Skip to content

runner/container: login-shell detection can hang before governed command starts #111

Description

@sixtoad

Dogfood reproduction

Discovered while rerunning the public Walk #83 stack from a clean, self-contained Walk repository.

  • Walk: v0.2.8, commit 01eca9ae52e4474bac9ae62dddba78ae32eb0393
  • Leash CLI: native-v0.3.12, commit 6415049
  • Leash manager image: sha256:05022acf2ab6bd73a5e27991a686af4968fcd9fd099d4685dff61017abdbb4e5
  • BME: 1.0.0-beta.65
  • Target user: non-root UID/GID 1001

The target image was freshly generated by Walk v0.2.8. Both declared runtime directories existed as UID/GID 1001 with mode 0700 and accepted non-root writes before the governed run.

After policy installation and Leash bootstrap completed, the runner printed:

bash: /home/agent/.profile: Permission denied

It then remained silent for more than three minutes. The target container contained only /leash/leash-entry-linux-amd64; bmad-run and the requested command were never launched. No agent request or repository content was sent to an LLM endpoint.

The relevant launcher path is containerLauncher.DetectShell, which probes with docker exec ... bash -lc true and then sh -lc true. The login-shell probe depends on profile reads that the active least-privilege policy can deny, and it has no probe-specific timeout or progress diagnostic.

Expected

Leash must either launch the governed command promptly or fail with a bounded, actionable shell-detection error. Shell discovery must not require widening policy to permit login-profile reads.

Acceptance criteria

  • Detect a usable shell without sourcing login profiles (for example a non-login probe or direct executable inspection).
  • Bound each container shell probe and report which probe timed out or failed.
  • Add a real container regression with a named non-root user and a denied/unreadable $HOME/.profile; the governed command must still start.
  • Cancellation during shell detection must terminate the probe and allow normal container/disposable-state cleanup.
  • Preserve existing target user, environment forwarding, interactive TTY behavior, and file/network policy; do not solve this by allowing .profile.

No host paths, credential contents, tokens, DNS addresses, private repository data, or internal registry details are included here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions