Skip to content

docs: add Qwen/Alibaba Cloud provider support - #6

Closed
Carlys17 wants to merge 1 commit into
Twigpine:mainfrom
Carlys17:add-qwen-alibaba-cloud-support
Closed

Carlys17 wants to merge 1 commit into
Twigpine:mainfrom
Carlys17:add-qwen-alibaba-cloud-support

Conversation

@Carlys17

@Carlys17 Carlys17 commented Apr 1, 2026

Copy link
Copy Markdown

Add Alibaba Cloud Coding Plan configuration with OpenAI and Anthropic protocol compatible endpoints

Add Alibaba Cloud Coding Plan configuration with OpenAI and Anthropic protocol compatible endpoints
@Carlys17 Carlys17 closed this Apr 1, 2026
@Carlys17
Carlys17 deleted the add-qwen-alibaba-cloud-support branch April 1, 2026 06:31
@Carlys17
Carlys17 restored the add-qwen-alibaba-cloud-support branch April 1, 2026 06:32
@Carlys17
Carlys17 deleted the add-qwen-alibaba-cloud-support branch April 1, 2026 06:32
boofpackdev added a commit to boofpackdev/openclaude that referenced this pull request Apr 4, 2026
…election priority

- Add ProviderRegistry singleton class with detect() method
- Implement provider selection priority:
  1. HERMES_ENDPOINT env var -> hermes provider
  2. CLAUDE_CODE_USE_OPENAI=1 -> openai provider
  3. Config file provider preference
  4. Default: hermes provider
- Add register(), get(), detect(), list() methods
- Add unit tests for registry selection logic
- Add ProviderInfo interface for registry listing

Closes Twigpine#6
Flo5k5 added a commit to Flo5k5/openclaude that referenced this pull request Apr 12, 2026
- Fix permission rule field: expression → ruleContent (Copilot #1)
- Handle empty command prefix: skip rule creation (Copilot Twigpine#2)
- Remove unused useTheme() import (Copilot Twigpine#3)
- Save permission rules under 'Bash' toolName so bashToolHasPermission
  can match them — Monitor delegates to Bash permission system (Copilot Twigpine#4)
- Remove unused logError import from MonitorMcpTask (Copilot Twigpine#6)
- Copilot Twigpine#5 (getAppState throws): same pattern as BashTool:915, not a bug
kevincodex1 pushed a commit that referenced this pull request Apr 13, 2026
* feat: implement Monitor tool for streaming shell output

Add the Monitor tool that executes shell commands in the background and
streams stdout line-by-line as notifications to the model. This enables
real-time monitoring of logs, builds, and long-running processes.

Implementation:
- MonitorTool (src/tools/MonitorTool/) — spawns LocalShellTask with
  kind='monitor', returns immediately with task ID
- MonitorMcpTask (src/tasks/MonitorMcpTask/) — task lifecycle management
  and agent cleanup via killMonitorMcpTasksForAgent()
- MonitorPermissionRequest — permission dialog component

The codebase already had all integration points wired (tools.ts, tasks.ts,
PermissionRequest.tsx, LocalShellTask kind='monitor', BashTool prompt).
This PR provides the missing implementations.

* fix: command-specific permission rule + architecture docs

- MonitorPermissionRequest: "don't ask again" now creates a
  command-prefix rule (like BashTool) instead of a blanket
  tool-name-only rule that would auto-allow all Monitor commands
- MonitorMcpTask: clarify architecture comments explaining why
  monitor_mcp type exists as a registry stub while actual tasks
  are local_bash with kind='monitor'

* fix: address Copilot review feedback

- Fix permission rule field: expression → ruleContent (Copilot #1)
- Handle empty command prefix: skip rule creation (Copilot #2)
- Remove unused useTheme() import (Copilot #3)
- Save permission rules under 'Bash' toolName so bashToolHasPermission
  can match them — Monitor delegates to Bash permission system (Copilot #4)
- Remove unused logError import from MonitorMcpTask (Copilot #6)
- Copilot #5 (getAppState throws): same pattern as BashTool:915, not a bug
kevincodex1 added a commit to kevincodex1/openclaude that referenced this pull request Apr 21, 2026
Addresses the security review on feat/bash-command-safety-classifier.
Each finding traced by reviewer is fixed locally; adversarial tests cover
each bypass pattern.

P0 — parser bypasses (CRITICAL / HIGH):

  #1  Escaped backslash before close quote — `echo "test\\" && rm -rf /`
      slipped through as one quoted echo. The prior `input[i-1] !== '\\'`
      check fails when the backslash itself is escaped. Replaced with an
      isCharEscaped() helper that counts consecutive backslashes; a quote
      is escaped only when preceded by an odd count. Applied in BOTH
      splitCompound AND tokenize so they agree on quote boundaries.

  #2  Process substitution not detected — `cat <(curl ...)` passed the cat
      safe gate. tokenize now returns null on `<(` / `>(` same as it did
      for `$(` / backticks, degrading to 'unknown'.

  Twigpine#3  Newline as command separator — `echo safe\nrm -rf /` was treated as
      one line by splitCompound (bash splits on \n = ;). Added \n to the
      separator list alongside ; | &.

P1 — classification bypasses (MEDIUM):

  Twigpine#4  Sensitive-path denylist — cat/head/tail/less/more/file/stat/wc and
      readlink/realpath now consult SENSITIVE_PATH_PATTERNS. /etc/shadow,
      ~/.ssh/id_rsa, /proc/*/environ, /dev/sd*, ~/.aws/credentials,
      ~/.kube/config, id_rsa / *.pem / *.key etc. degrade to 'unknown'.
      Public keys (*.pub) and normal files remain safe.

  Twigpine#5  `git config key value` misclassified — removed `config` from the
      READ_ONLY_SUBCOMMANDS list and added explicit unsafe gate: two+
      positional args with no --get/--list is a set, marked unsafe.
      --unset / --replace-all / --add / --unset-all also marked unsafe.
      Single-arg read form falls to 'unknown' (defers to existing rules).

  Twigpine#6  `git stash` (bare) misclassified — equivalent to `git stash push`,
      mutates worktree + index. Safe path now requires `git stash list`
      or `git stash show`; everything else in stash falls to unsafe or
      unknown.

P2 — hygiene (LOW):

  Twigpine#7  env / printenv removed from ALWAYS_SAFE_COMMANDS. Plain `env` dumps
      all environment variables (API keys, tokens) to the caller — not
      safe to auto-approve. FOO=bar cmd idiom still works via the existing
      env-assignment-prefix stripping.

  Twigpine#8  git gc / prune / repack / bisect removed from READ_ONLY_SUBCOMMANDS
      and added to the unsafe gate. gc repacks + deletes loose objects;
      bisect start/good/bad/reset/run/skip/terms/replay mutate HEAD.

Tests: 35 new adversarial cases across all 8 findings, plus regression
coverage (public keys still safe, FOO=bar pwd still safe, git stash
list/show still safe). Full suite: 1187/1187 pass. PR intent scan: clean.

Co-Authored-By: OpenClaude <openclaude@gitlawb.com>
C1ph3r404 referenced this pull request in C1ph3r404/openclaude Apr 29, 2026
* feat: implement Monitor tool for streaming shell output

Add the Monitor tool that executes shell commands in the background and
streams stdout line-by-line as notifications to the model. This enables
real-time monitoring of logs, builds, and long-running processes.

Implementation:
- MonitorTool (src/tools/MonitorTool/) — spawns LocalShellTask with
  kind='monitor', returns immediately with task ID
- MonitorMcpTask (src/tasks/MonitorMcpTask/) — task lifecycle management
  and agent cleanup via killMonitorMcpTasksForAgent()
- MonitorPermissionRequest — permission dialog component

The codebase already had all integration points wired (tools.ts, tasks.ts,
PermissionRequest.tsx, LocalShellTask kind='monitor', BashTool prompt).
This PR provides the missing implementations.

* fix: command-specific permission rule + architecture docs

- MonitorPermissionRequest: "don't ask again" now creates a
  command-prefix rule (like BashTool) instead of a blanket
  tool-name-only rule that would auto-allow all Monitor commands
- MonitorMcpTask: clarify architecture comments explaining why
  monitor_mcp type exists as a registry stub while actual tasks
  are local_bash with kind='monitor'

* fix: address Copilot review feedback

- Fix permission rule field: expression → ruleContent (Copilot #1)
- Handle empty command prefix: skip rule creation (Copilot #2)
- Remove unused useTheme() import (Copilot #3)
- Save permission rules under 'Bash' toolName so bashToolHasPermission
  can match them — Monitor delegates to Bash permission system (Copilot #4)
- Remove unused logError import from MonitorMcpTask (Copilot #6)
- Copilot #5 (getAppState throws): same pattern as BashTool:915, not a bug
kevincodex1 added a commit to kevincodex1/openclaude that referenced this pull request May 6, 2026
Addresses the security review on feat/bash-command-safety-classifier.
Each finding traced by reviewer is fixed locally; adversarial tests cover
each bypass pattern.

P0 — parser bypasses (CRITICAL / HIGH):

  #1  Escaped backslash before close quote — `echo "test\\" && rm -rf /`
      slipped through as one quoted echo. The prior `input[i-1] !== '\\'`
      check fails when the backslash itself is escaped. Replaced with an
      isCharEscaped() helper that counts consecutive backslashes; a quote
      is escaped only when preceded by an odd count. Applied in BOTH
      splitCompound AND tokenize so they agree on quote boundaries.

  #2  Process substitution not detected — `cat <(curl ...)` passed the cat
      safe gate. tokenize now returns null on `<(` / `>(` same as it did
      for `$(` / backticks, degrading to 'unknown'.

  Twigpine#3  Newline as command separator — `echo safe\nrm -rf /` was treated as
      one line by splitCompound (bash splits on \n = ;). Added \n to the
      separator list alongside ; | &.

P1 — classification bypasses (MEDIUM):

  Twigpine#4  Sensitive-path denylist — cat/head/tail/less/more/file/stat/wc and
      readlink/realpath now consult SENSITIVE_PATH_PATTERNS. /etc/shadow,
      ~/.ssh/id_rsa, /proc/*/environ, /dev/sd*, ~/.aws/credentials,
      ~/.kube/config, id_rsa / *.pem / *.key etc. degrade to 'unknown'.
      Public keys (*.pub) and normal files remain safe.

  Twigpine#5  `git config key value` misclassified — removed `config` from the
      READ_ONLY_SUBCOMMANDS list and added explicit unsafe gate: two+
      positional args with no --get/--list is a set, marked unsafe.
      --unset / --replace-all / --add / --unset-all also marked unsafe.
      Single-arg read form falls to 'unknown' (defers to existing rules).

  Twigpine#6  `git stash` (bare) misclassified — equivalent to `git stash push`,
      mutates worktree + index. Safe path now requires `git stash list`
      or `git stash show`; everything else in stash falls to unsafe or
      unknown.

P2 — hygiene (LOW):

  Twigpine#7  env / printenv removed from ALWAYS_SAFE_COMMANDS. Plain `env` dumps
      all environment variables (API keys, tokens) to the caller — not
      safe to auto-approve. FOO=bar cmd idiom still works via the existing
      env-assignment-prefix stripping.

  Twigpine#8  git gc / prune / repack / bisect removed from READ_ONLY_SUBCOMMANDS
      and added to the unsafe gate. gc repacks + deletes loose objects;
      bisect start/good/bad/reset/run/skip/terms/replay mutate HEAD.

Tests: 35 new adversarial cases across all 8 findings, plus regression
coverage (public keys still safe, FOO=bar pwd still safe, git stash
list/show still safe). Full suite: 1187/1187 pass. PR intent scan: clean.

Co-Authored-By: OpenClaude <openclaude@gitlawb.com>
The-FOOL-00 pushed a commit to The-FOOL-00/openclaude that referenced this pull request May 24, 2026
* feat: implement Monitor tool for streaming shell output

Add the Monitor tool that executes shell commands in the background and
streams stdout line-by-line as notifications to the model. This enables
real-time monitoring of logs, builds, and long-running processes.

Implementation:
- MonitorTool (src/tools/MonitorTool/) — spawns LocalShellTask with
  kind='monitor', returns immediately with task ID
- MonitorMcpTask (src/tasks/MonitorMcpTask/) — task lifecycle management
  and agent cleanup via killMonitorMcpTasksForAgent()
- MonitorPermissionRequest — permission dialog component

The codebase already had all integration points wired (tools.ts, tasks.ts,
PermissionRequest.tsx, LocalShellTask kind='monitor', BashTool prompt).
This PR provides the missing implementations.

* fix: command-specific permission rule + architecture docs

- MonitorPermissionRequest: "don't ask again" now creates a
  command-prefix rule (like BashTool) instead of a blanket
  tool-name-only rule that would auto-allow all Monitor commands
- MonitorMcpTask: clarify architecture comments explaining why
  monitor_mcp type exists as a registry stub while actual tasks
  are local_bash with kind='monitor'

* fix: address Copilot review feedback

- Fix permission rule field: expression → ruleContent (Copilot Twigpine#1)
- Handle empty command prefix: skip rule creation (Copilot Twigpine#2)
- Remove unused useTheme() import (Copilot Twigpine#3)
- Save permission rules under 'Bash' toolName so bashToolHasPermission
  can match them — Monitor delegates to Bash permission system (Copilot Twigpine#4)
- Remove unused logError import from MonitorMcpTask (Copilot Twigpine#6)
- Copilot Twigpine#5 (getAppState throws): same pattern as BashTool:915, not a bug
discopops pushed a commit to discopops/openclaude that referenced this pull request May 28, 2026
* feat: implement Monitor tool for streaming shell output

Add the Monitor tool that executes shell commands in the background and
streams stdout line-by-line as notifications to the model. This enables
real-time monitoring of logs, builds, and long-running processes.

Implementation:
- MonitorTool (src/tools/MonitorTool/) — spawns LocalShellTask with
  kind='monitor', returns immediately with task ID
- MonitorMcpTask (src/tasks/MonitorMcpTask/) — task lifecycle management
  and agent cleanup via killMonitorMcpTasksForAgent()
- MonitorPermissionRequest — permission dialog component

The codebase already had all integration points wired (tools.ts, tasks.ts,
PermissionRequest.tsx, LocalShellTask kind='monitor', BashTool prompt).
This PR provides the missing implementations.

* fix: command-specific permission rule + architecture docs

- MonitorPermissionRequest: "don't ask again" now creates a
  command-prefix rule (like BashTool) instead of a blanket
  tool-name-only rule that would auto-allow all Monitor commands
- MonitorMcpTask: clarify architecture comments explaining why
  monitor_mcp type exists as a registry stub while actual tasks
  are local_bash with kind='monitor'

* fix: address Copilot review feedback

- Fix permission rule field: expression → ruleContent (Copilot Twigpine#1)
- Handle empty command prefix: skip rule creation (Copilot Twigpine#2)
- Remove unused useTheme() import (Copilot Twigpine#3)
- Save permission rules under 'Bash' toolName so bashToolHasPermission
  can match them — Monitor delegates to Bash permission system (Copilot Twigpine#4)
- Remove unused logError import from MonitorMcpTask (Copilot Twigpine#6)
- Copilot Twigpine#5 (getAppState throws): same pattern as BashTool:915, not a bug
kevincodex1 added a commit to kevincodex1/openclaude that referenced this pull request Jun 23, 2026
Addresses the security review on feat/bash-command-safety-classifier.
Each finding traced by reviewer is fixed locally; adversarial tests cover
each bypass pattern.

P0 — parser bypasses (CRITICAL / HIGH):

  #1  Escaped backslash before close quote — `echo "test\\" && rm -rf /`
      slipped through as one quoted echo. The prior `input[i-1] !== '\\'`
      check fails when the backslash itself is escaped. Replaced with an
      isCharEscaped() helper that counts consecutive backslashes; a quote
      is escaped only when preceded by an odd count. Applied in BOTH
      splitCompound AND tokenize so they agree on quote boundaries.

  #2  Process substitution not detected — `cat <(curl ...)` passed the cat
      safe gate. tokenize now returns null on `<(` / `>(` same as it did
      for `$(` / backticks, degrading to 'unknown'.

  Twigpine#3  Newline as command separator — `echo safe\nrm -rf /` was treated as
      one line by splitCompound (bash splits on \n = ;). Added \n to the
      separator list alongside ; | &.

P1 — classification bypasses (MEDIUM):

  Twigpine#4  Sensitive-path denylist — cat/head/tail/less/more/file/stat/wc and
      readlink/realpath now consult SENSITIVE_PATH_PATTERNS. /etc/shadow,
      ~/.ssh/id_rsa, /proc/*/environ, /dev/sd*, ~/.aws/credentials,
      ~/.kube/config, id_rsa / *.pem / *.key etc. degrade to 'unknown'.
      Public keys (*.pub) and normal files remain safe.

  Twigpine#5  `git config key value` misclassified — removed `config` from the
      READ_ONLY_SUBCOMMANDS list and added explicit unsafe gate: two+
      positional args with no --get/--list is a set, marked unsafe.
      --unset / --replace-all / --add / --unset-all also marked unsafe.
      Single-arg read form falls to 'unknown' (defers to existing rules).

  Twigpine#6  `git stash` (bare) misclassified — equivalent to `git stash push`,
      mutates worktree + index. Safe path now requires `git stash list`
      or `git stash show`; everything else in stash falls to unsafe or
      unknown.

P2 — hygiene (LOW):

  Twigpine#7  env / printenv removed from ALWAYS_SAFE_COMMANDS. Plain `env` dumps
      all environment variables (API keys, tokens) to the caller — not
      safe to auto-approve. FOO=bar cmd idiom still works via the existing
      env-assignment-prefix stripping.

  Twigpine#8  git gc / prune / repack / bisect removed from READ_ONLY_SUBCOMMANDS
      and added to the unsafe gate. gc repacks + deletes loose objects;
      bisect start/good/bad/reset/run/skip/terms/replay mutate HEAD.

Tests: 35 new adversarial cases across all 8 findings, plus regression
coverage (public keys still safe, FOO=bar pwd still safe, git stash
list/show still safe). Full suite: 1187/1187 pass. PR intent scan: clean.

Co-Authored-By: OpenClaude <openclaude@gitlawb.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant