Micro-VM guests unconditionally boot with root debug console on vsock 1026
Maintainers usually reply within 1 day
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 67/100
Research direction
Read cmd/ateom-microvm/run.go at guestConfig() and cmd/ateom-microvm/internal/kata/config.go to trace how debug console parameters are added; also check the kata.DebugConsoleDump call sites in run.go. Done when the console parameters are enabled only with --kata-debug=true, production builds and release manifests do not enable them, and the relevant boot and failure paths still work.
Written by the indexing model from the issue text.
Description
This issue was generated as part of an AI review of pre-GA debug and diagnostic surfaces.
Problem Description
In cmd/ateom-microvm/run.go:716-722, guestConfig() unconditionally appends kata.WithDebugConsole() to the guest kernel command line parameters:
func (s *AteomService) guestConfig() (memMiB, vcpus int, kparams string) {
kparams = kata.WithDebugConsole()
if s.kataDebug {
kparams = kata.WithAgentDebug(kparams)
}
return kata.DefaultMemoryMiB, kata.DefaultVCPUs, kparams
}
In cmd/ateom-microvm/internal/kata/config.go:30-44, debugConsoleKernelParams is defined as:
baseKernelParams + " agent.debug_console agent.debug_console_vport=1026"
This configuration is applied on every actor boot, independent of whether the --kata-debug flag is enabled.
Impact
- The in-guest
kata-agentbinds an unauthenticated interactive root shell (/bin/bashor/bin/sh) on vsock port 1026. - Any entity with access to the host-side hybrid vsock socket (
/run/vc/vm/<actorUID>/hybrid.vsockor inside the worker pod) can connect withCONNECT 1026and immediately obtain a root interactive shell inside the tenant's micro-VM without authentication or audit logging. - On container start failures (
startActorContainersandstartRootfsContainer),ateom-microvmcallskata.DebugConsoleDump(run.go:881, 911) to execute shell commands (ip addr,ip route,ip neigh) inside the guest via the debug console and logs the output to host logs.
Proposed Remediation
- Remove
kata.WithDebugConsole()from the default boot parameters inguestConfig(). - Gate
agent.debug_consoleandagent.debug_console_vport=1026strictly behind--kata-debug=truefor local development. - Ensure production builds and release manifests do not enable in-guest debug consoles.
- Dominant language
- Go
- Stars
- 4.4k
- Forks
- 515
- Avg merge
- 2d 13h
- Merged PRs (30d)
- 279
Getting set up
- No Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from agent-substrate/substrate
-
area/security
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
agent-substrate/substrate#2276 ·
Maintainers usually reply within 1 day
-
area/network kind/bug
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
agent-substrate/substrate#2245 ·
Maintainers usually reply within 1 day
-
[Bug]: e2e script flag parsing is brokenPossibly taken @ericcurtin claimed this 1 day ago. Openarea/dev-infra area/tests kind/bug
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
agent-substrate/substrate#2217 · 1 comment ·
Maintainers usually reply within 1 day
-
Reject trailing YAML documents in actor-template create manifestsPossibly taken @ericcurtin claimed this 4 days ago. Openarea/cli kind/bug
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
agent-substrate/substrate#2156 · 1 comment ·
Maintainers usually reply within 1 day
-
area/storage kind/bug
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
agent-substrate/substrate#2155 · 1 comment ·
Maintainers usually reply within 1 day
All issues in agent-substrate/substrate
Similar issues
-
Difficulty 1/5 Under an hour Newbie friendliness 88/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 67/100
vanderheijden86/b9s#20 ·
-
go-battery needs an ndsctl on PATH: TestPurchaseSessionGuardHoldsThroughTheOutcomeUnknownWindow fails on bare hosts (passes with stub)Possibly taken A pull request linked to this issue is open or already merged. Open
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
OpenTollGate/tollgate-module-basic-go#726 ·
Maintainers usually reply within 1 day
-
ux waiting for feedback
Difficulty 2/5 1-3 hours Newbie friendliness 63/100
evcc-io/evcc#34527 · 1 comment ·
Maintainers usually reply within 1 day
-
phase:v3 type:harness
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
Maintainers usually reply within 1 day