open-swe/tests/github/test_pr_creation_guard.py
Adam Moussa d48cb12e08
Some checks failed
CI / Lint (push) Has been cancelled
CI / Format check (push) Has been cancelled
CI / Typecheck (push) Has been cancelled
CI / Unit tests (push) Has been cancelled
CI / Playwright E2E (push) Has been cancelled
CI / Docker build smoke (push) Has been cancelled
CI / Triage ledger up to date (push) Has been cancelled
CI / ui bun.lock in sync (push) Has been cancelled
feat(open-swe): port upstream clean batch (#1788, #1786, #1764, #1782, #1791, #1799) + guard hardening (#226)
* Fix: Fix Insecure Direct Object Reference in slack_start_new_thread.py (#1788)

Co-authored-by: corridor-security[bot] <203152403+corridor-security[bot]@users.noreply.github.com>
(cherry picked from commit 32e81f2979a7baf11fe387df59f7d13a31889c74)

* Fix PR creation guard shell bypasses (#1786)

Co-authored-by: langsmith-fleet[bot] <langsmith-fleet[bot]@users.noreply.github.com>
(cherry picked from commit 75fb8b487852003916c4984504a13ee7226b2ceb)

* fix: add exc_info to swallowed exception in push re-review webhook (#1764)

(cherry picked from commit ab85b372b4f37b7feb849054553daed10852a42c)

* chore: clarify shared response image guidance (#1782)

Co-authored-by: Ramon Nogueira <270434257+ramon-langchain@users.noreply.github.com>
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
(cherry picked from commit 2e8ff4b72f1148bb36c0c1181063a3abd78b15d0)

* fix: match embedded review description background (#1791)

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
(cherry picked from commit 4ea2441ada1229bc414b02950d821786be2f7301)

* fix: show current shared thread in sidebar (#1799)

* fix: show current shared thread in sidebar

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>

* fix: preserve resolved active sidebar threads

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>

---------

Co-authored-by: Ramon Nogueira <270434257+ramon-langchain@users.noreply.github.com>
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
Co-authored-by: Johannes du Plessis <51395795+johannes117@users.noreply.github.com>
(cherry picked from commit a77c4e475643b4a55bb2f0c93c0aa2669014fbac)

* chore: switch deferred items to landed in upstream-sync triage documentation and jsonl entries (fork PR #226).

Signed-off-by: Adam Moussa <adam@seahavenind.com>

* harden PR guards + sidebar after security review

- Mirror upstream #1786's nested-shell / executable-normalization hardening
  into the fork-only pr_verdict_guard.py (verdict-gating is a real fork
  control), keeping it in parity with pr_creation_guard.py.
- Close the glued short-flag bypass (bash -c'...') in BOTH guards: a shell's
  -c argument can be concatenated into the same argv token, which the
  space-separated -c detection missed. Diverges pr_creation_guard.py from
  upstream #1786 by design; to be upstreamed.
- Gate the new #1799 sidebar active-thread refresh on ownership so a non-owner
  viewing a shared thread reads last-known state without persisting a metadata
  write (mirrors the is_owner gate on the single-thread read path).
- Fix an F821 in the #1799 cherry-pick (Mapping import / concrete dict type).

Guards remain intentionally fail-open per the honest-agent threat model;
docstrings narrowed to name the residual exotic-shell / stdin-fed vectors.

---------

Signed-off-by: Adam Moussa <adam@seahavenind.com>
Co-authored-by: corridor-security[bot] <203152403+corridor-security[bot]@users.noreply.github.com>
Co-authored-by: John Kennedy <65985482+jkennedyvz@users.noreply.github.com>
Co-authored-by: langsmith-fleet[bot] <langsmith-fleet[bot]@users.noreply.github.com>
Co-authored-by: Suraj Bayas <surajyou24@gmail.com>
Co-authored-by: Ramon Nogueira <ramon.nogueira@langchain.dev>
Co-authored-by: Ramon Nogueira <270434257+ramon-langchain@users.noreply.github.com>
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
Co-authored-by: Johannes du Plessis <johannes@langchain.dev>
Co-authored-by: Johannes du Plessis <51395795+johannes117@users.noreply.github.com>
2026-07-24 18:49:53 -04:00

95 lines
3.8 KiB
Python

from __future__ import annotations
import json
from typing import Any
from langchain_core.messages import ToolMessage
from agent.middleware.pr_creation_guard import (
PullRequestCreationGuardMiddleware,
is_pr_creation_fallback_command,
)
class _Request:
def __init__(self, command: str) -> None:
self.tool_call = {
"name": "execute",
"args": {"command": command},
"id": "call-1",
}
async def _handler(_request: Any) -> ToolMessage:
return ToolMessage(content="allowed", tool_call_id="call-1")
def test_detects_pr_creation_fallback_commands() -> None:
assert is_pr_creation_fallback_command("GH_TOKEN=dummy gh pr create --draft")
assert is_pr_creation_fallback_command(
"gh api repos/langchain-ai/open-swe/pulls -X POST -f title=x"
)
assert is_pr_creation_fallback_command(
"gh api -X POST repos/langchain-ai/open-swe/pulls -f title=x"
)
assert is_pr_creation_fallback_command(
"GH_TOKEN=dummy gh api -X POST repos/langchain-ai/open-swe/pulls -f title=x"
)
assert is_pr_creation_fallback_command(
"curl -X POST https://api.github.com/repos/langchain-ai/open-swe/pulls -d '{}'"
)
assert is_pr_creation_fallback_command("/usr/bin/gh pr create --draft")
assert is_pr_creation_fallback_command(
"/usr/bin/curl -X POST https://api.github.com/repos/langchain-ai/open-swe/pulls -d '{}'"
)
assert is_pr_creation_fallback_command("bash -c 'gh pr create --draft'")
assert is_pr_creation_fallback_command("bash -c'gh pr create --draft'")
assert is_pr_creation_fallback_command("zsh -lc'gh pr create --draft'")
assert is_pr_creation_fallback_command("GH_TOKEN=dummy sh -c 'gh pr create --draft'")
assert is_pr_creation_fallback_command(
"zsh -lc 'gh api repos/langchain-ai/open-swe/pulls -X POST -f title=x'"
)
assert is_pr_creation_fallback_command(
"bash -c \"curl -X POST https://api.github.com/repos/langchain-ai/open-swe/pulls -d '{}'\""
)
assert is_pr_creation_fallback_command(
'bash -c \'sh -c "dash -c \\"zsh -c \\\\\\"gh pr create --draft\\\\\\"\\""\''
)
def test_allows_safe_pr_commands() -> None:
assert not is_pr_creation_fallback_command("GH_TOKEN=dummy gh pr view 1 --json url")
assert not is_pr_creation_fallback_command("gh pr list --head open-swe/foo")
assert not is_pr_creation_fallback_command("gh pr edit 1 --add-label ready")
assert not is_pr_creation_fallback_command("gh pr comment 1 --body done")
assert not is_pr_creation_fallback_command("bash -c 'gh pr view 1 --json url'")
assert not is_pr_creation_fallback_command("/usr/bin/gh pr view 1 --json url")
async def test_middleware_blocks_execute_pr_creation_fallbacks() -> None:
for command in (
"GH_TOKEN=dummy gh pr create --draft",
"gh api repos/langchain-ai/open-swe/pulls -X POST -f title=x",
"GH_TOKEN=dummy gh api -X POST repos/langchain-ai/open-swe/pulls -f title=x",
"curl -X POST https://api.github.com/repos/langchain-ai/open-swe/pulls -d '{}'",
):
result = await PullRequestCreationGuardMiddleware().awrap_tool_call(
_Request(command), _handler
)
assert isinstance(result, ToolMessage)
assert result.status == "error"
payload = json.loads(str(result.content))
assert payload["code"] == "pr_creation_fallback_blocked"
assert payload["recoverable_by_agent"] is False
assert "open_pull_request" in payload["error"]
assert payload["blocked_command"] == command
async def test_middleware_allows_safe_pr_view() -> None:
result = await PullRequestCreationGuardMiddleware().awrap_tool_call(
_Request("GH_TOKEN=dummy gh pr view 1 --json url"), _handler
)
assert isinstance(result, ToolMessage)
assert result.content == "allowed"