[BUG] Fix k8s_execute_command kubectl exec argv handling and honor container
メンテナーはふだん 3 日以内に返信
まだ誰も着手していません。
評価
調査の方向性
pkg/k8s/k8s.go の handleExecCommand から始め、コマンド、コンテナ、コマンド実行のエラーが kubectl の呼び出しとツールの結果にどのように到達するかを追跡します。空白で区切られたコマンド、コンテナの選択、stdout/stderr を公開する失敗についてテストを追加または更新します。記載された kubectl argv とエラーの動作が、指定されたバリデーションを弱めることなくカバーされていれば完了です。
索引モデルが issue の本文から書いたものです。
説明
Summary
The Kubernetes k8s_execute_command tool appears broken for typical multi-token commands: the logical command line is forwarded to kubectl exec incorrectly, the optional container parameter is ignored, and failures often surface only as generic exit status 1, which hides stdout/stderr and leads agents astray.
Current behavior
- Commands with operators like
|are rejected upfront by validation (potentially dangerous characters detected) — that part may be intentional for a strict safe mode, but it blocks common diagnostics (e.g.ss -tnp | grep 5000). - Even simple whitespace-separated commands (e.g.
echo test,ls -la,which ss,ss -tnp) fail withexit status 1despite working when invoked manually viakubectl exec … -- …. - In
pkg/k8s/k8s.go, the exec path passescommandtokubectlin a way that effectively treats the entire string as a single argument after--, instead of splitting into argv tokens (-- echo testvs-- "echo test"). - The
containerfield from the tool request does not result inkubectl exec -c <container>, so targeting a specific container in a multi-container pod is unreliable.
Expected behavior
- Commands without shell metacharacters should run with
kubectl-compatible argv: after--, each token becomes a separate argument (standardkubectl exec … -- cmd arg1 arg2 …). - When
containeris set and valid,kubectl execmust receive-c <container>. - On failure, surface
stderr/stdout(and non-zero exit) in the tool result/error path instead of opaqueexit status 1wherever possible.
Versions / scope
Still reproducible in the latest release v0.2.0 and on main (verified 2026-05-16): in pkg/k8s/k8s.go, handleExecCommand still passes the full command string as a single argv element after kubectl exec … -- and does not map the tool parameter container to kubectl exec -c …. The same behavior was already present in v0.1.3 and v0.1.4 — this code path did not change between those tags and v0.2.0 / current main.
A quick search of this repository’s issues/PRs did not find a dedicated report for k8s_execute_command / handleExecCommand (e.g. by name k8s_execute_command); if this duplicates something, please link and close.
Related but distinct: #54 / #55 (Cilium-focused kubectl exec -n). This report is about the general k8s_execute_command contract (argv splitting, -c, and error propagation).
Suggested upstream fix direction
- Structured API preferred long-term:
command+args[], or robust parsing rules documented and tested (avoid ambiguity with quoted args if staying string-only). - Honor
container→ always add-cwhen non-empty after validation. - Keep strict validation by default where appropriate; if shell/pipe features are needed, expose an explicit, opt-in mode (approval / documented risk) rather than silent breakage.
- Tests:
echo test,ls -la,ss -tnp, multi-container pod with-c, plus error cases that assert stderr is visible.
- 主要言語
- Go
- スター
- 35
- フォーク
- 28
- 平均マージ
- 3日 23時間
- マージ済み PR(30日)
- 3
環境構築
このプロジェクトの開発コンテナを、あなたの GitHub アカウントでブラウザ上に起動します。
- Dockerfile または Docker Compose ファイルあり
- プルリクエストのテンプレートなし
- コントリビューションガイドなし
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
kagent-dev/tools のほかの issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
kagent-dev/tools#54 ·
メンテナーはふだん 3 日以内に返信
-
難易度 4/5 3〜5日 初心者へのやさしさ 45/100
kagent-dev/tools#82 ·
メンテナーはふだん 3 日以内に返信
-
難易度 3/5 1〜2日 初心者へのやさしさ 78/100
kagent-dev/tools#80 ·
メンテナーはふだん 3 日以内に返信
-
難易度 3/5 1〜2日 初心者へのやさしさ 72/100
kagent-dev/tools#69 · コメント 1 件 ·
メンテナーはふだん 3 日以内に返信
-
難易度 3/5 1〜2日 初心者へのやさしさ 68/100
kagent-dev/tools#68 · コメント 1 件 ·
メンテナーはふだん 3 日以内に返信
kagent-dev/tools の issue をすべて見る
似ている issue
-
bug needs triage
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
netdata/netdata#24062 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 88/100
meshery/meshery#22119 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
メンテナーはふだん 1 日以内に返信
-
automation documentation
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
メンテナーはふだん 1 日以内に返信