Files
Mubashir RandClaude Opus 4.8 56d3877d98 fix: sandbox path jail bypassed by a slashless symlink (escape) (#249)
* fix: sandbox path jail bypassed by a slashless symlink (escape)

26-sandbox-runner-denylist: the path jail (_check_path_jail) only resolves and
prefix-checks arguments for which _looks_like_path() is true, which requires a
path separator (or exactly ./..). A symlink whose name has no slash — e.g.
`link.txt` in the project root pointing at /etc/passwd — is therefore never
jail-checked, so `cat link.txt` escapes the jail and reads files outside the
project root, exactly what the module's advertised "symlink-safe path jail" is
meant to prevent. (`sub/link.txt`, having a slash, is correctly denied; the
asymmetry is the tell.)

Also jail-check arguments that exist on disk under the root (os.path.lexists),
so a slashless symlink is resolved and refused. lexists catches the symlink
even when its target is missing.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* test: skip slashless-symlink jail test where symlinks are unsupported

os.symlink raises OSError on Windows without Developer Mode/admin, which
would fail this test spuriously in such CI. Skip instead of failing.

Addresses CodeRabbit review feedback on the PR.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-09-24 13:46:24 +05:30
..