Skip to content

fix(opencode): harden runtime image - #2

Draft
seonghobae wants to merge 13 commits into
devfrom
apk-cache-cleanup
Draft

seonghobae wants to merge 13 commits into
devfrom
apk-cache-cleanup

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 30, 2026 •

Copy link
Copy Markdown

Issue for this PR

Blocked: repository Issues are disabled. The create-issue API returned HTTP 410 on 2026-09-30 UTC, so a canonical local issue cannot currently be linked. The scanner evidence originates in PR #1. Keep this PR Draft until repository settings and the issue-first policy are reconciled.

Type of change

  • Bug fix
  • New feature
  • Refactor / code improvement
  • Documentation

What does this PR do?

This PR repairs three verified defects at the canonical OpenCode runtime-image boundary:

  1. Trivy DS-0025: apk add retained the downloaded repository index.
  2. Trivy DS-0001: the image used untagged alpine and a dynamic FROM build-${TARGETARCH}.
  3. Trivy DS-0002 plus the independent Semgrep missing-user rule: the final entrypoint ran as root.

The repair uses apk's native --no-cache, pins alpine:3.24.2 to multi-architecture manifest sha256:294b683cb724975bec92580e1e685676bd4b50bda910ddb8c51d4cabeaec77e6, selects the amd64 or arm64 binary through an ephemeral BuildKit mount, and runs the entrypoint as fixed UID/GID 10001 with HOME=/home/opencode. No scanner suppression, allowlist, or gate weakening is included.

Root cause and decision

The runtime Dockerfile, not the organization workflow, owned these findings. A tag-only base was rejected because resolved bytes could change. Duplicated final stages were rejected because they would create two release configurations. Copying both binaries into the final filesystem and deleting one was rejected because the unused binary would remain in an image layer. The selected design preserves the existing BuildKit TARGETARCH contract and fails closed for unsupported architectures.

The executable regression deliberately pins the canonical physical runtime instructions rather than partially emulating Docker or POSIX shell parsing. Trivy remains the independent semantic scanner.

Verification

  • Protected dev@b3f1a96c6dd7adeb28b36dd11add1998fc84d67b reproduced DS-0025.
  • Predecessor exact head 681b65a3c0d9a3af5569bd68caa46ed732e41050 removed DS-0025, then Security Scan run 36771095591, job 110077455374, exposed the same Dockerfile's DS-0001/DS-0002; SAST run 36771095492, job 110077389186, independently exposed the missing final user.
  • The hardening regression was RED against 681b65a…: unpinned base, dynamic final FROM, and no final USER.
  • Bun 1.3.14 executes the production-file regressions GREEN: 3 tests, 0 failures, 4 assertions, including lowercase-final-stage and missing-home negative cases.
  • Trivy v0.70.0 config scan of the repaired production Dockerfile: 0 MEDIUM/HIGH/CRITICAL failures.
  • Docker Hub returned the pinned OCI index on 2026-10-01 UTC with Linux amd64 and arm64 manifests.
  • Predecessor exact head b75ca1ed3dd46dcbfbf663a354b4624e60e7af59 has hosted Trivy and Semgrep proof for the production repair. Fresh hosted build, Security Scan, SAST, and qualifying independent approval are required for successor exact head 9d05f4f11fbd48cd909e5355591a66563010ff12. No container runtime was available locally, so no local image-build success is claimed.

Remaining verified gaps

The full exact-head scans still report inherited dependency findings in github/bun.lock and artifacts/glm52-rise-video/bun.lock, plus missing non-root users in other independently deployed container Dockerfiles. Those findings remain Open in docs/product-technical-gap-baseline.md; this PR does not suppress or claim them.

Screenshots / recordings

Not applicable; this is a runtime-image supply-chain repair with no UI change.

Checklist

  • I have tested my changes locally
  • I have not included unrelated changes in this PR

Status

Proposed / Draft. Linked-issue policy, fresh exact-head Checks, and a qualifying independent approval remain mandatory before Ready or merge.

