Skip to content

fix(core): correct exitCode null check in shell sandbox denial heuristic - #29186

Closed
chelsealong wants to merge 1 commit into
google-gemini:mainfrom
chelsealong:fix/shell-exitcode-null-check
Closed

chelsealong wants to merge 1 commit into
google-gemini:mainfrom
chelsealong:fix/shell-exitcode-null-check

Conversation

@chelsealong

Copy link
Copy Markdown

Fixes #29043

What broke

ShellToolInvocation's "Heuristic Sandbox Denial Detection" block
(packages/core/src/tools/shell.ts:868) checked:

(result.exitCode !== undefined && result.exitCode !== 0) ||

but ExecutionResult.exitCode is typed number | null
(packages/core/src/services/executionLifecycleService.ts:23) — it is
never undefined. Since null !== undefined is true, a process
killed by a signal without a captured signal string (exitCode === null) spuriously satisfied this guard and entered the sandbox-denial
heuristic, even though nothing indicates a sandbox denial in that
case. Three other checks in the same function already correctly use
!== null (e.g. the two result.exitCode !== null && result.exitCode !== 0 sites earlier in the method).

Fix

Changed the guard to result.exitCode !== null && result.exitCode !== 0, matching the sibling checks and the actual type.

Testing

Added a regression test in
packages/core/src/tools/shell.test.ts (sandbox heuristics
describe block) that resolves the execution promise with
exitCode: null, signal: null, error: null, aborted: false and
asserts sandboxManager.parseDenials is not called and the result
is not flagged SANDBOX_EXPANSION_REQUIRED.

Confirmed the test fails without the fix:

$ git checkout HEAD~1 -- packages/core/src/tools/shell.ts
$ npx vitest run src/tools/shell.test.ts -t "should NOT run sandbox denial detection"
 FAIL  src/tools/shell.test.ts > ShellTool > sandbox heuristics > should NOT run sandbox denial detection when exitCode is null without a signal
AssertionError: expected "spy" to not be called at all, but actually been called 1 times
$ git checkout HEAD -- packages/core/src/tools/shell.ts

And passes with the fix applied:

$ npx vitest run src/tools/shell.test.ts
 ✓ src/tools/shell.test.ts (90 tests | 1 skipped) 488ms
 Test Files  1 passed (1)
      Tests  89 passed | 1 skipped (90)

Also ran, both clean:

$ npx eslint packages/core/src/tools/shell.ts packages/core/src/tools/shell.test.ts --max-warnings 0
$ npx tsc --noEmit   # in packages/core

AI assistance disclosure

This change was prepared with the assistance of an AI coding agent
(Claude), including drafting the fix, the regression test, and this
PR description. All changes were reviewed and verified locally before
submission.

The sandbox denial heuristic in ShellToolInvocation checked
`result.exitCode !== undefined`, but ExecutionResult.exitCode is typed
`number | null`, never undefined. This meant signal-killed processes
with exitCode === null (and no captured signal) spuriously triggered
the sandbox-denial detection path. Three other checks in the same
function already use `!== null`; this aligns the fourth with them.
@chelsealong
chelsealong requested a review from a team as a code owner September 3, 2026 16:20
@github-actions github-actions Bot added the size/s A small PR label Sep 3, 2026
@github-actions

github-actions Bot commented Sep 3, 2026

Copy link
Copy Markdown

📊 PR Size: size/S

  • Lines changed: 36
  • Additions: +35
  • Deletions: -1
  • Files changed: 2

@github-actions

github-actions Bot commented Sep 3, 2026

Copy link
Copy Markdown

🛑 Action Required: Evaluation Approval

Steering changes have been detected in this PR. To prevent regressions, a maintainer must approve the evaluation run before this PR can be merged.

Maintainers:

  1. Go to the Workflow Run Summary.
  2. Click the yellow 'Review deployments' button.
  3. Select the 'eval-gate' environment and click 'Approve'.

Once approved, the evaluation results will be posted here automatically.

@gemini-code-assist

Copy link
Copy Markdown
Contributor

Summary of Changes

Hello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request addresses a bug in the shell tool's sandbox denial detection logic where an incorrect type check caused processes with null exit codes to be erroneously flagged as sandbox denials. By aligning the guard condition with the actual type definition of the exit code, the fix ensures more accurate heuristic behavior and includes a regression test to prevent future occurrences.

Highlights

  • Corrected exitCode null check: Updated the sandbox denial heuristic in ShellToolInvocation to correctly check for null instead of undefined when evaluating exitCode, preventing spurious sandbox denial triggers.
  • Added regression test: Introduced a new test case in shell.test.ts to verify that processes exiting with null exit codes without signals do not trigger the sandbox denial heuristic.
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize the Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counterproductive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution. ↩

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request modifies the sandbox denial detection logic in ShellToolInvocation to check if result.exitCode is not null instead of undefined. It also adds a unit test to ensure sandbox denial detection is not executed when exitCode is null without a signal. No review comments were provided, so there is no feedback to address.

@gemini-cli gemini-cli Bot added priority/p1 Important and should be addressed in the near term. area/security Issues related to security labels Sep 3, 2026
@gemini-cli

gemini-cli Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor

Hi there! Thank you for your interest in contributing to Gemini CLI.

To ensure we maintain high code quality and focus on our prioritized roadmap, we only guarantee review and consideration of pull requests for issues that are explicitly labeled as 'help wanted'.

This PR will be closed in 7 days if it remains without that designation. We encourage you to find and contribute to existing 'help wanted' issues in our backlog! Thank you for your understanding.

@gemini-cli

gemini-cli Bot commented Sep 18, 2026

Copy link
Copy Markdown
Contributor

This pull request is being closed as it has been open for 14 days without a 'help wanted' designation. We encourage you to find and contribute to existing 'help wanted' issues in our backlog! Thank you for your understanding.

This branch had an error being deployed

1 failed deployment
eval-gate — ec21e13b Deployed Sep 3, 2026 by chelsealong via Evaluate Steering & Regressions #1896
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/security Issues related to security priority/p1 Important and should be addressed in the near term. size/s A small PR status/pr-nudge-sent

Projects

None yet

Development

Successfully merging this pull request may close these issues.

bug: shell exit-code mapping checks exitCode !== undefined where the value type is number | null

1 participant