diff --git a/.gitea/workflows/hub-check.yml b/.gitea/workflows/hub-check.yml index 0e4a8a0..a5a6eb6 100644 --- a/.gitea/workflows/hub-check.yml +++ b/.gitea/workflows/hub-check.yml @@ -117,23 +117,21 @@ jobs: - name: Prove real Claude SDK Bash sandbox boundary run: | set -euo pipefail - # The proof requires uid>0, CapEff=0, NoNewPrivs=1. Gitea act often - # runs the job as root; drop to a dedicated user with emptied caps. + # The proof requires uid>0, CapEff=0, and NoNewPrivs=1. Gitea act often + # runs as root; switch to cphci then clear caps under no_new_privs. if ! id cphci >/dev/null 2>&1; then - sudo useradd --create-home --shell /bin/bash cphci + useradd --create-home --shell /bin/bash cphci fi - sudo install -d -o cphci -g cphci -m 0700 /w/t + install -d -o cphci -g cphci -m 0700 /w/t REPO_ROOT="$(cd .. && pwd)" NODE_BIN_DIR="$(dirname "$(command -v node)")" NPX_BIN="$(command -v npx)" - # Vitest/node_modules must be readable by cphci. - sudo chown -R cphci:cphci "$REPO_ROOT/hub" - sudo -u cphci env \ + chown -R cphci:cphci "$REPO_ROOT/hub" + runuser -u cphci -- env \ HOME="/home/cphci" \ PATH="$NODE_BIN_DIR:/usr/local/bin:/usr/bin:/bin" \ CPH_SANDBOX_TEST_ROOT=/w/t \ /usr/bin/setpriv \ - --reuid=cphci --regid=cphci --clear-groups \ --inh-caps=-all --bounding-set=-all --no-new-privs \ bash -lc "cd '$REPO_ROOT/hub' && '$NPX_BIN' vitest run test/integration/agent-sandbox-linux.test.ts"