Repository navigation
feat(rings): enhance command denylist enforcement with case-insensitive matching and injection prevention - #3095
Conversation
- Add CommandCheckResult dataclass to enforcer.py - Add check_command() method to RingEnforcer class - Integrate with existing DENIED_COMMANDS from hypervisor.sandbox - Extract base command from command strings with arguments - Add comprehensive unit tests in test_command_denylist.py - Export CommandCheckResult from rings package
…ve matching and injection prevention - Make check_command() case-insensitive to prevent bypass via case variation - Strip trailing shell metacharacters (;, &, |) to prevent command injection - Add comprehensive tests for edge cases (whitespace, special chars, partial matches, large inputs) - Update CHANGELOG.md and README.md with v2.1 additions - All 805 tests pass
- Apply ruff --fix to resolve UP045, UP035 type annotation issues - Apply ruff format to standardize code style across 30 source files - All 480 unit tests continue to pass Signed-off-by: jlaportebot <jlaportebot@gmail.com>
🤖 AI Agent: docs-sync-checker — Docs Sync
Docs SyncDocumentation is in sync. |
|
🔴 Contributor Check: HIGH
Automated check by AGT Contributor Check. |
🤖 AI Agent: breaking-change-detector — API Compatibility
API Compatibility
|
🤖 AI Agent: security-scanner — View details
No security issues found. |
🤖 AI Agent: code-reviewer — Action Items:
TL;DR: 0 blockers, 1 warning. The PR introduces improvements to command denylist enforcement and injection prevention, but the security measures need further scrutiny.
Action Items:
Warnings (fine as follow-up PRs):
|
🤖 AI Agent: test-generator — `agent-hypervisor/ring_enforcer.py`
|
PR Review Summary
Verdict: AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims. |
- Replace timezone.utc with datetime.UTC (Python 3.11+) - Fix import sorting (I001) - Apply line wrapping and formatting fixes - No functional changes
- Add docstring to ConfigScanner.scan() method in agent_discovery/scanners/config.py - Update CHANGELOG.md [Unreleased] section with command denylist enforcement feature - Update README.md to mention command denylist enforcement in Agent Hypervisor and runtime package descriptions Addresses AI review comments about missing docstrings and documentation sync.
Imran Siddique (imran-siddique)
left a comment
There was a problem hiding this comment.
Solid security hardening. The method correctly extracts the base command token, strips trailing metacharacters before the denylist lookup (preventing // injection bypass), and matches case-insensitively. The 21 edge-case tests cover the expected boundary conditions well. The accompanying cleanups and import-order normalizations in agent-discovery are welcome housekeeping. LGTM.
Imran Siddique (imran-siddique)
left a comment
There was a problem hiding this comment.
Solid security hardening. check_command correctly extracts the base command token, strips trailing metacharacters before the denylist lookup to prevent injection bypasses, and matches case-insensitively. 21 edge-case tests cover the expected boundary conditions well. The datetime.now(UTC) cleanups in agent-discovery are welcome housekeeping. LGTM.
c497c6f
into
microsoft:main
Summary
This PR enhances the command denylist enforcement in the execution rings system with:
Case-insensitive matching - Commands are now matched case-insensitively against the denylist, preventing bypass via case variation (e.g., vs )
Injection prevention - Added validation to prevent command injection through:
Comprehensive test coverage - Added extensive tests for the new enforcement logic
Changes
Testing
All existing tests pass. New tests added for:
Closes #3067