Skip to content
This repository was archived by the owner on Oct 9, 2026. It is now read-only.

fix: the command whitelist skips the built-in dangerous patterns - #45

Closed
mekjr1 wants to merge 1 commit into
mainfrom
fix/exec-custom-allow
Closed

mekjr1 wants to merge 1 commit into
mainfrom
fix/exec-custom-allow

Conversation

@mekjr1

@mekjr1 mekjr1 commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Fixes #38.

tools.exec.custom_allow_patterns (Config → Run Commands → Command Whitelist) never let a command through. guardCommand checked every deny pattern first and refused any match. It read the allow patterns only for a strict allowlist (allowPatterns) that nothing set.

Now the setting does what its hint says, by the rule the issue suggests:

  • ExecTool keeps the built-in deny patterns (denyPatterns) apart from custom_deny_patterns (customDenyPatterns). A command that matches a custom allow pattern skips the built-in patterns. The custom deny patterns apply to every command, so the protection TestShellTool_CustomAllowDoesNotBypassDenyPatterns covers stays: a whitelisted jq still can't read $ENV past a blacklist rule. The workspace limits apply as before.
  • The settings page's pattern tester (POST /api/config/test-command-patterns) checks the blacklist first. A command that both lists match shows as blocked; it showed as allowed. The page already shows blocked that way.
  • The unused strict allowlist is gone: allowPatterns, SetAllowPatterns and its "not in allowlist" refusal.

A whitelist pattern is matched against the whole command line, as the blacklist is. So ^git\s+push\b also lets whatever is chained after git push skip the built-in patterns. End a pattern with $ to allow a single command.

The whitelist hint now says which patterns a match skips and that the blacklist still applies, in all five languages. docs/use.md lists the whitelist among the command controls. CHANGELOG line.

Tests:

  • TestShellTool_CustomAllowPatterns now calls guardCommand. It called Execute without action, which refused before the guard ran. It checks that:
    • a whitelisted command passes a built-in pattern;
    • a command that isn't whitelisted doesn't;
    • a whitelisted command is still refused by a custom deny pattern, or when it leaves the workspace.
  • That test fails under both the old rule and a whitelist that skips the custom patterns too. TestShellTool_CustomAllowDoesNotBypassDenyPatterns also fails under the second.
  • TestHandleTestCommandPatterns_BlacklistOutranksWhitelist fails with the old tester.

@mekjr1

mekjr1 commented Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #63, which includes this change or replaces it.

@mekjr1 mekjr1 closed this Oct 9, 2026
mekjr1 added a commit that referenced this pull request Oct 9, 2026
Compa 4.0.0: one owner, on WhatsApp and Slack.

- **Channels:** the web chat, WhatsApp (native linked device, QR linking, files up to 50 MB), Slack (bot and app tokens), and the Slack and Teams webhooks. The other chat apps are no longer included.
- **Owner only:** the accounts in Allow From, in direct messages. Pairing binds the first account.
- **Message tool:** sends to any chat by default. Cron results, heartbeat messages and approval requests also go to the webhooks.
- **Dependencies:**
  - llmgw-core 1.9.1, llm-provider-auth 1.0.1, llm-translate 0.4.0.
  - Go 1.26.9 and golang.org/x/net 0.60.0, which fix vulnerabilities.
- **Go module path:** github.com/xibodev/compa/v4.
- **Release archives:** they hold THIRD_PARTY_NOTICES.
- **Upgrades:** a config.json saved by 1.0.0 loads.
- **Docs and website:** rewritten.
- **From the earlier PRs:** the fixes and features of #45 to #52 and #57 to #61.
@mekjr1
mekjr1 deleted the fix/exec-custom-allow branch October 9, 2026 03:27
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

tools.exec.custom_allow_patterns never allows a command

1 participant