Repository navigation
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 225a2a7d12
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| const git = parseGitCall(segment, segCwd); | ||
| if (!git?.write) continue; |
There was a problem hiding this comment.
Inspect shell payloads before allowing source writes
When a source-bound session wraps a mutation in a shell command such as bash -lc 'git commit -m x', sourceGuard only passes the outer bash invocation to parseGitCall; unlike substitution scanning, it never recurses into shellPayloads. The hook therefore allows the command and the commit runs in the native/main checkout, so recognized -c payloads must also be evaluated with the effective working directory.
Useful? React with 👍 / 👎.
| for (const segment of splitSegments(body)) { | ||
| const git = parseGitCall(segment, "/"); | ||
| if (git?.write) return `git ${git.verb}`; |
There was a problem hiding this comment.
Treat shell newlines as command separators
When a substitution contains commands separated by a newline, for example echo "$(printf ok\ngit push)", splitSegments returns one segment and tokenization sees only printf as the command, so riskyMutation returns null even though the shell subsequently executes git push. This bypasses SHELL-SUBST-01 without requiring a source binding; newline-separated commands need to be scanned individually.
Useful? React with 👍 / 👎.
| const tokens = tokenize(segment); | ||
| if (tokens[0] === "cd" && tokens[1]) { segCwd = resolve(segCwd, tokens[1]); continue; } |
There was a problem hiding this comment.
Preserve the prior cwd when cd may fail
In a source-bound session, cd /missing; git commit -m x is allowed: the guard unconditionally changes segCwd to the nonexistent path, the repository probe fails open, but the real shell keeps its original native-checkout cwd after the failed cd and then executes the commit there. The guard must account for cd failure when later commands are separated by ; rather than assuming every lexical cd succeeds.
Useful? React with 👍 / 👎.
Release codexclaw 0.2.41 from
devat225a2a7d.This release adds WORKTREE-GUARD-04 and SHELL-SUBST-01 (#284, #285). With a
cxc session sourcebinding, the PreToolUse guard denies git writes into another worktree of the same repository. It also denies command substitutions the shell would execute that run a git write or agh pr merge/close. Both checks run inside the existingworktree-guard-pretoolhook, so there are no new hooks and no new trust approvals (31 hooks). Versions, the manifest stamp0.2.41+codex.20261006130152, inventory, README badges (3745 tests) and the CHANGELOG are updated.Validation: #285 passed all 13 checks on
4a8c6f1a, including CI on ubuntu, macOS and Windows (both shards, both variants) and the packed-install lifecycle on all three platforms.