Starlark debug server: bind to loopback by default
Fixed in: Public main-branch fix committed 2026-07-21; first containing release not established
details
- Finding IDs
- F-BAZEL-001-004
- Status
- fixed publicly
- Fixed in
- Public main-branch fix committed 2026-07-21; first containing release not established
- Recorded credit
- Public fix author: twerth. Public 1seal credit and a causal link to our report are not established.
- Note
- The patch adds experimental_skylark_debug_server_address with default 127.0.0.1 instead of a wildcard listener. Debugging must be explicitly enabled and is disabled by default; a user can still configure a network-facing address. This records the matching default-bind correction, not unauthenticated access to ordinary Bazel builds.
F-BAZEL-001-004: Access control. An explicitly enabled debugger should not accept network connections beyond its intended local scope by default. Reviewed 7 Oct 2026. Mechanism assessed by 1seal.
Mechanism source for F-BAZEL-001-004
Security area (1seal assessment): Authorization. An explicitly enabled debugger should not accept network connections beyond its intended local scope by default. Reviewed 7 Oct 2026.