Skip to content

Run the server in a sandboxed container (Dockerfile, tests that prove each flag) - #51

Merged
csa7mdm merged 4 commits into
mainfrom
feat/container-image
Sep 25, 2026
Merged

csa7mdm merged 4 commits into
mainfrom
feat/container-image

Conversation

@csa7mdm

@csa7mdm csa7mdm commented Sep 25, 2026

Copy link
Copy Markdown
Owner

Level 1 of the sandbox roadmap: the whole server can run in a container. That covers all three places repository code executes: solution load (design-time builds), builds and tests, and restore.

What's in it

  • Dockerfile:
    • multi-stage build on mcr.microsoft.com/dotnet/sdk:10.0, pinned by digest;
    • non-root user mcp (uid 10001);
    • safe.directory '*', so git mode works on the bind-mounted repo;
    • setuid/setgid bits stripped;
    • /nuget (mode 1777) for the native-Linux --user form.
  • tests/Sandbox.Fixtures (not in the solution): seven tests that read the kernel's own state:
    • capability bounding set;
    • NoNewPrivs;
    • memory.max and memory.swap.max;
    • pids.max;
    • network interfaces;
    • host mounts;
    • read-only server files and package cache.
  • CI sandbox job (ubuntu-latest, native-Linux form):
    • image build, --help, and a stdio handshake asserting 37 tools;
    • restore, then the fixtures with every flag (all 7 must pass);
    • a negative control without the flags, where exactly the expected six must fail. A build error or a bad mount doesn't count as a pass.
  • Docs: README (short) and SECURITY.md (full) cover the commands for Docker Desktop and native Linux, what each flag blocks, the git-mode caveats (worktrees, core.autocrlf), Windows shells, and what the container does not protect.
  • Dependabot: tracks the base image, ignoring SDK major bumps.

Review

Two Opus rounds.

  • Round 1: 6 majors and 10 minors. Among them:

    • none of the original fixtures proved its control;
    • --memory without --memory-swap;
    • git "dubious ownership" broke dotnet_test_affected;
    • the writable shared NuGet volume.

    All fixed and verified by the reviewer: removing any single flag fails exactly its own test.

  • Round 2: 15 of 16 confirmed fixed. The new findings (1 major, 4 minors, 4 nits) were fixed by the lead session:

    • the image build was pinned to v0.3.3, which predates the Dockerfile; it's now v0.3.4;
    • Git Bash path mangling;
    • the negative control accepted any failure;
    • CI claims were overstated;
    • core.autocrlf.

Verified locally

The CI job's steps, run word for word on Docker Desktop:

  • the image builds;
  • --help works, and the stdio handshake lists 37 tools;
  • restore works in the --user form;
  • 7 of 7 pass with the flags;
  • without the flags 6 of 7 fail, all six expected names, exit 1, so the negative-control assertions match real output.

Release note

The docs point to docker build …DotNetDevMCP.git#v0.3.4. Cut v0.3.4 right after merging so that command works.

🤖 Generated with Claude Code

csa7mdm and others added 4 commits September 25, 2026 06:11
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- Docs pin the image build to v0.3.4 (v0.3.3 predates the Dockerfile).
- Windows: use PowerShell or WSL, or MSYS_NO_PATHCONV=1 in Git Bash.
- Native-Linux restore written out; a separate cache volume per form.
- core.autocrlf on Windows hosts: .gitattributes or GIT_CONFIG_* env.
- CI claims narrowed to what the sandbox job actually runs.
- Negative control asserts the exact six expected failures of seven.
- no-new-privileges wording; Dependabot ignores SDK major bumps.
- README section shortened; SECURITY.md holds the details.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@csa7mdm
csa7mdm merged commit 9d27ae0 into main Sep 25, 2026
7 of 8 checks passed
@csa7mdm csa7mdm mentioned this pull request Sep 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant