fix(sdk): bind workbench Git to a trusted executable - #467
fix(sdk): bind workbench Git to a trusted executable#467mldangelo-oai wants to merge 33 commits into
Conversation
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 5dc0f1c298
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Security review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
|
@codex review |
|
Security review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 9be47a60bb
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
|
Security review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 49000ab013
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
|
Codex Review: Didn't find any major issues. Keep it up! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
|
Security review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
…/codex/portfolio-pr-467-20260815
|
@codex review Please review the current head, |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 743e32f028
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Security review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
|
@codex review Please review the current head, |
|
Security review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c0142c5739
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Codex Review: Didn't find any major issues. More of your lovely PRs please. Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
|
Security review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
|
@codex review Please review the current head, |
|
Codex Review: Didn't find any major issues. Bravo. Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
|
@codex security review Please review the current head |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 76b9e90661
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review Please review exact head 0552695. The additive follow-up fixes the launch-directory exclusion and checks bundled-ripgrep staging against all actual protected inputs. The affected tests, installed-package checks, strict TypeScript consumers, and both full suites pass. The PR remains draft. |
|
Codex Review: Didn't find any major issues. Breezy! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
|
@codex security review Please review the current head |
|
Codex Review: Didn't find any major issues. Another round soon, please! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
|
@codex security review Please review exact head |
|
@codex review Please review exact head |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Codex Review: Something went wrong. Try again later by commenting “@codex review”. ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
|
Codex Review: Didn't find any major issues. Keep them coming! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
kmbroai
left a comment
There was a problem hiding this comment.
Critical review
Reviewed head 8f4f32a47b703c4f452e702d63fa708e91d22dbd, including the earlier executable-selection feedback.
Recommendation: keep this narrowed trusted-Git binding. No new blocking defect found in the reviewed changes. Host inspection is ineffective if the Python helper later performs a fresh PATH search inside the scan environment. Carrying the inspected invocation into the helper closes that gap without requiring a general tool-distribution subsystem.
Correctness and earlier comments
trusted_git_executable checks both lexical and canonical containment, preserves the invocation name for wrappers/multicall binaries, and validates native Windows invocation semantics without requiring an extension on the resolved native target. Missing/unusable binding returns the optional-Git failure status without executing the literal fallback string.
The host now retains the sanitized environment even when no executable is found. It derives protected roots from the selected filesystem inputs, not Git's configurable core.worktree, and carries the binding through .mcp.json. Inventory/ranking Git calls use the shared command wrapper with external diff/textconv disabled. This addresses the substantive earlier selection and invocation-path concerns.
The public CODEX_SECURITY_GIT configuration/disable proposal and bundled-ripgrep staging were removed. The current README correctly describes this variable as host-generated runtime data, so the old requests to preserve user overrides do not apply to the narrowed contract.
Simplification and limits
This is a good place to stop the abstraction: one inspected executable/environment pair and Python revalidation of the same binding. Do not reintroduce separate Git/ripgrep installers, broad launch-directory restrictions, or per-tool configuration flags without a demonstrated requirement.
The shared resolver still needs the distinction between a null executable and a sanitized environment; collapsing that back to null would recreate the earlier bug. Do not describe the binding as a cryptographic executable pin or a general sandbox—it establishes the selected trusted path under the repository-input threat model.
Verification
Ran four resolver/launcher/workbench suites: 13 passed, 2 skipped, 0 failed, then seven focused API/runtime Git integration cases: 7 passed, 0 failed. These include actual nested-repository shim rejection and an MCP launch with empty PATH. Linux, Bun 1.3.14 / Node 22.13.1 with cached dependencies. Native Windows alias behavior was source-reviewed but not executed on Windows; no model call occurred.
Summary
Prevent repository-controlled Git shims from running inside the bundled Python scan helpers.
The SDK now selects Git at the host boundary, sanitizes its environment against the scanned repository and knowledge-base sources, and carries that internal binding into the workbench and MCP process. Python revalidates the binding and never searches its inherited
PATHfor Git.Fixes #129. Incorporates the narrow approach from #140.
Changes
PATHto workbench commands and Codex. Forward only the internalCODEX_SECURITY_GITbinding through MCP.127without spawning fromPATH. Windows accepts native.exeand.cominvocations while rejecting canonical batch targets.0.1.29and document the Git binding as active-scan runtime data, not supported user configuration.Testing
467before the final focused review corrections: 1,585 passed, 30 skipped, 0 failed.pnpm run types,pnpm run format, Ruff, andgit diff --check: passed after the final changes.Risk and rollout
No CLI flag, supported environment setting, dependency, npm version, or root package export changes. The public
pluginExecutionEnvironmentsignature remains unchanged.CODEX_SECURITY_GITis overwritten by the SDK for child processes and is not user configuration.Git remains optional for directory scans. If the selected executable disappears, Python reports Git as unavailable and preserves the directory-snapshot fallback. Git-dependent diff scans still require Git. Safe operator Git and SSH settings remain available, while repository-scoped execution settings are removed before each probe.
The focused tests simulate Windows executable rules. Native Windows validation remains with CI.
Public disclosure review
The new branch update, title, description, commit, changed files, tests, and links use generic public-repository context. Historical public material on this pull request includes maintainer identity in older commit metadata, access-restricted automated report links, and detailed prior review discussions. Editing this description cannot remove those existing artifacts.