You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Part of #108 · Phase 6 · label: red-team · Do this after Phases 0-5, not before.
Red-teaming a codebase whose test suite cannot run and whose cloud path has never executed would just rediscover known defects. This issue is for adversarial review of the hardened system.
Scope
1. The remote -> local trust boundary
The deepest structural risk (see the Phase 3 security issue). Once payload authentication lands, attack it:
Tampered result.pkl with a valid-looking structure -> must be rejected
Replayed payload from a previous job -> must be rejected
Malicious error.pkl (the error path is easy to forget to authenticate)
A job that writes an oversized/zip-bomb result -> must fail gracefully, not OOM the client
Confirm the restricted unpickler cannot be escaped via __reduce__
Tracked as a sub-issue of #160 (deferred). Consolidated after a three-agent audit that verified every open issue against the code; see #160 for the plan and the ordering.
Part of #108 · Phase 6 · label: red-team · Do this after Phases 0-5, not before.
Red-teaming a codebase whose test suite cannot run and whose cloud path has never executed would just rediscover known defects. This issue is for adversarial review of the hardened system.
Scope
1. The remote -> local trust boundary
The deepest structural risk (see the Phase 3 security issue). Once payload authentication lands, attack it:
result.pklwith a valid-looking structure -> must be rejectederror.pkl(the error path is easy to forget to authenticate)__reduce__2. Injection into generated remote scripts
Script generation concatenates strings (
utils.py:1149-1186,executor_kubernetes.py:152-243,executor_cloud.py:376-414), andutils.py:1123emits unquotedexport {var}={value}.memory,time,partition,queue, env var names/values,remote_work_dir,cluster_name$(...), backticks, null bytes, unicode lookalikes3. Serialization / function-capture fuzzing
utils.py:81'seval(range_part)replacement cannot be driven to execute arbitrary codeexecutor_kubernetes.py:217'sexec(cleaned_source, ...)reconstruction is safe or gone4. Credential handling
/proc/<pid>/environin a way that surprises, a log, a traceback, or a temp file that outlives the process5. Concurrency and resource exhaustion
executor_cloud.py:438under concurrent mutation6. Cost safety
Method
bandit/pip-audit/ CodeQL wired into CIAcceptance criteria