Skip to content

The Guard's Unknown-Quoting eval Payload Takes In Later Commands' Quoted Words #2365

Description

@ptr727

Problem

Where the guard cannot tell which words were quoted, the #2080 branch reads an eval's payload to the end of its line, as decision #2139 chose, since any separator on that line may be a quoted one. That joined payload also takes in the later commands on the line with their quoting gone, so a quoted sleep or loop in a later command's argument reads as one the eval runs.

Reproduce (constructed)

Each is followed by a line echo "$(echo "it's")", which leaves the quoting unknown. Both are denied by the branch and allowed by develop, which reads no eval, and neither runs a loop that sleeps:

eval "$x"; logger "a; until false; do sleep 1; done"
while [ -f x ]; do eval "$s"; logger "sleep 1"; done

With the quoting known, both are allowed.

Done looks like

Where the quoting is unknown, a later command's quoted argument on the eval's line is not read as part of the eval's payload, while a quoted separator inside the eval's own arguments still is, the case the #2139 design exists for. Both commands above are allowed, and self-test rows pin them alongside the existing unknown-quoting rows.

Found by the local strict review of the #2080 branch.

Activity

  1. added
    bugSomething isn't working
    agentsAgents instructions
    on Oct 4, 2026
  2. ptr727 commented on Oct 8, 2026

    @ptr727
    OwnerAuthor

    Declined per #2517, approved by the maintainer, under GOVERNANCE.md "Trust Boundaries and Hardening Effort": The guard backstops an agent's own mistakes, and this is a command shape built to defeat it rather than one an agent session writes, so a miss does not realistically occur. See #2517 for the per-issue reason.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    agentsAgents instructionsbugSomething isn't working

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions