Skip to content

Fix secret leak via repo-local config, confine tools, fail on cut-off answers - #14

Merged
makefunstuff merged 1 commit into
mainfrom
claude/project-thread-2eykz8
Sep 29, 2026
Merged

makefunstuff merged 1 commit into
mainfrom
claude/project-thread-2eykz8

Conversation

@makefunstuff

Copy link
Copy Markdown
Owner

Requested by j · project thread

Before: a cloned repo's ./.clank/config.toml could set base_url plus api_key_env = "GITHUB_TOKEN", and clank -m hi sent that token to the repo's server (reproduced). clank-jev sent your Jev key to [clank].base_url. The model's read_file could read ~/.ssh or /dev/zero. A stream the server dropped mid-answer exited 0, and a -c tree with a missing file sent [context error: …] to the model and exited 0. clank-web --fetch failed on large pages when the 512 KiB cap split a UTF-8 character.

After: a working-directory config may only name CLANK_API_KEY / BRAVE_API_KEY / TAVILY_API_KEY (any other variable needs --config or CLANK_CONFIG, else exit 2). clank-jev reads only [clank].timeout. Tool paths must resolve inside the working directory, and read_file takes regular files up to 4 MB. Cut-off streams, non-JSON stream events and unreadable context leaves all exit 1. Fetch drops the split character.

Smaller fixes: stat reports symlinks, search stops at exactly 500 matches, read_file counts lines like wc and drops \r, invalid tool-call JSON is returned to the model as an error, a trailing / in base_url works, user:key@ in base_url is redacted from traces and errors, --show-thinking prints no stray blank line, clank-jev --min-prob must be in 0..=1. The pre-push hook now says it sends diffs to a third party.

How: config::load checks key-variable names for implied files only. tools::execute canonicalizes and confines every path. client::stream_round requires finish_reason or [DONE]. Tree::render returns Result. Docs (PROTOCOL.md, docs/clank-jev.md, docs/clank-web.md, STATUS.md) are updated and reflowed. New unit and stub-server tests cover each fix; cargo test --locked passes with -D warnings.

Not changed: the top-level json_schema request field (llama.cpp-specific) and the stdin read when stdin is an open non-TTY. Both need a design decision rather than a bug fix.

🤖 Generated with Claude Code

https://claude.ai/code/session_019RkP7NfSreh9VQeWSk47hb


Generated by Claude Code

…sses

- A ./.clank/config.toml found in the working directory may only name each
  section's own key variable (CLANK_API_KEY, BRAVE_API_KEY, TAVILY_API_KEY);
  another name needs --config or CLANK_CONFIG. A cloned repo could otherwise
  send any environment secret to an endpoint it also chose.
- clank-jev no longer takes its endpoint, model or key from [clank]; only
  [clank].timeout. The chat base_url was being used as the Jev URL.
- Tool paths are confined to the working directory; read_file refuses
  non-regular files and files over 4 MB, and counts lines like wc.
- A stream that ends without finish_reason or [DONE] is a failure (exit 1);
  non-JSON and error events mid-stream are reported, not skipped.
- A -c context tree whose file leaf cannot be read fails the run instead of
  sending "[context error: ...]" to the model; a node with file plus
  text/children is rejected.
- clank-web --fetch drops a character split by the 512 KiB cap instead of
  failing the whole page.
- stat reports symlinks, search stops at exactly 500 matches, invalid tool
  arguments come back to the model as an error, a trailing slash in base_url
  works, credentials in base_url are redacted from traces and errors,
  --show-thinking prints no stray blank line, clank-jev checks --min-prob.
- The pre-push hook says that it sends diffs to a third-party provider.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019RkP7NfSreh9VQeWSk47hb
@makefunstuff
makefunstuff marked this pull request as ready for review September 29, 2026 17:19
@makefunstuff
makefunstuff merged commit 039dbde into main Sep 29, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants