Skip to content

fix(core): resolve policy engine bugs affecting tool approvals - #26540

Closed
Abhijit-2592 wants to merge 2 commits into
mainfrom
abhijit-2592/fix-policy-engine
Closed

Abhijit-2592 wants to merge 2 commits into
mainfrom
abhijit-2592/fix-policy-engine

Conversation

@Abhijit-2592

@Abhijit-2592 Abhijit-2592 commented May 5, 2026 •

Copy link
Copy Markdown
Contributor

Summary

This PR fixes several critical issues in the policy engine that were preventing tool approvals from persisting correctly and causing unnecessary approval prompts in permissive modes (YOLO, AUTO_EDIT).

Details

  1. Regex Null-Byte Fix: The buildParamArgsPattern utility was incorrectly escaping null bytes using \\\\0. This caused property-matching regexes to fail against the stableStringify output (which uses literal \x00 markers), breaking permanent approvals for specific files or patterns.
  2. Redirection Downgrade Fix: Updated shouldDowngradeForRedirection to skip the automatic downgrade to ASK_USER when the approval mode is YOLO unconditionally. For AUTO_EDIT mode, the downgrade is skipped only if a sandbox is enabled, addressing security concerns regarding unauthorized file writes via shell redirection.
  3. Shell Wrapper Enhancements: Improved stripShellWrapper to recognize and strip generic shell program calls (e.g., sh script.sh, bash script.sh), allowing better matching against approved script paths.

Related Issues

Fixes #24772
Fixes #16970

How to Validate

  1. Run npm run test -w @google/gemini-cli-core -- src/policy/policy-engine.test.ts to verify policy engine logic.
  2. Run npm run test -w @google/gemini-cli-core -- src/utils/shell-utils.test.ts to verify shell wrapper stripping.
  3. Manually verify "Always Allow" persistence by approving a run_shell_command with a specific script and ensuring it doesn't prompt again in the same or future sessions.

Pre-Merge Checklist

  • Updated relevant documentation and README (if needed)
  • Added/updated tests (if needed)
  • Noted breaking changes (if any)
  • Validated on required platforms/methods:
    • MacOS
      • npm run

@Abhijit-2592
Abhijit-2592 requested a review from a team as a code owner May 5, 2026 21:04
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Summary of Changes

Hello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request addresses critical bugs within the policy engine that hindered the persistence of tool approvals and caused redundant user prompts in permissive modes. By refining regex matching, adjusting downgrade logic, and improving shell command parsing, the changes ensure a smoother and more consistent user experience when executing tools.

Highlights

  • Regex Null-Byte Fix: Updated the regex delimiter in buildParamArgsPattern from \0 to \x00 to correctly match stableStringify output, ensuring persistent tool approvals.
  • Redirection Downgrade Logic: Modified shouldDowngradeForRedirection to prevent unnecessary approval prompts in YOLO and AUTO_EDIT modes, regardless of sandbox status.
  • Shell Wrapper Improvements: Enhanced stripShellWrapper to identify and strip generic shell script execution patterns, improving path matching for approved tools.
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize the Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counterproductive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution. ↩

@github-actions

github-actions Bot commented May 5, 2026 •

Copy link
Copy Markdown

Size Change: +347 B (0%)

