Dogfood reproduction
Discovered while rerunning the public Walk #83 stack from a clean, self-contained Walk repository.
- Walk:
v0.2.8, commit 01eca9ae52e4474bac9ae62dddba78ae32eb0393
- Leash CLI:
native-v0.3.12, commit 6415049
- Leash manager image:
sha256:05022acf2ab6bd73a5e27991a686af4968fcd9fd099d4685dff61017abdbb4e5
- BME:
1.0.0-beta.65
- Target user: non-root UID/GID 1001
The target image was freshly generated by Walk v0.2.8. Both declared runtime directories existed as UID/GID 1001 with mode 0700 and accepted non-root writes before the governed run.
After policy installation and Leash bootstrap completed, the runner printed:
bash: /home/agent/.profile: Permission denied
It then remained silent for more than three minutes. The target container contained only /leash/leash-entry-linux-amd64; bmad-run and the requested command were never launched. No agent request or repository content was sent to an LLM endpoint.
The relevant launcher path is containerLauncher.DetectShell, which probes with docker exec ... bash -lc true and then sh -lc true. The login-shell probe depends on profile reads that the active least-privilege policy can deny, and it has no probe-specific timeout or progress diagnostic.
Expected
Leash must either launch the governed command promptly or fail with a bounded, actionable shell-detection error. Shell discovery must not require widening policy to permit login-profile reads.
Acceptance criteria
- Detect a usable shell without sourcing login profiles (for example a non-login probe or direct executable inspection).
- Bound each container shell probe and report which probe timed out or failed.
- Add a real container regression with a named non-root user and a denied/unreadable
$HOME/.profile; the governed command must still start.
- Cancellation during shell detection must terminate the probe and allow normal container/disposable-state cleanup.
- Preserve existing target user, environment forwarding, interactive TTY behavior, and file/network policy; do not solve this by allowing
.profile.
No host paths, credential contents, tokens, DNS addresses, private repository data, or internal registry details are included here.
Dogfood reproduction
Discovered while rerunning the public Walk #83 stack from a clean, self-contained Walk repository.
v0.2.8, commit01eca9ae52e4474bac9ae62dddba78ae32eb0393native-v0.3.12, commit6415049sha256:05022acf2ab6bd73a5e27991a686af4968fcd9fd099d4685dff61017abdbb4e51.0.0-beta.65The target image was freshly generated by Walk v0.2.8. Both declared runtime directories existed as UID/GID 1001 with mode 0700 and accepted non-root writes before the governed run.
After policy installation and Leash bootstrap completed, the runner printed:
It then remained silent for more than three minutes. The target container contained only
/leash/leash-entry-linux-amd64;bmad-runand the requested command were never launched. No agent request or repository content was sent to an LLM endpoint.The relevant launcher path is
containerLauncher.DetectShell, which probes withdocker exec ... bash -lc trueand thensh -lc true. The login-shell probe depends on profile reads that the active least-privilege policy can deny, and it has no probe-specific timeout or progress diagnostic.Expected
Leash must either launch the governed command promptly or fail with a bounded, actionable shell-detection error. Shell discovery must not require widening policy to permit login-profile reads.
Acceptance criteria
$HOME/.profile; the governed command must still start..profile.No host paths, credential contents, tokens, DNS addresses, private repository data, or internal registry details are included here.