Add apk's native no-cache option, retain a package-install policy regression, and record exact Trivy RCA plus the remaining runtime-image gaps.
@coderabbitai

coderabbitai Bot commented Sep 30, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

This PR doesn't fully meet our contributing guidelines and PR template.

What needs to be fixed:

  • PR description is missing required template sections. Please use the PR template.

Please edit this PR description to address the above within 2 hours, or it will be automatically closed.

If you believe this was flagged incorrectly, please let a maintainer know.

@github-actions

Copy link
Copy Markdown

Thanks for your contribution!

This PR doesn't have a linked issue. All PRs must reference an existing issue.

Please:

  1. Open an issue describing the bug/feature (if one doesn't exist)
  2. Add Fixes #<number> or Closes #<number> to this PR description

See CONTRIBUTING.md for details.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Exact-head COMMENT review for 5e7399d2d4d7c532f850d9677e0c954f2adc1421 (tree 423a559790e991c635094c696c1e30872e3afaf0) against protected dev@b3f1a96c6dd7adeb28b36dd11add1998fc84d67b.

RCA is anchored to OpenCode PR #1 Security Scan run 36358142730, job 109060466385, which reported Trivy DS-0025 at the canonical packages/opencode/Dockerfile:7. The RED predicate fails on the protected source because its real RUN apk add lacks --no-cache; the minimal production change uses apk's native option, and the durable package test rejects any future cache-retaining RUN apk add instruction.

This review found no additional blocker inside the claimed five-file boundary. It is COMMENT evidence, not approval. The remaining Trivy findings are explicitly preserved as Open Gap, and the absence of Bun/container/Trivy locally means fresh exact-head hosted Checks remain mandatory; no full-suite or scanner GREEN is claimed.

Copy link
Copy Markdown
Author

Hosted exact-head Security Scan evidence for 5e7399d2d4d7c532f850d9677e0c954f2adc1421:

  • run 36762591833, Trivy job 110048710614, scanned the published head.
  • DS-0025 is absent from the complete terminal finding inventory, directly proving the apk-cache repair.
  • The job remains correctly FAILURE because 33 unrelated inherited findings remain: dependency CVEs plus DS-0001 and DS-0002. None was excluded, downgraded, or claimed repaired.
  • Scorecard succeeded; skipped gitleaks/dependency-review/OSV lanes reflect changed-scope classification and are not reported GREEN.

Draft / Proposed / merge HOLD remains correct until all required exact-head Checks and qualifying independent review are complete.

Copy link
Copy Markdown
Author

Exact-head hosted RCA for 5e7399d2d4d7c532f850d9677e0c954f2adc1421:

  • Security Scan run 36762591833, job 110048710614 confirms the owned DS-0025 finding is absent after the --no-cache repair. The job still fails on 34 inherited findings: dependency CVEs in artifacts/glm52-rise-video/bun.lock and github/bun.lock, non-root DS-0002 across container Dockerfiles, and mutable/invalid FROM findings DS-0001. Those remain separate canonical-owner Gaps and are not suppressed here.
  • SAST run 36762592125, job 110048646619 reports 302 repository-wide Medium+ findings on protected-base code, including dynamic regex/path joins, shell spawn, missing non-root users, and insecure transport. None is introduced by this five-file delta; the workflow currently has no changed-delta baseline gate, so terminal failure is preserved rather than misreported as this leaf repair's source regression.
  • nix-eval, typecheck, and test remain queued; CodeQL PR is skipped. Queued and skipped are non-passing.
  • The repository has Issues disabled (create-issue API HTTP 410) while CONTRIBUTING requires a linked local issue. The PR template is now satisfied, but the contradictory issue-first gate remains an explicit Draft blocker.

No merge, bypass, suppression, force update, or destructive rebase.

Parse logical Docker RUN instructions, isolate apk add shell commands, and reject unrelated no-cache flags so the regression cannot pass vacuously.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Exact-head follow-up review: the prior regression could miss compound, indented, and line-continued apk installs, and its whole-instruction oracle could accept an unrelated neighboring --no-cache. Commit 2a162da0687855475cd745b1a2ac1010e7670861 adds the reproduced 1/3 RED fixture, parses logical RUN instructions into shell-command segments, reaches 3/3 GREEN, and adds a non-vacuous neighboring-flag case. This is a COMMENT, not an approval; fresh hosted Checks and qualifying independent approval remain required.

Copy link
Copy Markdown
Author

Exact-head evidence update for 2a162da0687855475cd745b1a2ac1010e7670861: Security Scan run 36763669749, Trivy job 110052358753, checked out and uploaded SARIF for this SHA. The log contains no DS-0025; the job remains failed because inherited CVE, DS-0001, and DS-0002 findings are still present. This proves only the apk-cache finding is absent and does not convert the overall security gate to GREEN. test 36763669821, typecheck 36763669495, and nix-eval 36763669744 are queued; Semgrep 36763669779 is in progress. PR remains Draft / merge HOLD.

Handle Docker instruction case, single background operators, and unquoted shell comments while preserving quoted hash literals in the package policy regression.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Exact-head follow-up review after the second independent adversarial pass. RED on 2a162da… reproduced three remaining oracle bypasses: single & borrowed a neighboring flag, an unquoted shell comment supplied a false flag, and lowercase Docker run was missed. Commit 4b1d3c6a89a317e36a126c1435e4d40cd367dadc detects and rejects those unsafe fixtures, preserves quoted #literal, retains the earlier direct/compound/continued cases, and detects the real install with --no-cache. This is COMMENT evidence, not approval; fresh exact-head hosted Checks remain mandatory.

Copy link
Copy Markdown
Author

Fresh exact-head scanner evidence for 4b1d3c6a89a317e36a126c1435e4d40cd367dadc: Security Scan run 36764257762, Trivy job 110054374089, is terminal failure on inherited findings, checked the exact SHA, and contains no DS-0025. This verifies the production apk-cache fix only; it does not make the overall security gate GREEN. test 36764257739 and typecheck 36764257877 remain queued, nix-eval 36764257802 remains pending, and Semgrep 36764257876 remains in progress. Draft / merge HOLD remains correct.

Recognize apk only at command position, reject no-cache redirect targets, and ignore quoted prose so the policy oracle reflects package-manager arguments.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Exact-head follow-up after the third independent adversarial pass. RED on 4b1d3c6… proved that RUN apk add curl > --no-cache borrowed a redirect filename and that RUN echo "apk add curl" was falsely classified. Commit 0e4a032df8c2d64a00a342166a76847dee7b7195 anchors detection at executable command position and accepts the option only before unquoted redirection; it preserves quoted #/> data and all earlier bypass fixtures. This is COMMENT evidence, not approval; fresh exact-head hosted Checks remain mandatory.

Copy link
Copy Markdown
Author

Fresh scanner evidence for final exact head 0e4a032df8c2d64a00a342166a76847dee7b7195: Security Scan run 36764813522, Trivy job 110056271817, checked this exact SHA and contains no DS-0025. It remains terminal RED with inherited DS-0001, DS-0002, and dependency findings; no overall security GREEN is claimed. test 36764813497, typecheck 36764813507, and nix-eval 36764813692 are queued; Semgrep 36764813592 is in progress. PR remains Draft / merge HOLD.

Replace the unsound shell parser with one narrow invariant: every literal apk add in a logical RUN instruction must immediately use unquoted --no-cache. Ambiguous shell forms fail safe.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Exact-head simplification review: repeated adversarial review showed that a bespoke partial shell parser could not support its broad claims. Commit 36cac84ef0379af04484bd8970fe8c3b099aefa6 deletes that parser and enforces one conservative textual invariant over logical Docker RUN instructions: every literal apk add must immediately use unquoted --no-cache. Leading redirections are now detected; ambiguous quoted/comment/redirection forms fail safe and are documented as such. This is COMMENT evidence, not approval; fresh exact-head hosted Checks remain mandatory.

Copy link
Copy Markdown
Author

Fresh final-head scanner evidence for 36cac84ef0379af04484bd8970fe8c3b099aefa6: Security Scan run 36765344259, Trivy job 110058062995, checked the exact SHA and contains no DS-0025. It remains terminal RED with inherited DS-0001, DS-0002, and dependency findings; this is not overall security GREEN. test 36765344023, typecheck 36765344387, and nix-eval 36765344316 remain queued; Semgrep 36765344267 is in progress. Draft / merge HOLD remains correct.

Keep an open logical Docker RUN buffered across blank and comment lines so a later literal apk add cannot escape the conservative no-cache policy.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Exact-head final bounded repair: RED on 36cac84… showed that an open continued RUN was incorrectly closed by an intervening Docker comment/blank line, allowing a later unsafe literal apk add to escape while the production install kept the oracle non-empty. Commit 1cefc5cfd5fd714fbca54c49ef38b7feb8e941fb keeps the buffer open across those lines and the exact fixture is now detected. Contract wording is narrowed to literal whitespace-separated occurrences; nonliteral shell expansions remain outside this regression and under hosted Trivy. COMMENT only; fresh exact-head Checks remain mandatory.

Reject non-default escape directives and RUN heredocs so unsupported logical-instruction syntax cannot bypass the narrow literal apk policy.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Exact-head final Docker-form repair: RED on 1cefc5c… proved that RUN heredocs and a non-default # escape= directive could hide literal unsafe installs from the default-backslash parser. Commit 7ca2330a5f7aa6013caf8dc92ad2c4ac68ec7baa emits explicit noncompliant policy subjects for both unsupported forms and narrows the documented supported syntax accordingly. The current Dockerfile still satisfies the literal immediate-unquoted-option invariant. COMMENT only; fresh exact-head hosted Checks remain mandatory.

Treat any heredoc operator in a RUN as unsupported so quoted and unquoted delimiter variants all fail closed.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Exact-head quoted-heredoc repair: predecessor 7ca2330… matched only unquoted word delimiters. Commit 51202d464677f4280cf8a853d9f6e5a070540951 conservatively rejects any << or <<- operator in a RUN, so unquoted, single-quoted, double-quoted, and tab-stripping heredoc variants all emit a failing policy subject. This remains COMMENT evidence, not approval; fresh exact-head hosted Checks are required.

Copy link
Copy Markdown
Author

Final exact-head evidence for 51202d464677f4280cf8a853d9f6e5a070540951: independent bounded delta review reported no findings after quoted/unquoted/<<- heredoc and non-default escape cases were made fail-closed. Security Scan run 36766596756, Trivy job 110062288585, checked this exact SHA and contains no DS-0025; it remains RED on inherited DS-0001, DS-0002, and dependency findings. test 36766596449, typecheck 36766596582, and nix-eval 36766596525 remain queued; Semgrep 36766596552 is in progress. This is not an APPROVED review or overall GREEN; Draft / merge HOLD remains correct.

Reject unescaped line continuations instead of partially emulating BuildKit, preserve escaped trailing backslashes, and ignore heredoc-like quoted data and late directive comments.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Exact-head follow-up review for 9846ad71911497fd7bd5f046379bfb8a07faca53. Independent review reproduced four predecessor fail-open paths caused by partial BuildKit continuation emulation (ap\\\nk add, a split heredoc operator, an EOF continuation, and an escaped trailing backslash swallowing the next instruction) plus two false positives (quoted << data and a late directive-shaped comment). The repair deletes continuation joining, fails closed on odd/unescaped trailing backslashes, preserves escaped pairs, scans each following instruction independently, recognizes heredoc operators only outside quotes, and limits escape-directive handling to the pre-instruction area. The predecessor predicate is RED on the added fixtures; Node 24.19.0 syntax validation and a Bun-compatible six-test mirror are GREEN. This is COMMENT evidence, not approval; fresh exact-head hosted Checks remain mandatory.

Repair exact-head identifier errors, replace the vacuous newline fixture, reject quoted/commented apk literals, and distinguish late directives and arithmetic shifts from unsupported forms.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Exact-head RCA follow-up: independent review proved predecessor 9846ad71911497fd7bd5f046379bfb8a07faca53 had two remote-only identifier errors plus four oracle defects (vacuous literal \\n, compliant-looking quoted/commented literals, parser-directive preamble overreach, and arithmetic-shift/heredoc confusion). Successor f7ffe1e4a3f2c677f55e7b38709c1952428aedb5 repairs the published source and adds executable fixtures for every miss. Node 24 Bun-compatible execution mirror: 9/9 PASS, including the production Dockerfile assertion. Hosted exact-head Checks and qualifying independent approval remain mandatory; PR stays Draft.

