Avoid cache ancestor writes in read-only sandboxes #96

Open
ober wants to merge 2 commits from fix/cache-root-existing-ancestors into master
Owner

Change

open_secure_cache_root now opens and validates each existing path component before attempting creation. It calls mkdirat only after openat returns ENOENT, then reopens and validates the component. This lets the bundled jerbuild use a populated cache inside a read-only sandbox.

The existing O_NOFOLLOW, descriptor-based traversal, owner/mode checks, and atomic bundle extraction path remain in place. A focused C test exercises the production function with existing and missing components, a denied mkdirat, a concurrent creator, a symlink substituted during that race, insecure modes, symlinks, and parent traversal. VERSION advances to 0.13.3 as required by repository policy.

Issue #93 concerns a separate MCP launcher/cache selection mismatch; this change addresses the concrete cache-root sandbox failure.

Verification (macOS arm64)

  • make test-secure-cache-root — pass.
  • make binary — pass.
  • make jerboa-smoke — pass, including a fresh bundle extraction and all multicall modes.
  • XDG_CACHE_HOME=/Users/user/work/jerboa-cache-fix/build/jerboa-smoke-cache sandbox-exec -p '(version 1)(deny default)(allow process-exec)(allow file-read*)' /Users/user/work/jerboa-cache-fix/dist/jerbuild --jerboa-home — pass against the populated cache with file writes denied.
  • git diff --check — pass.
## Change `open_secure_cache_root` now opens and validates each existing path component before attempting creation. It calls `mkdirat` only after `openat` returns `ENOENT`, then reopens and validates the component. This lets the bundled `jerbuild` use a populated cache inside a read-only sandbox. The existing `O_NOFOLLOW`, descriptor-based traversal, owner/mode checks, and atomic bundle extraction path remain in place. A focused C test exercises the production function with existing and missing components, a denied `mkdirat`, a concurrent creator, a symlink substituted during that race, insecure modes, symlinks, and parent traversal. `VERSION` advances to 0.13.3 as required by repository policy. Issue #93 concerns a separate MCP launcher/cache selection mismatch; this change addresses the concrete cache-root sandbox failure. ## Verification (macOS arm64) - `make test-secure-cache-root` — pass. - `make binary` — pass. - `make jerboa-smoke` — pass, including a fresh bundle extraction and all multicall modes. - `XDG_CACHE_HOME=/Users/user/work/jerboa-cache-fix/build/jerboa-smoke-cache sandbox-exec -p '(version 1)(deny default)(allow process-exec)(allow file-read*)' /Users/user/work/jerboa-cache-fix/dist/jerbuild --jerboa-home` — pass against the populated cache with file writes denied. - `git diff --check` — pass.
Fix secure cache root traversal under read-only sandbox
Some checks failed
required-ci / gerbil-compat (pull_request) Successful in 4m0s
version-policy / required (pull_request) Successful in 5m32s
required-ci / required (pull_request) Failing after 9m50s
dtrace / freebsd-usdt (pull_request) Has been cancelled
freebsd-required / required (pull_request) Has been cancelled
b45ef9b8ce
Declare cache-root C sources in system manifest
All checks were successful
required-ci / gerbil-compat (pull_request) Successful in 4m7s
version-policy / required (pull_request) Successful in 5m34s
dtrace / freebsd-usdt (pull_request) Successful in 14m24s
required-ci / required (pull_request) Successful in 14m55s
freebsd-required / required (pull_request) Successful in 16m17s
b8aa83a4ac
All checks were successful
required-ci / gerbil-compat (pull_request) Successful in 4m7s
version-policy / required (pull_request) Successful in 5m34s
Required
Details
dtrace / freebsd-usdt (pull_request) Successful in 14m24s
required-ci / required (pull_request) Successful in 14m55s
Required
Details
freebsd-required / required (pull_request) Successful in 16m17s
Required
Details
This pull request has changes conflicting with the target branch.
  • Makefile
View command line instructions

Manual merge helper

Use this merge commit message when completing the merge manually.

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin fix/cache-root-existing-ancestors:fix/cache-root-existing-ancestors
git switch fix/cache-root-existing-ancestors
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
ober/jerboa!96
No description provided.