Skip to content

Warn about unmatched Bubblewrap resolver mounts - #1441

Merged
Gudge (MGudgin) merged 1 commit into
mainfrom
user/gudge/mxc_507_dns_warning
Oct 9, 2026
Merged

Gudge (MGudgin) merged 1 commit into
mainfrom
user/gudge/mxc_507_dns_warning

Conversation

@MGudgin

@MGudgin Gudge (MGudgin) commented Oct 7, 2026 •

Copy link
Copy Markdown
Member

This PR adds a conditional Bubblewrap hint when the host /etc/resolv.conf
symlink names an absolute target with no overlapping known mount destination.
It reads the link but does not stat or canonicalize the target or policy
paths; the hint does not assert that DNS is unavailable or change execution.

Part of #507; #1442 covers the cwd hint. Neither PR alone closes #507.
This avoids the independent namespace preflight attempted in #1160.

Details

  • Compare baseline, virtual, and policy mount paths by components so
    unrelated policy grants can still receive an actionable hint.
  • Defer relative and ambiguous paths; symlink aliases and missing files
    can make an absolute-target hint inapplicable.
  • Cover resolver-link shapes and mount-argument parity without touching
    host /etc or changing sandbox mounts.

Tests

  • From src/, cargo fmt --all -- --check: passed.
  • cargo check -p mxc-sdk --all-targets --quiet: passed.
  • cargo clippy -p mxc-sdk --all-targets --quiet -- -D warnings: passed.
  • cargo test -p mxc-sdk --lib bwrap_command --quiet: 52 passed on Windows.
  • cargo check -p mxc-sdk --target x86_64-unknown-linux-gnu --all-targets --quiet: passed.
  • cargo clippy -p mxc-sdk --target x86_64-unknown-linux-gnu --all-targets --quiet -- -D warnings: passed.
  • Native Linux Bubblewrap tests were not run for this tree: WSL command
    execution hung. Earlier WSL runs used the pre-change tree.
Microsoft Reviewers: Open in CodeFlow

@MGudgin
Gudge (MGudgin) requested a review from a team as a code owner October 7, 2026 17:02
Copilot AI balanced review requested due to automatic review settings October 7, 2026 17:02
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Path overlap mishandles separator variants, causing false warnings for covered resolver targets.

1 open finding
What changed in this PR

Adds a conservative Bubblewrap warning when /etc/resolv.conf targets a file hidden from the sandbox.

Changes:

  • Detects hidden direct resolver symlink targets.
  • Retains warnings for SDK/CLI callers.
  • Adds focused tests and backend documentation.
File Description
bwrap_runner.rs Emits and tests resolver warnings.
bwrap_command.rs Determines whether mounts cover the target.
bubblewrap-backend.md Documents warning behavior and remediation.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/mxc-sdk/src/backends/bubblewrap/common/bwrap_command.rs
Copilot AI balanced review requested due to automatic review settings October 7, 2026 17:20
@MGudgin
Gudge (MGudgin) force-pushed the user/gudge/mxc_507_dns_warning branch from cdebf4f to b3cde42 Compare October 7, 2026 17:20
@MGudgin Gudge (MGudgin) changed the title feat(bwrap): warn on clearly hidden resolver symlink targets Warn about hidden Bubblewrap resolver targets Oct 7, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The implementation is conservative, well-tested, and preserves existing mount and execution behavior.

1 open finding

🧠 Review effort: Balanced

Copilot AI balanced review requested due to automatic review settings October 7, 2026 21:53

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

Virtual mounts are incorrectly treated as exposing host resolver files, suppressing required warnings.

0 open findings

1 resolved since last review
Previously missed (2)

In code that hasn't changed since last review

Medium severity Avoid treating tmpfs and symlinks as host-content mounts

src/​mxc-sdk/​src/​backends/​bubblewrap/​common/​bwrap_command.rs:119

/tmp and /var/run are not host-content mounts. --tmpfs /tmp creates an empty filesystem, and --symlink /run /var/run only redirects lookup; neither makes a host resolver file such as canonical /tmp/resolv.conf or /var/run/custom/resolv.conf available. Treating these destinations as overlap therefore suppresses the advisory for targets that are clearly hidden, contrary to the PR's stated behavior (the new test even incorrectly classifies /tmp/resolv.conf as covered). Count only mounts that expose the target's host contents, and handle /var/run by checking the corresponding /run target against actual bind mounts rather than considering the whole subtree covered.

Medium severity Correct test expectation for hidden files under tmpfs

src/​mxc-sdk/​src/​backends/​bubblewrap/​common/​bwrap_command.rs:511

This expectation encodes the same incorrect assumption: Bubblewrap's --tmpfs /tmp is empty and does not expose the host file /tmp/resolv.conf. This case should assert that the target is hidden so the regression test exercises the promised diagnostic.

🧠 Review effort: Balanced


Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.

Comment thread src/mxc-sdk/src/backends/bubblewrap/common/bwrap_runner.rs Outdated
Comment thread src/mxc-sdk/src/backends/bubblewrap/common/bwrap_runner.rs Outdated
Comment thread src/mxc-sdk/src/backends/bubblewrap/common/bwrap_runner.rs Outdated
Comment thread src/mxc-sdk/src/backends/bubblewrap/common/bwrap_command.rs Outdated
This PR adds a conditional mount hint when the host /etc/resolv.conf
symlink names an absolute target with no overlapping known destination.
It reads the link but does not canonicalize or stat target and policy
paths; the hint does not assert that DNS is unavailable.

Details

* Compare baseline, virtual, and policy mounts by path components.
* Defer relative and ambiguous spellings without changing sandbox mounts.
* Test direct and uncertain link shapes with temporary files outside /etc.
* Check emitted mount destinations with default and non-default policies.

Tests

* From src/, cargo fmt --all -- --check: passed.
* cargo check -p mxc-sdk --all-targets --quiet: passed.
* cargo clippy -p mxc-sdk --all-targets --quiet -- -D warnings: passed.
* cargo test -p mxc-sdk --lib bwrap_command --quiet: 52 passed.
* Linux-target mxc-sdk all-target check and Clippy: passed.
* Native Linux Bubblewrap tests not run: WSL command execution hung.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 6f448a40-019f-4bfd-82e0-ec6b7d23c4d8
Generated-with: gpt-6-sol
Copilot AI balanced review requested due to automatic review settings October 8, 2026 20:06
@MGudgin
Gudge (MGudgin) force-pushed the user/gudge/mxc_507_dns_warning branch from 8798aa1 to 019a500 Compare October 8, 2026 20:06
@MGudgin Gudge (MGudgin) changed the title Warn about hidden Bubblewrap resolver targets Warn about unmatched Bubblewrap resolver mounts Oct 8, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The diagnostic warns for chained and ambiguous targets that the stated requirements explicitly defer.

1 open finding

🧠 Review effort: Balanced

Comment thread src/mxc-sdk/src/backends/bubblewrap/common/bwrap_runner.rs
@MGudgin
Gudge (MGudgin) merged commit 39d49d3 into main Oct 9, 2026
31 checks passed
@MGudgin
Gudge (MGudgin) deleted the user/gudge/mxc_507_dns_warning branch October 9, 2026 03:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

feat(bwrap): Improve error reporting for deny by default file system semantics

3 participants