Skip to content
Open
Show file tree
Hide file tree
Changes from 11 commits
Commits
Show all changes
26 commits
Select commit Hold shift + click to select a range
2e592c5
fix(utils): never take NODE_TLS_REJECT_UNAUTHORIZED from the project …
10kH Oct 10, 2026
8d28032
fix(tmux-self-injection-guard): handle wrapper options and bundled sh…
Oct 10, 2026
2e9a7ce
fix(tmux-self-injection-guard, utils): Address 6 blocking review find…
Oct 10, 2026
3aebf1c
chore: remove TLS environment work that belongs to PR #6552
Oct 10, 2026
773cea9
restore: unrelated TUI drag-copy changes from origin/dev
Oct 10, 2026
a8f1341
merge: pull origin/dev for CI base
Oct 10, 2026
498eae8
fix(tmux-self-injection-guard): address all 5 blocking review findings
Oct 10, 2026
556fde0
fix(tmux-self-injection-guard): correct command boundary check in isC…
Oct 10, 2026
831a37a
fix(tmux-self-injection-guard): fix all blocking findings from probep…
Oct 10, 2026
8e62abd
test: mark socket override regression tests as TODO (issue #6564-6)
Oct 10, 2026
96b3528
fix(tmux-self-injection-guard): preserve command boundaries in lookup…
Oct 10, 2026
346b905
fix(tmux-self-injection-guard): handle bash long options in payload d…
Oct 10, 2026
6688fdc
chore: add changelog entry for tmux shell payload selection fix (issu…
Oct 10, 2026
8d536c8
fix(tmux-guard): resolve 4 critical blocking findings from PR #6564 r…
Oct 10, 2026
7f165fe
fix: address 6 blocking findings from probepark review on PR #6564
Oct 10, 2026
8d159fb
fix(tmux-self-injection-guard): handle quoted payloads and env --spli…
Oct 10, 2026
2f91383
fix(tmux-self-injection-guard): add long-option arity specs for timeo…
Oct 10, 2026
d29460e
fix(tmux-self-injection-guard): handle bundled -Oc option in bash
Oct 10, 2026
fdf4b37
fix(tmux-self-injection-guard): properly parse env option operands an…
Oct 10, 2026
ac13a8a
fix(tmux-self-injection-guard): normalize path-qualified wrapper comm…
Oct 10, 2026
dcf0c87
fix(tmux-self-injection-guard): improve socket assignment backtrackin…
Oct 10, 2026
72e8064
fix(tmux-self-injection-guard): fix env-S context, socket operands, a…
Oct 10, 2026
18828ff
fix(tmux-self-injection-guard): apply biome formatting
Oct 10, 2026
ea47dc7
Merge remote-tracking branch 'origin/dev' into wt-fix-6564-clean
gaebal-gajae Oct 11, 2026
3d41670
fix(tmux-self-injection-guard): address P1 blocking findings from sno…
gaebal-gajae Oct 11, 2026
8f68cee
fix: remove duplicate xargs --replace entry in long-option table
gaebal-gajae Oct 11, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 8 additions & 0 deletions packages/coding-agent/changelog.d/6564-tmux-guard-fixes.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
### Security

- fix(tmux-self-injection-guard): Fix multiple command-parsing vulnerabilities in the tmux injection guard
- Restrict `command -v`/`-V` lookup suppression to the same command invocation; previously suppressed across command boundaries (`;`, `|`)
- Preserve environment variable assignments like `env FOO=bar` in wrapper context; previously treated them as wrapped commands
- Separate flag-only options (`setsid -c/-w`, `sudo -s/-i`, `xargs -0/-t/-x`) from argument-taking options to prevent adjacent words from being consumed as option arguments
- Recognize shell option operands (`bash -O extglob`, `bash -o pipefail`) and skip over them when scanning for script payloads; previously halted at option operands
- Removed unreachable dead code in wrapper mode state machine
2 changes: 1 addition & 1 deletion packages/coding-agent/src/prompts/tools/read.md
Original file line number Diff line number Diff line change
Expand Up @@ -73,7 +73,7 @@ For `.sqlite`, `.sqlite3`, `.db`, `.db3`:

`agent://<id>`, `artifact://<id>`, `rule://<name>`, and `local://<name>.md` resolve transparently and accept the same line selectors as filesystem paths. Use `artifact://<id>` to recover full output that a previous bash/eval/tool result spilled or truncated.

Bundled skills have no filesystem home, so the skill tool and skill discovery report them as `embedded:gjc/skills/<name>/SKILL.md`; read that identifier verbatim. Bundled skill fragments, when surfaced, likewise use `embedded:gjc/skill-fragments/...` identifiers.
Bundled skills have no filesystem home, so the skill tool and skill discovery report them as `embedded:gjc/skills/<name>/SKILL.md`; read that identifier verbatim. Bundled skill fragments, when surfaced, likewise use `embedded:gjc/skill-fragments/…` identifiers.

<critical>
- Always include `path`; never call `read` with `{}`.
Expand Down
Loading
Loading