refactor(tools): group H pass 1 — dead code, shared read_pane bridge, zip/xml helpers, collapsed defensive layers
This commit is contained in:
+20
-37
@@ -1,22 +1,17 @@
|
||||
"""Conservative heredoc masking for shell-command scanners.
|
||||
|
||||
Guards that scan raw command text (the foreground background-'&' guard in
|
||||
``tools/terminal_tool.py``, blocked-command checks, ``cron/lifecycle_guard``)
|
||||
false-positive on heredoc *bodies*, which are usually inline data. Naively
|
||||
stripping every body is unsafe the other way (fake ``<<`` in quotes can
|
||||
swallow a real operator; unquoted bodies expand; ``bash <<'EOF'`` executes).
|
||||
Guards that scan raw command text (the background-'&' guard in ``tools/terminal_tool.py``,
|
||||
blocked-command checks, ``cron/lifecycle_guard``) false-positive on heredoc *bodies*, which
|
||||
are usually inline data. Naively stripping every body is unsafe the other way (fake ``<<``
|
||||
in quotes can swallow a real operator; unquoted bodies expand; ``bash <<'EOF'`` executes).
|
||||
|
||||
A body is masked ONLY when: every delimiter on the opener is quoted (no
|
||||
expansion); every heredoc is terminated by an exact delimiter line; the
|
||||
opener is a single command (no ``;``/``|``/``&`` and no ``$(...)``, backtick
|
||||
or process substitution); and the consumer is an allowlisted non-shell
|
||||
interpreter (``_INERT_HEREDOC_CONSUMER_RE``). Otherwise the command is
|
||||
returned untouched: a false positive is acceptable, hiding real shell syntax
|
||||
from a guard is not. Masked bodies become an equal number of newlines so
|
||||
``re.MULTILINE`` scanning keeps its line structure.
|
||||
|
||||
Adapted from Wolfram Ravenwolf's security-hardened rework of PR #63788
|
||||
(commit 69c7663c6de6b6cb05bf99203fa39673efe01ccf).
|
||||
A body is masked ONLY when: every delimiter on the opener is quoted (no expansion); every
|
||||
heredoc is terminated by an exact delimiter line; the opener is a single command (no
|
||||
``;``/``|``/``&`` and no ``$(...)``, backtick or process substitution); and the consumer is
|
||||
an allowlisted non-shell interpreter (``_INERT_HEREDOC_CONSUMER_RE``). Otherwise the command
|
||||
is returned untouched: a false positive is acceptable, hiding real shell syntax from a guard
|
||||
is not. Masked bodies become an equal number of newlines so ``re.MULTILINE`` scanning keeps
|
||||
its line structure. Adapted from Wolfram Ravenwolf's security-hardened rework of PR #63788.
|
||||
"""
|
||||
|
||||
from __future__ import annotations
|
||||
@@ -62,8 +57,7 @@ def _mask_simple_quotes(command: str) -> str:
|
||||
break
|
||||
result.append("''")
|
||||
cursor = closing + 1
|
||||
continue
|
||||
if char == '"':
|
||||
elif char == '"':
|
||||
end = _span_end(command, cursor, '"')
|
||||
if not command[cursor:end].endswith('"'):
|
||||
result.append(command[cursor:])
|
||||
@@ -71,14 +65,13 @@ def _mask_simple_quotes(command: str) -> str:
|
||||
segment = command[cursor:end]
|
||||
result.append(segment if "$(" in segment or "`" in segment else '""')
|
||||
cursor = end
|
||||
continue
|
||||
if char == "`":
|
||||
elif char == "`":
|
||||
end = _span_end(command, cursor, "`")
|
||||
result.append(command[cursor:end])
|
||||
cursor = end
|
||||
continue
|
||||
result.append(char)
|
||||
cursor += 1
|
||||
else:
|
||||
result.append(char)
|
||||
cursor += 1
|
||||
return "".join(result)
|
||||
|
||||
|
||||
@@ -88,9 +81,8 @@ def _parse_heredoc_operator(command: str, index: int):
|
||||
return None
|
||||
|
||||
cursor = index + 2
|
||||
strip_tabs = False
|
||||
if cursor < len(command) and command[cursor] == "-":
|
||||
strip_tabs = True
|
||||
strip_tabs = cursor < len(command) and command[cursor] == "-"
|
||||
if strip_tabs:
|
||||
cursor += 1
|
||||
while cursor < len(command) and command[cursor] in " \t":
|
||||
cursor += 1
|
||||
@@ -161,7 +153,6 @@ def _scan_heredoc_command_unit(command: str, start: int):
|
||||
return cursor, specs, unknown_operator, has_list_operator
|
||||
cursor += 1
|
||||
continue
|
||||
|
||||
if quote is not None:
|
||||
if quote in {'"', "`"} and char == "\\" and cursor + 1 < len(command):
|
||||
cursor += 2
|
||||
@@ -170,7 +161,6 @@ def _scan_heredoc_command_unit(command: str, start: int):
|
||||
quote = None
|
||||
cursor += 1
|
||||
continue
|
||||
|
||||
if char == "\\" and cursor + 1 < len(command):
|
||||
# Includes line continuations: the logical command keeps going.
|
||||
cursor += 2
|
||||
@@ -206,12 +196,7 @@ def _scan_heredoc_command_unit(command: str, start: int):
|
||||
return len(command), specs, unknown_operator, has_list_operator
|
||||
|
||||
|
||||
def _find_heredoc_close(
|
||||
command: str,
|
||||
body_start: int,
|
||||
delimiter: str,
|
||||
strip_tabs: bool,
|
||||
) -> int | None:
|
||||
def _find_heredoc_close(command: str, body_start: int, delimiter: str, strip_tabs: bool) -> int | None:
|
||||
"""Return the position after an exact shell heredoc terminator line."""
|
||||
cursor = body_start
|
||||
while True:
|
||||
@@ -237,9 +222,7 @@ def strip_inert_heredoc_bodies(command: str) -> str:
|
||||
command_start = 0
|
||||
|
||||
while command_start <= last_opener_index:
|
||||
command_end, specs, unknown_operator, has_list_operator = (
|
||||
_scan_heredoc_command_unit(command, command_start)
|
||||
)
|
||||
command_end, specs, unknown_operator, has_list_operator = _scan_heredoc_command_unit(command, command_start)
|
||||
if unknown_operator:
|
||||
return command
|
||||
if not specs:
|
||||
|
||||
Reference in New Issue
Block a user