Repository navigation
Reject direct issue creation and safe-output access in post-steps - #66064
Conversation
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
|
@copilot they also try to access the safeoutputs mcp storage file outputs.jsonl |
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Validation still permits prohibited operations and rejects valid read-only requests.
Review effort: Balanced
Findings: 7
Open (7)
Recognize gh issue commands after -R or --repo · New Correctly infer curl methods from body, GET, and overrides · New Detect issue creation via octokit.request and github.request · New Block access to raw safe-output files and runtime paths · New Validate file inputs for artifact upload actions · New Scan complete logical shell commands across continued lines · New Recognize gh api --input before the endpoint · New
What changed in this PR
Adds compiler checks intended to keep post-step issue publishing and agent-output access within the safe-output system.
Changes:
- Validates main and imported post-steps.
- Adds rejection, read-only, and compilation tests.
- Documents the restriction and safe-output alternative.
| File | Description |
|---|---|
pkg/workflow/workflow_builder_steps.go |
Validates merged post-steps. |
pkg/workflow/post_steps_validation.go |
Detects prohibited commands and output-file references. |
pkg/workflow/post_steps_validation_test.go |
Tests validation and compiler integration. |
docs/src/content/docs/reference/steps-jobs.md |
Documents post-step restrictions. |
| ) | ||
|
|
||
| var ( | ||
| postStepIssueCreateRE = regexp.MustCompile(`(?i)(?:^|[\s|;&])gh\s+issue\s+create\b`) |
There was a problem hiding this comment.
Added detection for gh -R/--repo before issue create and regression coverage confirming gh -R ... issue list remains allowed. Fix is in e24f63b.
| postStepIssueAPIRE = regexp.MustCompile(`(?i)(?:^|[/\s"'=])(?:https://api\.github\.com/)?repos/(?:[^/\s"'?]+/[^/\s"'?]+|\$\{\{\s*github\.repository\s*\}\}|\$\{?GITHUB_REPOSITORY\}?)/issues(?:[?"'\s]|$)`) | ||
| postStepAPIPostRE = regexp.MustCompile(`(?i)(?:^|\s)(?:-X\s+POST|--method(?:=|\s+)POST|-f(?:\s|=)|-F(?:\s|=)|--(?:raw-)?field(?:\s|=))`) | ||
| postStepAPIGetRE = regexp.MustCompile(`(?i)(?:^|\s)(?:-X\s+GET\b|--method(?:=|\s+)GET\b)`) | ||
| postStepCurlPostRE = regexp.MustCompile(`(?i)\bcurl\b[^\n]*\s(?:-X\s+POST\b|--request(?:=|\s+)POST\b|(?:-d|--data(?:-raw|-binary|-urlencode)?)(?:\s|=))`) |
There was a problem hiding this comment.
Curl validation now derives the effective method from JSON/data options, -G/--get, and explicit -X/--request overrides, with POST and GET regression cases. Fix is in e24f63b.
| postStepAPIPostRE = regexp.MustCompile(`(?i)(?:^|\s)(?:-X\s+POST|--method(?:=|\s+)POST|-f(?:\s|=)|-F(?:\s|=)|--(?:raw-)?field(?:\s|=))`) | ||
| postStepAPIGetRE = regexp.MustCompile(`(?i)(?:^|\s)(?:-X\s+GET\b|--method(?:=|\s+)GET\b)`) | ||
| postStepCurlPostRE = regexp.MustCompile(`(?i)\bcurl\b[^\n]*\s(?:-X\s+POST\b|--request(?:=|\s+)POST\b|(?:-d|--data(?:-raw|-binary|-urlencode)?)(?:\s|=))`) | ||
| postStepOctokitRE = regexp.MustCompile(`\b(?:github|octokit)(?:\.rest)?\.issues\.create\s*\(`) |
There was a problem hiding this comment.
Added checks for literal POST issue routes in both github.request and octokit.request; GET and issue-comment routes remain allowed. Fix is in e24f63b.
| postStepAPIGetRE = regexp.MustCompile(`(?i)(?:^|\s)(?:-X\s+GET\b|--method(?:=|\s+)GET\b)`) | ||
| postStepCurlPostRE = regexp.MustCompile(`(?i)\bcurl\b[^\n]*\s(?:-X\s+POST\b|--request(?:=|\s+)POST\b|(?:-d|--data(?:-raw|-binary|-urlencode)?)(?:\s|=))`) | ||
| postStepOctokitRE = regexp.MustCompile(`\b(?:github|octokit)(?:\.rest)?\.issues\.create\s*\(`) | ||
| postStepOutputRE = regexp.MustCompile(`(?i)(?:\bagent_output\.json\b|(?:safeoutputs|safe-outputs)/output\.json\b|\bGH_AW_AGENT_OUTPUT\b)`) |
There was a problem hiding this comment.
The validator now rejects outputs.jsonl, the collected safe-output path, GH_AW_SAFE_OUTPUTS, and the runtime-path expression. Fix is in e24f63b.
| if with, ok := step["with"].(map[string]any); ok { | ||
| if script, ok := with["script"].(string); ok { | ||
| scripts = append(scripts, script) | ||
| } | ||
| } |
There was a problem hiding this comment.
Added safe-output checks for path inputs to upload-artifact, cache, and upload-pages-artifact actions, including broad /tmp/gh-aw/ paths. The docs example now uploads only /tmp/gh-aw/agent/. Fix is in e24f63b.
|
|
||
| for _, script := range scripts { | ||
| createsIssue := postStepIssueCreateRE.MatchString(script) || postStepOctokitRE.MatchString(script) | ||
| for _, command := range ghAPICmdRE.FindAllStringSubmatch(script, -1) { |
There was a problem hiding this comment.
Shell validation now joins backslash-continued lines and splits commands at unquoted shell separators, preserving command boundaries. Added continued gh api and curl regressions. Fix is in e24f63b.
| createsIssue := postStepIssueCreateRE.MatchString(script) || postStepOctokitRE.MatchString(script) | ||
| for _, command := range ghAPICmdRE.FindAllStringSubmatch(script, -1) { | ||
| for _, args := range command { | ||
| if postStepIssueAPIRE.MatchString(parseGHAPIEndpoint(args)) && |
There was a problem hiding this comment.
Handled gh api --input before the endpoint in post-step endpoint parsing and added a regression case for that argument order. Fix is in e24f63b.
|
@copilot run pr-finisher skill |
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Post-step validation now rejects both |
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Post-step validation now rejects GitHub secret references in step-level |
|
@copilot merge main, recompile , fix golden wasm |
…support-for-post-steps Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Merged |
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Fixed the failing workflow tests in |
|
@copilot resolve the merge conflicts on this branch. |
…support-for-post-steps # Conflicts: # pkg/workflow/action_pins_test.go # pkg/workflow/compiler_jobs_test.go Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Merged the latest |
|
🎉 This pull request is included in a new release. Release: |
…ts changes Document engine.dynamic-workflows (schema default false, added in #66195), correct model-routing allowed-models to reflect that declared sub-agent models are now admitted separately from routing candidates (#66234), and note the compile-time rejection of issue creation and safe-output storage access in user post-steps (#66064). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

User post-steps can attempt to publish agent-generated issues outside safe outputs or read the agent’s output file directly. The compiler now reports these patterns as errors and points authors to safe outputs.
gh, REST, curl, and GitHub Script patterns, and for access toagent_output.json. Read-only issue queries remain allowed.safe-outputs.create-issuefor issue publishing. Document the restriction in the post-steps reference.