Commit Graph

17 Commits

Author SHA1 Message Date
roboomp 98a65ffbdf fix(coding-agent): blocked escaped reinterpreted payloads
- Preserved escaped control characters for the downstream reinterpretation safety decision.
- Covered the backslash-escaped git inline shell-alias bypass.

Fixes #7552
2026-08-03 21:18:35 +00:00
roboomp b621a9a637 fix(coding-agent): flagged double-quoted reinterpreted payloads
- Treated double-quoted shell-control chars like single-quoted ones so a -c/-e reinterpretation option still gates them.
- Covered the double-quoted git inline shell-alias bypass.

Fixes #7552
2026-08-03 21:13:13 +00:00
roboomp 9bcd31fcd2 fix(coding-agent): blocked reinterpreted quoted shell payloads
- Kept quoted shell controls prompt-gated when code-evaluation options can reinterpret the argument.
- Covered the reported git inline shell-alias bypass while retaining Cargo regex approval.

Fixes #7552
2026-08-03 21:08:52 +00:00
roboomp 54b2e38564 fix(coding-agent): allowed quoted bash pattern metacharacters
- Replaced the raw character guard with quote-aware scanning while retaining command substitution and unquoted shell-control protections.
- Added regression coverage for the reported Cargo benchmark filter.

Fixes #7552
2026-08-03 20:54:41 +00:00
roboomp e650607cad fix(coding-agent): segment bash approval commands with shell-aware tokenizer
The regex splitter only recognized `&&`, `||`, `;`, `|` and newlines, so a
single `&` (background operator) — also a command terminator — slipped a
dangerous command past a deny rule (`sleep 1 & rm -rf /tmp/x`), which under
approvalMode: yolo executed with no prompt.

Extract the shell-aware tokenizer from gh-cache-invalidation into a shared
tools/shell-tokenize.ts and reuse it for deny/prompt segmentation. It honors
every command boundary (`&&`, `||`, `;`, `|`, single `&`, subshells,
newlines) plus quoting and escapes, so both callers share one implementation.

Fixes #6695
2026-07-26 11:36:19 +00:00
roboomp 85110c366c fix(coding-agent): match bash deny/prompt patterns per command segment
bashApprovalPatternToRegExp anchors globs with ^...$ against the whole
normalized command, so a bash.patterns deny rule only fired when the
dangerous command was first in the line. A compound command such as
`cd /tmp && rm -rf /tmp/x` bypassed the rule and, under approvalMode:
yolo, executed with no prompt -- deny is the guard that outranks yolo.

deny/prompt rules now match the whole command or any single segment
(split on &&, ||, ;, |, newlines). allow rules still require the entire
command to match and never apply to compound lines, so a narrow allow
cannot vouch for a smuggled unsafe segment.

Fixes #6695
2026-07-26 11:28:48 +00:00
can1357 09d02c641f fix(coding-agent): closed bash approval rule bypasses
Tested the shell-control guard against the raw command: whitespace
normalization collapsed newlines/CR before the guard ran, so
'git status\nrm file.txt' rode a 'git *' allow rule while bash executed
both lines. Honored tool-owned allow/prompt policies in yolo mode so
per-command prompt rules were no longer silently discarded under the
default approvalMode. Added precision regression tests through the real
matcher (separators, subshells, redirects, env prefixes, path/quoting
variants) that fail on the unfixed head.
2026-07-23 17:30:32 +02:00
Cakrawala 6d7457663f feat(coding-agent): support per-command bash approval rules 2026-07-23 17:11:41 +07:00
can1357 ae1650d689 refactor: renamed search and find tools to grep and glob
- Renamed the `find` and `search` tools to `glob` and `grep` respectively across the codebase to improve command clarity.
- Implemented full-stack support for the renamed tools, including CLI arguments, system prompts, SDK exports, and tool registration.
- Added automated migration logic in `settings` to transform legacy `find` and `search` configuration keys to their new equivalents.
- Updated the `collab-web` renderer registry to ensure backwards compatibility with legacy tool outputs.
2026-06-27 00:57:55 +02:00
can1357 9d2728a455 ux(coding-agent): standardized truncation formatting for elided content
- Updated log and error truncation messages to use a consistent `[...Nch elided...]` format.
- Standardized diagnostics and prompt text output to improve consistency in reporting truncated information.
2026-06-19 04:45:08 +02:00
Guts e796a7db4d test(approval): add regression tests for MCP tool approval tier 2026-06-07 16:42:19 +02:00
can1357 535f7cfa89 fix(coding-agent/tools): reworked yolo approval resolution to honor user tool policies
- In `resolveApproval`, yolo mode now returns the user policy directly (`allow`/`prompt`/`deny`) and ignores tool `override` prompts.
- Updated approval-mode and approval unit tests to match the new behavior for critical bash patterns under yolo and auto-approve.
- Updated docs and settings metadata to describe yolo as user-policy-driven rather than override-driven.
2026-05-27 00:21:33 +02:00
can1357 e4a16451ec feat(coding-agent): added coding-agent approval types and mode options
- Added `ToolTier`, `ToolApproval`, and `ToolApprovalDecision` types and exported approval APIs.
- Updated approval-mode options from `auto|prompt|custom` to `always-ask|write|yolo` and defaulted mode to `yolo`.
- Changed approval resolution to apply per-tool decisions first, then mode-tier limits, with legacy-mode migration.
- Assigned read/write/exec `approval` and approval-detail prompts across built-in, custom, extension, and MCP tools.
2026-05-26 21:52:16 +02:00
can1357 be5837406b ux(coding-agent): implemented coding-agent tool approval selector
- Replaced tool-approval confirmations with an explicit Approve/Deny selector interface.
- Passed approval reason text as selector help and denied actions unless "Approve" was chosen.
- Removed formatApprovalPrompt, truncation helpers, and tool-specific prompt assembly logic.
- Deleted obsolete formatApprovalPrompt tests tied to removed approval prompt formatting.
2026-05-26 21:07:24 +02:00
oldschoola f5273eee6f fix(coding-agent): address PR #1378 review findings
- Decouple the per-tool approval gate from extension presence. ExtensionRunner
  and the ExtensionToolWrapper that hosts the gate are now constructed
  unconditionally in createAgentSession. Previously the runner was only built
  when extensionsResult.extensions.length > 0, so the entire approval system
  silently disappeared for sessions with no extensions loaded — any
  tools.approvalMode: prompt|custom setting was a no-op without feedback.
  Today this hole was masked by createAutoresearchExtension always being
  pushed inline; the unconditional construction makes the safety invariant
  explicit, and a new regression test in approval-mode.test.ts pins it.

- Extend CRITICAL_BASH_PATTERNS to cover remote-fetch-then-execute shapes
  that the original `bash <(curl …)` regex missed:
  - `source <(curl …)` / `. <(curl …)` (anchored at command boundary so
    `find . -name foo` doesn't false-positive)
  - `eval "$(curl …)"` / `eval $(curl …)` / `eval `curl …``
  Also adds `chmod -R` symbolic-mode forms (`u+x`, `u+rwx,o+w …`) targeting
  filesystem root, and `tee` / `tee -a` writes to /etc/{passwd,shadow,sudoers}
  (the standard way to write root-owned files without redirect). Benign
  forms (`source ./local.sh`, `chmod -R u+x ./build`, `tee /var/log/app.log`,
  `eval "$VAR"`) are pinned negative in the test suite.

- Extend formatApprovalPrompt with payload previews for the destructive tools
  that previously rendered as bare `Allow tool: <name>`: eval (language +
  first cell's code), task (agent + first task's id + assignment), ast_edit
  (first op's pattern / replacement / paths), browser (action + tab + url +
  code), and write content (alongside path). For `task` in particular this
  closes the gap that docs/approval-mode.md's "parent's approval covers the
  subagent" claim was waving at — the prompt now actually shows what's being
  delegated.

- Tighten isMcpToolName: drop the fallback `|| toolName.includes("__")` so
  an extension tool legally named `my__feature` or `pkg__util__do` is no
  longer falsely labelled `Origin: MCP server tool` in the approval prompt.
  Strict `mcp__` prefix only.

- Revert the cargo-cult `{ autoApprove: true } as AgentToolContext` insertions
  in agent-session-python-cleanup.test.ts and sdk-move-cwd.test.ts. The tests
  create sessions without passing settings, so the wrapper falls through to
  approvalMode "auto" automatically; the explicit flag was unnecessary and
  the `as AgentToolContext` cast hid that autoApprove lives on
  CustomToolContext, not AgentToolContext.

- Document in commands/launch.ts the dual --auto-approve declaration (oclif
  Flags for --help, manual parseArgs for runtime) so a future rename catches
  both call sites.

- Promote the subagent caveat in docs/approval-mode.md to a callout near the
  top: anything `task` is asked to do runs unattended once the parent task
  call is approved.

Verification:
- bun test packages/coding-agent/test/tools/approval.test.ts → 75 pass / 0 fail
  (was 57; +18 cases covering new remote-exec patterns, chmod symbolic, tee
  /etc, isMcp negative, and eval/task/ast_edit/browser/write payload previews)
- bun test packages/coding-agent/test/tools/approval-mode.test.ts → 7 pass /
  0 fail (was 7; +1 case asserting extensionRunner is always constructed)
- bun tsc --noEmit -p packages/coding-agent → clean
- bun x biome check . → clean
- Windows EBUSY tempdir-cleanup noise in agent-session-python-cleanup and
  sdk-move-cwd is pre-existing on this branch (already documented in the
  PR body) and absent on Linux CI.
2026-05-26 20:53:35 +02:00
oldschoola 384f429461 fix(coding-agent): tighten approval edge cases and rewrite mode docs
- approval: user 'tool: deny' now wins over critical-pattern override
  (the override only tightens allow->prompt; it must never re-arm a denied tool).
- approval: rename hindsight policy keys to match registered tool names
  (recall/retain/reflect, not hindsight_recall/hindsight_retain).
- approval: head+tail truncation for bash/ssh command prompts so a
  destructive suffix buried after a long benign preamble stays visible.
- task/executor: force tools.approvalMode='auto' in createSubagentSettings
  so subagents (which have no UI) cannot deadlock on per-tool prompts;
  the parent's approval of the task call is the authorization.
- docs/approval-mode: rewrite so every example surfaces tools.approvalMode
  and explains that tools.approval is ignored outside 'custom' mode.
2026-05-26 20:53:35 +02:00
oldschoola 4d26453a0b feat(coding-agent): restore per-tool approval policies with safer defaults
Re-introduces the per-tool approval system from luzidd's commit 39124f3 (which
is no longer reachable from main) and improves it before re-landing.

What's restored:
- ApprovalPolicy (allow/deny/prompt) plus DEFAULT_APPROVAL_POLICIES.
- ACTION_EXCEPTIONS registry (LSP read-only, bash critical patterns).
- getApprovalPolicy() six-level resolution order.
- ExtensionToolWrapper.execute() gate before extension handlers.
- --auto-approve / --yolo CLI flag and tools.approval.<tool> user config.
- docs/approval-mode.md user guide.

What's improved over the original:
- Replaced unchecked 'as any' casts with typed unknown narrowing helpers.
- Validate userConfig values: invalid strings, numbers, etc. fall through to
  the built-in default instead of being silently honoured (typo no longer
  locks a tool out or grants implicit approval).
- Expanded CRITICAL_BASH_PATTERNS: chmod -R /, chown -R /, bash <(curl ...),
  writes to /etc/passwd|shadow|sudoers, shutdown/reboot/halt/init 0,
  kill -9 1, nc -e / nc -c reverse shells. Pattern shapes require a
  command-position boundary so 'npm run reboot-tests' and 'echo "shutdown the
  queue"' don't false-positive.
- Added DEBUG_READONLY_ACTIONS exception so DAP inspection actions (threads,
  stack_trace, variables, scopes, read_memory, …) auto-allow while
  execution-side actions (launch, attach, continue, evaluate, write_memory,
  set_breakpoint, …) still prompt.
- formatApprovalPrompt: labels mcp__<server>__<tool> calls as MCP server
  tools, surfaces ssh host + command, recognises the modern § hashline header
  for edit, and truncates >240-char fields so a heredoc-sized body cannot
  blow out the confirmation dialog.
- Test suite grown from 40 to 57 cases — new coverage for invalid user
  config, the extended critical-bash patterns, benign-keyword negatives,
  debug exceptions, MCP/ssh prompt formatting, and command truncation.

Verification:
- bun test packages/coding-agent/test/tools/approval.test.ts -> 57 pass
- bun x biome check . -> clean
- bun run check:ts across all 9 workspaces -> clean
2026-05-26 20:53:33 +02:00