mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-10-07 16:19:09 +00:00
Harden the workflow-push approval guard against three bypasses found by the security review: - H6: the push parser passed through (returned None, unguarded) git invoked via a path (`/usr/bin/git`), a wrapper (`command`/`env` ...), or with leading global options (`git -c`, `--git-dir`, `--no-pager`). Recognize wrapped and path-qualified git as pushes, and block pushes carrying unsupported global options instead of running them unguarded. - H1: the base was fetched via the `origin` remote name, which the sandbox can split from the push destination via `remote set-url --push`. Fetch the base from the effective push URL (`git remote get-url --push`) so the base and the push target are the same authenticated repo. - H3: an unreadable head workflow tree (`ls-tree` failure) skipped the guard; fail closed (block) instead, mirroring the base-read path. Adds tests for each. All confirmed guard bypasses are caught by the langsmith unelevated-token backstop today; these close the guard's own logic for non-langsmith providers too. Claude-Session: https://claude.ai/code/session_01GxSndB7VoGQyeS196eUr5E |
||
|---|---|---|
| .. | ||
| __init__.py | ||
| check_message_queue.py | ||
| ensure_no_empty_msg.py | ||
| exclude_tools.py | ||
| model_fallback.py | ||
| notify_step_limit.py | ||
| plan_mode.py | ||
| refresh_github_proxy.py | ||
| refresh_slack_status.py | ||
| repair_orphaned_tool_calls.py | ||
| sandbox_circuit_breaker.py | ||
| sanitize_thinking_blocks.py | ||
| sanitize_tool_inputs.py | ||
| settle_review_check.py | ||
| tool_artifact.py | ||
| tool_error_handler.py | ||
| workflow_push_guard.py | ||