Skip to content

fix(security): require explicit SANDBOX_ALLOW_FULL_ACCESS to enable FullAccess policy - #967

Merged
zmanian merged 3 commits into
nearai:stagingfrom
zmanian:security/pr516-fullaccess-rebased
Mar 12, 2026
Merged

zmanian merged 3 commits into
nearai:stagingfrom
zmanian:security/pr516-fullaccess-rebased

Conversation

@zmanian

@zmanian zmanian commented Mar 11, 2026

Copy link
Copy Markdown
Collaborator

Supersedes #516.

Why this replacement exists:

  • the original PR branch lives on difflabai/ironclaw
  • this credential could not push required rebases back to that fork
  • this branch carries the same FullAccess hardening rebased onto current staging

Scope preserved from #516:

  • require explicit SANDBOX_ALLOW_FULL_ACCESS=true opt-in
  • preserve audit visibility for FullAccess execution
  • keep the updated config/test coverage aligned with current staging

Please review/merge this replacement instead of the original blocked PR.

gabehamilton and others added 3 commits March 11, 2026 16:03
…ullAccess policy

FullAccess policy bypasses Docker entirely and runs commands via sh -c
directly on the host. Previously, setting SANDBOX_POLICY=full_access
alone was sufficient to enable this, which could be triggered
accidentally or via prompt injection if tool approval is bypassed.

This adds a double opt-in guard:

- New SANDBOX_ALLOW_FULL_ACCESS=true env var must ALSO be set for
  FullAccess to take effect. Without it, the policy is downgraded to
  WorkspaceWrite with a tracing::error! log.

- At execution time, every FullAccess command emits a tracing::warn!
  with the command and working directory for audit visibility.

- The FullAccess variant now documents its blast radius (host shell,
  unrestricted filesystem/network/environment).

- SandboxConfig and SandboxModeConfig gain an allow_full_access field,
  wired through from_env() and the builder.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
- Add doc comment on builder .policy() warning that FullAccess requires
  .allow_full_access(true) or execution will return SandboxError::Config
- Sanitize audit log: log only binary name instead of full command to
  prevent secret leakage; add [FullAccess] prefix for grep-ability
- Add test_builder_full_access_without_allow_returns_error test covering
  the builder path without explicit allow_full_access(true)
- Fix doc comment mismatch: config.rs and SandboxPolicy::FullAccess docs
  said "will downgrade to WorkspaceWrite" but runtime returns
  SandboxError::Config -- aligned docs with actual behavior

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
…alizers

After upstream merge, src/config/sandbox.rs had two issues:
- Duplicate mod tests block (upstream's original tests at line 271 + our
  new FullAccess guard tests at line 478) caused E0428 compile error
- Upstream test struct literals for SandboxModeConfig were missing the
  new allow_full_access field (E0063)

Fixes: merge the two mod tests into one; add allow_full_access: false to
the sandbox_mode_config_custom_values and sandbox_mode_to_sandbox_config
test struct initializers.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@github-actions github-actions Bot added scope: sandbox Docker sandbox size: M 50-199 changed lines labels Mar 11, 2026
@github-actions github-actions Bot added risk: medium Business logic, config, or moderate-risk modules contributor: core 20+ merged PRs labels Mar 11, 2026
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Summary of Changes

Hello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request significantly enhances the security posture of the sandbox feature by introducing a mandatory double opt-in for the highly privileged FullAccess policy. Previously, setting SANDBOX_POLICY=full_access was sufficient to enable direct host command execution. Now, users must also explicitly set SANDBOX_ALLOW_FULL_ACCESS=true, preventing accidental or unintended execution of commands outside the sandbox environment. This change includes robust validation, automatic policy downgrading, and improved logging for better auditing.

Highlights

  • Double Opt-in for FullAccess Policy: Introduced a new configuration option, SANDBOX_ALLOW_FULL_ACCESS, which must be explicitly set to true to enable the highly privileged FullAccess sandbox policy. If FullAccess is requested without this explicit opt-in, the policy is automatically downgraded to WorkspaceWrite.
  • Enhanced Security and Auditability: Implemented runtime checks to enforce the SANDBOX_ALLOW_FULL_ACCESS requirement, preventing accidental host-level command execution. Added warning logs for FullAccess executions to improve audit visibility, detailing the binary and current working directory.
  • Comprehensive Test Coverage: Added new unit tests to verify that FullAccess policy is correctly downgraded or blocked when SANDBOX_ALLOW_FULL_ACCESS is not set, and that it functions as expected when explicitly enabled.
  • Configuration and Documentation Updates: Updated .env.example with the new SANDBOX_ALLOW_FULL_ACCESS variable and clarified documentation for the FullAccess policy, highlighting its 'BLAST RADIUS' and the double opt-in requirement.
Changelog
  • .env.example
    • Added SANDBOX_ALLOW_FULL_ACCESS variable with a default of false and detailed comments explaining its purpose and implications.
    • Included other Docker Sandbox related variables for clarity.
  • src/config/sandbox.rs
    • Added allow_full_access boolean field to SandboxModeConfig struct.
    • Updated Default implementation to set allow_full_access to false.
    • Modified from_env to parse SANDBOX_ALLOW_FULL_ACCESS from environment variables.
    • Implemented logic in to_sandbox_config to downgrade FullAccess policy to WorkspaceWrite if allow_full_access is false, logging a warning.
    • Added allow_full_access to the SandboxConfig conversion.
    • Added new unit tests (test_full_access_downgraded_without_allow, test_full_access_allowed_with_explicit_opt_in, test_non_full_access_policy_unaffected, test_readonly_policy_unaffected) to verify the new behavior.
  • src/sandbox/config.rs
    • Added allow_full_access boolean field to SandboxConfig struct with extensive documentation on its security implications.
    • Updated Default implementation to set allow_full_access to false.
    • Expanded documentation for SandboxPolicy::FullAccess to detail its "BLAST RADIUS" and the requirement for SANDBOX_ALLOW_FULL_ACCESS=true.
  • src/sandbox/manager.rs
    • Modified execute method to perform a runtime check for self.config.allow_full_access when policy is FullAccess. If false, it returns a SandboxError::Config.
    • Added tracing::warn! log for FullAccess execution, including the binary name and current working directory, to enhance auditability.
    • Updated SandboxManagerBuilder with a new allow_full_access method and enhanced documentation for the policy method, clarifying the double opt-in requirement.
    • Modified existing tests (test_direct_execution_success, test_direct_execution_truncates_large_output) to explicitly set allow_full_access: true.
    • Added new unit tests (test_direct_execution_blocked_without_allow, test_builder_full_access_without_allow_returns_error) to confirm that FullAccess is blocked without explicit allowance.
Activity
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here.

You can also get AI-powered code generation, chat, as well as code reviews directly in the IDE at no cost with the Gemini Code Assist IDE Extension.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution. ↩

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces a critical security enhancement by requiring an explicit opt-in (SANDBOX_ALLOW_FULL_ACCESS=true) to use the FullAccess sandbox policy. The changes are well-implemented with a defense-in-depth approach:

  1. At configuration time, if FullAccess is set without the explicit opt-in, the policy is safely downgraded to WorkspaceWrite with a log message.
  2. At execution time, there's an additional check that returns an error if FullAccess is attempted without being allowed, preventing misuse through direct API calls.
    The changes include updated documentation, configuration examples, and comprehensive tests covering the new logic. My feedback includes a minor suggestion to adjust a log level for better semantic accuracy.

Comment thread src/config/sandbox.rs

// Double opt-in guard: FullAccess requires SANDBOX_ALLOW_FULL_ACCESS=true
if policy == SandboxPolicy::FullAccess && !self.allow_full_access {
tracing::error!(

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

The use of tracing::error! here might be too strong, as the situation is handled gracefully by downgrading the policy to WorkspaceWrite. An error log level typically indicates a failure that prevents an operation from completing, whereas this is a preventative measure for a misconfiguration. Using tracing::warn! would be more appropriate to alert the operator of the misconfiguration and the automatic downgrade without implying a failure.

Suggested change
tracing::error!(
tracing::warn!(

@zmanian
zmanian enabled auto-merge (squash) March 11, 2026 23:31
@zmanian
zmanian merged commit 8bbb43d into nearai:staging Mar 12, 2026
9 checks passed
@ironclaw-ci ironclaw-ci Bot mentioned this pull request Mar 12, 2026
bkutasi pushed a commit to bkutasi/ironclaw that referenced this pull request Mar 28, 2026
…ullAccess policy (nearai#967)

* fix(security): require explicit SANDBOX_ALLOW_FULL_ACCESS to enable FullAccess policy

FullAccess policy bypasses Docker entirely and runs commands via sh -c
directly on the host. Previously, setting SANDBOX_POLICY=full_access
alone was sufficient to enable this, which could be triggered
accidentally or via prompt injection if tool approval is bypassed.

