mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-10-07 16:19:09 +00:00
The parser failed closed on any execute command containing shell
metacharacters, even ones with no `git push` at all (a bundled
clone+commit heredoc, `echo x && ls`). That blocked the E2E full-flow
implement step before it could push, so the opened PR carried an empty
file list and Playwright failed — and it would break most real agent
shell usage (pipes, redirects, heredocs, env vars).
Engage the guard only when the command genuinely invokes `git push`,
detected precisely on the shlex-normalized token stream. Push the E2E
branch as a standalone, inspectable `git push` rather than bundling it
in the heredoc.
Hardening (from an adversarial security-review pass): a `git push` the
shell would run can hide from a literal token scan via fused separators
(`true;git push`), subshell/grouping (`(git push …)`), value-option
splicing (`git -c ; git push`), or expansion/quoting (`git${IFS}push`,
`git $(printf push)`, `git $'push'`, `git $'\x70ush'`). Fail closed on
those via a quote-aware command skeleton (ANSI-C `$'…'` decoded) while
still allowing legitimate metacharacter commands — chained commits,
pipes, redirects, `$VAR`, and `$'…\t…'` format strings.
|
||
|---|---|---|
| .. | ||
| dashboard | ||
| integrations | ||
| middleware | ||
| skills | ||
| tools | ||
| utils | ||
| webhooks | ||
| analyzer.py | ||
| chat.py | ||
| ci_autofix.py | ||
| ci_monitor.py | ||
| completion.py | ||
| dispatch.py | ||
| encryption.py | ||
| prompt.py | ||
| reconcile.py | ||
| review_style_collector.py | ||
| review_style_guidance.py | ||
| reviewer.py | ||
| reviewer_diff.py | ||
| reviewer_eval_store.py | ||
| reviewer_findings.py | ||
| reviewer_groups.py | ||
| reviewer_publish.py | ||
| reviewer_reconcile.py | ||
| reviewer_trace_context.py | ||
| scheduler.py | ||
| server.py | ||
| webapp.py | ||