Repository navigation
feat(harness): hidden-access log collected from the macOS sandbox's own denial reports - #591
Merged
Merged
Conversation
…wn denial reports
The postflight excludes any session whose hidden-access log is not
`complete`, and nothing produced one. `hidden_access_log.SandboxReportCollector`
streams the kernel's sandbox denial reports (`log stream`, sender Sandbox)
for the launch window, keeps those whose process name is an executable
admitted by the arm, validator or any prepared worker policy, classifies
targets against the arm's readable and hidden roots (hidden roots win), and
retains the postflight's four-key log beside a collection record (window,
selection, counts, pids, marker outcomes, never targets).
The kernel does not report every denial it enforces: on the development host
it stopped reporting denials by third-party binaries (the admitted uv
interpreter, node) while still reporting Apple-signed ones and enforcing all.
Completeness therefore rests on positive controls: at the start and end of
the window the collector runs the arm's own admitted executable under the
arm's profile against a fresh controller-owned canary and requires the
sandbox to report that exact denial. A missing marker, a late, dead or
killed stream, a reader or teardown failure all leave `complete` false and
the log is always retained. A duplicate summary weighs its N further
occurrences (the first is its own line); rows are parsed, never searched
(the stream escapes slashes). `run_engineering_session` accepts
`hidden_access_log = {"collect": "macos-sandbox-reports"}`, refuses arms
without an interpreter, shell or cat for the markers and dynamically
provisioned workers, and marks the log confinement-active only when the
verified wrapped command runs under the real sandbox-exec. Successors
cse-causal-study-v25 / cse-causal-study-pilot-v11; registry count -> 62.
TRT-6, TRT-3, CON-8, CON-5. Refs #347, #567, ADR-66.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EMTXwWm3ZppWcJvQQw2qbf
This was referenced Sep 14, 2026
Contributor
Author
|
Review findings for PR #591:
I’m fixing these on the PR branch and will follow up with verification results. |
heyong4725
force-pushed
the
feat/sandbox-access-log
branch
from
September 18, 2026 21:33
30a79e0 to
bb69b2c
Compare
Contributor
Author
|
Review resolution for the findings above:
Local verification: 79 collector/confinement tests, 213 matched-session/postflight tests, and 27 freeze-registry tests pass; both new manifests pass |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Scope
Adds a macOS sandbox denial collector for the hidden-access log required by postflight (TRT-3/TRT-6/TRT-9, CON-5/CON-8). This is unscored engineering evidence and does not authorize pilot or confirmatory collection.
The controller starts
log streamfor the launch window, parses sandbox denial reports, selects process names admitted by the arm, validator and prepared workers, and classifies denied targets against the arm's authority roots. It retains the four-keyhidden-access-log.jsonand a companionhidden-access-collection.jsoncontaining the window, counts, process names, PIDs, marker outcomes and coverage, without target paths. Denials by other processes or operations against a canary remain in the event log.At both ends of the window the collector runs an admitted arm executable under the arm's profile against a fresh controller-owned canary. A marker passes only when the stream reports that executable's file-read denial on the exact canary. Missing reports, an unhealthy reader or stream, or any selected process name without a positive control leaves
complete: false. The log is retained even when the launch or teardown fails. Canaries use/private/tmpon macOS and the system temporary directory where that path is unavailable.matched_campaign.pyacceptshidden_access_log: {"collect": "macos-sandbox-reports"}for an engineering session. It refuses dynamic worker policies and arms without a marker-capable executable.adapter_activeis tied to the verified realsandbox-execcommand. The collector source joins the controller files bound by admission.Limits
macOS can enforce a denial without reporting it to the unified log; this was observed for third-party binaries on the development host. A missing positive control excludes the session. Process selection is by name because the report has no ancestry; distinct binaries with the same process name cannot be separated by this sensor. The operator must run one session at a time and avoid simultaneous capability audits. Independent coverage evidence remains necessary before using the log for study collection.
Stack and registrations
This branch includes merged
mainthrough #590 and now targetsmain. It preserves CSE v25 and pilot v11 unchanged and adds append-only CSE v26 and pilot v12 registrations. Their seed commitments are inherited unverified, all pending gates remain pending, and neither authorizes collection.Verification
Locally: 79 collector and confinement tests, 213 matched-session and postflight tests, and 27 freeze-registry tests pass. Both new manifests pass
freeze check --allow-withheld-seeds. Ruff, trace coverage, docs inventory and claim-evidence checks pass. macOS and Linux full CI are running.Refs #347, #567, ADR-66. Original implementation authored with Claude Code; review findings and fixes are recorded in PR comments.