Security follow-up from the per-PR review (non-blocking, defense-in-depth): - Replace the save_memory name blocklist with an allowlist regex (^[A-Za-z0-9][A-Za-z0-9._-]*$, max 128) so dot-only/hidden/backslash/NUL/ over-long names are rejected outright, not written as malformed-but-contained files. - Write via os.open(..., O_NOFOLLOW): the open fails (ELOOP) if the final path component is a pre-planted symlink, closing the TOCTOU where a symlink in _box-drafts/ could redirect the write outside the dir. O_CREAT|O_TRUNC keeps overwrite-on-resave for regular files. Tests: adds allowlist-rejection + symlink-refusal cases (21 pass). |
||
|---|---|---|
| .. | ||
| sim | ||
| __init__.py | ||
| conftest.py | ||
| test_apply_verify_workflow_hardening.py | ||
| test_billing.py | ||
| test_build_verify_subgraph.py | ||
| test_builders.py | ||
| test_builders_llm.py | ||
| test_checker_intake.py | ||
| test_ci_fetcher.py | ||
| test_ci_gate.py | ||
| test_ci_gate_workflow.py | ||
| test_clarifier.py | ||
| test_clarifier_llm.py | ||
| test_claude_code_adapter.py | ||
| test_claude_code_live.py | ||
| test_coordinator.py | ||
| test_deadline_timer.py | ||
| test_dispatcher.py | ||
| test_fixer.py | ||
| test_github_adapter.py | ||
| test_github_intake.py | ||
| test_github_live.py | ||
| test_graph.py | ||
| test_invoker.py | ||
| test_ledger.py | ||
| test_operator_cli.py | ||
| test_planner.py | ||
| test_recovery.py | ||
| test_responder.py | ||
| test_resume_worker.py | ||
| test_review_loop.py | ||
| test_review_loop_llm.py | ||
| test_run_team.py | ||
| test_schema.py | ||
| test_slack_adapter.py | ||
| test_slack_listener.py | ||
| test_slack_live.py | ||
| test_state_store.py | ||
| test_task_model.py | ||
| test_transport_base.py | ||
| test_verifier.py | ||
| test_verifier_llm.py | ||
| test_ws5_memory_handbook.py | ||