[Init] Initial commit - NetMesh terminal manager
Some checks failed
build-packages / resolve bundled mosh-client (push) Has been cancelled
build-packages / resolve bundled et-client (push) Has been cancelled
build-packages / build-macos (push) Has been cancelled
build-packages / build-windows (push) Has been cancelled
build-packages / build-linux-x64 (push) Has been cancelled
build-packages / build-linux-arm64 (push) Has been cancelled
build-packages / release (push) Has been cancelled
build-packages / update Nix release metadata (push) Has been cancelled
build-packages / bump homebrew tap (push) Has been cancelled
test / lint-and-test (push) Has been cancelled
AI automation / Route event (push) Has been cancelled
AI automation / Hand reopened issue to maintainers (push) Has been cancelled
AI automation / Clean source issue state (push) Has been cancelled
AI automation / Reconcile handoffs (push) Has been cancelled
AI automation / Classify issue (push) Has been cancelled
AI automation / Claude Code smoke (push) Has been cancelled
AI automation / Review issue follow-up (push) Has been cancelled
AI automation / Publish issue follow-up (push) Has been cancelled
AI automation / Implement with Claude Code (push) Has been cancelled
AI automation / Publish implement PR (push) Has been cancelled
AI automation / Continue queued issue comments (push) Has been cancelled
AI automation / Codex review loop (push) Has been cancelled
AI automation / Publish Codex fix (push) Has been cancelled
AI automation / Clear Codex dispatch marker (push) Has been cancelled
AI automation / Own PR re-request Codex (push) Has been cancelled
AI automation / External PR re-request Codex (push) Has been cancelled
AI automation / Poll Codex reaction / retry (push) Has been cancelled
build-et-binaries / build-linux-x64 (push) Has been cancelled
build-et-binaries / build-linux-arm64 (push) Has been cancelled
build-et-binaries / build-macos-universal (push) Has been cancelled
build-et-binaries / build-windows-x64 (push) Has been cancelled
build-et-binaries / release (push) Has been cancelled
Some checks failed
build-packages / resolve bundled mosh-client (push) Has been cancelled
build-packages / resolve bundled et-client (push) Has been cancelled
build-packages / build-macos (push) Has been cancelled
build-packages / build-windows (push) Has been cancelled
build-packages / build-linux-x64 (push) Has been cancelled
build-packages / build-linux-arm64 (push) Has been cancelled
build-packages / release (push) Has been cancelled
build-packages / update Nix release metadata (push) Has been cancelled
build-packages / bump homebrew tap (push) Has been cancelled
test / lint-and-test (push) Has been cancelled
AI automation / Route event (push) Has been cancelled
AI automation / Hand reopened issue to maintainers (push) Has been cancelled
AI automation / Clean source issue state (push) Has been cancelled
AI automation / Reconcile handoffs (push) Has been cancelled
AI automation / Classify issue (push) Has been cancelled
AI automation / Claude Code smoke (push) Has been cancelled
AI automation / Review issue follow-up (push) Has been cancelled
AI automation / Publish issue follow-up (push) Has been cancelled
AI automation / Implement with Claude Code (push) Has been cancelled
AI automation / Publish implement PR (push) Has been cancelled
AI automation / Continue queued issue comments (push) Has been cancelled
AI automation / Codex review loop (push) Has been cancelled
AI automation / Publish Codex fix (push) Has been cancelled
AI automation / Clear Codex dispatch marker (push) Has been cancelled
AI automation / Own PR re-request Codex (push) Has been cancelled
AI automation / External PR re-request Codex (push) Has been cancelled
AI automation / Poll Codex reaction / retry (push) Has been cancelled
build-et-binaries / build-linux-x64 (push) Has been cancelled
build-et-binaries / build-linux-arm64 (push) Has been cancelled
build-et-binaries / build-macos-universal (push) Has been cancelled
build-et-binaries / build-windows-x64 (push) Has been cancelled
build-et-binaries / release (push) Has been cancelled
This commit is contained in:
73
electron/bridges/aiBridge/sdk/env.cjs
Normal file
73
electron/bridges/aiBridge/sdk/env.cjs
Normal file
@@ -0,0 +1,73 @@
|
||||
"use strict";
|
||||
|
||||
/**
|
||||
* Env construction for SDK agent subprocesses.
|
||||
*
|
||||
* Consolidates the env hardening that previously lived in
|
||||
* the removed raw-process handler (DANGEROUS_ENV_KEYS) and the per-spawn merge
|
||||
* helpers used by SDK agent launches.
|
||||
* Callers inject the netcatty helpers so this module stays pure/testable.
|
||||
*/
|
||||
|
||||
// Env var names that can be used for code injection into a child process.
|
||||
// Mirror of the set in the (now-removed) raw agent spawn handler.
|
||||
const DANGEROUS_ENV_KEYS = new Set([
|
||||
"LD_PRELOAD", "LD_LIBRARY_PATH",
|
||||
"DYLD_INSERT_LIBRARIES", "DYLD_LIBRARY_PATH", "DYLD_FRAMEWORK_PATH",
|
||||
"NODE_OPTIONS", "ELECTRON_RUN_AS_NODE",
|
||||
"PYTHONPATH", "RUBYLIB", "PERL5LIB",
|
||||
"BASH_ENV", "ENV", "CDPATH", "PROMPT_COMMAND",
|
||||
]);
|
||||
|
||||
function isDangerousEnvKey(key) {
|
||||
const normalized = String(key || "").toUpperCase();
|
||||
return DANGEROUS_ENV_KEYS.has(normalized) || normalized.startsWith("BASH_FUNC_");
|
||||
}
|
||||
|
||||
/**
|
||||
* Build the env handed to an SDK agent subprocess.
|
||||
*
|
||||
* @param {object} args
|
||||
* @param {Record<string,string>} args.shellEnv Resolved shell env (PATH-augmented).
|
||||
* @param {Record<string,string>} [args.requestedAgentEnv] Per-agent env from the UI (filtered).
|
||||
* @param {(e:Record<string,string>)=>Record<string,string>} [args.withCliDiscoveryEnv]
|
||||
* netcatty helper that injects the tool-CLI discovery file path.
|
||||
* @param {(e:Record<string,string>)=>Record<string,string>} [args.normalizeClaudeCodeExecutableEnv]
|
||||
* netcatty helper that rewrites CLAUDE_CODE_EXECUTABLE to a runnable path (claude only).
|
||||
* @returns {Record<string,string>}
|
||||
*/
|
||||
function buildSdkAgentEnv({
|
||||
shellEnv,
|
||||
requestedAgentEnv,
|
||||
withCliDiscoveryEnv,
|
||||
normalizeClaudeCodeExecutableEnv,
|
||||
}) {
|
||||
const filteredShellEnv = {};
|
||||
if (shellEnv && typeof shellEnv === "object") {
|
||||
for (const [k, v] of Object.entries(shellEnv)) {
|
||||
if (typeof v === "string" && !isDangerousEnvKey(k)) {
|
||||
filteredShellEnv[k] = v;
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
const filteredRequested = {};
|
||||
if (requestedAgentEnv && typeof requestedAgentEnv === "object") {
|
||||
for (const [k, v] of Object.entries(requestedAgentEnv)) {
|
||||
if (typeof v === "string" && !isDangerousEnvKey(k)) {
|
||||
filteredRequested[k] = v;
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
let env = { ...filteredShellEnv, ...filteredRequested };
|
||||
if (typeof withCliDiscoveryEnv === "function") {
|
||||
env = withCliDiscoveryEnv(env);
|
||||
}
|
||||
if (typeof normalizeClaudeCodeExecutableEnv === "function") {
|
||||
env = normalizeClaudeCodeExecutableEnv(env);
|
||||
}
|
||||
return env;
|
||||
}
|
||||
|
||||
module.exports = { buildSdkAgentEnv, DANGEROUS_ENV_KEYS, isDangerousEnvKey };
|
||||
Reference in New Issue
Block a user