Skip to content

fix(capability): detect native and escaped Windows private paths in public-safe-outbound - #6223

Open
JasonBuildAI wants to merge 1 commit into
loopx-project:mainfrom
JasonBuildAI:codex/public-safe-outbound-windows-path-v5r2
Open

JasonBuildAI wants to merge 1 commit into
loopx-project:mainfrom
JasonBuildAI:codex/public-safe-outbound-windows-path-v5r2

Conversation

@JasonBuildAI

@JasonBuildAI JasonBuildAI commented Oct 11, 2026 •

Copy link
Copy Markdown
Contributor

Goal And Delivered Outcome

Author Declaration

Implemented against

Criterion (spec clause) Disposition Symbol / path Test or command
Native drive-letter spelling is a hit and fails the scan implemented loopx/capabilities/public_safe_outbound/scanner.py (private_abs_path) loopx/capabilities/public_safe_outbound/tests/test_scanner.py::test_detects_native_windows_private_path
UNC spelling is a hit and fails the scan implemented same same
Escaped serialized spelling (C:\\Users\\<name>\\...) is a hit implemented same ...::test_detects_escaped_and_mixed_windows_private_path
Mixed and drive-rooted separator spellings are hits implemented same same
A drive path outside the private roots stays clean implemented same ...::test_native_windows_path_outside_the_private_roots_stay_clean
Case-insensitive Windows spellings (C:\users\...) deferred — Unchanged; disclosed in #6220
Non-ASCII user names (/home/<non-ASCII-name>/) out_of_scope — Pre-existing name class shared by every spelling; separate decision
  • Self-check before submission: ran the module tests, ruff check on the capability, and examples/capability-extension-registry-smoke.py, and compared the old and new rule on a 16-case matrix (POSIX hits and clean inputs unchanged). An independent review round reproduced one escaped-spelling miss in the first revision; this head fixes it and pins it with tests. Two environment-level issues are disclosed rather than hidden: tests/capabilities/test_capability_extension_registry.py::test_installed_runtime_is_catalog_truth_and_cli_default fails identically on the unmodified baseline (entrypoint_missing), and a host route conflict makes loopx check unavailable in this checkout; neither is touched by this change.

Scope And Continuation

  • Completed scope and remaining work: reduce private_abs_path to one separator-run pattern that keeps the existing root keywords and covers the POSIX, native Windows, mixed, rooted and escaped spellings, plus tests; 60 lines added, 2 removed. Remaining: case-insensitive spellings and non-ASCII user names stay out of scope as disclosed above.
  • Slice boundary / successor: complete within this scope; no successor task needed. Those two gaps change every spelling class and should be decided together with the sibling boundary scan.

Validation

  • Tested revision: ce83ba927ddc27954ba3ae444f0bc452d6d86d29
  • Run state: finished
  • Input classes: synthetic
Check kind Result Public-safe evidence / limitation
regression_parity passed Old vs new rule on the same inputs: native, escaped (JSON), mixed and rooted spellings ok=False + private_abs_path hit after being ok=True/0 hits on the old rule; all four POSIX spellings and the clean inputs unchanged (16-case matrix). Pre-fix test run: 1 failed / 5 passed (AssertionError: drive); after: 7 passed.
real_entrypoint passed Shipped scan_cli (python -m loopx.capabilities.public_safe_outbound.scan_cli --scan-root ... --format json): a .json file with the escaped path and a .md with the native path exit 0 / hit_count 0 → exit 1 / hit_count 3 (escaped + native + POSIX control); a clean file is not hit.
unit passed loopx/capabilities/public_safe_outbound/tests/test_scanner.py: 7 passed.
static passed ruff check loopx/capabilities/public_safe_outbound: clean.
integration passed examples/capability-extension-registry-smoke.py: ok (capability registry unchanged).
real_backend not_applicable Pure text rule table; no backend or persisted state involved.
  • Coverage and gaps: The tests cover every new spelling class plus the negative drive-path case; the POSIX arm and clean input keep their existing tests. Not run: full CI here (first-time workflow approval may hold checks), plus the two pre-existing environment issues above. Case-insensitive spellings, non-ASCII user names and the trailing-separator requirement remain outside the rule as before (disclosed above; the trailing separator matches the POSIX spelling). The separator-run class widens the conservative surface exactly as the sibling fix(contract): block native, mixed and escaped Windows private paths in the boundary scan #6161 rule does: a separator run plus a private root segment is a hit, consistent with the capability's documented preference for false positives over misses; an ordinary drive path still stays clean.

Frontend / Visual Evidence

  • UI impact: none

Type of Change

  • Bug fix

LoopX Area

  • Capability or extension (providers, adapters, skills)

Technical Direction

  • Direction / acceptance reference, when applicable: N/A — ordinary capability bug fix; no roadmap/RFC claim.

Shared-authority RFC fixture impact

  • Production-scale fixture schema: N/A
  • Semantic dimensions changed, or reviewed no-impact rationale: N/A — no RFC claim
  • Provider conformance arms run: N/A
  • Read-only legacy/file/PostgreSQL three-arm rehearsal: N/A

Boundary Checklist

  • Neither the diff nor this PR body/comments/attachments disclose private state, credentials, raw traces or verifier output, internal links, or local machine paths (including .loopx/, .codex/goals/, and live ACTIVE_GOAL_STATE.md).
  • I did not duplicate maintainer-owned benchmark work unless a maintainer split out a public issue for it.
  • I kept the change scoped to the linked issue/task.
  • I completed the visual evidence section for UI changes, or marked UI impact none.
  • Every commit includes a DCO Signed-off-by trailer (git commit -s).

JasonBuildAI added a commit to JasonBuildAI/loopx that referenced this pull request Oct 11, 2026
… for agent-v5r2 claim

Signed-off-by: JasonBuildAI <jasonbuildai@gmail.com>
@JasonBuildAI
JasonBuildAI force-pushed the codex/public-safe-outbound-windows-path-v5r2 branch from 1f8b351 to a5de384 Compare October 11, 2026 10:04
…ublic-safe-outbound

The builtin fail-closed pre-submission scrub only recognized the POSIX spelling
of a private absolute path. On a Windows host the same private path written as
C:\Users\<name>\... or \\server\Users\<name>\..., and the escaped form a
serialized string produces (C:\\Users\\<name>\\...), passed the scan with
hit_count 0 while its POSIX spelling was blocked. loopx-project#6161 repaired the same
spelling class in the public/private boundary scan and names this rule as its
deliberately deferred successor owner.

Match a separator run at every junction of private_abs_path, covering the POSIX,
native Windows, mixed, rooted and escaped spellings of the same roots, and pin
the native, escaped and mixed forms with tests.

Closes loopx-project#6220
Follow-up to loopx-project#6161

Signed-off-by: JasonBuildAI <jasonbuildai@gmail.com>
@JasonBuildAI
JasonBuildAI force-pushed the codex/public-safe-outbound-windows-path-v5r2 branch from a5de384 to ce83ba9 Compare October 11, 2026 10:27
@JasonBuildAI JasonBuildAI changed the title fix(capability): detect native Windows private paths in public-safe-outbound fix(capability): detect native and escaped Windows private paths in public-safe-outbound Oct 11, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug]: builtin public-safe-outbound scanner misses native Windows private paths (C:\Users\... and UNC)

1 participant