Close six bypasses Codex found on the round-45 branch. Five harden the workdir-module
import vetter (the only scan of a helper .py the user wrote before import); the sixth
adds an openssl output-file scan.
- ctypes / native modules: the vetter only treated subprocess / pty as execution
modules, so a helper doing import ctypes reached UNGUARDED native libc
(ctypes.CDLL(None).open/write) bypassing the patched Python open / os.open. Refuse
ctypes / _ctypes / cffi and the source-executing runpy / code / codeop.
- dynamic import: a helper bypassed the literal import subprocess check with
importlib.import_module('subprocess'). Refuse import_module / reload whose target
is a denied module (constant or module name); a dynamic import_module target fails
closed.
- closure / frame gadgets: __closure__ / cell_contents / f_locals / __globals__ /
__subclasses__ (etc.) recover a runtime guard wrapper's original unguarded callable
or walk to os / builtins. Refuse the top-level _GADGET_DUNDERS set inside a workdir
helper too.
- indirect import-machinery access: the vetter caught only the literal
sys.meta_path attribute, so vars(sys)['meta_path'][:] = [...] (or
getattr(sys, 'meta_path')) removed the vetter and imported an unscanned sibling.
Refuse getattr / vars namespace-dict access on sys / os / builtins / importlib /
deserializer modules (constant sink name, or a non-constant name that cannot be
proven benign).
- subscripted builtins: imported helpers run with __builtins__ as a dict, so
__builtins__['ev'+'al'](...) reached eval past the attribute checks. Refuse a
subscript into __builtins__ / a builtins alias whose (statically foldable) key is
an execution builtin, and fail closed on a non-constant key.
- openssl output files: openssl rand -out /tmp/p 4 (and -writerand / -keyout /
-CAout / ...) writes a host file in an unguarded child. Block an openssl output-file
flag whose value escapes the workdir; a workdir-local -out and the no-output forms
(openssl rand -hex, openssl dgst) stay allowed. openssl joins the argv tail-scan set
so the subprocess.run(['openssl', ...]) form is covered too.
Regression coverage: TestRound46Bypasses in tests/test_sandbox_tools.py (openssl
escaping output blocked in the shell-string and argv forms; -hex / dgst / workdir-local
-out allowed) and six workdir-module vetter cases in
tests/test_sandbox_runtime_backstop.py (ctypes, dynamic import, __closure__, indirect
vars(sys) meta_path, subscripted __builtins__['eval'] denied; importlib.import_module of
json still allowed).