Skip to content

feat(scanner): reject plugin vercel deploy and fly deploy - #1174

Draft
seonghobae wants to merge 16 commits into
feat/claude-plugin-terraform-helm-1099from
feat/claude-plugin-hosted-deploy-1099
Draft

feat(scanner): reject plugin vercel deploy and fly deploy#1174
seonghobae wants to merge 16 commits into
feat/claude-plugin-terraform-helm-1099from
feat/claude-plugin-hosted-deploy-1099

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 8, 2026

Copy link
Copy Markdown
Contributor

Successor of #1173 / issue #1099. Does not Close those. terraform apply and helm install stay #1173. kubectl apply and docker push stay #1172. Pass is not Noema admission.

Unique delta

Fail closed when a plugin hook or manifest runs hosted-platform deploy writes that #1173 left as inventory:

  • vercel deploy as claude-plugin-vercel-deploy-command (CWE-269)
  • fly deploy and flyctl deploy as claude-plugin-fly-deploy-command (CWE-250)
  • vercel ls and fly status stay inventory
  • README vercel wording is not a hook command
  • unquoted # vercel deploy comments and echo/printf/print lookalikes are not this class, including reporting-only manifest command values and deploy-like description prose
  • echo done && fly deploy and vercel deploy # note stay positive
  • terraform apply stays claude-plugin-terraform-apply-command
  • snippets are command labels, not tokens or secrets

#1173 remains owner of terraform apply and helm install.

Evidence

  • RED 50b5551 then GREEN af6b2ec for the original fail-closed class

  • RED 8b1e262 then GREEN 590f477 for hook executable-command precision (review 5136517688)

  • follow-up RED e257d90538c6d8c9a68bfc57661b4eb7198a68df proves raw whole-manifest scanning still misclassified description prose and reporting-only command values; GREEN 746501ec718cf248f69ca00f385c813531d6167a parses only structural manifest command strings and applies the same bounded shell-context rule while preserving a later real deploy command

  • tests/test_claude_plugin_hosted_deploy.py plus sibling terraform/helm lock

  • predecessor plugin coverage suite 403 passed; the new exact head has Python AST validation but no hosted workflow because this PR remains stacked on a custom base, so it stays Draft pending stacked integration evidence

  • Normal two-parent descendant d8f5f76400f952410d1f4e0cda268a2e3d184c45 integrates feat(scanner): fail closed on plugin terraform apply and helm install #1173 command-context RED/GREEN without force-push; compare to current parent 41669d695c60... is 7 ahead / 0 behind and preserves this PR's unique delta.

  • Candidate source AST passes; the final stacked detector preserves 3/3 negative command-context and 2/2 later-real-command probes. Custom-base hosted workflow evidence remains absent, so Draft stays required.

Relates to #1099. Relates to #1173.

Current quoted-command context repair

This descendant inherits #1173 RED d7384e53d44a426356a73e24b2b9cc3fe153de27 and final canonical repair 3a5b14771cc7abb6553fa1ec9bcd8b62acc947ac without copying a leaf workaround. Exact head: 2967d093985f96dd0830cd600b86f7f07c7235df; current parent: 3a5b14771cc7abb6553fa1ec9bcd8b62acc947ac; Git compare is 0 behind and preserves this PR's unique detector/test delta. The top #1183 source AST and extracted helper probes pass quoted/reporting negatives while preserving direct and command-substitution positives. This custom-base PR stays Draft until its own hosted integration and independent review are terminal.

Current assignment-value context repair — 2026-09-08

This normal two-parent descendant inherits canonical #1173 RED 90ae232e852b3d01463d978f9bccd9157c341fe7 and GREEN 1e6a3eb43a5bc2d146656af13e7fa6cad2a77315 without a leaf workaround. Exact head: 8b1965da8972a627d40fb7b1866b6828007a4a13; current parent: 1e6a3eb43a5bc2d146656af13e7fa6cad2a77315; Git compare is 0 behind and preserves this PR's unique detector/test delta. Assignment-value negatives and environment-prefix/direct/substitution positives are present in the exact tree. This custom-base PR remains Draft until its own hosted integration and independent current-head review are terminal. Earlier head strings in this body are historical evidence only.

Current heredoc-safe restack — 2026-09-08

Canonical #1173 exact head 184b4b4f55906284ac1d8059e46cec8f0d9cfc9a fixes closed literal here-document payload false positives with RED 6f6be77d... → GREEN 12faf2f.... This branch was integrated non-destructively on parent 184b4b4f55906284ac1d8059e46cec8f0d9cfc9a; exact branch ref is c069e93ed7ca0b82fd19179a6b68f671c3d0be20. GitHub compare reports behind_by=0, ahead_by=16; the PR's unique detector delta remains in the tree. Exact-head hosted integration and independent review are not terminal, so this PR remains Draft. Earlier head strings are historical evidence only.

Current canonical-base blocker — 2026-09-08

Canonical parent #1173 advanced to exact head 873370bfceba0f161c6d1682459741f84d0ef92a with RED/GREEN regression coverage for non-executing :/true/false argument text. This branch has not yet integrated that parent and therefore remains Draft and not merge-ready. Its hosted-deploy delta is preserved; predecessor Checks are not transferred. Non-force restack and fresh exact-head evidence are required.

Current structured-argv parent blocker — 2026-09-08

Canonical parent #1173 is now 18ca616c2ba4c4322f64e39336c5dc809bbac81a after structured-manifest argv RED 82a0cc8..., rejected generic-join boundary RED c76b1bd..., and direct-executable GREEN. Current #1174 head c069e93ed7ca0b82fd19179a6b68f671c3d0be20 diverges at parent 184b4b4...: GitHub compare reports 16 ahead / 6 behind. The hosted-deploy delta remains preserved, but this PR stays Draft and not merge-ready until the canonical parent is non-force integrated and fresh hosted/current-head review evidence exists.

Current nested-shell parent blocker — 2026-09-08

Canonical parent #1173 is now exact head 8d35ff91e042761d1fda0554b5c93d116d7c8865 after direct structured-argv and nested-shell RED/GREEN repair, including runtime-confirmed common and Bash-specific execution-preserving option states plus noexec/value-taking/order negatives. Current #1174 head c069e93ed7ca0b82fd19179a6b68f671c3d0be20 diverges at 184b4b4...; GitHub compare reports 16 ahead / 19 behind. The hosted-deploy delta remains preserved, but this PR stays Draft and not merge-ready until the canonical parent is non-force integrated and fresh exact-head hosted/review evidence exists. Earlier parent counts in this body are historical evidence only.

Current canonical-parent blocker — 2026-09-08

Canonical #1173 advanced non-destructively to 825bf7e46a829b9a09e1c551d896030b2358a5b4 after integrating #1172's typed argv/nested-shell repair. This exact head remains c069e93ed7ca0b82fd19179a6b68f671c3d0be20; comparison is 16 ahead / 25 behind from merge base 184b4b4f55906284ac1d8059e46cec8f0d9cfc9a. The hosted-deploy delta is preserved, but this PR remains Draft and not merge-ready until the canonical parent is integrated without force and fresh exact-head validation runs.

Current canonical-parent blocker — 2026-09-08

Canonical #1173 advanced non-destructively to exact head 5e40f9154d411aaaccca3a935f858a8ad5ef7b84 after integrating GitHub, kubectl/Docker, and Terraform/Helm command-context contracts. Current #1174 head c069e93ed7ca0b82fd19179a6b68f671c3d0be20 diverges from merge base 184b4b4f55906284ac1d8059e46cec8f0d9cfc9a: 16 ahead / 36 behind. The hosted-deploy delta remains preserved, but this PR stays Draft and not merge-ready until non-force integration and fresh exact-head validation/review. Earlier counts are historical evidence only.

Lock hook and manifest vercel deploy and fly deploy as fail-closed
findings. Keep vercel ls, fly status, terraform apply, and README
wording on their existing classes. Relates to #1099.
Fail closed on hook and manifest vercel deploy as
claude-plugin-vercel-deploy-command and fly deploy as
claude-plugin-fly-deploy-command. vercel ls, fly status,
terraform apply, and README wording stay their existing classes.
Relates to #1099.
@coderabbitai

coderabbitai Bot commented Sep 8, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

seonghobae added a commit that referenced this pull request Sep 8, 2026
Summary:
- Snapshot 2026-09-08 00:08 UTC records Draft #1174 `af6b2ec` stacked on #1173.
- Hook vercel deploy and fly deploy fail closed.
- Remaining leftover: deep directory recursion, Cosign/GPG.

Rationale:
- #999 is the single writer of the product-technical gap baseline.
- Do not Close #1099 or #1173.

Tests:
- documentation-only; detector evidence lives on #1174 (1845/1845)

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Current-head security review found one unresolved precision obligation. _vercel_deploy_command_hits and _fly_deploy_command_hits search the entire hook text with raw regex, so non-executable text such as # vercel deploy or echo "fly deploy" is reported as hosted write authority even though the hook does not execute those CLIs. The PR contract says the plugin “runs” the command, and existing tests cover README exclusion but not hook comment/echo lookalikes. Keep this Draft and add RED production-path negatives before a bounded implementation repair; preserve real direct commands and manifest command values as positives. This is a false-positive boundary, not grounds to weaken fail-closed handling of executable deploy commands.

@seonghobae seonghobae added enhancement New feature or request priority: medium Normal-priority or P2 work labels Sep 8, 2026 — with ChatGPT Codex Connector
Hook comments and echo/printf lookalikes must not fail closed as
vercel deploy or fly deploy. Direct commands, chained commands, and
inline comments after a real CLI stay positive. Relates to #1099.
Ignore unquoted hook comments and echo/printf/print lookalikes so
vercel deploy and fly deploy fail closed only when the plugin runs
those CLIs. Manifest command values stay positive. Relates to #1099.
seonghobae added a commit that referenced this pull request Sep 8, 2026
Exact head 590f477 repairs review 5136517688: hook comments and
echo/printf lookalikes are not vercel/fly deploy. Relates to #1099.
seonghobae added a commit that referenced this pull request Sep 8, 2026
Merge concurrent #1036 placeholder-repair snapshot. Exact head
590f477 repairs review 5136517688 comment/echo false positives.
Relates to #1099.
seonghobae added a commit that referenced this pull request Sep 8, 2026
Summary:
- Snapshot 2026-09-08 03:09 UTC records Draft #1175 `eb2389e` stacked on #1174.
- Checksum digest rows without a sibling signature fail closed.
- Remaining leftover: deep directory recursion.

Rationale:
- #999 is the single writer of the product-technical gap baseline.
- Do not Close #1099, #1174, or #1169.

Tests:
- documentation-only; detector evidence lives on #1175 (416 passed)

Copy link
Copy Markdown
Contributor Author

Stack admission is now a verified prerequisite, not a reason to retarget or no-op this dependent PR. Fresh evidence: #1174 exact head 590f4771e55600375902157e57863f43584225d5, correctly based on current #1173 head e465cd71b495215e6ab7bc1ce298b588c0edfd75, has zero repository PR workflow runs because protected develop limits eight repository pull_request triggers to long-lived base branches. Existing workflow-owner PR #1096 now carries deterministic RED f1172f0b5cbeb8ce0f7f7ef8c38a468353b45f62 and minimal candidate fix cf5e3557109cfb947d1a487cc0f9503242ca30e5, removing only PR base filters while preserving push/path filters. #1096's current SHA has materialized repository workflows and remains Draft pending terminal current-head checks/review. Keep #1174 stacked and Draft; after #1096 lands on protected develop, this exact #1174 generation (or its ordinary descendant if content changes) must earn its own Tests/security/review receipts. Do not retarget to hide the dependency, reuse predecessor receipts, or generate a source-neutral CI wake-up commit.

seonghobae added a commit that referenced this pull request Sep 8, 2026
…ssor

Preserve #1175 checksum/signature delta while integrating #1174 RED e257d90 and GREEN 746501e through a normal two-parent merge. No force update.
seonghobae added a commit that referenced this pull request Sep 8, 2026
Preserve #1176 path-depth delta while merging current #1175, including #1174 manifest-command precision. Normal two-parent merge; no force update.
seonghobae added a commit that referenced this pull request Sep 8, 2026
Summary:
- Snapshot 2026-09-08 04:13 UTC records Draft #1177 `af6aa91` stacked on #1176.
- Executable aws/gcloud/az deploy writes fail closed.
- Remaining leftover: aws s3 sync/cp and az containerapp up.

Rationale:
- #999 is the single writer of the product-technical gap baseline.
- Do not Close #1099, #1176, or #1174.

Tests:
- documentation-only; detector evidence lives on #1177 (438 passed)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request priority: medium Normal-priority or P2 work

Projects

Status: Backlog

Development

Successfully merging this pull request may close these issues.

1 participant