Devlog

A real machine to break into

Gate D: the sandbox proves it has no way out. Then Mission 001's privesc chain passes end to end on a live container.

Written after the fact, from the commit history and the design logs.

Mission 001’s target is not a text file pretending to be a server. It is a real Docker container: an SSH daemon and nginx on a private bridge network, started per session.

The test that mattered was Gate D, the network isolation proof. It ran in February and again today, and passed every check both times: the sandbox has no default route, egress is blocked (ping, curl, raw TCP to the outside all fail), DNS is dead, and yet attacker-to-target traffic flows exactly as it should. A player can break into the box. The box cannot reach anything else, including the internet and the host.

Today the preflight ran the mission as designed, end to end: log in with the weak account, try to read the flag, get denied, escalate through the intended path, read it. The container’s content checks passed too.

Why this mattered: it was the difference between “hacking” as scripted text and an actual machine behaving like a machine. And it is also the part of the old architecture that cannot ship. A Steam demo cannot ask players to install Docker and Postgres. That realism now has to live inside Drift Core’s modelled hosts, with golden transcripts proving the model earns the trade. The container stays in the repo as the reference implementation the model is tested against.