Commit Graph

10 Commits

Author SHA1 Message Date
can1357 7cebe901b7 refactor(coding-agent): narrowed over-exported internal symbols
- 28 symbols across discovery, mcp header policy, agent-hub projection and
  rendering, the agent registry, shell tokenizing and changelog comparison
  were exported but referenced only inside their own module; they are now
  module-private, shrinking the deep-import surface.
- Kept AGENT_PLUGIN_MANIFEST_SCHEMA, AGENT_PLUGIN_MCP_SCHEMA,
  parseAgentPluginManifest, clearAgentPluginRootCache and mergeMCPHeaders
  exported: each is a seam for tests that defend real parsing or header
  precedence behavior.
- Nothing reachable from an explicit exports entry or public barrel changed.
2026-08-08 06:32:01 +02:00
can1357 8b9579c06a fix(bash): preserve escaped newline semantics 2026-08-07 13:39:54 +02:00
roboomp 2597244b00 fix(bash): constrain leading cd extraction to a single path token
The `cd <path> && ...` extractor matched everything up to the first `&&`
with a greedy regex, so a redirect or extra argument before the `&&` was
swallowed into the structured cwd. `cd /tmp 2>/dev/null && echo ok` became
cwd `/tmp 2>/dev/null`, which failed fs.stat and killed the command before
the shell ran.

Replace the regex with `extractLeadingCdTarget`, a quote/escape-aware
scanner in shell-tokenize.ts that captures exactly one path token and
bails (leaving the command for the shell) when anything else — a redirect,
extra argument, shell expansion, or a non-`&&` separator — precedes the
top-level `&&`.

Fixes #7883
2026-08-07 06:43:55 +00:00
roboomp 430e4e386b fix(tool): preserved piped stdin across continuations
Retained pending pipeline state across blank and comment-only continuation
lines, and parsed Bash's |& operator as a single pipe boundary. Added
regression coverage for both forms and aligned the Bash interceptor docs.

Fixes #7496
2026-08-03 12:45:50 +00:00
roboomp cbfbcd865e fix(tool): exempt piped-stdin stages from bash interceptor
The 17.2.2 compound-fragment matching splits commands on every unquoted
operator including `|`, so a downstream pipe stage like `grep x` in
`printf 'x\n' | grep x` became a standalone interception candidate and was
routed to the `grep` tool, which searches paths and cannot consume the
previous stage's stdout.

`extractFlatShellCommandSegments` now flags each segment that receives piped
stdin from a single unquoted `|`, and `interceptionCandidates` skips those:
a stdin-consuming stage cannot be replaced by a path-based dedicated tool.
Standalone (`grep pattern path`), first-stage (`grep x file | wc`), and
`&&`/`||`/`;`-sequenced commands still match.

Fixes #7496
2026-08-03 12:36:36 +00:00
can1357 80a46c2d4c fix(coding-agent): avoid splitting parameter expansions 2026-07-31 19:07:18 +02:00
Vincent Huang 296ece7ea5 fix(coding-agent): handle input fd redirects in interceptor 2026-08-01 00:34:19 +12:00
Vincent Huang 270590c225 fix(coding-agent): avoid splitting Bash redirection operators 2026-07-31 23:51:18 +12:00
Vincent Huang edb0deebb4 fix(coding-agent): inspect compound Bash commands in interceptor rules
Match interceptor regexes against conservative, raw shell command segments
in addition to the complete command, so anchored rules can detect commands
after &&, ||, ;, |, &, and newlines without treating quoted or escaped text
as commands.

Add extractFlatShellCommandSegments() to preserve source text for
user-configured regexes, unlike the token-based approval matcher.
Add skipShellWord() and environment-assignment stripping so rules can match
commands prefixed with NAME=value assignments. Preserve the original command
in interception errors after extracting a leading cd command.
2026-07-31 23:26:43 +12:00
roboomp e650607cad fix(coding-agent): segment bash approval commands with shell-aware tokenizer
The regex splitter only recognized `&&`, `||`, `;`, `|` and newlines, so a
single `&` (background operator) — also a command terminator — slipped a
dangerous command past a deny rule (`sleep 1 & rm -rf /tmp/x`), which under
approvalMode: yolo executed with no prompt.

Extract the shell-aware tokenizer from gh-cache-invalidation into a shared
tools/shell-tokenize.ts and reuse it for deny/prompt segmentation. It honors
every command boundary (`&&`, `||`, `;`, `|`, single `&`, subshells,
newlines) plus quoting and escapes, so both callers share one implementation.

Fixes #6695
2026-07-26 11:36:19 +00:00