Skip to content

The Guard's Stdin Redirect Scan Ends Early at a Separator Inside a Target Expansion #2225

Description

@ptr727

_redirects_stdin in host-setup/agent-safety/claude/gh-write-guard.py ends its scan early when a redirect target is an expansion holding a separator or a parenthesis, so it credits an earlier binding and never reaches the later one bash applies.

Allowed on develop, and each loop reads /dev/zero forever:

while read l; do sleep 30; done < ${g:-;} < /dev/zero
while read l; do sleep 30; done < $( echo x ) < /dev/zero

The operator lex splits ${g:-;} at the ; and $( echo x ) at the (, so the scan meets a separator token inside the target, returns the bound the < before it set, and never sees < /dev/zero. Bash reads both expansions as one word, so the last binding is the stream.

The scan should not credit a binding whose target is an expansion it cannot read whole, since what follows that expansion is still the loop's own invocation.

Found by a local strict review pass on feature/auto-2152 (#2152), which made a trailing comment's stop refuse this same class for a #. The separator and parenthesis shapes predate that branch.

Activity

  1. added
    bugSomething isn't working
    agentsAgents instructions
    pre-existingReview finding classed pre-existing per local-strict-review Disposing of Findings
    on Oct 1, 2026
  2. ptr727 commented on Oct 8, 2026

    @ptr727
    OwnerAuthor

    Declined per #2517, approved by the maintainer, under GOVERNANCE.md "Trust Boundaries and Hardening Effort": The guard backstops an agent's own mistakes, and this is a command shape built to defeat it rather than one an agent session writes, so a miss does not realistically occur. See #2517 for the per-issue reason.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    agentsAgents instructionsbugSomething isn't workingpre-existingReview finding classed pre-existing per local-strict-review Disposing of Findings

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions