Skip to content

Close CMUX local-acceptance child environments - #1091

Merged
teamleaderleo merged 3 commits into
mainfrom
fix/cmux-accept-local-child-env-v2
Sep 21, 2026
Merged

teamleaderleo merged 3 commits into
mainfrom
fix/cmux-accept-local-child-env-v2

Conversation

@teamleaderleo

Copy link
Copy Markdown
Owner

Follow-up repair for the execution-safety finding recorded on merged #1088.

#1088 correctly made accept-local the only path that can mint candidate-eligible CMUX fleet receipts, but its two Python child front doors inherited the full operator environment. That violates docs/AGENT_EXECUTION_SAFETY.md and leaves ambient Python/Git/credential state able to influence acceptance before CMUX's own workload runner closes its child environment.

This repair keeps the same acceptance semantics and closes only that subprocess boundary:

  • both the CMUX profile runner and post-run fleet bootstrap execute through python -I;
  • both receive one explicit environment allowlist;
  • LC_ALL / LANG are fixed to C;
  • TMPDIR is a private mode-0700 directory inside the acceptance attempt;
  • only reviewed toolchain/home path inputs can pass through: PATH, HOME, CARGO_HOME, RUSTUP_HOME, DEVELOPER_DIR;
  • ambient PYTHONPATH, PYTHONHOME, SSH-agent variables, Git redirect variables, credentials/tokens, unrelated locale, and caller TMPDIR are excluded.

Regression coverage injects hostile/sentinel ambient values and proves neither child receives them, while preserving the existing cold-state runner contract and post-run bootstrap flow.

Owned fence: scripts/cmux_fleet.py, scripts/test-cmux-fleet.py, docs/CMUX_FLEET_ENROLLMENT.md.
Excluded: CMUX workload semantics, role/capacity policy, routing, physical lease acquisition, and #1084 execution-role logic.

Because this repairs execution/acceptance authority, final merge requires implementation-independent exact-head acceptance under docs/AGENT_COORDINATION.md.

Related: #1057, #1088, manaflow-ai/cmux#13411.

Copy link
Copy Markdown
Owner Author

@greptile-apps review

Please review exact head 5493fc95e656c09a20f58a8431fa90afb405d425. Focus on the execution-safety boundary: both accept-local Python children now use -I, a shared explicit environment allowlist, forced C locale, and an attempt-private mode-0700 TMPDIR. The regression injects PYTHONPATH/PYTHONHOME/SSH/Git/secret sentinels and asserts neither child receives them.

Copy link
Copy Markdown
Owner Author

@coderabbitai review

Please review exact repaired head 5493fc95e656c09a20f58a8431fa90afb405d425, especially closed child environment / python -I / sentinel leakage.

@coderabbitai

coderabbitai Bot commented Sep 21, 2026

Copy link
Copy Markdown

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

printf '%s\n' '== HEAD =='
git rev-parse HEAD
git status --short
printf '%s\n' '== COMMIT =='
git show -s --format='%H%n%P%n%s' 5493fc95e656c09a20f58a8431fa90afb405d425
printf '%s\n' '== CHANGED FILES =='
git diff --name-status 5493fc95e656c09a20f58a8431fa90afb405d425^ 5493fc95e656c09a20f58a8431fa90afb405d425
printf '%s\n' '== DIFF =='
git diff --find-renames --find-copies --unified=80 5493fc95e656c09a20f58a8431fa90afb405d425^ 5493fc95e656c09a20f58a8431fa90afb405d425 -- scripts/cmux_fleet.py scripts/test-cmux-fleet.py docs/CMUX_FLEET_ENROLLMENT.md
printf '%s\n' '== OUTLINE: scripts/cmux_fleet.py =='
ast-grep outline scripts/cmux_fleet.py --items all --type function,class
printf '%s\n' '== OUTLINE: scripts/test-cmux-fleet.py =='
ast-grep outline scripts/test-cmux-fleet.py --items all --type function,class
printf '%s\n' '== CHILD-PROCESS AND ENVIRONMENT REFERENCES =='
rg -n -C 5 -e 'subprocess\.' -e '\benv\b' -e 'PYTHONPATH|PYTHONHOME|SSH_AUTH_SOCK|GIT_|TMPDIR|LC_ALL|LANG|sys\.executable|python' scripts/cmux_fleet.py scripts/test-cmux-fleet.py

