copied the orig folder to current folder
This commit is contained in:
@@ -0,0 +1,109 @@
|
||||
# GENERATED — do not edit. Source: scripts/gen-harbor-dockerfiles.ts (fragments + member metadata).
|
||||
# Per-repo harbor task Dockerfile for potion-voice. Node service/lambda; no test suite.
|
||||
|
||||
FROM node:14-bullseye
|
||||
|
||||
# Debian bullseye is archived: repoint apt + skip the date check.
|
||||
RUN printf 'deb http://archive.debian.org/debian bullseye main\ndeb http://archive.debian.org/debian bullseye-updates main\ndeb http://snapshot.debian.org/archive/debian-security/20260901T000000Z bullseye-security main\n' > /etc/apt/sources.list \
|
||||
&& printf 'Acquire::Check-Valid-Until "false";\nAcquire::Retries "5";\n' > /etc/apt/apt.conf.d/99no-check-valid-until \
|
||||
&& apt-get update \
|
||||
&& apt-get install -y --no-install-recommends \
|
||||
sudo \
|
||||
jq \
|
||||
ca-certificates \
|
||||
&& rm -rf /var/lib/apt/lists/*
|
||||
|
||||
# --- Python >=3.10 for the reduced-toolset agent's str_replace_editor ---
|
||||
# str_replace_editor (shebang `python3`) uses dataclass(kw_only=True) → it requires Python
|
||||
# >=3.10. The era-matched base ships Debian's older system python (ruby:3.2.1/3.1.2 → 3.9,
|
||||
# ruby:2.6.6 → 3.7), so install a modern CPython via uv (a single static binary that downloads
|
||||
# a managed interpreter — no compile, no apt, works even on archived buster) and make it the
|
||||
# default `python3`. Without this the agent's file editor can't load and every trial dies at
|
||||
# agent setup (NonZeroAgentExitCodeError). Independent of the repo's own runtime.
|
||||
RUN curl -fsSL https://astral.sh/uv/install.sh | env UV_INSTALL_DIR=/usr/local/bin sh \
|
||||
&& uv python install 3.10 \
|
||||
&& ln -sf "$(uv python find 3.10)" /usr/local/bin/python3 \
|
||||
&& python3 --version
|
||||
|
||||
# Install Claude Code globally (the grader in test.sh runs `claude`). Retry the
|
||||
# network install, then FAIL THE BUILD if `claude` isn't on PATH — a missing grader
|
||||
# CLI silently zeros every reward, so a broken image must NEVER be cached.
|
||||
# NOTE: download-to-file, NOT `curl … | bash` — a pipe returns bash's exit (0 on
|
||||
# empty stdin), masking a failed curl so the retry would break after one attempt.
|
||||
# CLAUDE_CODE_MIN is the oldest CLI the grader model accepts. Referencing it in the RUN
|
||||
# puts it in the layer's cache key, so bumping it rebuilds the install everywhere, and the
|
||||
# assert refuses to cache an image whose installer returned something older.
|
||||
ARG CLAUDE_CODE_MIN=2.1.251
|
||||
RUN for i in 1 2 3; do \
|
||||
if curl -fsSL https://claude.ai/install.sh -o /tmp/claude-install.sh && bash /tmp/claude-install.sh; then break; fi; \
|
||||
echo "WARNING: claude install attempt $i failed; retrying in 5s" >&2; sleep 5; \
|
||||
done; \
|
||||
rm -f /tmp/claude-install.sh; \
|
||||
for p in /root/.claude-code/claude /root/.local/bin/claude "$(find /root -name claude -type f 2>/dev/null | head -1)"; do \
|
||||
[ -n "$p" ] && [ -x "$p" ] && ln -sf "$p" /usr/local/bin/claude && break; \
|
||||
done; \
|
||||
command -v claude >/dev/null 2>&1 || { echo "FATAL: claude CLI not installed (see the install output above) — the grader needs it" >&2; exit 1; }; \
|
||||
_v="$(claude --version 2>/dev/null | grep -oE '[0-9]+\.[0-9]+\.[0-9]+' | head -1)"; \
|
||||
[ "$(printf '%s\n%s\n' "$CLAUDE_CODE_MIN" "$_v" | sort -V | head -1)" = "$CLAUDE_CODE_MIN" ] \
|
||||
|| { echo "FATAL: claude $_v is older than $CLAUDE_CODE_MIN, the minimum the grader needs" >&2; exit 1; }; \
|
||||
echo "claude $_v installed at $(command -v claude)"
|
||||
|
||||
# Install the Codex CLI at BUILD time, like claude: one fetch per image rather than one per
|
||||
# trial. Never fatal — agent-setup still has the network (the DNS jail lands after it), so a
|
||||
# codex-less image costs a slower first trial, not a broken build on a worker's machine.
|
||||
RUN for i in 1 2 3; do \
|
||||
if curl -fsSL https://chatgpt.com/codex/install.sh -o /tmp/codex-install.sh \
|
||||
&& CODEX_INSTALL_DIR=/usr/local/bin CODEX_NON_INTERACTIVE=true sh /tmp/codex-install.sh; then break; fi; \
|
||||
echo "WARNING: codex install attempt $i failed; retrying in 5s" >&2; sleep 5; \
|
||||
done; \
|
||||
rm -f /tmp/codex-install.sh; \
|
||||
if ! command -v codex >/dev/null 2>&1 && [ -x "$HOME/.local/bin/codex" ]; then \
|
||||
ln -sf "$HOME/.local/bin/codex" /usr/local/bin/codex; \
|
||||
fi; \
|
||||
if ! command -v codex >/dev/null 2>&1 && command -v npm >/dev/null 2>&1; then \
|
||||
npm install -g @openai/codex@latest || true; \
|
||||
fi; \
|
||||
command -v codex >/dev/null 2>&1 \
|
||||
&& echo "codex installed at $(command -v codex)" \
|
||||
|| echo "WARNING: codex CLI not installed (see the install output above)" >&2
|
||||
|
||||
# Restrict DNS to the model endpoint when DNSJAIL_ALLOW is set (the agent supplies it).
|
||||
# Source: scripts/lib/dns-jail-container.sh, staged here by build-workspace.sh.
|
||||
COPY dns-jail/ /opt/raccoon-dns-jail/
|
||||
RUN if [ -f /opt/raccoon-dns-jail/dns-jail-container.sh ]; then \
|
||||
install -m 0755 /opt/raccoon-dns-jail/dns-jail-container.sh /usr/local/bin/raccoon-dns-jail \
|
||||
&& sh -n /usr/local/bin/raccoon-dns-jail; \
|
||||
else echo "NOTE: no DNS jail script staged; trials on this image run unjailed" >&2; fi
|
||||
|
||||
# Resolver for the trial DNS allowlist (scripts/dnsjail.py); if this
|
||||
# does not land, trials just run unjailed.
|
||||
RUN (command -v apk >/dev/null 2>&1 && apk add --no-cache dnsmasq bind-tools) \
|
||||
|| (apt-get update && apt-get install -y --no-install-recommends dnsmasq-base dnsutils \
|
||||
&& rm -rf /var/lib/apt/lists/*) \
|
||||
|| true
|
||||
|
||||
USER root
|
||||
|
||||
WORKDIR /workspace
|
||||
COPY workspace/ .
|
||||
|
||||
# Block CC's network tools — agent should execute code locally, not fetch
|
||||
RUN mkdir -p .claude && \
|
||||
echo '{"permissions":{"deny":["WebFetch","WebSearch"]}}' > .claude/settings.json
|
||||
|
||||
RUN git init && \
|
||||
git config user.email "dev@agent" && \
|
||||
git config user.name "Dev" && \
|
||||
git add -A && \
|
||||
git commit -m "initial" --quiet
|
||||
|
||||
# Install JS deps via npm (no yarn.lock committed).
|
||||
RUN npm install --no-audit --no-fund
|
||||
|
||||
# Fail loudly if any load-bearing tool is missing.
|
||||
RUN for t in node npm claude; do \
|
||||
command -v "$t" >/dev/null 2>&1 || { echo "FATAL: required tool '$t' missing from image" >&2; exit 1; }; \
|
||||
done; \
|
||||
echo "toolchain OK"
|
||||
|
||||
CMD ["sleep", "infinity"]
|
||||
@@ -0,0 +1 @@
|
||||
0
|
||||
@@ -0,0 +1,137 @@
|
||||
#!/bin/sh
|
||||
# Restrict this container's DNS to the hosts in DNSJAIL_ALLOW (space-separated), leaving
|
||||
# every other name unresolvable. Runs as root, inside the container.
|
||||
#
|
||||
# Baked into the task images and invoked by the agent (scripts/dnsjail.py); shipped to the
|
||||
# Explore container by the toolkit packaging. Both surfaces run this same file. Supplied from
|
||||
# outside: DNSJAIL_ALLOW, the hosts the agent will actually dial -- every one must resolve or
|
||||
# no jail happens -- and DNSJAIL_ALLOW_EXTRA, nice-to-haves that only warn if they do not.
|
||||
#
|
||||
# An unreachable model endpoint is a dead trial or a dead session, so nothing here is
|
||||
# applied before it is verified, and any doubt leaves the container's DNS untouched.
|
||||
set -u
|
||||
|
||||
STATE=/tmp/.dnsjail
|
||||
CONTROL=example.com # must NOT resolve through us; proves we reached our own filter
|
||||
|
||||
bounded() { if command -v timeout >/dev/null 2>&1; then timeout 5 "$@"; else "$@"; fi; }
|
||||
# Exact match: docker's own embedded resolver is 127.0.0.11, which a prefix match reads as
|
||||
# already-jailed — and then resolv.orig is never captured, so unjail has nothing to restore.
|
||||
jailed_now() { grep -qE '^nameserver[[:space:]]+127\.0\.0\.1[[:space:]]*$' /etc/resolv.conf 2>/dev/null; }
|
||||
|
||||
# Stop only the dnsmasq we started, so a declined run leaves nothing bound on :53 that a
|
||||
# later run could mistake for its own filter.
|
||||
drop_ours() {
|
||||
if [ -s "$STATE/dnsmasq.pid" ]; then
|
||||
pid=$(cat "$STATE/dnsmasq.pid")
|
||||
# /tmp survives docker stop/start but pids restart at 1, so last boot's pid may now be
|
||||
# some service's child. Confirm it is dnsmasq before signalling it.
|
||||
case "$(cat "/proc/$pid/comm" 2>/dev/null)" in
|
||||
dnsmasq) kill "$pid" 2>/dev/null || true ;;
|
||||
esac
|
||||
rm -f "$STATE/dnsmasq.pid" 2>/dev/null || true
|
||||
fi
|
||||
}
|
||||
|
||||
# Never `exit`: a caller may source this, so bailing out has to fall through rather than
|
||||
# end the caller's shell.
|
||||
dnsjail_apply() {
|
||||
required="${DNSJAIL_ALLOW:-}"
|
||||
extra="${DNSJAIL_ALLOW_EXTRA:-}"
|
||||
allow=$(echo $required $extra) # unquoted: collapses to a single-spaced word list
