[Init] Initial commit - NetMesh terminal manager
Some checks failed
build-packages / resolve bundled mosh-client (push) Has been cancelled
build-packages / resolve bundled et-client (push) Has been cancelled
build-packages / build-macos (push) Has been cancelled
build-packages / build-windows (push) Has been cancelled
build-packages / build-linux-x64 (push) Has been cancelled
build-packages / build-linux-arm64 (push) Has been cancelled
build-packages / release (push) Has been cancelled
build-packages / update Nix release metadata (push) Has been cancelled
build-packages / bump homebrew tap (push) Has been cancelled
test / lint-and-test (push) Has been cancelled
AI automation / Route event (push) Has been cancelled
AI automation / Hand reopened issue to maintainers (push) Has been cancelled
AI automation / Clean source issue state (push) Has been cancelled
AI automation / Reconcile handoffs (push) Has been cancelled
AI automation / Classify issue (push) Has been cancelled
AI automation / Claude Code smoke (push) Has been cancelled
AI automation / Review issue follow-up (push) Has been cancelled
AI automation / Publish issue follow-up (push) Has been cancelled
AI automation / Implement with Claude Code (push) Has been cancelled
AI automation / Publish implement PR (push) Has been cancelled
AI automation / Continue queued issue comments (push) Has been cancelled
AI automation / Codex review loop (push) Has been cancelled
AI automation / Publish Codex fix (push) Has been cancelled
AI automation / Clear Codex dispatch marker (push) Has been cancelled
AI automation / Own PR re-request Codex (push) Has been cancelled
AI automation / External PR re-request Codex (push) Has been cancelled
AI automation / Poll Codex reaction / retry (push) Has been cancelled
build-et-binaries / build-linux-x64 (push) Has been cancelled
build-et-binaries / build-linux-arm64 (push) Has been cancelled
build-et-binaries / build-macos-universal (push) Has been cancelled
build-et-binaries / build-windows-x64 (push) Has been cancelled
build-et-binaries / release (push) Has been cancelled

This commit is contained in:
2026-09-13 18:24:01 +08:00
commit 3c72efcb7f
3255 changed files with 907009 additions and 0 deletions

View File

@@ -0,0 +1,73 @@
"use strict";
/**
* Env construction for SDK agent subprocesses.
*
* Consolidates the env hardening that previously lived in
* the removed raw-process handler (DANGEROUS_ENV_KEYS) and the per-spawn merge
* helpers used by SDK agent launches.
* Callers inject the netcatty helpers so this module stays pure/testable.
*/
// Env var names that can be used for code injection into a child process.
// Mirror of the set in the (now-removed) raw agent spawn handler.
const DANGEROUS_ENV_KEYS = new Set([
"LD_PRELOAD", "LD_LIBRARY_PATH",
"DYLD_INSERT_LIBRARIES", "DYLD_LIBRARY_PATH", "DYLD_FRAMEWORK_PATH",
"NODE_OPTIONS", "ELECTRON_RUN_AS_NODE",
"PYTHONPATH", "RUBYLIB", "PERL5LIB",
"BASH_ENV", "ENV", "CDPATH", "PROMPT_COMMAND",
]);
function isDangerousEnvKey(key) {
const normalized = String(key || "").toUpperCase();
return DANGEROUS_ENV_KEYS.has(normalized) || normalized.startsWith("BASH_FUNC_");
}
/**
* Build the env handed to an SDK agent subprocess.
*
* @param {object} args
* @param {Record<string,string>} args.shellEnv Resolved shell env (PATH-augmented).
* @param {Record<string,string>} [args.requestedAgentEnv] Per-agent env from the UI (filtered).
* @param {(e:Record<string,string>)=>Record<string,string>} [args.withCliDiscoveryEnv]
* netcatty helper that injects the tool-CLI discovery file path.
* @param {(e:Record<string,string>)=>Record<string,string>} [args.normalizeClaudeCodeExecutableEnv]
* netcatty helper that rewrites CLAUDE_CODE_EXECUTABLE to a runnable path (claude only).
* @returns {Record<string,string>}
*/
function buildSdkAgentEnv({
shellEnv,
requestedAgentEnv,
withCliDiscoveryEnv,
normalizeClaudeCodeExecutableEnv,
}) {
const filteredShellEnv = {};
if (shellEnv && typeof shellEnv === "object") {
for (const [k, v] of Object.entries(shellEnv)) {
if (typeof v === "string" && !isDangerousEnvKey(k)) {
filteredShellEnv[k] = v;
}
}
}
const filteredRequested = {};
if (requestedAgentEnv && typeof requestedAgentEnv === "object") {
for (const [k, v] of Object.entries(requestedAgentEnv)) {
if (typeof v === "string" && !isDangerousEnvKey(k)) {
filteredRequested[k] = v;
}
}
}
let env = { ...filteredShellEnv, ...filteredRequested };
if (typeof withCliDiscoveryEnv === "function") {
env = withCliDiscoveryEnv(env);
}
if (typeof normalizeClaudeCodeExecutableEnv === "function") {
env = normalizeClaudeCodeExecutableEnv(env);
}
return env;
}
module.exports = { buildSdkAgentEnv, DANGEROUS_ENV_KEYS, isDangerousEnvKey };