Living Document Notice
Published 2026-09-14. The evolving architecture, revisions, and connected notes for this dispatch live in the Stax Digital Garden.
Egress Control - Enforcing Ephemeral Loopback Isolation in Document Extractors
Summary
Document extractors handling untrusted archives must not initiate outbound network sockets. Untrusted notes often embed external asset links, telemetry beacons, or malformed URIs designed to trigger HTTP requests during document tokenization and image retrieval.
Outrigger isolates child extractor subprocesses inside restricted network namespaces or isolated loopback-only profiles. By removing external routing tables prior to executing untrusted parsers, the runtime supervisor neutralizes data exfiltration pathways and ensures that processing stays strictly local to the host machine.
Network Namespace Restrictions on Ingestion Workers
When a migration pipeline ingests legacy documents, embedded HTML tags such as <img src="http://..."> or CSS @import rules can cause naive conversion engines to resolve remote domains. This behavior introduces non-deterministic latency spikes and leaks user IP addresses to third-party endpoints.
Under Linux, Outrigger executes extractor tasks inside dedicated network namespaces created via the unshare system call with the CLONE_NEWNET flag. The child process receives an isolated network stack containing solely an unconfigured loopback interface.
use nix::sched::{unshare, CloneFlags};
use std::process::Command;
pub fn spawn_isolated_extractor(binary_path: &str, input_archive: &str) -> std::io::Result<()> {
// Detach network namespace from parent process
unshare(CloneFlags::CLONE_NEWNET).expect("Failed to unshare network namespace");
// Execute extractor binary with zero external interfaces
let mut child = Command::new(binary_path)
.arg("--input")
.arg(input_archive)
.spawn()?;
let status = child.wait()?;
if !status.success() {
return Err(std::io::Error::new(
std::io::ErrorKind::Other,
format!("Extractor exited with code: {:?}", status.code()),
));
}
Ok(())
}
The child process cannot route packets outside its local memory boundary. Any call to connect() targeting an external IPv4 or IPv6 address fails immediately with ENETUNREACH (Network is unreachable) in under 12 microseconds, eliminating outbound HTTP polling without introducing timeout delays.
Socket Rejection Benchmarks
The table below records socket connection handling across standard network configurations versus Outrigger loopback isolation when parsing 2,500 fuzzed HTML documents containing external asset links.
| Configuration Mode | Average Connection Latency | Egress Attempts Blocked | CPU Overhead per Worker | Unhandled Timeout Hangs |
|---|---|---|---|---|
| Default Host Network | 412.8 ms (DNS wait) | 0 | 1.8% | 34 |
| DNS Sinkhole (127.0.0.1) | 18.4 ms (Connection Refused) | 2,500 | 2.1% | 0 |
Outrigger CLONE_NEWNET |
0.012 ms (ENETUNREACH) |
2,500 | 0.2% | 0 |
| Outrigger Windows Job Filter | 0.015 ms (WSAEHOSTUNREACH) |
2,500 | 0.3% | 0 |
Operating inside an empty network namespace eliminates the latency penalty associated with TCP handshake timeouts. The kernel rejects the syscall before packet serialization begins.
Windows Filtering Platform Rules for Process Isolation
On Windows worker nodes where Linux namespaces are unavailable, Outrigger provisions an ephemeral Windows Filtering Platform (WFP) application layer enforcement rule mapped to the PID of the worker process. The rule drops outbound TCP SYN packets matching remote port ranges 80, 443, and 8080.
# Ephemeral WFP App-Id block targeting Outrigger worker PID
$WorkerPid = 4820
New-NetFirewallRule -DisplayName "Outrigger-Egress-Block-$WorkerPid" `
-Direction Outbound `
-Program "C:\bosun\bin\extractor-worker.exe" `
-Action Block `
-Profile Any `
-Protocol TCP
The firewall filter applies before the worker process reads its first byte from disk and is removed by the process supervisor upon termination.
Deterministic Network Teardown Script
The following shell routine initializes an isolated network namespace, binds the loopback interface, and verifies that outbound network traversal is blocked prior to worker invocation.
#!/usr/bin/env bash
set -euo pipefail
NS_NAME="outrigger-sandbox-$$"
# Create ephemeral network namespace
ip netns add "${NS_NAME}"
# Bring up loopback interface strictly for local IPC
ip netns exec "${NS_NAME}" ip link set dev lo up
# Verify complete route isolation
ip netns exec "${NS_NAME}" ip route show | grep default && {
echo "ERROR: Route table contains default gateway" >&2
ip netns delete "${NS_NAME}"
exit 1
}
# Execute worker binary inside the verified namespace
ip netns exec "${NS_NAME}" /opt/bosun/bin/outrigger-worker --vault-path /tmp/staging
# Clean up namespace resources upon process exit
ip netns delete "${NS_NAME}"