Close seven follow-up findings Codex raised on the round-36..38 git / env /
import-vetter work (5 P1 bypasses + 2 P2 false positives):
- sys.meta_path mutation (P1): the workdir-module vetter is installed as the first
sys.meta_path finder, but the static analyzer never rejected mutating that list, so
sandboxed code could sys.meta_path.pop(0) (or clear / reassign / del) to drop the
vetter, then write and import a planted evil.py. Deny any Store / Del / mutating
method on sys.meta_path (bound, unbound list.*, subscript, and reassignment);
reading / iterating the list stays allowed.
- env strips git hook suppression (P1): the env-based core.hooksPath suppression only
helps if the child keeps the injected GIT_CONFIG_* vars, but env -i /
--ignore-environment starts git with an empty environment and env -u
GIT_CONFIG_COUNT / --unset=GIT_CONFIG_* removes it, re-enabling a planted
.git/hooks/*. Flag an env wrapper that drops the suppression before a git child
(git-config-env-override). env -i before a non-git command stays allowed.
- git include.path (P1): include.path / includeIf.<cond>.path pull in another config
file whose contents git honors, so an included workdir config can set core.hooksPath
even though the direct key is blocked. Treat any include*.path key as exec-capable in
_git_config_key_is_exec (covers git -c and git config forms).
- pyc-only workdir import (P1): the import vetter only inspected modules whose origin
ends in .py, so a planted sourceless evil.pyc imported via the default bytecode
loader ran unscanned. Refuse any non-source (.pyc / .so / ...) workdir module
outright; only a readable .py is source-scanned.
- from-os sink workdir import (P1): the vetter rejected import subprocess / from
subprocess but not from os import system (a bare sink name), so such a helper ran an
unguarded child at import time. Reject a from os / from posix import of a sink name
(or a star import), and flag an actual sink-named call on any receiver.
- workdir-module attribute FP (P2): the vetter refused any module containing an
attribute named system / popen / ... regardless of receiver, so a benign helper with
a data attribute (p.system = 'linux') failed to import. Scope rejection to actual
sink CALLS and to sink references rooted at os / posix; an unrelated same-named
attribute is no longer a sink.
- single-quoted command-sub FP (P2): the sensitive-read scanner extracted $() /
backtick payloads without tracking quote state, so echo '$(cat /etc/passwd)' (a
literal, since single quotes suppress substitution in POSIX) was blocked as a secret
read. Track single / double quote state in _extract_command_subs; substitutions
inside double quotes are still extracted.
Regression coverage: TestRound39Bypasses in tests/test_sandbox_tools.py (meta_path
mutation, env -i/-u git strip, include.path, double-quote-sub still blocks, plus a
benign-allowed set incl. the single-quote literal) and three workdir-module import
tests in tests/test_sandbox_runtime_backstop.py (pyc-only denied, from-os denied,
benign same-named attribute allowed).