Compare commits

...

2 Commits

Author SHA1 Message Date
CleverAgents Bot 67a61472e0 ci: stop master workflow on PR updates
CI / lint (pull_request) Has been cancelled
CI / typecheck (pull_request) Has been cancelled
CI / security (pull_request) Has been cancelled
CI / quality (pull_request) Has been cancelled
CI / unit_tests (pull_request) Has been cancelled
CI / integration_tests (pull_request) Has been cancelled
CI / e2e_tests (pull_request) Has been cancelled
CI / coverage (pull_request) Has been cancelled
CI / build (pull_request) Has been cancelled
CI / docker (pull_request) Has been cancelled
CI / helm (pull_request) Has been cancelled
CI / push-validation (pull_request) Has been cancelled
CI / status-check (pull_request) Has been cancelled
Remove the stale pull_request trigger from master.yml so PR branch commits do not launch the master workflow.

Maintenance patch for PR #11014.
2026-06-10 20:20:34 -04:00
HAL9000 876a7b57b8 fix(security): fix file_tools.py validate_path startswith bypass #7478
CI / benchmark-publish (pull_request) Has been skipped
CI / build (pull_request) Successful in 49s
CI / lint (pull_request) Successful in 1m7s
CI / helm (pull_request) Successful in 46s
CI / quality (pull_request) Successful in 1m12s
CI / benchmark-regression (pull_request) Failing after 1m17s
CI / typecheck (pull_request) Successful in 1m40s
CI / push-validation (pull_request) Successful in 45s
CI / security (pull_request) Successful in 1m58s
CI / integration_tests (pull_request) Successful in 4m18s
CI / e2e_tests (pull_request) Failing after 4m15s
CI / unit_tests (pull_request) Successful in 6m2s
CI / docker (pull_request) Successful in 1m28s
CI / coverage (pull_request) Successful in 10m44s
CI / status-check (pull_request) Failing after 3s
- Add CHANGELOG.md Security section entry for validate_path path traversal fix.
- Update CONTRIBUTORS.md with HAL 9000 contribution description.
- Fix BDD test scenario tag from @tdd_issue_7558 to @tdd_issue_7478.

ISSUES CLOSED: #7478
2026-05-08 02:44:18 +00:00
4 changed files with 14 additions and 3 deletions
-2
View File
@@ -3,8 +3,6 @@ name: CI
on:
push:
branches: [master, develop]
pull_request:
branches: [master, develop]
vars:
docker_prefix: "http://harbor.cleverthis.com/docker/"
+12
View File
@@ -96,6 +96,18 @@ The format follows [Keep a Changelog](https://keepachangelog.com/en/1.1.0/).
### Security
- **file_tools.py `validate_path` startswith bypass** (#7478): Replaced the insecure
`str(target).startswith(str(root))` prefix check in
`cleveragents.tool.builtins.file_tools.validate_path()` with a proper
`Path.relative_to(root)` containment guard. The old string-prefix approach was
vulnerable to a path-traversal bypass: a sandbox root of ``/tmp/sandbox`` combined
with a crafted path resolving to ``/tmp/sandbox-evil`` would incorrectly pass the
``startswith`` check because the resolved target string literally begins with the
root string. The new implementation uses Python's built-in ``Path.relative_to()``
which correctly rejects any target that is not *within* the sandbox directory
hierarchy, including the prefix-collision case where a sibling directory name
shadowed (i.e., was a string prefix of) the sandbox name.
- **aiohttp upgraded to >=3.13.4 to remediate CVE-2026-34513 and CVE-2026-34515** (#1549, #1544):
Added an explicit `aiohttp>=3.13.4` dependency constraint to `pyproject.toml` to remediate
two high-severity open redirect vulnerabilities. Both CVEs affect the CleverAgents platform's
+1
View File
@@ -19,6 +19,7 @@ Below are some of the specific details of various contributions.
* HAL 9000 has contributed the plan concurrency race-condition fix (#7989): wired `LockService` into the plan lifecycle, guarding `execute_plan()` and `apply_plan()` with plan-level advisory locks and unique per-invocation owner identities to prevent silent concurrent state corruption.
* HAL 9000 has contributed the bug-hunt-pool-supervisor non-blocking tracking fix: updated step 5 to be best-effort and added rule 9 to prevent the automation-tracking-manager call from blocking the main supervisor loop.
* HAL 9000 has contributed the plugin entry point security hardening fix (#7476): enforced entry point allowlist validation before importing plugin modules to prevent malicious plugin loading.
* HAL 9000 has contributed the `file_tools.py validate_path` path traversal startswith bypass fix (#7478): replaced the insecure `str(target).startswith(str(root))` prefix check with a proper `Path.relative_to(root)` containment guard to correctly reject sibling-directory prefix-collision escape paths.
* HAL 9000 has contributed the benchmark workflow separation (#9040): moved the benchmark-regression job out of the default PR workflow into a dedicated scheduled workflow, reducing median PR CI turnaround time from 99-132 minutes to under 30 minutes.
* HAL 9000 has contributed the agent-evolution-pool-supervisor PR metadata assignment (#7888): the supervisor now automatically looks up the Type/Automation label and earliest open milestone before dispatching improvement PR creation workers, ensuring all generated improvement PRs have correct Type labels and milestone assignments.
* This project was made possible thanks to considerable donation of time, money, and resources by CleverThis, Inc.
+1 -1
View File
@@ -160,7 +160,7 @@ Feature: Built-in File Tools
Then the tool result should not be successful
And the tool result error should mention "traversal"
@tdd_issue @tdd_issue_7558
@tdd_issue @tdd_issue_7478
Scenario: Path traversal with sandbox name prefix collision is rejected
Given a temporary sandbox directory
And a sibling directory with a name that is a prefix of the sandbox name