security

package
v0.2.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 6, 2026 License: MIT Imports: 19 Imported by: 0

Documentation

Index

Constants

View Source
const (
	DefaultCheckTimeout   = 5 * time.Minute
	DefaultMaxOutputBytes = 256 * 1024
)
View Source
const InjectionQuestionSetID = "security.tool-output-injection"
View Source
const QuestionSetID = "security.command-risk"

Variables

This section is empty.

Functions

func RequireCommandAuthorization

func RequireCommandAuthorization(checksDigest, authorizedDigest string) error

RequireCommandAuthorization refuses execution when the operator has not authorized this exact checks.json digest for the run.

Types

type ArgvRequest

type ArgvRequest struct {
	Argv           []string
	WorkingDir     string // relative to Workspace unless absolute and allowed
	Timeout        time.Duration
	Workspace      string
	AllowRead      []string
	MaxOutputBytes int
	// UseShell is an explicit opt-in for shell syntax. ExtraEnv and InheritEnv
	// are explicit opt-ins for additional environment privileges.
	UseShell   bool
	ExtraEnv   []string
	InheritEnv bool
	// AuthorizedDigest must equal ChecksDigest; --auto alone is not permission.
	ChecksDigest     string
	AuthorizedDigest string
	Security         *config.Config
}

ArgvRequest runs one planner-proposed check command. Argv is executed without a shell unless UseShell is explicitly set. Stdin is closed, the environment is limited, output is bounded, and the process group is cleaned up on exit or cancellation.

type ArgvResult

type ArgvResult struct {
	ExitCode    int
	TimedOut    bool
	Stdout      []byte
	Stderr      []byte
	Truncated   bool
	Duration    time.Duration
	CommandLine string
}

ArgvResult is the bounded outcome of a planner-proposed command.

func RunArgv

func RunArgv(ctx context.Context, req ArgvRequest) (ArgvResult, error)

RunArgv executes a planner-proposed command only after authorization and local security checks. It never invents a command or uses a shell by default.

type Decision

type Decision struct {
	Deny   bool
	Reason string
	Score  *registry.Decision
	Shadow bool
}

func CheckLocal

func CheckLocal(cfg *config.Config, req Request) Decision

CheckLocal is used at execution points where a second Jev request would duplicate a verdict already made by the pre-tool hook.

func Evaluate

func Evaluate(ctx context.Context, cfg *config.Config, req Request, decider *registry.Decider) (Decision, error)

Evaluate checks deterministic rules before making an optional bounded Jev request. Jev errors have no effect on the deterministic decision.

type InjectionRequest

type InjectionRequest struct{ Body, Runtime, Tool, Workspace, SessionKey, ToolInput, RawPointer, SDLCRunID string }

type InjectionVerdict

type InjectionVerdict struct {
	Halt, Shadow          bool
	Score, Confidence     float64
	Reason, Excerpt, Hash string
	Hits                  []string
}

func CheckInjection

func CheckInjection(ctx context.Context, cfg *config.Config, req InjectionRequest, decider *registry.Decider) InjectionVerdict

CheckInjection fails open on Jev and redaction errors. The caller stores a review before replacing output; a failed review write must not hide content.

type Request

type Request struct {
	Command, Cwd, Workspace, Runtime string
}

Directories

Path Synopsis
Package config loads layered security policies.
Package config loads layered security policies.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL