open-swe/agent/middleware
amoussa1229 38d7929545 Re-add trusted-base change detection for workflow push guard
The head-tree fingerprint keeps the security win (approval binds to the exact
workflow files and blob SHAs at the pushed head), but the guard was firing on
every push because it no longer compared against a base. This change re-adds
change detection using a base fetched from the authenticated remote at guard
time:

- Fetches the pushed branch from the remote; if it does not exist (new branch),
  fetches the remote's default branch via ls-remote and a fallback chain.
- Compares the head workflow tree (ls-tree) against the freshly fetched base
  (FETCH_HEAD), not against any local refs/remotes/origin/* ref.
- Returns None (no guard) when the workflow trees are identical, so code-only
  pushes to a branch that already contains workflow files are not blocked.
- Updated test_non_workflow_push_runs_without_approval to use a non-empty-but
  unchanged workflow tree.

Refs: 98
2026-07-01 21:08:29 +00:00
..
__init__.py chore: sync upstream/main, defer #1621 modular webhooks (#81) 2026-06-30 16:45:19 -04:00
check_message_queue.py chore: sync upstream/main, defer #1621 modular webhooks (#81) 2026-06-30 16:45:19 -04:00
ensure_no_empty_msg.py chore: sync upstream/main, defer #1621 modular webhooks (#81) 2026-06-30 16:45:19 -04:00
exclude_tools.py feat: add reviewer graph + eval target wiring (#1241) 2026-05-06 10:15:58 -07:00
model_fallback.py feat: migrate model providers to Bedrock (Claude) + Fireworks (everything else) (#62) 2026-06-29 15:57:19 -04:00
notify_step_limit.py fix: notify users via Slack when agent hits model call step limit (#1204) 2026-05-01 14:24:25 -07:00
plan_mode.py chore: sync upstream/main, defer #1621 modular webhooks (#81) 2026-06-30 16:45:19 -04:00
refresh_github_proxy.py fix: refresh sandbox GitHub proxy token before mid-run expiry (#1496) 2026-06-11 10:59:21 -07:00
refresh_slack_status.py fix Slack assistant status endpoint (#1272) 2026-05-08 13:07:32 -07:00
repair_orphaned_tool_calls.py fix: repair orphaned tool calls before model calls (#1604) 2026-06-24 12:58:10 -07:00
sandbox_circuit_breaker.py fix: recover from mid-run sandbox death (#1274) 2026-05-08 12:55:36 -07:00
sanitize_thinking_blocks.py feat: migrate model providers to Bedrock (Claude) + Fireworks (everything else) (#62) 2026-06-29 15:57:19 -04:00
sanitize_tool_inputs.py fix: coerce malformed integer strings in read_file offset/limit params (#1216) 2026-05-01 14:29:48 -07:00
settle_review_check.py fix: settle incomplete review check as neutral, not failure (#1501) 2026-06-11 13:03:34 -07:00
tool_artifact.py feat(open-swe): stream agent chat via @langchain/react v2 protocol (#1475) 2026-06-11 09:54:35 -07:00
tool_error_handler.py fix: keep sandbox backend stable across recovery (#1294)w 2026-05-11 16:03:38 -07:00
workflow_push_guard.py Re-add trusted-base change detection for workflow push guard 2026-07-01 21:08:29 +00:00