open-swe/agent/utils
Adam Moussa a33aaec495
fix: resolve security-review findings (sandbox isolation, IAM list scope, webhook replay, info-leak) (#54)
* fix: enforce a replay window on Linear webhooks (AUTHZ-001)

verify_linear_signature accepted any correctly-signed body with no freshness
check, so a captured request could be replayed indefinitely. Parse the
signed webhookTimestamp (Unix ms) and reject requests outside a 60s window,
failing closed when the field is missing or malformed — mirroring the Slack
verifier.

* fix: stop leaking upstream auth-error bodies into user comments

get_github_token_for_user folded the raw upstream response text into the
error string that becomes a Slack/Linear comment (AUTH-RESP-LEAK-01). Log the
full body server-side only and return a generic "GitHub auth failed (status
<code>)". Also document the accepted shared-installation-token blast radius on
the bot-token-only path (AUTHZ-003).

* fix: bind sandbox and token caches to repo to prevent thread-id collision

A PR head-branch name is attacker-controllable and get_thread_id_from_branch
derives a thread_id from its first UUID with no repo binding (TID-COLLIDE-01).
The in-memory sandbox cache and the per-thread GitHub-token cache were keyed on
thread_id alone, and a cached sandbox was reused after only an echo-ping, so a
different repo's webhook could bind to another thread's sandbox or token.

Without changing the persistent thread-id scheme:
- Persist the bound repo (owner/name) in thread metadata on sandbox creation and
  refuse to reuse a sandbox whose bound repo does not match the current event
  (SandboxRepoMismatchError); the in-memory proxy also carries the binding.
- Bind the GitHub-token cache entries to their repo and evict on a cross-repo
  read so a colliding thread_id cannot be served another repo's token.
- Thread repo through the reviewer and the webhook token resolvers.

* fix: scope s3:ListBucket to the releases/ prefix (F-1/IAC-04)

The instance role and the GitHub deploy app role granted s3:ListBucket on the
whole assets bucket. Every caller (deploy.sh, the publish/rollback scripts)
only ever lists under releases/, so add a StringLike s3:prefix=releases/*
condition. GetBucketLocation has no s3:prefix in its request context, so it
moves to its own unconditioned statement. Also document the accepted F-2
cross-env existence-oracle residual on BatchGetSecretValue.

* chore: suppress test-fixture credential false positive; document AUTHZ-002

Add a machine-level suppression for the fake Datadog key in the
test_team_credentials encryption-roundtrip fixture (CWE-798, not a real
credential). Clarify that the within-org thread-write path is intentional by
design (AUTHZ-002) — comment only, no behavior change.

* fix: casefold repo-binding keys to avoid spurious cross-repo mismatch

GitHub owner/name are case-insensitive. Casefold the owner/name key on both the
write (binding) and read (compare) sides — repo_cache_key and the metadata
bound_repo read — so Org/Repo and org/repo resolve to one repo and a legitimate
same-repo run cannot raise a spurious SandboxRepoMismatchError (Gap 2).

* fix: stop leaking upstream auth body in unexpected-result branch

The 2xx-but-missing-token/url branch echoed the parsed upstream response body
into the user-facing error. Return a generic message and log response_data
server-side only, mirroring the existing HTTPStatusError fix (Gap 4).

* fix: fail closed for unbound-legacy sandboxes and catch repo mismatch

Gap 1: a thread with a persisted sandbox_id but no in-memory cache and no
recorded bound_repo (a pre-binding legacy thread, post-deploy) previously
reconnected-and-served the sandbox to the current repo, then rebound it. Now
fail closed: drop the stale id and recreate a fresh sandbox bound to this repo,
logging a reconnect-with-missing-binding event. A sandbox is never served to a
repo unless its binding is known and matches; new threads bind on first run
unchanged.

Gap 3: catch SandboxRepoMismatchError at the agent and reviewer run entrypoints,
log it for alarming, and surface a clean sanitized error instead of letting an
opaque deep-stack exception crash-loop the worker.

* chore: suppress test-fixture credential false positive in token-TTL tests

Add a machine-level suppression for the fake "ghp_secret" GitHub token used by
the cached-token TTL/revocation unit tests (CWE-798). Not a real credential and
not a valid PAT; scoped to the unit test only.
2026-06-29 12:21:19 -04:00
..
agents_md.py feat: reviewer enforces AGENTS.md/CLAUDE.md repo rules as mandatory pass (#1569) 2026-06-18 11:13:58 -07:00
analyzer_skills.py feat: outcomes dataset + bootstrap/continual split via skills (#1365) 2026-06-01 13:25:12 -07:00
api_standards_skill.py feat: apply API standards skill in PR reviews for API changes (#1452) 2026-06-08 14:37:04 -07:00
auth.py fix: resolve security-review findings (sandbox isolation, IAM list scope, webhook replay, info-leak) (#54) 2026-06-29 12:21:19 -04:00
authorship.py Adopt Sea Haven agent conventions, no attribution (#30) 2026-06-27 22:08:45 -04:00
comments.py chore: Drop monorepo (#1029) 2026-03-06 16:10:34 -08:00
dashboard_links.py feat: plan mode with model-driven entry and collaborative review (#1580) 2026-06-23 12:06:58 -07:00
github_app.py perf: cut review-chat time-to-first-token (#1598) 2026-06-23 12:32:10 -07:00
github_checks.py feat: shared GitHub HTTP helper with retries, rate-limit handling [closes OPE-45] (#1565) 2026-06-17 14:45:57 -07:00
github_ci.py feat: shared GitHub HTTP helper with retries, rate-limit handling [closes OPE-45] (#1565) 2026-06-17 14:45:57 -07:00
github_comments.py Adopt Sea Haven agent conventions, no attribution (#30) 2026-06-27 22:08:45 -04:00
github_feedback.py feat: outcomes dataset + bootstrap/continual split via skills (#1365) 2026-06-01 13:25:12 -07:00
github_http.py feat: shared GitHub HTTP helper with retries, rate-limit handling [closes OPE-45] (#1565) 2026-06-17 14:45:57 -07:00
github_org_membership.py fix: Lock dashboard login to GitHub org members (#1367) 2026-06-01 20:56:30 +00:00
github_proxy.py fix: refresh sandbox GitHub proxy token before mid-run expiry (#1496) 2026-06-11 10:59:21 -07:00
github_token.py fix: resolve security-review findings (sandbox isolation, IAM list scope, webhook replay, info-leak) (#54) 2026-06-29 12:21:19 -04:00
langsmith.py feat: plan mode with model-driven entry and collaborative review (#1580) 2026-06-23 12:06:58 -07:00
linear.py fix: use thread-level LangSmith URLs instead of run-level URLs to fix broken trace links (#1217) 2026-04-23 13:46:28 -07:00
linear_team_repo_map.py chore: Add langsmith deployments data plane linear project (#1044) 2026-03-09 18:36:00 -07:00
model.py feat: validate LLM API keys on startup (#1438) 2026-06-18 09:24:46 -07:00
multimodal.py feat: handle images sent to non-vision models in Slack, Linear, and web UI (#1560) 2026-06-17 09:12:52 -07:00
repo.py feat: extract repo parsing into shared util, add linear comment repo override (#1103) 2026-03-20 13:34:00 -07:00
repo_prep.py fix: reviewer can silently review a stale checkout on reused sandboxes (#1503) 2026-06-11 13:42:10 -07:00
reviewer_outcomes.py feat: outcomes dataset + bootstrap/continual split via skills (#1365) 2026-06-01 13:25:12 -07:00
sandbox.py feat: repo-scoped dynamic sandbox snapshots (#1595) 2026-06-23 12:24:11 -07:00
sandbox_paths.py fix: better custom backend support (#1071) 2026-03-17 11:55:36 -07:00
sandbox_state.py fix: resolve security-review findings (sandbox isolation, IAM list scope, webhook replay, info-leak) (#54) 2026-06-29 12:21:19 -04:00
slack.py feat: add size caps for PR diff, fetch_url, Slack threads, pagination, message queue [closes OPE-51] (#1567) 2026-06-17 15:40:59 -07:00
slack_feedback.py feat: outcomes dataset + bootstrap/continual split via skills (#1365) 2026-06-01 13:25:12 -07:00
thread_ops.py fix: serialize Slack run dispatch (#1591) 2026-06-23 12:04:08 -07:00
tracing.py feat: route graphs to separate LangSmith tracing projects (#1508) 2026-06-11 17:57:16 -07:00