Skip to content

fix: decouple source file and tool response limits - #11391

Merged
jbg merged 2 commits into
mainfrom
jbg/security-source-file-limit-followup
Aug 20, 2026
Merged

jbg merged 2 commits into
mainfrom
jbg/security-source-file-limit-followup

Conversation

@jbg

@jbg jbg commented Aug 20, 2026

Copy link
Copy Markdown
Collaborator

Summary

  • decouple trusted source-file bounds from the user-tunable tool-response offload threshold
  • preserve character-based tool-response limits for skill supporting files
  • cap Recipe, Subrecipe, Agent, Project, and source-management file reads at the existing 1 MiB scheduled-recipe byte ceiling
  • cover recipes above the default tool-response threshold and source files above the independent safety limit

Security invariant

Trusted source files remain descriptor-confined and memory-bounded, without making valid recipe loading depend on GOOSE_MAX_TOOL_RESPONSE_SIZE.

Review follow-up

Follow-up to #11342, addressing #11342 (comment).

Verification

  • cargo fmt --all -- --check
  • cargo test -p goose skills::supporting_files::tests --lib — 11 passed
  • cargo test -p goose recipe::read_recipe_file_content::tests --lib — 4 passed
  • cargo clippy -p goose --all-targets -- -D warnings
  • git diff origin/main...HEAD --check

This finding was discovered by Project Loupe

@jbg
jbg marked this pull request as ready for review August 20, 2026 11:11

@DOsinga DOsinga left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The independent byte limit fixes the coupling identified in #11342 while preserving character-based supporting-file limits and descriptor-confined reads. The regression tests cover both sides of that behavior, and CI is green.

@jbg
jbg added this pull request to the merge queue Aug 20, 2026
Merged via the queue into main with commit 8343c4a Aug 20, 2026
29 of 30 checks passed
@jbg
jbg deleted the jbg/security-source-file-limit-followup branch August 20, 2026 14:12
alexhancock added a commit that referenced this pull request Aug 20, 2026
…bined

* origin/main: (85 commits)
  feat(desktop): sort configured providers to the top of the provider list (#11409)
  fix(cli): refuse symlink diagnostics outputs (#11398)
  test(plugins): isolate GOOSE_PATH_ROOT in discovery tests (#11407)
  fix(config): serialize secret mutations (#11388)
  fix: decouple source file and tool response limits (#11391)
  chore(deps): bump pctx_code_mode from 0.4.1 to 0.5.0 (#11245)
  fix(security): suppress sensitive OTLP traces (#11381)
  feat(openrouter): forward session_id and add app category header (#10868)
  feat(acp): derive and forward thinking effort from the ACP harness (#10949)
  fix(aws_bedrock): replace flat model list with routing table, add Gemma 4 Mantle support (#10297)
  Add GPT-5.6 follow-up support for Codex and Responses API (#10460)
  fix(update): fetch attestation bundles from bundle_url (#10557)
  fix(security): fail closed on invalid default GCP credentials (#11363)
  fix(codex): reject socket-backed MCP extensions (#11304)
  fix: pass complete response to stop hooks (#11366)
  fix: contain and bound skill supporting file reads (#11342)
  chore(deps): bump the ui-minor-and-patch group across 1 directory with 53 updates (#11386)
  fix(security): bound call graph traversal (#11193)
  fix: pin arrayref to known-good commit (#11389)
  feat(providers): add SayGM as declarative OpenAI-compatible provider (#11267)
  ...

# Conflicts:
#	crates/goose/src/agents/agent.rs
lifeizhou-ap added a commit that referenced this pull request Aug 21, 2026
* main: (70 commits)
  cli: remove recipe secret discovery (#11435)
  fix(openrouter): escape Gemini tool response ref keys (#11276)
  fix(security): honor MCP tool model visibility in Code Mode (#11425)
  fix(providers): estimate cost for Azure Foundry models via inferred catalog pricing (#11264)
  feat(providers): add Gondola as declarative OpenAI-compatible provider (#11421)
  feat(otel): add request params, response metadata, tool call parity, and agent identification (#11261)
  fix(providers): coalesce consecutive Thinking blocks in collect_stream (#11317)
  feat(hooks): add PreToolUseResult event and stable tool_call_id across tool lifecycle (#11120)
  add MCP conformance tests to goose CI (combines #10800 + #10801) (#10940)
  feat(desktop): sort configured providers to the top of the provider list (#11409)
  fix(cli): refuse symlink diagnostics outputs (#11398)
  test(plugins): isolate GOOSE_PATH_ROOT in discovery tests (#11407)
  fix(config): serialize secret mutations (#11388)
  fix: decouple source file and tool response limits (#11391)
  chore(deps): bump pctx_code_mode from 0.4.1 to 0.5.0 (#11245)
  fix(security): suppress sensitive OTLP traces (#11381)
  feat(openrouter): forward session_id and add app category header (#10868)
  feat(acp): derive and forward thinking effort from the ACP harness (#10949)
  fix(aws_bedrock): replace flat model list with routing table, add Gemma 4 Mantle support (#10297)
  Add GPT-5.6 follow-up support for Codex and Responses API (#10460)
  ...
lifeizhou-ap added a commit to Wolfe-Jam/goose that referenced this pull request Aug 21, 2026
* main: (107 commits)
  fix(providers): inform user of clipboard copy and remove copilot auth retry on timeout (aaif-goose#11160)
  feat(desktop): select saved recipes when creating a schedule (aaif-goose#10892)
  More provider test scripts (aaif-goose#10515)
  cli: remove recipe secret discovery (aaif-goose#11435)
  fix(openrouter): escape Gemini tool response ref keys (aaif-goose#11276)
  fix(security): honor MCP tool model visibility in Code Mode (aaif-goose#11425)
  fix(providers): estimate cost for Azure Foundry models via inferred catalog pricing (aaif-goose#11264)
  feat(providers): add Gondola as declarative OpenAI-compatible provider (aaif-goose#11421)
  feat(otel): add request params, response metadata, tool call parity, and agent identification (aaif-goose#11261)
  fix(providers): coalesce consecutive Thinking blocks in collect_stream (aaif-goose#11317)
  feat(hooks): add PreToolUseResult event and stable tool_call_id across tool lifecycle (aaif-goose#11120)
  add MCP conformance tests to goose CI (combines aaif-goose#10800 + aaif-goose#10801) (aaif-goose#10940)
  feat(desktop): sort configured providers to the top of the provider list (aaif-goose#11409)
  fix(cli): refuse symlink diagnostics outputs (aaif-goose#11398)
  test(plugins): isolate GOOSE_PATH_ROOT in discovery tests (aaif-goose#11407)
  fix(config): serialize secret mutations (aaif-goose#11388)
  fix: decouple source file and tool response limits (aaif-goose#11391)
  chore(deps): bump pctx_code_mode from 0.4.1 to 0.5.0 (aaif-goose#11245)
  fix(security): suppress sensitive OTLP traces (aaif-goose#11381)
  feat(openrouter): forward session_id and add app category header (aaif-goose#10868)
  ...
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants