Add a sandbox enforcement test job that runs a probe corpus against the shipped sandbox

Problem

We have no test anywhere that confirms a sandbox actually enforces the policy we hand it.

The only coverage today lives in ee/spec/lib/gitlab/duo_workflow/sandbox_spec.rb in the monolith, and it is unit-level: it asserts on the generated shell strings and on the JSON passed to srt. Nothing executes a sandbox and checks that a blocked operation actually fails. That means the srt config has never been confirmed as enforced either, not just the new nono path.

This surfaced during AppSec review of the nono (Landlock) sandbox MR: gitlab-org/gitlab!252331 (comment 3760245705)

Why this repo

The test needs a real Linux kernel and the sandbox binaries on PATH, so it does not belong in the monolith's RSpec suite. Putting it here means it sits next to the thing it validates and runs whenever the image or the sandbox version is bumped, which is exactly when enforcement is most likely to regress.

Proposal

Add a CI job that runs a corpus of probes against whichever sandbox the image ships, asserting each probe is blocked or allowed as expected. The corpus should be sandbox-agnostic so the same job can be pointed at srt, at nono, and at any future sandbox or new release of an existing one.

Probes to cover, at minimum:

  • Read ~/.ssh (must be blocked)
  • Write outside the workspace and /tmp (must be blocked)
  • Write inside the workspace and /tmp (must be allowed)
  • Reach a non-allowlisted domain (must be blocked)
  • Reach an allowlisted domain (must be allowed)
  • Non-HTTP egress (behaviour currently unknown, needs to be pinned down)
  • Reach an RFC1918 address (nono reportedly allows these by default, which may differ from srt)

The last two are open questions rather than known-good expectations. Part of the value here is establishing what the current behaviour actually is, then locking it in.

Acceptance criteria

  • A probe corpus exists in this repo, expressed so it can run against any sandbox binary
  • A CI job runs the corpus against the sandbox shipped in each image variant
  • The job fails the pipeline when a probe that should be blocked succeeds
  • Results for srt and nono are captured and compared, so any behavioural difference between them is visible
  • Non-HTTP egress and RFC1918 behaviour are documented based on observed results

References