Skip to content

fix(init-firewall): unblock startup on dead allowlist host (#94) - #96

Merged
gatezh merged 1 commit into
masterfrom
fix/init-firewall-dead-allowlist-host
May 4, 2026
Merged

gatezh merged 1 commit into
masterfrom
fix/init-firewall-dead-allowlist-host

Conversation

@gatezh

@gatezh gatezh commented May 4, 2026

Copy link
Copy Markdown
Owner

What

Fixes #94. init-firewall.sh no longer aborts container startup when an allowlist host stops resolving in DNS, and removes the now-dead statsig.anthropic.com entry that triggered the regression.

Why

statsig.anthropic.com has been retired as part of Anthropic's ongoing migration off Statsig (anthropics/claude-code#7151). The resolver loop in both copies of init-firewall.sh treated any unresolvable host as fatal (exit 1), so VS Code's postStartCommand failed and the devcontainer was unusable for any consumer that bind-mounts these scripts unmodified — including the claude-code template, claude-bun, and this repo's own sandbox. Same upstream bug is open as anthropics/claude-code#55623.

Changes

  • Drop statsig.anthropic.com from the allowlist loop in .devcontainer/claude-sandbox/init-firewall.sh and claude-bun/.devcontainer/init-firewall.sh. statsig.com stays.
  • Make the resolver tolerant: log WARN: Failed to resolve <host> — skipping and continue instead of exit 1. The default-DROP OUTPUT policy plus the explicit REJECT keep the perimeter fail-closed — a skipped host simply gets no allow rule, which is the right posture.
  • Adjacent consistency fix in claude-bun: add -exist to both ipset add calls so duplicate IPs from DNS no longer abort the script. claude-sandbox already used -exist; this brings claude-bun into line and avoids the latent failure mode reported in [BUG] init-firewall.sh fails on duplicate IPs from DNS — container fails to start anthropics/claude-code#35197.

Notes

  • The fail-closed contract is unchanged: any host that fails resolution is silently denied, not allowed.
  • No devcontainer.json, README, or CI workflow changes — same script contract, same invocation path.
  • The claude-code plugin variant doesn't ship its own copy of the script (bind-mount), so its consumers inherit the fix automatically.

Test plan

  • Rebuild claude-sandbox devcontainer: postStartCommand finishes without Failed to resolve aborting the run.
  • Rebuild claude-bun devcontainer: same.
  • In each container, the script's own self-tests pass — https://example.com is blocked, https://api.github.com/zen is reachable.
  • bash -n syntax check on both scripts (already run locally — passes).

`statsig.anthropic.com` no longer resolves (Statsig migration), and the
resolver loop's `exit 1` was killing `postStartCommand` for every
consumer of these scripts. Two fixes:

- Drop `statsig.anthropic.com` from the allowlist in both
  `.devcontainer/claude-sandbox/init-firewall.sh` and
  `claude-bun/.devcontainer/init-firewall.sh`.
- Make the resolver tolerant: log `WARN` and `continue` instead of
  exiting. The default-DROP OUTPUT policy plus the explicit REJECT
  rule keep the perimeter fail-closed — a skipped host gets no allow
  rule, which is the desired posture.

Bundled adjacent consistency fix in `claude-bun`: add `-exist` to the
two `ipset add` calls so duplicate IPs returned by DNS no longer abort
the script (matches the existing `claude-sandbox` script and avoids
the failure mode in anthropics/claude-code#35197).
@gatezh
gatezh merged commit 9d7ff47 into master May 4, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[BUG] init-firewall.sh aborts startup: statsig.anthropic.com no longer resolves

1 participant