Skip to content

feat(sandbox): quarantine untrusted patch/code/data analysis with exact evidence #9

Description

@seonghobae

Buyer / product boundary

Noema provides an evidence-producing quarantine plane for untrusted repository patches/code/files without exposing reviewer/model/GitHub-write/NVIDIA NIM/OIDC/release/deployment or host-Docker authority to the analyzed workload. Callers receive exact source/patch/runtime/result provenance rather than arbitrary shell authority.

Protected truth — 2026-08-25

Current protected main is GitHub-verified 2c83355529447248c246805d1954f268e027d2ab. The dedicated patch-validator image/runtime/supply-chain slice entered protected history through #407 as squash commit 8ce7c7536888ec0b596e18368eedd9379deec64f and remains present on the current protected lineage. The older #407 integration SHA is historical integration evidence, not the current protected tip.

Phase A — exact-source quarantine: protected

Protected source preserves exact repository/base/head/patch/profile binding; allowlisted validation profiles; strict patch path/mode/hunk/file-count/governance-path validation; exact Git/worktree/tree/object identity; archive/materialized-file parity; descriptor-safe/no-follow/size-bounded reads; bounded no-network/read-only/non-root isolation without Docker socket or privileged credentials; and trusted-host result validation.

Phase B — dedicated validator image: protected

#407 exact head 871490009a65336003047a85b994581ed3e36b44 reached terminal success in Application CI 32619804074, reviewer-ci 32619804030, central Security Scan 32619804069, and dedicated patch-validator-image 32619804032, with zero unresolved review findings, before squash integration as protected commit 8ce7c7536888ec0b596e18368eedd9379deec64f.

Protected source on current main@2c833555... still includes the fully-static scratch runtime, no-network/read-only/numeric-non-root smoke, exact source/image/receipt binding, Trivy/Syft/Grype/CycloneDX/SBOM evidence, pinned scanners, reviewed bundled-runtime identities/provenance/applicability, fail-closed vulnerability thresholds, exact Noema smoke-repository binding and receipt-path identity stability.

Historical predecessor #67 was semantically compared against the integrated successor and closed as superseded without merge. #66 owns protected-main operational image acceptance plus later immutable publication/signing/attestation/activation.

No GitHub release currently exists for Noema. Historical PR-head image evidence does not substitute for protected-main operational acceptance or an immutable published artifact.

Acceptance criteria

Exact-source quarantine

  • Exact-source patch quarantine is protected on current main.
  • Preserve credential-free typed validation profiles and exact source/patch/result evidence binding.
  • Preserve hostile malformed/oversized/path/symlink/special-file/archive/result-channel regressions.
  • Re-run protected-main operational acceptance when this boundary is included in an immutable release candidate; retain exact evidence rather than reusing historical PR checks.

Dedicated image

  • Reconstruct the image/runtime/verifier/reviewer integration on protected lineage.
  • Require exact static-runtime identity and required JavaScript capabilities.
  • Require real no-network/read-only/non-root smoke and exact source/image/receipt binding.
  • Bind SBOM, vulnerability and embedded-runtime inventories to exact image/source identity.
  • Repair builder/runtime/scanner evidence failures test-first without weakening image isolation or scanner threshold.
  • Reject malformed/ambiguous validator-image identities, cross-repository smoke evidence, duplicate CycloneDX image authority and receipt-path replacement.
  • Keep raw scanner evidence distinct from reviewed applicability evidence.
  • Obtain terminal-success dedicated image + application/reviewer/central Security evidence on one unchanged exact head before feat(sandbox): restack patch-validator image on current main #407 integration.
  • Re-read exact head/live base/reviews/scanner authority and merge only the unchanged gate-clean successor.
  • Re-prove protected-main image/runtime operational acceptance through feat(supply-chain): build, attest, and activate the patch-validator image #66's protected workflow_dispatch evidence path on the then-current protected revision.
  • Complete feat(supply-chain): build, attest, and activate the patch-validator image #66 publication/signing/attestation/activation without exposing publication credentials to untrusted execution.

Extended graph/code/data capability

  • Add future capabilities only as versioned allowlisted operation profiles, never arbitrary caller/model commands.
  • Bound file count/bytes, output bytes, CPU, memory, process count, wall time and network authority per profile.
  • Preserve exact source/data/artifact hashes and provenance for every retained result.
  • Add hostile/malformed/oversized/symlink/special-file/fork/network/timeout/forged-result tests per profile.
  • Keep model judgement, sandbox evidence, required checks, formal review, merge, release and deployment as distinct authorities.
  • Reconcile canonical architecture/threat-model/test/traceability documentation only when an extended profile is actually accepted.

Guardrails

No arbitrary model-generated shell command, self-modifying/branch-patching workflow, Docker socket, host-writable final evidence directory, GitHub write/reviewer/model/NVIDIA NIM/OIDC/signing/publication/release/deployment credential exposure, invented outbound license, or claim that sandbox PASS itself is approval/merge/release/acquisition authority.

Related: #5, #27, #29, #66, #407.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: apiAPI, protocol, event, or external contractarea: authAuthentication, authorization, identity, or tenant isolationarea: ci-cdCI, GitHub Actions, checks, release, or supply chainarea: securitySecurity boundary, hardening, or vulnerability preventionpriority: mediumNormal-priority or P2 workstatus: blockedBlocked by conflict, dependency, or required prerequisitetype: featureNew or expanded product capability

    Type

    No type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions