Repository navigation
Close the custom grader sandbox escape - #67475
Conversation
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
There was a problem hiding this comment.
🟡 Changes recommended
The CLI’s unconditional --permission flag breaks grader execution with Node 20 installations.
1 open finding
What changed in this PR
Restricts custom JavaScript graders using permission-enabled Node subprocesses and VM-realm input reconstruction.
Changes:
- Removes source-pattern blocking.
- Adds subprocess isolation and sandbox-escape regression tests.
- Updates grader security documentation.
| File | Description |
|---|---|
pkg/workflow/graders_config.go |
Removes script blocklist validation. |
pkg/workflow/graders_config_test.go |
Tests blocklist removal. |
pkg/cli/graders_run.go |
Enables Node permissions and clears environment. |
pkg/cli/graders_run.cjs |
Reconstructs inputs inside the VM realm. |
pkg/cli/graders_run_test.go |
Adds CLI sandbox regression tests. |
actions/setup/js/trace_graders.cjs |
Restricts grader subprocess capabilities. |
actions/setup/js/trace_graders_worker.cjs |
Hardens worker context and result serialization. |
actions/setup/js/trace_graders.test.cjs |
Tests process access and command execution. |
docs/src/content/docs/specs/graders-specification.md |
Documents isolation requirements. |
docs/src/content/docs/reference/glossary.md |
Updates grader isolation description. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.
Merge current main, select supported Node permission flags, allow only the canonical runtime file, close the worker bootstrap constructor access, and preserve non-finite grader errors. Add compatibility and regression coverage. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
|
@copilot address the following outstanding work in one pass:
Push the necessary fixes, reply to each listed review thread and resolve it when addressed. Ignore feedback already answered or resolved. Use the pr-finisher skill and stop when only human review or CI remains; do not trigger CI. Sous-chef head: 3c90a73
|
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Completed. |

Inline JavaScript graders ran in Node’s
vmcontext, which is not a security boundary; source-pattern blocking could not prevent sandbox escapes. This change restricts grader subprocesses and removes reliance on the blocklist.processorrequire, or execute a command.