Length of output: 27055


🏁 Script executed:

#!/bin/bash
set -euo pipefail

head=5493fc95e656c09a20f58a8431fa90afb405d425
implementation=635f53691e1c42ac0e24c9ffbc7d3969d3b65689

printf '%s\n' '== IMPLEMENTATION COMMIT AND PATCH =='
git show -s --format='%H%n%P%n%s' "$implementation"
git diff --find-renames --unified=50 "$implementation"^ "$implementation" -- scripts/cmux_fleet.py scripts/test-cmux-fleet.py

printf '%s\n' '== EXACT HEAD: CHILD ENVIRONMENT AND ACCEPT-LOCAL =='
git show "$head:scripts/cmux_fleet.py" | nl -ba | sed -n '1080,1320p'
printf '%s\n' '== EXACT HEAD: TESTS FOR ENVIRONMENT AND BOTH CHILDREN =='
git show "$head:scripts/test-cmux-fleet.py" | nl -ba | sed -n '420,620p'

printf '%s\n' '== EXACT HEAD: ALL SUBPROCESS CALL SITES =='
git show "$head:scripts/cmux_fleet.py" | grep -n -E 'subprocess\.(run|Popen|call|check_call|check_output)|os\.system|exec' -C 9

printf '%s\n' '== EXACT HEAD: ENVIRONMENT AND TEMPORARY-DIRECTORY REFERENCES =='
git show "$head:scripts/cmux_fleet.py" | grep -n -E 'acceptance_child_environment|os\.environ|TemporaryDirectory|mkdtemp|TMPDIR|LC_ALL|LANG|chmod|umask' -C 5

printf '%s\n' '== EXACT HEAD: FILE MODES AND IMPORTS =='
git show "$head:scripts/cmux_fleet.py" | nl -ba | sed -n '1,80p'

Length of output: 52631


🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo="teamleaderleo/glaeda"
head="5493fc95e656c09a20f58a8431fa90afb405d425"

printf '%s\n' '== PR METADATA =='
gh pr view 1091 --repo "$repo" --json number,baseRefOid,headRefOid,commits,files --jq '{
  number,
  baseRefOid,
  headRefOid,
  commits: [.commits[] | {oid: .oid, messageHeadline: .messageHeadline}],
  files: [.files[] | .path]
}'

base="$(gh pr view 1091 --repo "$repo" --json baseRefOid --jq .baseRefOid)"
printf '%s\n' '== BASE-TO-REQUESTED-HEAD STAT =='
git diff --stat "$base" "$head"
printf '%s\n' '== BASE-TO-REQUESTED-HEAD FILES =='
git diff --name-status "$base" "$head"
printf '%s\n' '== BASE-TO-REQUESTED-HEAD DIFF =='
git diff --find-renames --check "$base" "$head"
git diff --find-renames --unified=35 "$base" "$head" -- scripts/cmux_fleet.py scripts/test-cmux-fleet.py docs/CMUX_FLEET_ENROLLMENT.md

Length of output: 29440


@teamleaderleo I reviewed exact commit 5493fc95e656c09a20f58a8431fa90afb405d425.

I found no issues in the requested child-environment boundary.

  • Both Python child processes use sys.executable -I.
  • Both receive the same explicit environment allowlist.
  • LC_ALL and LANG are forced to C.
  • TMPDIR is under the mode-0700 acceptance attempt directory.
  • The allowlist excludes the injected Python, SSH, Git, locale, temporary-directory, and secret sentinel values.
  • The regression coverage checks both child invocations, including -I, the closed environment, and the private TMPDIR.

I did not execute repository tests. The review used static inspection only.

Note: #1091 now has a later commit, 9615cfde5be7dc66308e1121c9ac00a1bc3a68e6. This review applies only to the requested commit.

You are interacting with an AI system.

@teamleaderleo
teamleaderleo force-pushed the fix/cmux-accept-local-child-env-v2 branch from 9615cfd to 64f1bc8 Compare September 21, 2026 19:56
@teamleaderleo teamleaderleo reopened this Sep 21, 2026

Copy link
Copy Markdown
Owner Author

@greptile-apps review

Exact rebased repair head: 17e381506b2eab418a7b15300ab1c293fd8686e6. Review the closed child environment / python -I / sentinel leakage boundary.

Copy link
Copy Markdown
Owner Author

@coderabbitai review

Exact rebased repair head: 17e381506b2eab418a7b15300ab1c293fd8686e6. Review the closed child environment / python -I / sentinel leakage boundary.

@coderabbitai

coderabbitai Bot commented Sep 21, 2026

Copy link
Copy Markdown

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo="teamleaderleo/glaeda"
head="17e381506b2eab418a7b15300ab1c293fd8686e6"

printf '%s\n' '== REQUESTED COMMIT =='
git show -s --format='%H%n%P%n%s' "$head"

printf '%s\n' '== PR METADATA =='
gh pr view 1091 --repo "$repo" --json number,baseRefOid,headRefOid,commits,files --jq '{
  number,
  baseRefOid,
  headRefOid,
  commits: [.commits[] | {oid: .oid, messageHeadline: .messageHeadline}],
  files: [.files[] | .path]
}'

base="$(gh pr view 1091 --repo "$repo" --json baseRefOid --jq .baseRefOid)"
printf '%s\n' '== BASE-TO-REQUESTED-HEAD FILES =='
git diff --name-status "$base" "$head"
printf '%s\n' '== BASE-TO-REQUESTED-HEAD CHECK =='
git diff --check "$base" "$head"
printf '%s\n' '== BASE-TO-REQUESTED-HEAD DIFF =='
git diff --find-renames --unified=45 "$base" "$head" -- scripts/cmux_fleet.py scripts/test-cmux-fleet.py docs/CMUX_FLEET_ENROLLMENT.md

printf '%s\n' '== OUTLINE: scripts/cmux_fleet.py =='
ast-grep outline scripts/cmux_fleet.py --items all --type function,class
printf '%s\n' '== OUTLINE: scripts/test-cmux-fleet.py =='
ast-grep outline scripts/test-cmux-fleet.py --items all --type function,class

printf '%s\n' '== SUBPROCESS AND ENVIRONMENT REFERENCES AT REQUESTED COMMIT =='
git show "$head:scripts/cmux_fleet.py" | nl -ba | grep -E -C 8 'subprocess\.|os\.environ|acceptance_child_environment|TemporaryDirectory|mkdtemp|TMPDIR|LC_ALL|LANG|sys\.executable|python'
printf '%s\n' '== TEST REFERENCES AT REQUESTED COMMIT =='
git show "$head:scripts/test-cmux-fleet.py" | nl -ba | grep -E -C 8 'subprocess\.|PYTHONPATH|PYTHONHOME|SSH_AUTH_SOCK|GIT_|TMPDIR|LC_ALL|LANG|sentinel|environment|sys\.executable|python' || true

Length of output: 55340


@teamleaderleo I reviewed exact commit 17e381506b2eab418a7b15300ab1c293fd8686e6.

I found no issues in the requested child-environment boundary.

  • accept_local() starts both Python children with sys.executable -I.
  • Both children receive the same explicit child_environment.
  • The environment includes only PATH, optional reviewed home/toolchain inputs, LC_ALL=C, LANG=C, and attempt-local TMPDIR.
  • TMPDIR is state_root / "tmp". The code creates it with mode 0700.
  • The environment does not inherit PYTHONPATH, PYTHONHOME, SSH-agent variables, Git variables, credentials, caller locale, or caller TMPDIR.
  • The regression test injects hostile ambient values. It verifies the environment for both child invocations, verifies -I, verifies the forced locale, and verifies the private temporary directory mode.
  • The existing cold-state runner contract remains checked.

I performed static inspection only. I did not execute repository code or tests.

You are interacting with an AI system.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant