Sub-agent DAG nodes never get the sandbox executor: exec runs on the host with tools.sandbox enabled
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 68/100
Research direction
Start with run_dag() in raven/agent/subagent/dag_runner.py around line 262 and SubAgentDagTool in raven/agent/subagent/dag_tool.py around line 2345. Compare the spawn paths where SubagentManager builds an executor, then verify how the sandbox reaches each DAG node backend. Done means a boxlite DAG node runs uname -s as Linux on macOS and the behavior is covered by a test.
Written by the indexing model from the issue text.
Description
Version: main @ e1769411 (Raven v0.2.1), macOS arm64, boxlite==0.9.5
Config: tools.sandbox = {"backend": "boxlite", "allow_net": false, "extra_volumes": [["<host dir>", "/data", "ro"]]}
What happens: every node of a sub-agent DAG (a mode: dag playbook, or a graph the model submits through run_subagent_dag) runs exec on the host, not in the sandbox VM. A node on the builtin Raven agent that runs pwd; ls /data prints the host workspace path and ls: /data: No such file or directory. The same command through spawn runs inside the VM.
Why: run_dag() takes sandbox: Any = None (raven/agent/subagent/dag_runner.py, signature around line 262) and hands it to each node backend, but SubAgentDagTool calls run_dag(...) (raven/agent/subagent/dag_tool.py, around line 2345) without passing sandbox, so the raven_loop node backend builds its ExecTool on DirectExecutor. SubagentManager builds a real executor with build_executor(self._sandbox_config, ...), but only on the spawn paths.
Why it matters: docs/sandbox/usage.md says Raven "does not silently fall back to host execution". Here it does, silently, on exactly the path most likely to process untrusted input in parallel. A node that reads attacker-controlled text gets a host shell.
Suggested fix: give SubAgentDagTool access to the manager's sandbox config and pass an executor into run_dag (or build one per node the way the spawn path does), and add a test that a DAG node's uname -s is Linux when backend is boxlite on macOS.
- Dominant language
- Python
- Stars
- 4.1k
- Forks
- 94
- Avg merge
- 10h 2m
- Merged PRs (30d)
- 376
Getting set up
This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from EverMind-AI/Raven
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
EverMind-AI/Raven#798 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
EverMind-AI/Raven#797 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
EverMind-AI/Raven#640 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
EverMind-AI/Raven#479 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 1/5 Under an hour Newbie friendliness 75/100
EverMind-AI/Raven#474 · 2 comments ·
Maintainers usually reply within 1 day
All issues in EverMind-AI/Raven
Similar issues
-
Difficulty 1/5 Under an hour Newbie friendliness 72/100
letsencrypt/cp-cps#353 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
PedestrianDynamics/pyFDS-Evac#394 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
DOI-USGS/pywatershed#421 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
python-pillow/Pillow#10087 · 1 comment ·
Maintainers usually reply within 1 day