🔒 Fix missing capability checks in std.socket network operations - #109
🔒 Fix missing capability checks in std.socket network operations#109Tcode-Motion wants to merge 3 commits into
Conversation
Added `Capability::Network` checks in `stdlib/src/socket.rs` before `TcpStream::connect` and `TcpListener::bind` to ensure network access is restricted when the capability is denied. Registered the network capability in the `std.socket` module exports. Added `test_socket_module_sandboxing` to explicitly test privileged vs unprivileged contexts. Co-authored-by: Tcode-Motion <188012755+Tcode-Motion@users.noreply.github.com>
|
👋 Jules, reporting for duty! I'm here to lend a hand with this pull request. When you start a review, I'll add a 👀 emoji to each comment to let you know I've read it. I'll focus on feedback directed at me and will do my best to stay out of conversations between you and other bots or reviewers to keep the noise down. I'll push a commit with your requested changes shortly after. Please note there might be a delay between these steps, but rest assured I'm on the job! For more direct control, you can switch me to Reactive Mode. When this mode is on, I will only act on comments where you specifically mention me with New to Jules? Learn more at jules.google/docs. For security, I will only act on instructions from the user who triggered this task. |
Added `Capability::Network` checks in `stdlib/src/socket.rs` before `TcpStream::connect` and `TcpListener::bind` to ensure network access is restricted when the capability is denied. Registered the network capability in the `std.socket` module exports. Added `test_socket_module_sandboxing` to explicitly test privileged vs unprivileged contexts. Co-authored-by: Tcode-Motion <188012755+Tcode-Motion@users.noreply.github.com>
🎯 What: The vulnerability fixed
Missing sandbox enforcement in
std.socketallowed scripts to bypass security restrictions.TcpStream::connectandTcpListener::bindwere being executed without verifying if the executing context had theCapability::Networkpermission.A malicious script running in a restricted sandbox could bypass the security policy to establish outbound network connections or bind to local ports, leading to potential data exfiltration or unauthorized network interactions.
🛡️ Solution: How the fix addresses the vulnerability
Introduced explicit capability checks in
stdlib/src/socket.rsfor bothconnectandlistenstandard functions. Ifctx.config.capabilities.contains(&Capability::Network)evaluates to false, aRuntimeErrorof typeInvalidOperationindicating a security policy violation is returned. The capability was also added to the module'srequired_capabilitieslist, and tests were added to confirm the security sandbox enforcement behaves correctly in both privileged and unprivileged scenarios.PR created automatically by Jules for task 9655494105280129390 started by @Tcode-Motion