From 1fd0ef75208d09d4dee4e22982f7a8d564562751 Mon Sep 17 00:00:00 2001 From: teknium1 <127238744+teknium1@users.noreply.github.com> Date: Mon, 14 Sep 2026 18:59:57 -0700 Subject: [PATCH] test(cron): trim the heredoc-walk regression to its two invariants Keep the inert-body path (false) and the unquoted-body path (still true); the `sh -c`-in-`cat` heredoc and plain script-reference cases are already pinned by the existing lifecycle-guard suites. Comment shortened to the WHY. --- cron/lifecycle_guard.py | 12 ++---- .../cron/test_lifecycle_guard_heredoc_walk.py | 43 ++++--------------- 2 files changed, 12 insertions(+), 43 deletions(-) diff --git a/cron/lifecycle_guard.py b/cron/lifecycle_guard.py index 54251c2dc4..5b9f41dc6a 100644 --- a/cron/lifecycle_guard.py +++ b/cron/lifecycle_guard.py @@ -921,15 +921,9 @@ def _contains_unsafe_gateway_action( read_remote_script=read_remote_script, ) - # The referenced-script and `-c` payload walks must see the same masked view the direct - # scan sees (#110422): `_direct_lifecycle_scan` masks provably-inert heredoc bodies via - # `strip_inert_heredoc_bodies`, but the walks below ran on the unmasked command. A path (or an - # `sh -c` payload) inside such a body is never shell-executed, so walking it is a pure false - # positive — e.g. a >1 MiB path mentioned in a `python3 - <<'PY'` body fails closed and - # hard-blocks an innocent command. The stripper only masks under its conservative contract - # (quoted delimiters, exact terminator, single simple command, allowlisted consumer, no command - # substitution); anything ambiguous stays visible and fail-closed, and masking is a no-op when - # the command has no `<<`. + # The walks below must see the same masked view `_direct_lifecycle_scan` sees (#110422): a + # path or `sh -c` payload inside a provably-inert heredoc body is never shell-executed, and an + # oversized data file mentioned there otherwise fails closed as a "script". from tools.shell_heredoc import strip_inert_heredoc_bodies walk_command = strip_inert_heredoc_bodies(command) diff --git a/tests/cron/test_lifecycle_guard_heredoc_walk.py b/tests/cron/test_lifecycle_guard_heredoc_walk.py index 2244899e65..54cd8ea155 100644 --- a/tests/cron/test_lifecycle_guard_heredoc_walk.py +++ b/tests/cron/test_lifecycle_guard_heredoc_walk.py @@ -1,52 +1,27 @@ -"""Inert-heredoc masking in the referenced-script walk (regression for #110422). +"""The referenced-script walk sees the same inert-heredoc-masked view as the direct scan (#110422). -The direct lifecycle scan masks provably-inert heredoc bodies -(``strip_inert_heredoc_bodies``), but the referenced-script and ``-c`` payload -walks in ``_contains_unsafe_gateway_action`` ran on the unmasked command: a -path (or an ``sh -c`` payload) inside such a body is never shell-executed, so -walking it was a pure false positive — e.g. a >1 MiB path mentioned in a -``python3 - <<'PY'`` body failed closed and hard-blocked an innocent command. -The walks now use the same masked view as the direct scan. +``_direct_lifecycle_scan`` masks provably-inert heredoc bodies (quoted delimiter, allowlisted +data consumer such as ``python3 - <<'PY'``), but ``_contains_unsafe_gateway_action`` walked +referenced scripts and ``sh -c`` payloads on the raw command, so a >1 MiB data path mentioned +inside the Python body failed closed as an oversized "script". """ -from __future__ import annotations - -from cron.lifecycle_guard import ( - contains_gateway_lifecycle_command_or_referenced_script, -) - -guard = contains_gateway_lifecycle_command_or_referenced_script +from cron.lifecycle_guard import contains_gateway_lifecycle_command_or_referenced_script as guard def _big_file(tmp_path): - """A regular file over the 1 MiB referenced-script cap.""" path = tmp_path / "big_blob.bin" path.write_bytes(b"\0" * (2 * 1024 * 1024)) return path def test_inert_heredoc_body_path_not_walked_as_script(tmp_path): - """A >1 MiB path inside a provably-inert heredoc body is not a script reference.""" big = _big_file(tmp_path) - command = f"python3 - <<'PY'\n{big}\nPY" - assert guard(command, cwd=str(tmp_path)) is False - - -def test_inert_heredoc_body_sh_c_prose_not_extracted(tmp_path): - """An `sh -c` line inside an inert body is printed data, not an executed payload.""" - command = 'cat <<\'EOF\'\nsh -c "hermes gateway restart"\nEOF' + command = f"python3 - <<'PY'\nfrom pathlib import Path\nprint(Path('{big}').stat().st_size)\nPY" assert guard(command, cwd=str(tmp_path)) is False def test_unquoted_heredoc_body_path_still_walked(tmp_path): - """Unquoted delimiter = expansion-capable = still visible to the walk, fail-closed.""" + """An expansion-capable body is not provably inert: the walk still sees it and fails closed.""" big = _big_file(tmp_path) - command = f"cat > /tmp/x < /tmp/x <