invocation now requires a flag that Node 20 does not recognize (--experimental-permission is the Node 20 spelling). The repository documents Node 20.19.6 on ubuntu-latest (scratchpad/ubuntulatest.md:43-47), while the CLI documentation only says Node.js is required, so gh aw graders run will fail before executing the grader in that supported/common environment. Please detect the available permission flag or require Node >=22.13 with an actionable version error and update the documented prerequisite and compatibility tests. - Close the custom grader sandbox escape #67475 (comment)

Push the necessary fixes, reply to each listed review thread and resolve it when addressed. Ignore feedback already answered or resolved. Use the pr-finisher skill and stop when only human review or CI remains; do not trigger CI.

Sous-chef head: 3c90a73
Sous-chef work: 9b4cf8e46cd08d2edf493af752b5c69627e8e313c10d748c7cf59e9119ab1b48
Sous-chef state: e04969b8152be4e1fb625462f9e3f7da3e2a8b133d956a8672787848d7556378

Generated by 👨‍🍳 PR Sous Chef · pi · haiku45 · 7.46 AIC · ⌖ 20.5 AIC · ⊞ 1K · ◷
Comment /souschef to run again

Copilot AI and others added 2 commits October 10, 2026 21:02
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>

Copilot AI commented Oct 10, 2026

Copy link
Copy Markdown
Contributor Author

@copilot address the following outstanding work in one pass:

  1. Update this branch with the latest main using make merge-main, resolving any conflicts and preserving the intended changes....

Completed. make merge-main confirmed main was already merged. The Node runtime compatibility fix is in 15274c5; follow-ups are 8423dce and d8d595f. The linked review thread is already resolved. Local grader tests, lint, formatting, and the final impacted-test gate passed. The docs build could not be completed locally because the npm feed hostname failed DNS resolution. No CI was triggered; fresh CI and human review remain.

Copilot AI requested a review from gh-aw-bot October 10, 2026 21:10
@pelikhan
pelikhan merged commit fa6eef5 into main Oct 10, 2026
3 checks passed
@pelikhan
pelikhan deleted the copilot/aw-top-10-close-custom-grader-sandbox-escape branch October 10, 2026 22:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[AW Top 10] 09 Close the custom grader sandbox escape

4 participants