[BUG] Fix k8s_execute_command kubectl exec argv handling and honor container
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 55/100
Direzione di ricerca
Inizia in pkg/k8s/k8s.go, in handleExecCommand, e segui come gli errori del comando, del container e dell'esecuzione del comando arrivano all'invocazione di kubectl e al risultato dello strumento. Aggiungi o aggiorna i test per i comandi separati da spazi bianchi, la selezione del container e i fallimenti che espongono stdout/stderr; il lavoro è completato quando i kubectl argv elencati e il comportamento degli errori sono coperti senza indebolire la validazione indicata.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Summary
The Kubernetes k8s_execute_command tool appears broken for typical multi-token commands: the logical command line is forwarded to kubectl exec incorrectly, the optional container parameter is ignored, and failures often surface only as generic exit status 1, which hides stdout/stderr and leads agents astray.
Current behavior
- Commands with operators like
|are rejected upfront by validation (potentially dangerous characters detected) — that part may be intentional for a strict safe mode, but it blocks common diagnostics (e.g.ss -tnp | grep 5000). - Even simple whitespace-separated commands (e.g.
echo test,ls -la,which ss,ss -tnp) fail withexit status 1despite working when invoked manually viakubectl exec … -- …. - In
pkg/k8s/k8s.go, the exec path passescommandtokubectlin a way that effectively treats the entire string as a single argument after--, instead of splitting into argv tokens (-- echo testvs-- "echo test"). - The
containerfield from the tool request does not result inkubectl exec -c <container>, so targeting a specific container in a multi-container pod is unreliable.
Expected behavior
- Commands without shell metacharacters should run with
kubectl-compatible argv: after--, each token becomes a separate argument (standardkubectl exec … -- cmd arg1 arg2 …). - When
containeris set and valid,kubectl execmust receive-c <container>. - On failure, surface
stderr/stdout(and non-zero exit) in the tool result/error path instead of opaqueexit status 1wherever possible.
Versions / scope
Still reproducible in the latest release v0.2.0 and on main (verified 2026-05-16): in pkg/k8s/k8s.go, handleExecCommand still passes the full command string as a single argv element after kubectl exec … -- and does not map the tool parameter container to kubectl exec -c …. The same behavior was already present in v0.1.3 and v0.1.4 — this code path did not change between those tags and v0.2.0 / current main.
A quick search of this repository’s issues/PRs did not find a dedicated report for k8s_execute_command / handleExecCommand (e.g. by name k8s_execute_command); if this duplicates something, please link and close.
Related but distinct: #54 / #55 (Cilium-focused kubectl exec -n). This report is about the general k8s_execute_command contract (argv splitting, -c, and error propagation).
Suggested upstream fix direction
- Structured API preferred long-term:
command+args[], or robust parsing rules documented and tested (avoid ambiguity with quoted args if staying string-only). - Honor
container→ always add-cwhen non-empty after validation. - Keep strict validation by default where appropriate; if shell/pipe features are needed, expose an explicit, opt-in mode (approval / documented risk) rather than silent breakage.
- Tests:
echo test,ls -la,ss -tnp, multi-container pod with-c, plus error cases that assert stderr is visible.
- Lingua principale
- Go
- Stelle
- 36
- Fork
- 29
- Merge medio
- 3g 23h
- PR unite (30g)
- 3
Preparare l'ambiente
Avvia il container di sviluppo del progetto nel browser, con il tuo account GitHub.
- Include un Dockerfile o un file Docker Compose
- Nessun modello di pull request
- Nessuna guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di kagent-dev/tools
-
[BUG] MCP clients get no tools from v0.3.0: kubescape_get_vulnerability_details outputSchema is not an objectForse già presa @nishanthchandr4 l’ha presa 1 giorno fa. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
kagent-dev/tools#87 · 2 commenti ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
kagent-dev/tools#54 ·
-
[FEATURE] Add a limit parameter to k8s_get_resources to bound context growthForse già presa @anjosluc l’ha presa 22 giorni fa. Aperta
Difficoltà 4/5 3-5 giorni Idoneità per principianti 45/100
kagent-dev/tools#82 ·
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 78/100
kagent-dev/tools#80 ·
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 72/100
kagent-dev/tools#69 · 1 commento ·
Tutte le issue di kagent-dev/tools
Issue simili
-
Service process inherits the caller's cwd at first use, holding that folder open on Windows (EBUSY)Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
I maintainer di solito rispondono entro 1 giorno
-
[docs] Media elements cannot load from a custom protocol (video/audio report MEDIA_ERR_SRC_NOT_SUPPORTED)Forse già presa @vst93 l’ha presa oggi. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
evilmartians/lefthook#1588 ·
I maintainer di solito rispondono entro 1 giorno
-
documentation
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 82/100
gravitational/teleport#69847 ·
I maintainer di solito rispondono entro 11 giorni