Conversation
The sandbox control listener requires no TLS client certificate; peers prove themselves with the EdDSA session bearer on each RPC. A connection that completed TLS was nevertheless charged one of the 128 control slots and held it indefinitely, so a same-UID workload process reaching the Unix socket could exhaust the capacity the supervisor needs to reconnect. - Acquire the control slot on the first authenticated RPC of a connection and return RESOURCE_EXHAUSTED when none is available. - Arm a 10-second deadline on every connection until a bearer is accepted, and make the gRPC transport report EOF on shutdown so a peer that never sent an HTTP/2 preface is actually torn down. - Admit same-namespace Unix peers only when they are the sandbox or one of its ancestors, so an orphan reparented to PID 1 or a subreaper is rejected even when the sandbox is not PID 1. - Correct comments that described the channel as mutual TLS and document the trust model in the sandbox architecture doc. Signed-off-by: Drew Newberry <anewberry@nvidia.com>
drew
requested review from
a team,
derekwaynecarr,
mrunalp and
sjenning
as code owners
September 27, 2026 00:12
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The sandbox control listener presents a server certificate only and authenticates each RPC with the EdDSA session bearer. A connection that merely completed TLS was still charged one of the 128 control slots and could hold it indefinitely. Because the Docker and Podman control socket is reachable by same-UID workload processes (Landlock does not govern
connect()on a filesystem socket), a hostile workload could exhaust the capacity the supervisor needs to reconnect, which after 30 seconds terminates the workload. This PR charges slots only after authentication, bounds and times out connections awaiting a bearer, and tightens the Unix peer check.Related Issue
No issue required: obvious localized hardening of existing sandbox control-channel admission; no user-visible behavior or API change.
Changes
RESOURCE_EXHAUSTEDwhen none is available, instead of charging it after TLS.init: true).architecture/sandbox.md.Related observations (not changed here)
Reviewing the sandbox/agent split also surfaced design-level points worth a separate discussion. None are addressed by this PR:
Testing
mise run pre-commitpassesmise run testpassesmise run e2e:dockerpassesNew tests in the boundary server Linux module: a raw TLS client with no bearer holds no slot and is closed at the deadline; gRPC with a missing or malformed bearer holds no slot while a valid bearer charges exactly one slot and leaves the unauthenticated pool; an authenticated RPC is refused when slots are exhausted; a full unauthenticated pool closes its oldest connection and waits for the permit before admitting a new peer; a connection waiting for that permit keeps the original deadline. Ran the full
boundary_servermodule (35 tests),mise run pre-commit,mise run test, andmise run e2e:dockeron Linux ARM64. The earlier sandbox and Docker-driver Clippy checks in arust:1.95-bookwormcontainer also passed.Checklist
🤖 Generated with Claude Code