Copy link
Copy Markdown
Author

Hosted exact-head evidence for f7ffe1e4a3f2c677f55e7b38709c1952428aedb5: Security Scan run 36770313364, Trivy job 110074766514, checked out and verified that exact SHA. DS-0025 is absent. The run remains FAILURE on inherited CVEs plus DS-0001/DS-0002; those findings are not hidden or claimed fixed. SAST/typecheck/test/nix-eval remain pending and CodeQL is skipped while Draft, so merge remains HOLD.

Remove the speculative Docker/shell parser and assert the exact runtime package-install instruction. Trivy remains the whole-tree semantic verifier.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Exact-head repair: fresh review of f7ffe1e4a3f2c677f55e7b38709c1952428aedb5 proved the generic shell oracle remained bypassable by literal quote concatenation and vacuous control-operator comments. 681b65a3c0d9a3af5569bd68caa46ed732e41050 removes that speculative parser and pins the canonical physical RUN apk add --no-cache libgcc libstdc++ ripgrep instruction. Protected-base fixture is RED; Node 24 Bun-compatible production assertion is 1/1 PASS. Hosted exact-head Checks and qualifying independent approval remain mandatory; Draft/merge HOLD is preserved.

Copy link
Copy Markdown
Author

Current exact-head evidence for 681b65a3c0d9a3af5569bd68caa46ed732e41050: Security Scan run 36771095591, Trivy job 110077455374, verified the exact SHA. DS-0025 is absent. The run remains FAILURE on 25 inherited CVE records plus 2 DS-0001 and 7 DS-0002 records; none are masked or claimed repaired. SAST and product Checks remain pending/queued, CodeQL is skipped while Draft, and qualifying APPROVED count remains zero.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fresh bounded exact-head review found no concrete defect in 681b65a3c0d9a3af5569bd68caa46ed732e41050. Remote/local blobs match; the predecessor parser was deleted (180 lines removed) and the remaining 11-line production assertion is non-vacuous within its documented scope. Protected-base, empty, missing, duplicate, and directly unsafe canonical lines fail exact array equality; the current canonical line passes. Test path resolution, RCA/CHANGELOG scope, and Trivy ownership are consistent. This is a COMMENT review, not qualifying APPROVED authority; hosted product Checks and independent approval remain required.

Copy link
Copy Markdown
Author

Exact-head SAST follow-up for 681b65a3c0d9a3af5569bd68caa46ed732e41050: run 36771095492, job 110077389186, verified the exact SHA and completed FAILURE on the existing full-repository Semgrep inventory. The changed regression file packages/opencode/test/security/runtime-image-apk-cache.test.ts has zero reported findings. A normalized rule/path/line/message comparison against predecessor job 110074716384 found no added or removed finding record, so this commit introduced no SAST delta. The full-repository SAST debt remains open; test/typecheck/nix-eval are still queued and CodeQL remains skipped while Draft.

Copy link
Copy Markdown
Author

Exact-head security RCA for 681b65a3c0d9a3af5569bd68caa46ed732e41050:

  • Security run 36771095591, Trivy job 110077455374, scanned the exact head and failed on 34 real repository-wide Medium/High findings. The log includes vulnerable locks (baseline-browser-mapping, browserslist, fast-uri, nanoid, postcss, undici) and container findings such as missing non-root USER and unpinned FROM images. This is not the earlier mirror BLOB_UNKNOWN: Trivy fell back to GHCR, downloaded the DB, produced SARIF, and the explicit finding gate failed.
  • Semgrep run 36771095492, job 110077389186, produced 302 WARNING/ERROR findings and failed the Medium+ gate. Concrete examples include shell-enabled spawning in packages/opencode/src/util/process.ts:115 and packages/tui/src/editor.ts:36, missing non-root users in Dockerfiles, insecure TLS bypass, path traversal, and dynamic-regexp findings.
  • nix 36771095496, typecheck 36771095659, and test 36771095614 remain queued; queued is not GREEN.

