mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-10-07 16:19:09 +00:00
The parser failed closed on any execute command containing shell
metacharacters, even ones with no `git push` at all (a bundled
clone+commit heredoc, `echo x && ls`). That blocked the E2E full-flow
implement step before it could push, so the opened PR carried an empty
file list and Playwright failed — and it would break most real agent
shell usage (pipes, redirects, heredocs, env vars).
Engage the guard only when the command genuinely invokes `git push`,
detected precisely on the shlex-normalized token stream. Push the E2E
branch as a standalone, inspectable `git push` rather than bundling it
in the heredoc.
Hardening (from an adversarial security-review pass): a `git push` the
shell would run can hide from a literal token scan via fused separators
(`true;git push`), subshell/grouping (`(git push …)`), value-option
splicing (`git -c ; git push`), or expansion/quoting (`git${IFS}push`,
`git $(printf push)`, `git $'push'`, `git $'\x70ush'`). Fail closed on
those via a quote-aware command skeleton (ANSI-C `$'…'` decoded) while
still allowing legitimate metacharacter commands — chained commits,
pipes, redirects, `$VAR`, and `$'…\t…'` format strings.
|
||
|---|---|---|
| .. | ||
| __init__.py | ||
| check_message_queue.py | ||
| ensure_no_empty_msg.py | ||
| exclude_tools.py | ||
| model_fallback.py | ||
| notify_step_limit.py | ||
| plan_mode.py | ||
| refresh_github_proxy.py | ||
| refresh_slack_status.py | ||
| repair_orphaned_tool_calls.py | ||
| sandbox_circuit_breaker.py | ||
| sanitize_thinking_blocks.py | ||
| sanitize_tool_inputs.py | ||
| settle_review_check.py | ||
| tool_artifact.py | ||
| tool_error_handler.py | ||
| workflow_push_guard.py | ||