Documentation
¶
Index ¶
Constants ¶
const ( DefaultCheckTimeout = 5 * time.Minute DefaultMaxOutputBytes = 256 * 1024 )
const InjectionQuestionSetID = "security.tool-output-injection"
const QuestionSetID = "security.command-risk"
Variables ¶
This section is empty.
Functions ¶
func RequireCommandAuthorization ¶
RequireCommandAuthorization refuses execution when the operator has not authorized this exact checks.json digest for the run.
Types ¶
type ArgvRequest ¶
type ArgvRequest struct {
Argv []string
WorkingDir string // relative to Workspace unless absolute and allowed
Timeout time.Duration
Workspace string
AllowRead []string
MaxOutputBytes int
// UseShell is an explicit opt-in for shell syntax. ExtraEnv and InheritEnv
// are explicit opt-ins for additional environment privileges.
UseShell bool
ExtraEnv []string
InheritEnv bool
// AuthorizedDigest must equal ChecksDigest; --auto alone is not permission.
ChecksDigest string
AuthorizedDigest string
Security *config.Config
}
ArgvRequest runs one planner-proposed check command. Argv is executed without a shell unless UseShell is explicitly set. Stdin is closed, the environment is limited, output is bounded, and the process group is cleaned up on exit or cancellation.
type ArgvResult ¶
type ArgvResult struct {
ExitCode int
TimedOut bool
Stdout []byte
Stderr []byte
Truncated bool
Duration time.Duration
CommandLine string
}
ArgvResult is the bounded outcome of a planner-proposed command.
func RunArgv ¶
func RunArgv(ctx context.Context, req ArgvRequest) (ArgvResult, error)
RunArgv executes a planner-proposed command only after authorization and local security checks. It never invents a command or uses a shell by default.
type Decision ¶
func CheckLocal ¶
CheckLocal is used at execution points where a second Jev request would duplicate a verdict already made by the pre-tool hook.
type InjectionRequest ¶
type InjectionRequest struct{ Body, Runtime, Tool, Workspace, SessionKey, ToolInput, RawPointer, SDLCRunID string }
type InjectionVerdict ¶
type InjectionVerdict struct {
Halt, Shadow bool
Score, Confidence float64
Reason, Excerpt, Hash string
Hits []string
}
func CheckInjection ¶
func CheckInjection(ctx context.Context, cfg *config.Config, req InjectionRequest, decider *registry.Decider) InjectionVerdict
CheckInjection fails open on Jev and redaction errors. The caller stores a review before replacing output; a failed review write must not hide content.