Skip to content

fix: narrow bash manifest-write detection to actual write targets - #65

Merged
algomaster99 merged 3 commits into
mainfrom
fix/bash-manifest-write-detection
Sep 25, 2026
Merged

algomaster99 merged 3 commits into
mainfrom
fix/bash-manifest-write-detection

Conversation

@algomaster99

Copy link
Copy Markdown
Member

Summary

looksLikeManifestWrite's regex checks only required a known manifest name and a write construct (redirect, tee, sed -i, etc.) to both appear somewhere in the bash command string, not that the write construct's target was actually the manifest. That produced false positives on commands that merely read or mentioned a manifest without writing to it, e.g. a read with a stderr redirect elsewhere in the command, or a manifest named in an unrelated later shell clause than the actual write.

Before / after

# before
$ echo '{"tool_name":"Bash","tool_input":{"command":"cat package.json 2>/dev/null"}}' | ./yul
# exit 2, blocks the read as if it were a write

# after
$ echo '{"tool_name":"Bash","tool_input":{"command":"cat package.json 2>/dev/null"}}' | ./yul
# exit 0, passes through

Change

redirectToManifestRE and writeConstructToManifestRE now require the manifest name to sit at the write construct's own target position, scoped to the same shell clause (stops at ;, &&, ||, |, newlines) so a write in one clause can't match a manifest name that only appears in a different clause.

Added regression cases to TestLooksLikeManifestWrite covering both the false-positive fixes and confirming genuine manifest writes (heredocs, in-place edits, multi-source moves, relative directory prefixes) still block correctly.

🤖 Generated with Claude Code

looksLikeManifestWrite previously only checked that a known manifest
name and a write construct (redirect, tee, sed -i, etc.) both appeared
somewhere in the command string, not that the write construct actually
targeted the manifest. This false-positived on commands where the
manifest name is merely read or mentioned but nothing is written to
it (e.g. a read with a stderr redirect elsewhere in the command, or
the manifest named in an unrelated later clause).

redirectToManifestRE and writeConstructToManifestRE now require the
manifest name to immediately follow the write construct's own target
position, scoped to the same shell clause (stopped at ;, &&, ||, |, and
newlines) so a write in one clause can't match a manifest name that
only appears in another.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
algomaster99 added a commit that referenced this pull request Sep 25, 2026
run_case.sh generated a `hook`-condition settings.json with the matcher
hardcoded to "Write|Edit", so the Bash-write-detection heuristic added
in a prior commit was never exercised by any benchmark run - Claude
Code never routed Bash tool calls to the hook at all, regardless of
whether they touched a manifest. Every recorded run's "0 Bash
interceptions" reflected a wiring gap, not evidence the feature works
or that no bypass attempts occurred.

Depends on the fix in #65 for the underlying Bash heuristic's false
positives; landing this before that fix would flood benchmark
transcripts with spurious blocks on read-only commands.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@algomaster99
algomaster99 force-pushed the fix/bash-manifest-write-detection branch from 0ec1539 to b4e760f Compare September 25, 2026 11:37
Signed-off-by: Aman Sharma <mannu.poski10@gmail.com>
@algomaster99
algomaster99 force-pushed the fix/bash-manifest-write-detection branch from b4e760f to d450cb0 Compare September 25, 2026 11:39
@algomaster99
algomaster99 merged commit 86e4de3 into main Sep 25, 2026
2 checks passed
@algomaster99
algomaster99 deleted the fix/bash-manifest-write-detection branch September 25, 2026 11:40
frankreyesgarcia added a commit to frankreyesgarcia/yul that referenced this pull request Sep 27, 2026
…hains-project#65, package-manager CLI pin detection chains-project#69, ecosyste.ms GH Actions SHA resolution chains-project#64, and more)
frankreyesgarcia added a commit to frankreyesgarcia/yul that referenced this pull request Sep 27, 2026
opencode-yul is now published at v0.0.17 (just merged from upstream),
covering Write/Edit/Bash natively with the narrower write-target-aware
bash regex (main.go chains-project#65) - this local plugin was duplicating that exact
bash-forwarding logic. Trimmed it down to the one thing still not
upstream: blocking reads of OpenCode's own credential store. Renamed
yul-bash.js -> yul-auth-guard.js to match what it actually does now.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant