Skip to content

fix(security): add re.DOTALL to prevent multiline bypass of dangerous command detection - #233

Merged
teknium1 merged 1 commit into
NousResearch:mainfrom
Farukest:fix/dangerous-pattern-multiline-bypass
Mar 2, 2026
Merged

fix(security): add re.DOTALL to prevent multiline bypass of dangerous command detection#233
teknium1 merged 1 commit into
NousResearch:mainfrom
Farukest:fix/dangerous-pattern-multiline-bypass

Conversation

@Farukest

@Farukest Farukest commented Mar 1, 2026

Copy link
Copy Markdown
Contributor

Added TestMultilineBypass to tests/tools/test_approval.py with 4 tests:

  • curl ... \\\n| sh detected
  • wget ... \\\n| bash detected
  • dd \\\nif=... detected
  • chmod --recursive \\\n777 detected

All 4 fail without the fix, all 33 tests pass with it.

Closes #232

@ibhagwan

ibhagwan commented Mar 1, 2026

Copy link
Copy Markdown
Contributor

Mind me asking what formatter does this project use? opencode is messing up the format making it much harder to track the actual changes.

@teknium1
teknium1 merged commit 4faf2a6 into NousResearch:main Mar 2, 2026
@teknium1

teknium1 commented Mar 2, 2026

Copy link
Copy Markdown
Contributor

Merged — thanks for the security fix! Added 2 extra find-pattern newline tests as a follow-up.

@ibhagwan

ibhagwan commented Mar 2, 2026

Copy link
Copy Markdown
Contributor

Merged — thanks for the security fix! Added 2 extra find-pattern newline tests as a follow-up.

@teknium1, this project needs a formatter standard / guidelines urgently, submitting #268 was extra hard due to this.

@Farukest

Farukest commented Mar 3, 2026

Copy link
Copy Markdown
Contributor Author

Merged — thanks for the security fix! Added 2 extra find-pattern newline tests as a follow-up.

Thanks :)
Good call on the extra find pattern tests 👍

@you-ventures

Copy link
Copy Markdown

Verified complete during PRD audit 2026-04-19. All requirements implemented and tested — 12/12 pages serving full SPA with live API data.

angelburgosrosado pushed a commit to angelburgosrosado/hermes-agent that referenced this pull request Apr 27, 2026
…ltiline bypass of dangerous command detection

Authored by Farukest. Fixes NousResearch#232.
waefrebeorn pushed a commit to waefrebeorn/slermes that referenced this pull request Jul 2, 2026
…ltiline bypass of dangerous command detection

Authored by Farukest. Fixes NousResearch#232.
teddyjfpender added a commit to teddyjfpender/superforecasting-agent that referenced this pull request Jul 5, 2026
Task NousResearch#233. The root: the free-tier drain routed material-change alerts
to run_autopilot, whose first line hard-raised without an active
policy — but watched sources attach WITHOUT enabling autopilot (a
deliberate per-question opt-in), so 130 alerts across 58 policy-less
questions could never resolve. The policy governs materiality
thresholds + auto-commit, NOT the deterministic re-check: an accidental
hard dependency.

Decision (a), blanket-seed rejected: run_autopilot(require_policy=False)
degrades to a conservative zero-spend source re-check (audit row, no
proposals, no fabricated autopilot_runs); the explicit
forecast autopilot run path still raises loudly. Seeding default
policies on 1000 watched sources vs 17 deliberate opt-ins would have
switched on proposal-generation the operator never chose.

LIVE REPAIR PROVEN: faithful-copy drain 130/130 resolved at 0 tokens;
then live via the CLI, 130 -> 128 with real acks and no
LedgerNotFoundError. The armed nightly self-check and operator R now
drain the rest free.

4 new tests (red->green, fail-soft fold, explicit-path raises,
policy-present unchanged); warnings+autopilot+cron+ledger suites 667.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Dangerous command detection can be bypassed with newlines

4 participants