This adds a double opt-in guard:

- New SANDBOX_ALLOW_FULL_ACCESS=true env var must ALSO be set for
  FullAccess to take effect. Without it, the policy is downgraded to
  WorkspaceWrite with a tracing::error! log.

- At execution time, every FullAccess command emits a tracing::warn!
  with the command and working directory for audit visibility.

- The FullAccess variant now documents its blast radius (host shell,
  unrestricted filesystem/network/environment).

- SandboxConfig and SandboxModeConfig gain an allow_full_access field,
  wired through from_env() and the builder.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix(sandbox): address review feedback on FullAccess double opt-in

- Add doc comment on builder .policy() warning that FullAccess requires
  .allow_full_access(true) or execution will return SandboxError::Config
- Sanitize audit log: log only binary name instead of full command to
  prevent secret leakage; add [FullAccess] prefix for grep-ability
- Add test_builder_full_access_without_allow_returns_error test covering
  the builder path without explicit allow_full_access(true)
- Fix doc comment mismatch: config.rs and SandboxPolicy::FullAccess docs
  said "will downgrade to WorkspaceWrite" but runtime returns
  SandboxError::Config -- aligned docs with actual behavior

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix: merge duplicate mod tests; add allow_full_access to struct initializers

After upstream merge, src/config/sandbox.rs had two issues:
- Duplicate mod tests block (upstream's original tests at line 271 + our
  new FullAccess guard tests at line 478) caused E0428 compile error
- Upstream test struct literals for SandboxModeConfig were missing the
  new allow_full_access field (E0063)

Fixes: merge the two mod tests into one; add allow_full_access: false to
the sandbox_mode_config_custom_values and sandbox_mode_to_sandbox_config
test struct initializers.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Gabe Hamilton <gabe@near.ai>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
drchirag1991 pushed a commit to drchirag1991/ironclaw that referenced this pull request Apr 8, 2026
…ullAccess policy (nearai#967)

* fix(security): require explicit SANDBOX_ALLOW_FULL_ACCESS to enable FullAccess policy

FullAccess policy bypasses Docker entirely and runs commands via sh -c
directly on the host. Previously, setting SANDBOX_POLICY=full_access
alone was sufficient to enable this, which could be triggered
accidentally or via prompt injection if tool approval is bypassed.

This adds a double opt-in guard:

- New SANDBOX_ALLOW_FULL_ACCESS=true env var must ALSO be set for
  FullAccess to take effect. Without it, the policy is downgraded to
  WorkspaceWrite with a tracing::error! log.

- At execution time, every FullAccess command emits a tracing::warn!
  with the command and working directory for audit visibility.

- The FullAccess variant now documents its blast radius (host shell,
  unrestricted filesystem/network/environment).

- SandboxConfig and SandboxModeConfig gain an allow_full_access field,
  wired through from_env() and the builder.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix(sandbox): address review feedback on FullAccess double opt-in

- Add doc comment on builder .policy() warning that FullAccess requires
  .allow_full_access(true) or execution will return SandboxError::Config
- Sanitize audit log: log only binary name instead of full command to
  prevent secret leakage; add [FullAccess] prefix for grep-ability
- Add test_builder_full_access_without_allow_returns_error test covering
  the builder path without explicit allow_full_access(true)
- Fix doc comment mismatch: config.rs and SandboxPolicy::FullAccess docs
  said "will downgrade to WorkspaceWrite" but runtime returns
  SandboxError::Config -- aligned docs with actual behavior

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix: merge duplicate mod tests; add allow_full_access to struct initializers

After upstream merge, src/config/sandbox.rs had two issues:
- Duplicate mod tests block (upstream's original tests at line 271 + our
  new FullAccess guard tests at line 478) caused E0428 compile error
- Upstream test struct literals for SandboxModeConfig were missing the
  new allow_full_access field (E0063)

Fixes: merge the two mod tests into one; add allow_full_access: false to
the sandbox_mode_config_custom_values and sandbox_mode_to_sandbox_config
test struct initializers.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Gabe Hamilton <gabe@near.ai>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: core 20+ merged PRs risk: medium Business logic, config, or moderate-risk modules scope: sandbox Docker sandbox size: M 50-199 changed lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants