Repository navigation
fix(core): correct exitCode null check in shell sandbox denial heuristic - #29186
chelsealong wants to merge 1 commit into
Conversation
The sandbox denial heuristic in ShellToolInvocation checked `result.exitCode !== undefined`, but ExecutionResult.exitCode is typed `number | null`, never undefined. This meant signal-killed processes with exitCode === null (and no captured signal) spuriously triggered the sandbox-denial detection path. Three other checks in the same function already use `!== null`; this aligns the fourth with them.
|
📊 PR Size: size/S
|
🛑 Action Required: Evaluation ApprovalSteering changes have been detected in this PR. To prevent regressions, a maintainer must approve the evaluation run before this PR can be merged. Maintainers:
Once approved, the evaluation results will be posted here automatically. |
Summary of ChangesHello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed! This pull request addresses a bug in the shell tool's sandbox denial detection logic where an incorrect type check caused processes with null exit codes to be erroneously flagged as sandbox denials. By aligning the guard condition with the actual type definition of the exit code, the fix ensures more accurate heuristic behavior and includes a regression test to prevent future occurrences. Highlights
Using Gemini Code AssistThe full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips. Invoking Gemini You can request assistance from Gemini at any point by creating a comment using either
Customization To customize the Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a Limitations & Feedback Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counterproductive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here. Footnotes
|
There was a problem hiding this comment.
Code Review
This pull request modifies the sandbox denial detection logic in ShellToolInvocation to check if result.exitCode is not null instead of undefined. It also adds a unit test to ensure sandbox denial detection is not executed when exitCode is null without a signal. No review comments were provided, so there is no feedback to address.
|
Hi there! Thank you for your interest in contributing to Gemini CLI. To ensure we maintain high code quality and focus on our prioritized roadmap, we only guarantee review and consideration of pull requests for issues that are explicitly labeled as 'help wanted'. This PR will be closed in 7 days if it remains without that designation. We encourage you to find and contribute to existing 'help wanted' issues in our backlog! Thank you for your understanding. |
|
This pull request is being closed as it has been open for 14 days without a 'help wanted' designation. We encourage you to find and contribute to existing 'help wanted' issues in our backlog! Thank you for your understanding. |
Fixes #29043
What broke
ShellToolInvocation's "Heuristic Sandbox Denial Detection" block(
packages/core/src/tools/shell.ts:868) checked:but
ExecutionResult.exitCodeis typednumber | null(
packages/core/src/services/executionLifecycleService.ts:23) — it isnever
undefined. Sincenull !== undefinedistrue, a processkilled by a signal without a captured
signalstring (exitCode === null) spuriously satisfied this guard and entered the sandbox-denialheuristic, even though nothing indicates a sandbox denial in that
case. Three other checks in the same function already correctly use
!== null(e.g. the tworesult.exitCode !== null && result.exitCode !== 0sites earlier in the method).Fix
Changed the guard to
result.exitCode !== null && result.exitCode !== 0, matching the sibling checks and the actual type.Testing
Added a regression test in
packages/core/src/tools/shell.test.ts(sandbox heuristicsdescribe block) that resolves the execution promise with
exitCode: null, signal: null, error: null, aborted: falseandasserts
sandboxManager.parseDenialsis not called and the resultis not flagged
SANDBOX_EXPANSION_REQUIRED.Confirmed the test fails without the fix:
And passes with the fix applied:
Also ran, both clean:
AI assistance disclosure
This change was prepared with the assistance of an AI coding agent
(Claude), including drafting the fix, the regression test, and this
PR description. All changes were reviewed and verified locally before
submission.