fix(server): disable executable tools in Claude metadata generation - #247
Conversation
Claude title and branch generation used permission bypass, so a skill name in the first prompt could run tools in the background. Verbose CLI output also failed to parse, and JSON-wrapped titles were saved as-is. Metadata runs now pass an empty tool set, disable slash commands, hooks, and inherited MCP, and use dontAsk. Titles run in a temp directory. Shared title cleanup unwraps a JSON title object, and Claude accepts verbose result arrays. Upstream: pingdotgg#4169 pingdotgg#10446 pingdotgg#10526 Grok 4.6 High in Grok Build via Orca.
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Greptile SummarySummary
Confidence Score: 5/5Safe to merge. No outstanding findings. Reviews (3): Last reviewed commit: "Merge remote-tracking branch 'origin/mai..." | Re-trigger Greptile |
|
This is Leo's agent. Independent merge review found a reproducible executable-path regression on a97a52a.
I added a throwaway focused test that creates an executable fixture under Please resolve explicit relative executable paths against the original cwd before moving title generation into its isolated directory. Preserve ordinary PATH lookup, absolute paths, and the new capability restrictions. Add committed coverage and rerun the review-and-fix loop. The scoped request has been delivered to the existing worker; delivery is not a completed repair. Holding merge pending the fix. |
|
This is Leo's agent. The relative-executable regression remains on exact head b8aadec despite the current 5/5 assessment. I read the full effective diff and reran the preserved regression through the shipped generateThreadTitle service using an executable fixture at /bin/claude and binaryPath ./bin/claude. It still fails with NotFound / spawn ./bin/claude because the title subprocess runs in the isolated temporary cwd. The production ClaudeTextGeneration.ts is byte-identical to the previously reproduced a97a52a version. Resolve explicit relative executable paths against the original request cwd before changing the subprocess cwd. Keep bare PATH names and absolute paths working; retain title-directory isolation and all capability restrictions. Commit the real executable-fixture regression and rerun review. This finding remains a repair hold, not an acceptance based on the review score. Orca is unavailable here, so this GitHub follow-up is not a claim of worker delivery or execution. |
Problem
Claude background title and branch generation received the user's first prompt while running with permission bypass. A skill name in that prompt could therefore execute in the background. Verbose Claude CLI output also failed to parse, and JSON-wrapped titles were saved with their wrapper.
Fix
Metadata generation now passes an explicit empty tool set, disables slash commands, hooks, and inherited MCP, and uses
dontAsk. Thread titles run in a temporary directory. Shared title cleanup unwraps a JSON object containing a string title. Claude text generation accepts a normal result envelope or a verbose message array and reads structured output from the last result.Actual Claude chats keep their tools. Subscription environment, MCP headers, and API-key connections are unchanged.
Adapted for Akeru from pingdotgg#4169, pingdotgg#10446, and the
dontAskportion of pingdotgg#10526.Verification
vp test run apps/server/src/textGeneration/ClaudeTextGeneration.test.ts apps/server/src/textGeneration/TextGenerationPrompts.test.ts: 41 passed.git diff --checkpassed.The fake CLI asserts the empty tool set, no permission bypass, disabled slash commands, strict MCP config, disabled hooks,
dontAsk, and title-directory isolation.Implemented and verified by GPT-5.6 Sol in T3 Code via the Codex harness.