Skip to content

Release codexclaw 0.2.41 - #286

Merged
lidge-jun merged 8 commits into
mainfrom
dev
Oct 6, 2026
Merged

lidge-jun merged 8 commits into
mainfrom
dev

Conversation

@lidge-jun

Copy link
Copy Markdown
Owner

Release codexclaw 0.2.41 from dev at 225a2a7d.

This release adds WORKTREE-GUARD-04 and SHELL-SUBST-01 (#284, #285). With a cxc session source binding, the PreToolUse guard denies git writes into another worktree of the same repository. It also denies command substitutions the shell would execute that run a git write or a gh pr merge/close. Both checks run inside the existing worktree-guard-pretool hook, so there are no new hooks and no new trust approvals (31 hooks). Versions, the manifest stamp 0.2.41+codex.20261006130152, inventory, README badges (3745 tests) and the CHANGELOG are updated.

Validation: #285 passed all 13 checks on 4a8c6f1a, including CI on ubuntu, macOS and Windows (both shards, both variants) and the packed-install lifecycle on all three platforms.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-06T13:47:36.164494Z 225a2a7 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 225a2a7d12

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +291 to +292
const git = parseGitCall(segment, segCwd);
if (!git?.write) continue;

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Inspect shell payloads before allowing source writes

When a source-bound session wraps a mutation in a shell command such as bash -lc 'git commit -m x', sourceGuard only passes the outer bash invocation to parseGitCall; unlike substitution scanning, it never recurses into shellPayloads. The hook therefore allows the command and the commit runs in the native/main checkout, so recognized -c payloads must also be evaluated with the effective working directory.

Useful? React with 👍 / 👎.

Comment on lines +113 to +115
for (const segment of splitSegments(body)) {
const git = parseGitCall(segment, "/");
if (git?.write) return `git ${git.verb}`;

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Treat shell newlines as command separators

When a substitution contains commands separated by a newline, for example echo "$(printf ok\ngit push)", splitSegments returns one segment and tokenization sees only printf as the command, so riskyMutation returns null even though the shell subsequently executes git push. This bypasses SHELL-SUBST-01 without requiring a source binding; newline-separated commands need to be scanned individually.

Useful? React with 👍 / 👎.

Comment on lines +289 to +290
const tokens = tokenize(segment);
if (tokens[0] === "cd" && tokens[1]) { segCwd = resolve(segCwd, tokens[1]); continue; }

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Preserve the prior cwd when cd may fail

In a source-bound session, cd /missing; git commit -m x is allowed: the guard unconditionally changes segCwd to the nonexistent path, the repository probe fails open, but the real shell keeps its original native-checkout cwd after the failed cd and then executes the commit there. The guard must account for cd failure when later commands are separated by ; rather than assuming every lexical cd succeeds.

Useful? React with 👍 / 👎.

@github-actions github-actions Bot added the documentation Improvements or additions to documentation label Oct 6, 2026
@lidge-jun
lidge-jun merged commit 96e8d5c into main Oct 6, 2026
28 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant