Some checks failed
build-packages / resolve bundled mosh-client (push) Has been cancelled
build-packages / resolve bundled et-client (push) Has been cancelled
build-packages / build-macos (push) Has been cancelled
build-packages / build-windows (push) Has been cancelled
build-packages / build-linux-x64 (push) Has been cancelled
build-packages / build-linux-arm64 (push) Has been cancelled
build-packages / release (push) Has been cancelled
build-packages / update Nix release metadata (push) Has been cancelled
build-packages / bump homebrew tap (push) Has been cancelled
test / lint-and-test (push) Has been cancelled
AI automation / Route event (push) Has been cancelled
AI automation / Hand reopened issue to maintainers (push) Has been cancelled
AI automation / Clean source issue state (push) Has been cancelled
AI automation / Reconcile handoffs (push) Has been cancelled
AI automation / Classify issue (push) Has been cancelled
AI automation / Claude Code smoke (push) Has been cancelled
AI automation / Review issue follow-up (push) Has been cancelled
AI automation / Publish issue follow-up (push) Has been cancelled
AI automation / Implement with Claude Code (push) Has been cancelled
AI automation / Publish implement PR (push) Has been cancelled
AI automation / Continue queued issue comments (push) Has been cancelled
AI automation / Codex review loop (push) Has been cancelled
AI automation / Publish Codex fix (push) Has been cancelled
AI automation / Clear Codex dispatch marker (push) Has been cancelled
AI automation / Own PR re-request Codex (push) Has been cancelled
AI automation / External PR re-request Codex (push) Has been cancelled
AI automation / Poll Codex reaction / retry (push) Has been cancelled
build-et-binaries / build-linux-x64 (push) Has been cancelled
build-et-binaries / build-linux-arm64 (push) Has been cancelled
build-et-binaries / build-macos-universal (push) Has been cancelled
build-et-binaries / build-windows-x64 (push) Has been cancelled
build-et-binaries / release (push) Has been cancelled
74 lines
2.5 KiB
JavaScript
74 lines
2.5 KiB
JavaScript
"use strict";
|
|
|
|
/**
|
|
* Env construction for SDK agent subprocesses.
|
|
*
|
|
* Consolidates the env hardening that previously lived in
|
|
* the removed raw-process handler (DANGEROUS_ENV_KEYS) and the per-spawn merge
|
|
* helpers used by SDK agent launches.
|
|
* Callers inject the netcatty helpers so this module stays pure/testable.
|
|
*/
|
|
|
|
// Env var names that can be used for code injection into a child process.
|
|
// Mirror of the set in the (now-removed) raw agent spawn handler.
|
|
const DANGEROUS_ENV_KEYS = new Set([
|
|
"LD_PRELOAD", "LD_LIBRARY_PATH",
|
|
"DYLD_INSERT_LIBRARIES", "DYLD_LIBRARY_PATH", "DYLD_FRAMEWORK_PATH",
|
|
"NODE_OPTIONS", "ELECTRON_RUN_AS_NODE",
|
|
"PYTHONPATH", "RUBYLIB", "PERL5LIB",
|
|
"BASH_ENV", "ENV", "CDPATH", "PROMPT_COMMAND",
|
|
]);
|
|
|
|
function isDangerousEnvKey(key) {
|
|
const normalized = String(key || "").toUpperCase();
|
|
return DANGEROUS_ENV_KEYS.has(normalized) || normalized.startsWith("BASH_FUNC_");
|
|
}
|
|
|
|
/**
|
|
* Build the env handed to an SDK agent subprocess.
|
|
*
|
|
* @param {object} args
|
|
* @param {Record<string,string>} args.shellEnv Resolved shell env (PATH-augmented).
|
|
* @param {Record<string,string>} [args.requestedAgentEnv] Per-agent env from the UI (filtered).
|
|
* @param {(e:Record<string,string>)=>Record<string,string>} [args.withCliDiscoveryEnv]
|
|
* netcatty helper that injects the tool-CLI discovery file path.
|
|
* @param {(e:Record<string,string>)=>Record<string,string>} [args.normalizeClaudeCodeExecutableEnv]
|
|
* netcatty helper that rewrites CLAUDE_CODE_EXECUTABLE to a runnable path (claude only).
|
|
* @returns {Record<string,string>}
|
|
*/
|
|
function buildSdkAgentEnv({
|
|
shellEnv,
|
|
requestedAgentEnv,
|
|
withCliDiscoveryEnv,
|
|
normalizeClaudeCodeExecutableEnv,
|
|
}) {
|
|
const filteredShellEnv = {};
|
|
if (shellEnv && typeof shellEnv === "object") {
|
|
for (const [k, v] of Object.entries(shellEnv)) {
|
|
if (typeof v === "string" && !isDangerousEnvKey(k)) {
|
|
filteredShellEnv[k] = v;
|
|
}
|
|
}
|
|
}
|
|
|
|
const filteredRequested = {};
|
|
if (requestedAgentEnv && typeof requestedAgentEnv === "object") {
|
|
for (const [k, v] of Object.entries(requestedAgentEnv)) {
|
|
if (typeof v === "string" && !isDangerousEnvKey(k)) {
|
|
filteredRequested[k] = v;
|
|
}
|
|
}
|
|
}
|
|
|
|
let env = { ...filteredShellEnv, ...filteredRequested };
|
|
if (typeof withCliDiscoveryEnv === "function") {
|
|
env = withCliDiscoveryEnv(env);
|
|
}
|
|
if (typeof normalizeClaudeCodeExecutableEnv === "function") {
|
|
env = normalizeClaudeCodeExecutableEnv(env);
|
|
}
|
|
return env;
|
|
}
|
|
|
|
module.exports = { buildSdkAgentEnv, DANGEROUS_ENV_KEYS, isDangerousEnvKey };
|