-
Notifications
You must be signed in to change notification settings - Fork 70
fix(broker): scope credentials passed to spawned workers #1854
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from all commits
Commits
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,78 @@ | ||
| //! Relay-owned credentials a spawned process must not inherit from the | ||
| //! spawning process's environment. Every agent worker and every spawn-time | ||
| //! helper (MCP registration, model probes, session pre-creation) strips this | ||
| //! list first; a worker then receives only what it is meant to hold through an | ||
| //! explicit `Command::env`, which still wins after the scrub. | ||
|
|
||
| use tokio::process::Command; | ||
|
|
||
| pub const INHERITED_RELAY_CREDENTIAL_ENV_KEYS: &[&str] = &[ | ||
| // The broker's local HTTP API key (set on the broker process at startup). | ||
| "RELAY_BROKER_API_KEY", | ||
| // The node's control-plane credential. | ||
| "RELAY_NODE_TOKEN", | ||
| // The broker's own registration identity proof. | ||
| "RELAY_AGENT_IDENTITY_KEY", | ||
| // Whoever launched the broker; each worker gets its own. | ||
| "RELAY_AGENT_TOKEN", | ||
| "AGENT_RELAY_RESULT_TOKEN", | ||
| // Workspace credentials. Re-added from the broker's explicit worker | ||
| // environment when the broker delegates them; never taken from ambient | ||
| // environment. | ||
| "RELAY_API_KEY", | ||
| "RELAY_WORKSPACE_KEY", | ||
| "AGENT_RELAY_WORKSPACE_KEY", | ||
| "RELAY_WORKSPACES_JSON", | ||
| ]; | ||
|
|
||
| /// Remove [`INHERITED_RELAY_CREDENTIAL_ENV_KEYS`] from a command's inherited | ||
| /// environment. Call before applying the command's own environment: a later | ||
| /// `Command::env` for the same key still wins. | ||
| pub fn remove_inherited_relay_credentials(command: &mut Command) { | ||
| for key in INHERITED_RELAY_CREDENTIAL_ENV_KEYS { | ||
| command.env_remove(key); | ||
| } | ||
| } | ||
|
|
||
| /// A `Command` for `program` that does not inherit relay credentials. Use it for | ||
| /// every process the broker starts on an agent's behalf, including spawn-time | ||
| /// helpers that never become the agent (MCP registration, model probes). | ||
| pub fn scrubbed_command(program: impl AsRef<std::ffi::OsStr>) -> Command { | ||
| let mut command = Command::new(program); | ||
| remove_inherited_relay_credentials(&mut command); | ||
| command | ||
| } | ||
|
|
||
| #[cfg(test)] | ||
| mod tests { | ||
| use super::*; | ||
|
|
||
| #[test] | ||
| fn scrubbed_command_removes_every_relay_credential() { | ||
| let mut command = scrubbed_command("true"); | ||
| command.env("RELAY_AGENT_TOKEN", "own-token"); | ||
| let envs: std::collections::HashMap<_, _> = command | ||
| .as_std() | ||
| .get_envs() | ||
| .map(|(key, value)| { | ||
| ( | ||
| key.to_string_lossy().into_owned(), | ||
| value.map(|v| v.to_owned()), | ||
| ) | ||
| }) | ||
| .collect(); | ||
| for key in INHERITED_RELAY_CREDENTIAL_ENV_KEYS { | ||
| if *key == "RELAY_AGENT_TOKEN" { | ||
| continue; | ||
| } | ||
| assert_eq!(envs.get(*key), Some(&None), "{key} must be removed"); | ||
| } | ||
| // An explicit value set after construction still wins. | ||
| assert_eq!( | ||
| envs.get("RELAY_AGENT_TOKEN"), | ||
| Some(&Some("own-token".into())) | ||
| ); | ||
| // Everything else is left to normal inheritance. | ||
| assert!(!envs.contains_key("PATH")); | ||
| } | ||
| } |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
When spawning Grok, Gemini, or Droid,
build_mcp_argsruns theirmcp remove/addsubprocesses insnippets.rs, while Codex can run its app-server or model probe, all before execution reaches this scrub. Those provider processes therefore still inheritRELAY_BROKER_API_KEY,RELAY_NODE_TOKEN, andRELAY_AGENT_IDENTITY_KEY, exposing the credentials this patch intends to withhold even though the final worker command is clean. Apply the same scrub to every spawn-timeCommand, or sanitize the environment passed into these helpers before invoking them.Useful? React with 👍 / 👎.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Fixed in 30fc1af. The credential list moved into
relay_pty::credentials, with ascrubbed_command(program)constructor. Every spawn-time helper now builds its command through it:mcp add/mcp removesubprocesses (snippets.rs)codex debug models(worker.rs)app-server(relay-pty/codex_session.rs)The broker re-exports the same helper, so worker spawns and helpers share one list. A new unit test asserts that
scrubbed_commandremoves every key and that an explicit value set afterwards still wins. Results: relay-pty 253 passed, broker 1309 passed, clippy-D warningsclean on both libs.