Skip to content

fix(core): preserve env prefixes in saved shell patterns - #53802

Draft
zenv-dev wants to merge 2 commits into
anomalyco:v2from
zenv-dev:env-saved-pattern
Draft

zenv-dev wants to merge 2 commits into
anomalyco:v2from
zenv-dev:env-saved-pattern

Conversation

@zenv-dev

@zenv-dev zenv-dev commented Oct 7, 2026 •

Copy link
Copy Markdown

Issue for this PR

Fixes #52720 (saved-pattern mismatch). Related: #45914.

Type of change

  • Bug fix
  • New feature
  • Refactor / code improvement
  • Documentation

What does this PR do?

Always allow drops leading environment assignments, so a saved rule cannot match a repeated command. Commands with inline assignments keep their literal leading source, including preceding redirects, in native V2 proposals from both shell scanners. Raw permission checks, deny precedence, unprefixed proposals, PowerShell handling and executable arity are unchanged. Proposals whose new prefix contains *, ? or \ are omitted rather than widened; no env-stripped authorization fallback.

How did you verify your code works?

From packages/core, via the isolated test wrapper:

  • Native shell parser/scanner, permission and tool suite (21 files): 3267 pass, 356 skip, 0 fail, 74899 expects, exit 0. Root bun run check: 36 of 36 tasks, exit 0, pre-existing lint output only; focused lint and Prettier clean.
  • The four original native tests, in pre-extension form, give 0 pass / 4 fail on pristine source at release v2.0.25 and mainline snapshot 62e087ff; source checkouts only, release binary not executed.
  • Each added negative case (an additional assignment, a different executable, an unprefixed command) asks once with the raw resource when only the scoped saved rule exists, before adding a separate printf * rule, and writes no marker. Controlled broader grants make these checks fail for both scanners while waiting for the required prompt. Scanner messages name portable or Tree-sitter.
  • The native environment prefixes group stays at 4 tests, 138 expects.

Native execution regressions are POSIX-only; Windows execution and updating the installed CLI were not tested.

Screenshots / recordings

Not applicable (no UI change).

Checklist

  • I have tested my changes locally
  • I have not included unrelated changes in this PR

@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

The following comment was made by an LLM, it may be inaccurate:

Keep the literal leading source of commands with inline assignments in
shell approval proposals from both scanners. Retain raw authorization
resources and omit proposals whose new prefix cannot be represented
literally by the matcher. Leave no-assignment proposals unchanged.

Constraint: Preserve raw authorization and configured deny precedence
Not-tested: Installed CLI update and Windows execution
@zenv-dev zenv-dev changed the title fix(opencode): preserve env prefixes in saved shell patterns fix(core): preserve env prefixes in saved shell patterns Oct 8, 2026
@zenv-dev
zenv-dev changed the base branch from dev to v2 October 8, 2026 10:16
Extend the native shell approval fixture so an additional assignment, a
different executable and a bare command must still ask before the
auxiliary broad grant is added. Also inline the single-use scan
argument, rename the changed-argument check and label each scanner
assertion so a failure names the scanner that ran.

Constraint: raw authorization unchanged; test-only, no production change

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

bash permission "Always allow" never matches commands with leading environment variable assignments

1 participant