-
Notifications
You must be signed in to change notification settings - Fork 0
π‘οΈ Sentinel: [MEDIUM] sandboxed_web_e2e.pyμ subprocess νΈμΆμ shell=False λͺ μ #1156
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. Weβll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Closed
Closed
Changes from all commits
Commits
Show all changes
49 commits
Select commit
Hold shift + click to select a range
1cf0e71
fix(security): make sandbox subprocess mode explicit
seonghobae 96c42ce
보μ: sandboxed_web_e2e.pyμ subprocess νΈμΆμ shell=False μΆκ°
seonghobae 72f9161
fix(sandbox): satisfy Ruff and Bandit subprocess contracts
seonghobae 64df5b6
보μ: sandboxed_web_e2e.pyμ subprocess νΈμΆμ shell=False μΆκ°
seonghobae 021f2a2
fix(sandbox): retain subprocess lint suppressions on current head
seonghobae 0622231
보μ: sandboxed_web_e2e.pyμ subprocess νΈμΆμ shell=False μΆκ°
seonghobae 3e91f12
fix: document trusted subprocess lint suppressions
seonghobae b3905f9
보μ: sandboxed_web_e2e.pyμ subprocess νΈμΆμ shell=False μΆκ°
seonghobae 0cd77d0
fix: retain trusted subprocess lint evidence
seonghobae 19c73a0
보μ: sandboxed_web_e2e.pyμ subprocess νΈμΆμ shell=False μΆκ°
seonghobae b84e7a3
fix: retain trusted subprocess lint evidence
seonghobae dcf3196
보μ: sandboxed_web_e2e.pyμ subprocess νΈμΆμ shell=False μΆκ°
seonghobae 893f854
fix: retain trusted subprocess lint evidence
seonghobae 71e7b4f
보μ: sandboxed_web_e2e.pyμ subprocess νΈμΆμ shell=False μΆκ°
seonghobae 73fdbf7
fix: retain trusted subprocess lint evidence
seonghobae 4b9508a
보μ: sandboxed_web_e2e.pyμ subprocess νΈμΆμ shell=False μΆκ°
seonghobae 020c6b8
fix(security): retain subprocess lint evidence
seonghobae 1e85ab0
보μ: sandboxed_web_e2e.pyμ subprocess νΈμΆμ shell=False μΆκ°
seonghobae 65246be
Merge remote-tracking branch 'origin/main' into HEAD
seonghobae deacb92
Merge remote-tracking branch 'origin/fix-sandboxed-web-e2e-b603-32043β¦
seonghobae d5f2d10
fix(security): keep PR scoped to sandbox subprocess
seonghobae 7ed6f15
보μ: sandboxed_web_e2e.pyμ subprocess νΈμΆμ shell=False μΆκ°
seonghobae 6c77c0f
보μ: sandboxed_web_e2e.pyμ subprocess νΈμΆμ shell=False μΆκ°
seonghobae 209fd38
fix(security): preserve sandbox lint evidence
seonghobae 1c00cde
보μ: sandboxed_web_e2e.pyμ subprocess νΈμΆμ shell=False μΆκ°
seonghobae 7c0be13
fix(security): retain sandbox subprocess contract
seonghobae 2b88970
보μ: sandboxed_web_e2e.pyμ subprocess νΈμΆμ shell=False μΆκ°
seonghobae 4988c32
fix(security): restore scoped sandbox PR diff
seonghobae 071a9ce
보μ: sandboxed_web_e2e.pyμ subprocess νΈμΆμ shell=False μΆκ°
seonghobae 79395ed
fix(security): restore sandbox PR scope after concurrent update
seonghobae 1780b4d
보μ: sandboxed_web_e2e.pyμ subprocess νΈμΆμ shell=False μΆκ°
seonghobae 19b53a7
fix(security): keep sandbox PR limited to requested files
seonghobae f19549c
보μ: sandboxed_web_e2e.pyμ subprocess νΈμΆμ shell=False μΆκ°
seonghobae 558c437
chore: restore sentinel PR scope
seonghobae 42ff0bb
보μ: sandboxed_web_e2e.pyμ subprocess νΈμΆμ shell=False μΆκ°
seonghobae dee2528
chore: restore sentinel PR scope
seonghobae da0673a
보μ: sandboxed_web_e2e.pyμ subprocess νΈμΆμ shell=False μΆκ°
seonghobae 1f811e8
chore: restore sentinel PR scope
seonghobae 8b0f7a7
보μ: sandboxed_web_e2e.pyμ subprocess νΈμΆμ shell=False μΆκ°
seonghobae d4948f2
chore: restore sentinel PR scope
seonghobae 86bdbc2
Merge branch 'main' into fix-sandboxed-web-e2e-b603-3204335274775172996
opencode-agent[bot] 0270c9c
fix(security): restrict readiness checks to loopback
seonghobae 684063a
보μ: sandboxed_web_e2e.pyμ wait_for_url ν¨μ SSRF μ·¨μ½μ μμ
seonghobae 7655ab6
Revert "보μ: sandboxed_web_e2e.pyμ wait_for_url ν¨μ SSRF μ·¨μ½μ μμ "
seonghobae 4ab419a
보μ: sandboxed_web_e2e.pyμ wait_for_url ν¨μ SSRF μ·¨μ½μ μμ
seonghobae 2ba74d0
test: complete sandboxed web E2E docstrings
seonghobae a0cde93
보μ: sandboxed_web_e2e.pyμ wait_for_url ν¨μ SSRF μ·¨μ½μ μμ
seonghobae 6aee33e
test: document sandboxed web e2e doubles
seonghobae 66d65c1
보μ: sandboxed_web_e2e.pyμ wait_for_url ν¨μ SSRF μ·¨μ½μ μμ
seonghobae File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
31 changes: 0 additions & 31 deletions
31
.github/workflows/quarantine-sandbox-hourly-review-repair.yml
This file was deleted.
Oops, something went wrong.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
π΄ Organization-wide review budget resets for every repository, flooding CI each sweep
The review and branch-update budgets are handed to each repository in full (
--review-dispatch-limit "$ORG_SWEEP_REVIEW_DISPATCH_LIMIT"at.github/workflows/pr-review-merge-scheduler.yml:828) instead of being shared and drawn down across the whole run, so every repository restarts the entire budget.Impact: A single scheduled sweep can start many long-running review and branch-update jobs across all organization repositories every 15 minutes, instead of the intended small org-wide cap.
Removed org-wide budget accumulation across the repository loop
The previous code initialized
org_review_dispatches_used=0/org_branch_updates_used=0before the loop, computed a per-target remaining limit (review_dispatch_limit=$((ORG_SWEEP_REVIEW_DISPATCH_LIMIT - org_review_dispatches_used))), passed that remaining amount to the scheduler, and after each repository incremented the used counters by parsing the sweep output. This PR removes all of that (see the deleted lines around.github/workflows/pr-review-merge-scheduler.yml:803-806and:835-884on the LEFT side) and now passes the raw env varsORG_SWEEP_REVIEW_DISPATCH_LIMIT/ORG_SWEEP_BRANCH_UPDATE_LIMITdirectly at.github/workflows/pr-review-merge-scheduler.yml:828-829. With the default value'1'per repository and dozens of target repositories, the effective total becomeslimit Γ repository_countper sweep. The deleted code explicitly warned: "These are organization-wide budgets. They must be consumed across the repository loop, not reset for every target repository; resetting them here can enqueue hundreds of long-running review jobs per sweep." The matching contract assertions intests/test_required_workflow_queue_contract.pywere also removed.Prompt for agents
Was this helpful? React with π or π to provide feedback.