These are owner-repository baseline defects, not a reason to weaken scanners or add broad suppressions in this APK-cache leaf. Keep this PR Draft/HOLD and repair the canonical dependency/container/process boundaries through RED→GREEN owner changes, then non-force integrate/retest this leaf. No rerun, merge, bypass, or close was attempted.

Pin the Alpine multi-architecture manifest, select the requested runtime binary without a dynamic FROM, and drop privileges to a fixed OpenCode identity with an explicit home. Retain RED/GREEN evidence and the remaining shared-container and dependency gaps.
@seonghobae seonghobae changed the title fix(opencode): omit apk cache from runtime image fix(opencode): harden runtime image Oct 1, 2026

Copy link
Copy Markdown
Author

Exact-head source-repair receipt for b75ca1ed3dd46dcbfbf663a354b4624e60e7af59:

  • Security Scan run 36846920652, Trivy job 110319188061, verified the submitted SHA. Findings decreased from 34 to 31. packages/opencode/Dockerfile now has zero findings: both DS-0001 results and its DS-0002 result are absent.
  • SAST run 36846920748, Semgrep job 110319152776, verified the submitted SHA. Findings decreased from 302 to 301 and ERROR findings from 9 to 8. packages/opencode/Dockerfile now has zero findings; the missing-user result is absent.
  • Local Bun 1.3.14: 2 tests, 0 failures, 3 assertions.
  • Local Trivy v0.70.0 config scan of the production Dockerfile: 0 MEDIUM/HIGH/CRITICAL failures.
  • Docker Hub's OCI index for the pinned digest exposes Linux amd64 and arm64 manifests.

The hosted gates correctly remain RED on inherited findings outside this runtime-image delta: two vulnerable lockfiles, six other container Dockerfiles without non-root users, and the existing Semgrep corpus. No suppression or gate weakening was introduced. PR remains Draft/Proposed; queued product Checks and qualifying independent approval are still required.

Count Docker FROM instructions case-insensitively and pin the exact user/group/home creation boundary. Retain lowercase final-stage and missing-home mutations as executable negative cases.

Copy link
Copy Markdown
Author

Independent review of b75ca1ed3dd46dcbfbf663a354b4624e60e7af59 found a P2 regression-oracle gap: the predicate counted only uppercase FROM instructions and asserted HOME without pinning account/home creation.

RCA/RED:

  • Appending from alpine AS bypass plus the expected final USER/ENV/ENTRYPOINT made the predecessor predicate return true.
  • Replacing adduser ... -h /home/opencode with adduser ... -H also returned true, although BusyBox would suppress home creation.

Successor 9d05f4f11fbd48cd909e5355591a66563010ff12 counts FROM case-insensitively, pins the exact group/user/home instructions, and retains both mutations as negative executable cases. Bun 1.3.14: 3 tests, 0 failures, 4 assertions. Production Dockerfile bytes are unchanged from the hosted-scanned predecessor. Fresh successor exact-head Checks and independent review remain required; Draft/Proposed is unchanged.

Copy link
Copy Markdown
Author

Exact-head hosted evidence for 9d05f4f11fbd48cd909e5355591a66563010ff12:

  • SAST Semgrep run 36848110084, job 110323025333, checked out the exact submitted revision (expected_sha = actual_sha = 9d05f4f…). It reports 301 repository findings (8 error, 293 warning), down from the predecessor's 302/9/293; packages/opencode/Dockerfile has zero findings. The remaining findings are outside this bounded runtime-image repair and stay open rather than being suppressed.
  • Security Scan run 36848110099, Trivy job 110323068088, also verified exact checkout and reports 31 inherited findings; packages/opencode/Dockerfile has zero. Remaining paths are dependency locks (25) and other container sources (6).
  • Product test, typecheck, and nix-eval runs are still queued. CodeQL is skipped by workflow policy.

The PR remains Draft/Proposed. These bounded source repairs do not convert inherited repository-wide red gates into GREEN and do not constitute approval or merge authority.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant