Security evaluation of Nono as alternative to SRT

Overview

As part of &22766 and the evaluation in #605838 (closed), Nono is being proposed as a replacement for Anthropic Sandbox Runtime (SRT) for Duo Agent Platform runner sandboxing.

This issue tracks the security evaluation and review of Nono to validate it as a robust security boundary.

Background & Context

The current runner sandbox uses SRT (Anthropic Sandbox Runtime via bubblewrap and Linux mount namespaces), which has significant limitations in non-root or hardened environments (such as FedRAMP images) and requires root or unprivileged user namespaces.

Nono is an alternative sandbox runtime utilizing Linux Landlock for filesystem isolation and a local proxy for network domain filtering, operating without requiring root or namespace capabilities.

Scope of Security Evaluation

  • AppSec Boundary Review:
    • Evaluate Nono's Landlock-based filesystem isolation (read/write restrictions, protection of sensitive directories such as ~/.ssh and credential stores).
    • Review network egress filtering and ensure proxy enforcement cannot be bypassed by child processes or unsetting environment variables.
    • Verify fail-closed behavior across all failure scenarios (ensuring tasks fail rather than execute unsandboxed).
  • Attack Surface & Sandbox Escape Analysis:
    • Assess potential bypass mechanisms, kernel version dependencies, and Landlock ABI compatibility across supported runner host kernels.
    • Evaluate interaction with container runtimes and seccomp profiles.
  • Supply Chain & OSS Review:
    • Review third-party dependency posture, Apache-2.0 license compliance, provenance, and binary verification/pinning for packaging into GitLab runner images.
  • Compliance & Hardened Environments:
    • Review compatibility and security posture for FedRAMP and enterprise hardened runner environments.
Edited by 🤖 GitLab Bot 🤖