Total Size: 34 MB

Filename Size Change
./bundle/chunk-32FGWL3S.js 0 B -14.7 MB (removed) 🏆
./bundle/chunk-46SZMMNN.js 0 B -658 kB (removed) 🏆
./bundle/chunk-F6WF3VCE.js 0 B -19.5 kB (removed) 🏆
./bundle/chunk-JX2FGYWO.js 0 B -2.78 MB (removed) 🏆
./bundle/chunk-KM5NSTLI.js 0 B -12.5 kB (removed) 🏆
./bundle/chunk-QI72UPDC.js 0 B -3.8 kB (removed) 🏆
./bundle/chunk-XU2XS4AU.js 0 B -3.43 kB (removed) 🏆
./bundle/chunk-YHMTF3MY.js 0 B -49.2 kB (removed) 🏆
./bundle/core-ADXFKO77.js 0 B -48.8 kB (removed) 🏆
./bundle/devtoolsService-ZLIIDPQP.js 0 B -28 kB (removed) 🏆
./bundle/gemini-ARBICVSJ.js 0 B -583 kB (removed) 🏆
./bundle/interactiveCli-RVPIYA25.js 0 B -1.29 MB (removed) 🏆
./bundle/liteRtServerManager-7RAGIEEW.js 0 B -2.11 kB (removed) 🏆
./bundle/oauth2-provider-C7EUKDPI.js 0 B -9.16 kB (removed) 🏆
./bundle/chunk-67IYKR3J.js 12.5 kB +12.5 kB (new file) 🆕
./bundle/chunk-BB6DIRZF.js 19.5 kB +19.5 kB (new file) 🆕
./bundle/chunk-MIYJZK7Z.js 3.8 kB +3.8 kB (new file) 🆕
./bundle/chunk-N57LT2K7.js 49.2 kB +49.2 kB (new file) 🆕
./bundle/chunk-Q2HU3MNK.js 658 kB +658 kB (new file) 🆕
./bundle/chunk-R4O3UB4O.js 14.7 MB +14.7 MB (new file) 🆕
./bundle/chunk-YNRTMHB5.js 2.78 MB +2.78 MB (new file) 🆕
./bundle/chunk-ZO4WUH7E.js 3.43 kB +3.43 kB (new file) 🆕
./bundle/core-JCNGBXSJ.js 48.8 kB +48.8 kB (new file) 🆕
./bundle/devtoolsService-P63MCO7U.js 28 kB +28 kB (new file) 🆕
./bundle/gemini-XGQY6YHL.js 583 kB +583 kB (new file) 🆕
./bundle/interactiveCli-KVZCJIP4.js 1.29 MB +1.29 MB (new file) 🆕
./bundle/liteRtServerManager-UCCNUYTL.js 2.11 kB +2.11 kB (new file) 🆕
./bundle/oauth2-provider-7SDTA6LO.js 9.16 kB +9.16 kB (new file) 🆕
ℹ️ View Unchanged
Filename Size Change
./bundle/bundled/third_party/index.js 8 MB 0 B
./bundle/chunk-34MYV7JD.js 2.45 kB 0 B
./bundle/chunk-5AUYMPVF.js 858 B 0 B
./bundle/chunk-5PS3AYFU.js 1.18 kB 0 B
./bundle/chunk-664ZODQF.js 124 kB 0 B
./bundle/chunk-DAHVX5MI.js 206 kB 0 B
./bundle/chunk-IUUIT4SU.js 56.5 kB 0 B
./bundle/chunk-RJTRUG2J.js 39.8 kB 0 B
./bundle/chunk-VJSUVOZ4.js 1.97 MB 0 B
./bundle/cleanup-YLXGC75Z.js 0 B -932 B (removed) 🏆
./bundle/devtools-36NN55EP.js 696 kB 0 B
./bundle/dist-T73EYRDX.js 356 B 0 B
./bundle/events-XB7DADIJ.js 418 B 0 B
./bundle/examples/hooks/scripts/on-start.js 188 B 0 B
./bundle/examples/mcp-server/example.js 1.43 kB 0 B
./bundle/gemini.js 5.1 kB 0 B
./bundle/getMachineId-bsd-TXG52NKR.js 1.55 kB 0 B
./bundle/getMachineId-darwin-7OE4DDZ6.js 1.55 kB 0 B
./bundle/getMachineId-linux-SHIFKOOX.js 1.34 kB 0 B
./bundle/getMachineId-unsupported-5U5DOEYY.js 1.06 kB 0 B
./bundle/getMachineId-win-6KLLGOI4.js 1.72 kB 0 B
./bundle/memoryDiscovery-NGHTMHWQ.js 980 B 0 B
./bundle/multipart-parser-KPBZEGQU.js 11.7 kB 0 B
./bundle/node_modules/@google/gemini-cli-devtools/dist/client/main.js 222 kB 0 B
./bundle/node_modules/@google/gemini-cli-devtools/dist/src/_client-assets.js 229 kB 0 B
./bundle/node_modules/@google/gemini-cli-devtools/dist/src/index.js 13.4 kB 0 B
./bundle/node_modules/@google/gemini-cli-devtools/dist/src/types.js 132 B 0 B
./bundle/sandbox-macos-permissive-open.sb 890 B 0 B
./bundle/sandbox-macos-permissive-proxied.sb 1.31 kB 0 B
./bundle/sandbox-macos-restrictive-open.sb 3.36 kB 0 B
./bundle/sandbox-macos-restrictive-proxied.sb 3.56 kB 0 B
./bundle/sandbox-macos-strict-open.sb 4.82 kB 0 B
./bundle/sandbox-macos-strict-proxied.sb 5.02 kB 0 B
./bundle/src-QVCVGIUX.js 47 kB 0 B
./bundle/start-F4MWAQZS.js 0 B -652 B (removed) 🏆
./bundle/tree-sitter-7U6MW5PS.js 274 kB 0 B
./bundle/tree-sitter-bash-34ZGLXVX.js 1.84 MB 0 B
./bundle/cleanup-WWYA7CQF.js 932 B +932 B (new file) 🆕
./bundle/start-VAPXFGQD.js 652 B +652 B (new file) 🆕

compressed-size-action

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request modifies the policy engine to remove sandbox checks for shell redirection in AUTO_EDIT and YOLO modes, updates JSON property matching patterns to use hex null characters, and enhances shell wrapper stripping to support direct script execution. A critical security concern was raised regarding the removal of the sandbox check in AUTO_EDIT mode, as it could allow unauthorized file writes via shell redirection when a sandbox is not active.

Comment thread packages/core/src/policy/policy-engine.ts Outdated
@gemini-cli gemini-cli Bot added priority/p1 Important and should be addressed in the near term. area/core Issues related to User Interface, OS Support, Core Functionality 🔒 maintainer only ⛔ Do not contribute. Internal roadmap item. labels May 5, 2026

@Abhijit-2592 Abhijit-2592 left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I have applied the suggested security fix. The sandboxEnabled check is now restored for AUTO_EDIT mode, ensuring that shell redirection requires a sandbox in that mode, while YOLO mode remains unaffected. Thanks for catching this!

Fixes #24772, #16970.

- Fixes regex null-byte mismatch in `buildParamArgsPattern` so "always allow" works.
- Removes sandbox requirement from `shouldDowngradeForRedirection` so YOLO/AUTO_EDIT modes behave correctly.
- Enhances `stripShellWrapper` to recognize generic shell scripts (e.g., `sh script.sh`).
@Abhijit-2592
Abhijit-2592 force-pushed the abhijit-2592/fix-policy-engine branch from eaaa9e3 to 11eadac Compare May 5, 2026 21:42
}

// In AUTO_EDIT mode, only bypass downgrade if sandboxing is enabled.
const sandboxEnabled = !(this.sandboxManager instanceof NoopSandboxManager);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

i'm not sure this is going to fix the issue the user is reporting, since wouldn't this still ask for approval?

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

+1

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/core Issues related to User Interface, OS Support, Core Functionality 🔒 maintainer only ⛔ Do not contribute. Internal roadmap item. priority/p1 Important and should be addressed in the near term. priority/p2 Important but can be addressed in a future release. size/s A small PR

Projects

None yet

4 participants