|
||||
# A blank required list means no model endpoint was found: jailing would strand the agent.
|
||||
set -- $required
|
||||
[ $# -gt 0 ] || return 0
|
||||
|
||||
# Already jailed by us, with our resolver alive and the same allowlist? Do nothing. Tearing
|
||||
# down and rebinding :53 races the kernel releasing the socket, and losing that race ends
|
||||
# in a fail-open restore -- so a second apply (the codex fresh path, rejail, run-app) would
|
||||
# silently UNjail a working container.
|
||||
if jailed_now && [ -s "$STATE/dnsmasq.pid" ] &&
|
||||
[ "$(cat "/proc/$(cat "$STATE/dnsmasq.pid")/comm" 2>/dev/null)" = "dnsmasq" ] &&
|
||||
[ "$(cat "$STATE/allow" 2>/dev/null)" = "$required" ] &&
|
||||
[ "$(cat "$STATE/allow-extra" 2>/dev/null)" = "$extra" ]; then
|
||||
return 0
|
||||
fi
|
||||
|
||||
# The state dir has to work first: it holds what unjail restores, and a failed write here
|
||||
# is what would otherwise truncate /etc/resolv.conf. Sticky world-writable so run-app,
|
||||
# running as the container user in Explore, can drop its own lift markers.
|
||||
mkdir -p "$STATE" 2>/dev/null || return 0
|
||||
chmod 1777 "$STATE" 2>/dev/null || true
|
||||
: > "$STATE/.probe" 2>/dev/null || return 0
|
||||
rm -f "$STATE/.probe" 2>/dev/null || true
|
||||
|
||||
# Never forward to ourselves. Re-applying to an already-jailed container would otherwise
|
||||
# read 127.0.0.1 out of resolv.conf and point dnsmasq at its own socket, blackholing
|
||||
# every name.
|
||||
src=/etc/resolv.conf
|
||||
if jailed_now && [ -s "$STATE/resolv.orig" ]; then src="$STATE/resolv.orig"; fi
|
||||
up=$(awk '/^nameserver[ \t]+[0-9]+\./{print $2; exit}' "$src" 2>/dev/null)
|
||||
[ "$up" = "127.0.0.1" ] && up=""
|
||||
|
||||
if [ -n "$up" ] && command -v dnsmasq >/dev/null 2>&1; then
|
||||
srv=""
|
||||
for h in $allow; do srv="$srv --server=/$h/$up"; done
|
||||
drop_ours
|
||||
# cache-size=0: every lookup goes upstream, so a jailed container sees what an unjailed
|
||||
# one would rather than an answer this resolver decided to keep.
|
||||
dnsmasq --no-resolv --no-hosts --listen-address=127.0.0.1 --bind-interfaces \
|
||||
--cache-size=0 --pid-file="$STATE/dnsmasq.pid" --address=/#/ $srv \
|
||||
>/dev/null 2>>"$STATE/dnsmasq.err" || true
|
||||
fi
|
||||
|
||||
# Ask the resolver directly: the model endpoint must answer and the control must not --
|
||||
# otherwise we are looking at somebody else's resolver, not our filter. Only the FIRST
|
||||
# host gates the jail: an extra host that CNAMEs outside the allowlist cannot resolve
|
||||
# through the catch-all, and one of those must not silently disable the whole jail.
|
||||
live=1
|
||||
for h in $required; do
|
||||
bounded nslookup "$h" 127.0.0.1 >/dev/null 2>&1 || { live=""; break; }
|
||||
done
|
||||
if [ -n "$live" ] && bounded nslookup "$CONTROL" 127.0.0.1 >/dev/null 2>&1; then live=""; fi
|
||||
# The extras are reported, never fatal: one that CNAMEs outside the allowlist cannot
|
||||
# resolve through the catch-all, and must not take the whole jail down with it.
|
||||
if [ -n "$live" ]; then
|
||||
for h in $extra; do
|
||||
bounded nslookup "$h" 127.0.0.1 >/dev/null 2>&1 ||
|
||||
echo "dns-jail: $h does not resolve through the jail (CNAME outside the allowlist?)" >&2
|
||||
done
|
||||
fi
|
||||
|
||||
if [ -z "$live" ]; then
|
||||
# Say why. A silent decline is indistinguishable from a jail that worked, and the
|
||||
# reason is usually one line from dnsmasq (gVisor sandboxes, for instance, have no
|
||||
# AF_NETLINK, so dnsmasq cannot start there at all).
|
||||
echo "dns-jail: declined, this container keeps normal network access${DNSJAIL_WHY:-}" >&2
|
||||
[ -s "$STATE/dnsmasq.err" ] && sed 's/^/dns-jail: /' "$STATE/dnsmasq.err" >&2
|
||||
drop_ours
|
||||
# Failing open has to mean actually open, including when an earlier run left this
|
||||
# container jailed.
|
||||
if jailed_now && [ -s "$STATE/resolv.orig" ]; then
|
||||
cat "$STATE/resolv.orig" > /etc/resolv.conf 2>/dev/null || true
|
||||
fi
|
||||
return 0
|
||||
fi
|
||||
|
||||
# Capture what unjail restores — but never overwrite it with an already-jailed file, which
|
||||
# would leave unjail a permanent no-op.
|
||||
if ! jailed_now; then
|
||||
cp /etc/resolv.conf "$STATE/resolv.orig" 2>/dev/null || return 0
|
||||
fi
|
||||
printf '%s\n' "$required" > "$STATE/allow" 2>/dev/null || true
|
||||
printf '%s\n' "$extra" > "$STATE/allow-extra" 2>/dev/null || true
|
||||
# A marker from a run-app that was killed would otherwise keep the jail disarmed forever.
|
||||
rm -rf "$STATE/lifts" 2>/dev/null || true
|
||||
|
||||
# /etc/resolv.conf is a bind mount, so it is truncated in place, never renamed over —
|
||||
# which means the replacement has to be complete BEFORE the write starts. Keep every
|
||||
# non-nameserver directive docker set (options, search).
|
||||
{ printf 'nameserver 127.0.0.1\n'
|
||||
grep -vE '^[[:space:]]*nameserver' /etc/resolv.conf
|
||||
} > "$STATE/resolv.jailed" 2>/dev/null
|
||||
[ -s "$STATE/resolv.jailed" ] || return 0
|
||||
cat "$STATE/resolv.jailed" > /etc/resolv.conf
|
||||
}
|
||||
|
||||
dnsjail_apply || true
|
||||
Reference in New Issue
Block a user