Repository navigation
Re-Triage the Open Hardening Backlog Against the Trust-Boundary and Design Rules #2517
Description
Activity
- addeddecisionA question waiting on the maintainer, alone or beside whatever else the issue carriesA question waiting on the maintainer, alone or beside whatever else the issue carries
on Oct 8, 2026 Maintainer's answer, given in the
windowslane's closing session: run this triage in an attended session of its own. That session writes a disposition comment on each issue named here, then brings the whole list back for one approval. #2495 stays parked until then. Thedecisionlabel stays on until that approval is given.Drafted dispositions, awaiting the maintainer's approval
Drafted by a read-only pass against "Trust Boundaries and Hardening Effort" and #2516's reuse rule. Nothing has been closed. The maintainer approves the closes as one decision.
Close, declined with the reason given (25):
Issue Reason #2399 A reviewer bot does not post thousands of unclosed <summaryopeners, and GitHub's 65536-character cap holds the measured worst case to about 2s of slowness, not a silent failure.#2414 A bot overview does not hide a </details>in an HTML comment, and the issue says it fails loudly.#2416 No measured reviewer posts an unclosed blockquoted <detailsopener, and the issue says it blocks nothing.#2438 - #2440, #2442 - #2451 The guard is a backstop against an agent's own mistakes, and each shape (an empty evalprefix, a trailing backslash beside a loop,time -p -p eval, a command of 109 KB to 330 KB, and the rest) is not one an agent session writes. Where the guard misses one, the result is a loud hang or a false deny.#2495 -Diris typed by the maintainer,C:\x\..is not a realistic typo, and the ownership marker bounds the damage.#1044 The maintainer's own .agents/skillstree, where an unreadable nested directory does not realistically occur.#1130 GH_WRITE_GUARD_ALLOW_PRIMARY_CHECKOUTis set by the maintainer, so being session-wide is a documented property.#1420 --excludeis typed by the maintainer, and the scope line prints the file counts, so an empty scan is visible.#1618 Hardens a test that guards a scanner against an input nothing produces. #1764 Already landed: host-setup/bootstrap.ps1on develop takes a lock (Get-LockPath), from e853b3a.#1765 A bracketed -Diris typed by the maintainer and fails loudly.#1869 Needs a corrupt git index, and the cost is a wrong dirty flag in that corner case. #2013 The issue says no fleet caller writes either shape. Consolidate: #2479 into #2480, one recognizer for Copilot's collapsible overview blocks.
Keep: #1404, #1628, #1637, #1657, #2163, #1071, #1425, #2282, and #2480 are bugs on the ordinary path or silent failures in the real deployment. #1127 needs the maintainer's judgment on whether a deliberate
-c core.hooksPathbypass is a mistake the guard must stop.Not yet read: about 45 more guard issues in the same family as #2438 - #2451, and #2441 itself, were judged from their titles only, so they get a read of their own before any disposition.
First batch applied, second batch drafted
Applied, approved by the maintainer. The 25 closes above are closed, each with its reason. #2479 is folded into #2480. #1127 is kept: the guard should stop a deliberate hook bypass.
Second batch, drafted from a full read of the 42 guard-family issues. Nothing here is applied yet.
- Close (26): gh-write-guard installer: four small pre-existing correctness gaps found via PR #1086's review #1087 (its matcher item is already fixed on develop, and the rest is installer cosmetics), Stop an Inherited timeout Bound From Reaching a Loop Under a Nested timeout #2055, The Wait-Loop Bound Check Counts a Comparison Bash Never Evaluates #2058, A Heredoc Body Kept as the Safe Direction Vouches for a Wait-Loop Bound #2063, A Heredoc Closed by the End of a Substitution Stays Open to the Guard #2065, Quoted Operator as a Redirect Target Draws a False Deny From the Guard's Wait Rule #2075, Read a --foreground timeout as Signalling Only Its Direct Child #2078, The Guard's while read Bound Credits a Condition That Never Exhausts Its Input #2160, Read a Launcher That Builds an Inner timeout as Nesting #2195, Stop Two-Heredoc Lines Doubling the Guard's Readings per Line #2199, Count Only Real Heredoc Openers in the Guard's In-Order Reading #2201, Read Both Heredocs Around a Matching Arithmetic Shift in the Guard #2202, The Guard's Wait-Loop Depth Cap Allows a Loop Nested Past It #2205, The Guard's Stdin Redirect Scan Ends Early at a Separator Inside a Target Expansion #2225, Read a Run as No Bound Where the Quote Mask Is Unknown in the Wait-Loop Check #2307, Read a Function or Alias Shadowing timeout as No Bound in the Wait-Loop Check #2309, Honor the Quote Mask in the _runs_as_command Short-Circuit #2310, Allow a Bounded Wrapper Inside a function-Keyword Definition #2314, Read a timeout Sending an Ignored or Stopping Signal as No Bound #2316, Probe Which Signal Spellings uutils timeout Reads as Signal 0 #2317, The Guard's eval Reading Ends Its Arguments at a Parenthesis #2362, The Guard's eval Reading Ends Its Payload at a Quoted Newline #2363, The Guard's read Bound Ignores a Group's Input Redirection #2364, The Guard's Unknown-Quoting eval Payload Takes In Later Commands' Quoted Words #2365, A Launcher May Run eval Through /usr/bin/command on Some Hosts #2441, each a command shape built to defeat the guard rather than one an agent session writes, and State the Guard's In-Order Heredoc Reading Condition as the Code Applies It #2200, whose docstrings state a stricter condition than the code applies, which errs in the safe direction.
- Consolidate into Shlex Parsing Successfully but Wrongly Hides a Command From the Guard's Context Scan #1959 (12): A Command Substitution Inside Double Quotes Hides a Loop When a Line's Quoting Does Not Parse #1843, Read a Multi-Line Quote Whole in the Guard's Token Fallback #1910, A Substitution Nested in an Opaque Word Hides a Command From the Guard's Token Fallback #1958, The Guard Folds a Backslash-Newline to a Space Where Bash Deletes It #2064, A Heredoc Opener Inside a Multi-Line Quote Strips the Commands After It #2111, Fold a Line Continuation the Way Bash Does Before the Guard Reads a Command #2113, The Guard's Wait-Loop Rule Misses a Loop Keyword Glued to $' or a Backtick #2138, The Guard's Wait-Loop Rule Misses a Loop Inside a Process Substitution #2204, The Guard's Wait-Loop Rule Misses a Loop Inside a Double-Quoted Command Substitution #2206, The Guard's Wait-Loop Rule Reads an ANSI-C Quoted bash -c Payload Undecoded #2226, Split an Operator After an Escaped Backslash the Way Bash Does #2313, The Guard Reads No ANSI-C Quoted Payload #2366. Each is a case of the guard's lexer splitting a command differently from bash. Shlex Parsing Successfully but Wrongly Hides a Command From the Guard's Context Scan #1959's single bash-aware scanner removes the class, and each shape becomes a self-test row there.
- Keep: Shlex Parsing Successfully but Wrongly Hides a Command From the Guard's Context Scan #1959, since a multi-line script with an apostrophe in a comment is an ordinary agent shape that silently skips the wait-loop check. Deny the Remaining core.hooksPath and no-verify Bypass Routes in the Guard #2177, since the maintainer decided the guard stops hook bypass. docker_lint.py --root mounts the live checkout, bypassing a repo's secrets-on-disk exclusion #1090, which is
docker_lint.pyrather than the guard and can mount a git-ignored secrets file into a third-party container, so it needs the maintainer's judgment. - Skipped: Strip Every Heredoc Body a Line Opens in the Wait-Loop Rule #2203 is a merged pull request, not an issue.
- removeddecisionA question waiting on the maintainer, alone or beside whatever else the issue carriesA question waiting on the maintainer, alone or beside whatever else the issue carries
on Oct 8, 2026
Problem
#2507 landed "Trust Boundaries and Hardening Effort", and #2516 adds "Design Before Code". Open issues filed before either rule existed still ask for work the rules now decline, and every unattended run that ranks the backlog can pick one up. Carved out of #2516, since closing an issue on judgment is the maintainer's call and the guard's issues are attended-only work.
Clusters to re-triage
gh-write-guardagainst a command shape built to defeat it, such as a trailing backslash, a loop reached through brace expansion, or a payload of hundreds of kilobytes. The guard is a backstop against an agent's mistakes, not a boundary against an attacker, so the question for each is whether a real session produces that shape.pr_review.pymarkup-reader issues, such as Bound SUMMARY's Scan So an Unclosed summary Tag Costs Linear Time #2399, Mask HTML Comments Before pr_review.py Reads details Tags #2414, and Stop a Blockquoted details Opener's Scan at Its Own Line's End #2416. Each hardens a reader against a constructed review body. The question for each is whether a real reviewer posts that shape.host-setup/menu.ps1already canonicalizes the same way, so if anything is kept, it is reuse of that check rather than a second one.Done when
Each issue above has a comment stating its disposition against the two rules, with the reason: close as declined, keep, or fold into a consolidation issue naming every site. The maintainer approves the closes, as one decision over the whole list rather than one per issue.
Related: #2516, #2507, #2431.
🤖 Generated with Claude Code