Run the server in a sandboxed container (Dockerfile, tests that prove each flag) - #51
Merged
Merged
Conversation
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- Docs pin the image build to v0.3.4 (v0.3.3 predates the Dockerfile). - Windows: use PowerShell or WSL, or MSYS_NO_PATHCONV=1 in Git Bash. - Native-Linux restore written out; a separate cache volume per form. - core.autocrlf on Windows hosts: .gitattributes or GIT_CONFIG_* env. - CI claims narrowed to what the sandbox job actually runs. - Negative control asserts the exact six expected failures of seven. - no-new-privileges wording; Dependabot ignores SDK major bumps. - README section shortened; SECURITY.md holds the details. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Level 1 of the sandbox roadmap: the whole server can run in a container. That covers all three places repository code executes: solution load (design-time builds), builds and tests, and restore.
What's in it
Dockerfile:mcr.microsoft.com/dotnet/sdk:10.0, pinned by digest;mcp(uid 10001);safe.directory '*', so git mode works on the bind-mounted repo;/nuget(mode 1777) for the native-Linux--userform.tests/Sandbox.Fixtures(not in the solution): seven tests that read the kernel's own state:NoNewPrivs;memory.maxandmemory.swap.max;pids.max;sandboxjob (ubuntu-latest, native-Linux form):--help, and a stdio handshake asserting 37 tools;core.autocrlf), Windows shells, and what the container does not protect.Review
Two Opus rounds.
Round 1: 6 majors and 10 minors. Among them:
--memorywithout--memory-swap;dotnet_test_affected;All fixed and verified by the reviewer: removing any single flag fails exactly its own test.
Round 2: 15 of 16 confirmed fixed. The new findings (1 major, 4 minors, 4 nits) were fixed by the lead session:
v0.3.3, which predates the Dockerfile; it's nowv0.3.4;core.autocrlf.Verified locally
The CI job's steps, run word for word on Docker Desktop:
--helpworks, and the stdio handshake lists 37 tools;--userform;Release note
The docs point to
docker build …DotNetDevMCP.git#v0.3.4. Cut v0.3.4 right after merging so that command works.🤖 Generated with Claude Code