Repository navigation
Conversation
Validate local launch directories against the agent-home boundary before choosing a working-directory policy. Use the per-channel temporary root for protected launch paths so checkpoints and command diffs cannot capture runtime credentials or the conversation's own transcript. Add boundary and real-git regressions, portable test-home isolation, and document the fallback behavior. Co-authored-by: Codex <noreply@openai.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Starting a local surface from Raven's instance directory or Agent home previously made that directory the turn's working directory without validating it. Checkpoints could store provider credentials, OAuth tokens, memory, transcripts, and rendered agent configs; command diffs could also report the conversation's own transcript.
This covers local surfaces sharing build_local_sessions, including a WebUI process that falls back to standalone serve.
Type
Verification
uv run pytest tests/test_core_engine_stack.py tests/test_agent_workdir.py tests/test_runtime_checkpoint.py tests/test_cli_a2a_commands.py tests/test_rpc_bootstrap.py -q -n 4 --tb=short --cov=raven.core.engine_stack --cov-branch --cov-report=term-missing --cov-report=json: 123 passed, 2 POSIX-only tests skipped on Windows.uv run python scripts/coverage_gate.py diff --base-ref origin/main --threshold 90: 100% of 16 changed executable lines covered. Windows coverage path separators were normalized before the gate.uv run ruff check raven evolver agents plugins-dist tests scripts docs-site: passed.uv run ruff format --check raven evolver agents plugins-dist tests scripts docs-site: passed, 2162 files formatted.uv run ty check raven/core/engine_stack.py: passed.uv run lint-imports: all 10 contracts kept.uv run python scripts/check_large_files.py origin/main,uv run python scripts/check_source_language.py origin/main, andgit diff --cached --check: passed.uv run pre-commit run --files CONTEXT.md docs-site/docs/using-raven.md docs-site/docs/using-raven.zh.md raven/core/engine_stack.py tests/conftest.py tests/test_core_engine_stack.py tests/test_runtime_checkpoint.py: all applicable hooks passed.Ten new regression cases failed against the original implementation before the fix.
make ciis unavailable on this Windows host without make or WSL; the relevant Makefile checks were run directly as listed above.Relevant tests pass locally
Relevant lint / type checks pass locally
User-facing docs or screenshots are updated when needed
Risk
A local surface launched from a protected runtime directory now works in a per-channel temporary directory and emits a warning. Valid project launches and validated overrides keep their existing behavior.
Previously created shadow histories remain on disk and require separate cleanup; credentials exposed by an earlier snapshot require rotation. Reverting the squash commit restores the previous directory selection and reintroduces the unsafe launch behavior.
Related Issues
Fixes #850