mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-09-30 12:43:16 +00:00
Some checks failed
CI / Lint (push) Has been cancelled
CI / Format check (push) Has been cancelled
CI / Typecheck (push) Has been cancelled
CI / Unit tests (push) Has been cancelled
CI / Playwright E2E (push) Has been cancelled
CI / Docker build smoke (push) Has been cancelled
CI / Triage ledger up to date (push) Has been cancelled
CI / ui bun.lock in sync (push) Has been cancelled
* Fix: Fix Insecure Direct Object Reference in slack_start_new_thread.py (#1788) Co-authored-by: corridor-security[bot] <203152403+corridor-security[bot]@users.noreply.github.com> (cherry picked from commit 32e81f2979a7baf11fe387df59f7d13a31889c74) * Fix PR creation guard shell bypasses (#1786) Co-authored-by: langsmith-fleet[bot] <langsmith-fleet[bot]@users.noreply.github.com> (cherry picked from commit 75fb8b487852003916c4984504a13ee7226b2ceb) * fix: add exc_info to swallowed exception in push re-review webhook (#1764) (cherry picked from commit ab85b372b4f37b7feb849054553daed10852a42c) * chore: clarify shared response image guidance (#1782) Co-authored-by: Ramon Nogueira <270434257+ramon-langchain@users.noreply.github.com> Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com> (cherry picked from commit 2e8ff4b72f1148bb36c0c1181063a3abd78b15d0) * fix: match embedded review description background (#1791) Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com> (cherry picked from commit 4ea2441ada1229bc414b02950d821786be2f7301) * fix: show current shared thread in sidebar (#1799) * fix: show current shared thread in sidebar Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com> * fix: preserve resolved active sidebar threads Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com> --------- Co-authored-by: Ramon Nogueira <270434257+ramon-langchain@users.noreply.github.com> Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com> Co-authored-by: Johannes du Plessis <51395795+johannes117@users.noreply.github.com> (cherry picked from commit a77c4e475643b4a55bb2f0c93c0aa2669014fbac) * chore: switch deferred items to landed in upstream-sync triage documentation and jsonl entries (fork PR #226). Signed-off-by: Adam Moussa <adam@seahavenind.com> * harden PR guards + sidebar after security review - Mirror upstream #1786's nested-shell / executable-normalization hardening into the fork-only pr_verdict_guard.py (verdict-gating is a real fork control), keeping it in parity with pr_creation_guard.py. - Close the glued short-flag bypass (bash -c'...') in BOTH guards: a shell's -c argument can be concatenated into the same argv token, which the space-separated -c detection missed. Diverges pr_creation_guard.py from upstream #1786 by design; to be upstreamed. - Gate the new #1799 sidebar active-thread refresh on ownership so a non-owner viewing a shared thread reads last-known state without persisting a metadata write (mirrors the is_owner gate on the single-thread read path). - Fix an F821 in the #1799 cherry-pick (Mapping import / concrete dict type). Guards remain intentionally fail-open per the honest-agent threat model; docstrings narrowed to name the residual exotic-shell / stdin-fed vectors. --------- Signed-off-by: Adam Moussa <adam@seahavenind.com> Co-authored-by: corridor-security[bot] <203152403+corridor-security[bot]@users.noreply.github.com> Co-authored-by: John Kennedy <65985482+jkennedyvz@users.noreply.github.com> Co-authored-by: langsmith-fleet[bot] <langsmith-fleet[bot]@users.noreply.github.com> Co-authored-by: Suraj Bayas <surajyou24@gmail.com> Co-authored-by: Ramon Nogueira <ramon.nogueira@langchain.dev> Co-authored-by: Ramon Nogueira <270434257+ramon-langchain@users.noreply.github.com> Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com> Co-authored-by: Johannes du Plessis <johannes@langchain.dev> Co-authored-by: Johannes du Plessis <51395795+johannes117@users.noreply.github.com>
133 lines
5.4 KiB
Python
133 lines
5.4 KiB
Python
from __future__ import annotations
|
|
|
|
import json
|
|
from typing import Any
|
|
|
|
from langchain_core.messages import ToolMessage
|
|
|
|
from agent.middleware.pr_verdict_guard import (
|
|
PullRequestVerdictGuardMiddleware,
|
|
is_pr_verdict_fallback_command,
|
|
)
|
|
|
|
|
|
class _Request:
|
|
def __init__(self, command: str, *, tool: str = "execute") -> None:
|
|
self.tool_call = {
|
|
"name": tool,
|
|
"args": {"command": command},
|
|
"id": "call-1",
|
|
}
|
|
|
|
|
|
async def _handler(_request: Any) -> ToolMessage:
|
|
return ToolMessage(content="allowed", tool_call_id="call-1")
|
|
|
|
|
|
def test_detects_gh_pr_review_verdict_flags() -> None:
|
|
assert is_pr_verdict_fallback_command("gh pr review 12 --approve")
|
|
assert is_pr_verdict_fallback_command("gh pr review -a")
|
|
assert is_pr_verdict_fallback_command("gh pr review 12 -r -b 'needs work'")
|
|
assert is_pr_verdict_fallback_command("gh pr review 12 --request-changes")
|
|
assert is_pr_verdict_fallback_command("gh pr review --approve=true")
|
|
assert is_pr_verdict_fallback_command("gh pr review --request-changes='fix it'")
|
|
assert is_pr_verdict_fallback_command("GH_TOKEN=dummy gh pr review 5 --approve")
|
|
assert is_pr_verdict_fallback_command("git fetch && gh pr review 3 -a")
|
|
|
|
|
|
def test_detects_gh_api_review_verdicts() -> None:
|
|
assert is_pr_verdict_fallback_command(
|
|
"gh api repos/langchain-ai/open-swe/pulls/5/reviews -f event=APPROVE"
|
|
)
|
|
assert is_pr_verdict_fallback_command(
|
|
"gh api repos/o/r/pulls/5/reviews -X POST -f event=REQUEST_CHANGES"
|
|
)
|
|
assert is_pr_verdict_fallback_command(
|
|
"gh api repos/o/r/pulls/5/reviews/9/events -f event=approve"
|
|
)
|
|
assert is_pr_verdict_fallback_command(
|
|
"gh api https://api.github.com/repos/o/r/pulls/5/reviews -f event=APPROVE"
|
|
)
|
|
|
|
|
|
def test_detects_curl_review_verdicts() -> None:
|
|
assert is_pr_verdict_fallback_command(
|
|
'curl -X POST https://api.github.com/repos/o/r/pulls/5/reviews -d \'{"event": "APPROVE"}\''
|
|
)
|
|
assert is_pr_verdict_fallback_command(
|
|
"curl https://api.github.com/repos/o/r/pulls/5/reviews/9/events "
|
|
'--json \'{"event":"REQUEST_CHANGES"}\''
|
|
)
|
|
|
|
|
|
def test_detects_nested_and_normalized_verdict_commands() -> None:
|
|
assert is_pr_verdict_fallback_command("/usr/bin/gh pr review 12 --approve")
|
|
assert is_pr_verdict_fallback_command(
|
|
"/usr/bin/curl -X POST https://api.github.com/repos/o/r/pulls/5/reviews "
|
|
'-d \'{"event": "APPROVE"}\''
|
|
)
|
|
assert is_pr_verdict_fallback_command("bash -c 'gh pr review 12 --approve'")
|
|
assert is_pr_verdict_fallback_command("bash -c'gh pr review 12 --approve'")
|
|
assert is_pr_verdict_fallback_command("zsh -lc'gh pr review 12 --approve'")
|
|
assert is_pr_verdict_fallback_command("GH_TOKEN=dummy sh -c 'gh pr review -a'")
|
|
assert is_pr_verdict_fallback_command(
|
|
"zsh -lc 'gh api repos/o/r/pulls/5/reviews -X POST -f event=REQUEST_CHANGES'"
|
|
)
|
|
assert is_pr_verdict_fallback_command(
|
|
'bash -c "curl -X POST https://api.github.com/repos/o/r/pulls/5/reviews '
|
|
'-d \'{\\"event\\": \\"APPROVE\\"}\'"'
|
|
)
|
|
assert is_pr_verdict_fallback_command(
|
|
'bash -c \'sh -c "dash -c \\"zsh -c \\\\\\"gh pr review 12 --approve\\\\\\"\\""\''
|
|
)
|
|
|
|
|
|
def test_allows_safe_review_commands() -> None:
|
|
assert not is_pr_verdict_fallback_command("gh pr review 12 --comment -b 'looks good'")
|
|
assert not is_pr_verdict_fallback_command("gh pr review -c")
|
|
assert not is_pr_verdict_fallback_command("gh pr review")
|
|
assert not is_pr_verdict_fallback_command("gh pr diff 12")
|
|
assert not is_pr_verdict_fallback_command("gh pr view 12 --json reviews")
|
|
assert not is_pr_verdict_fallback_command("gh api repos/o/r/pulls/5/reviews")
|
|
assert not is_pr_verdict_fallback_command("gh pr create --draft")
|
|
assert not is_pr_verdict_fallback_command("curl https://api.github.com/repos/o/r/pulls/5")
|
|
assert not is_pr_verdict_fallback_command("bash -c 'gh pr review 12 --comment -b ok'")
|
|
assert not is_pr_verdict_fallback_command("/usr/bin/gh pr view 12 --json reviews")
|
|
|
|
|
|
async def test_middleware_blocks_execute_verdict_fallbacks() -> None:
|
|
for command in (
|
|
"gh pr review 12 --approve",
|
|
"gh api repos/o/r/pulls/5/reviews -f event=REQUEST_CHANGES",
|
|
'curl -X POST https://api.github.com/repos/o/r/pulls/5/reviews -d \'{"event": "APPROVE"}\'',
|
|
):
|
|
result = await PullRequestVerdictGuardMiddleware().awrap_tool_call(
|
|
_Request(command), _handler
|
|
)
|
|
|
|
assert isinstance(result, ToolMessage)
|
|
assert result.status == "error"
|
|
payload = json.loads(str(result.content))
|
|
assert payload["code"] == "pr_verdict_fallback_blocked"
|
|
assert payload["error_type"] == "PullRequestVerdictFallbackBlocked"
|
|
assert payload["recoverable_by_agent"] is False
|
|
assert "publish_review" in payload["error"]
|
|
assert payload["blocked_command"] == command
|
|
|
|
|
|
async def test_middleware_allows_comment_review() -> None:
|
|
result = await PullRequestVerdictGuardMiddleware().awrap_tool_call(
|
|
_Request("gh pr review 12 --comment -b 'nit: rename'"), _handler
|
|
)
|
|
|
|
assert isinstance(result, ToolMessage)
|
|
assert result.content == "allowed"
|
|
|
|
|
|
async def test_middleware_ignores_other_tools() -> None:
|
|
result = await PullRequestVerdictGuardMiddleware().awrap_tool_call(
|
|
_Request("gh pr review 12 --approve", tool="read_file"), _handler
|
|
)
|
|
|
|
assert isinstance(result, ToolMessage)
|
|
assert result.content == "allowed"
|