Module: SecurityBox::Envelope

Defined in:
lib/security_box/envelope.rb

Overview

Host-side validation of the guest result envelope.

The guest reports its result either via /work/out.json or, when /work is unavailable, via a sentinel line on stdout (format: __SECURITY_BOX_RESULT__:<token>:<json>). Both embed the per-eval random token the host generated. An envelope is trusted only when it parses, the token matches and every field has the expected type; otherwise nil is returned and the execution is reported as a sandbox failure.

Constant Summary collapse

SENTINEL =

Keep in sync with lib/security_box/guest/main.rb.

"__SECURITY_BOX_RESULT__"

Class Method Summary collapse

Class Method Details

.from_stdout(stdout, token) ⇒ Object

Scans captured stdout for exactly one sentinel line carrying token. Zero or multiple sentinel lines (e.g. a guest forging an extra one) yield nil.



35
36
37
38
39
40
41
42
# File 'lib/security_box/envelope.rb', line 35

def from_stdout(stdout, token)
  prefix = "#{SENTINEL}:"
  lines = stdout.to_s.split("\n").select { |line| line.start_with?(prefix) }
  return nil unless lines.size == 1

  _sentinel, _embedded_token, json = lines.first.split(":", 3)
  parse(json, token)
end

.parse(raw, token) ⇒ Object

Parses raw (JSON text) and validates it against token. Returns the envelope Hash or nil when invalid/untrusted.



21
22
23
24
25
26
27
28
29
30
# File 'lib/security_box/envelope.rb', line 21

def parse(raw, token)
  return nil unless raw.is_a?(String) && token.is_a?(String) && !token.empty?

  envelope = JSON.parse(raw)
  return nil unless valid?(envelope, token)

  envelope
rescue JSON::ParserError, TypeError, ArgumentError
  nil
end