Repository navigation
fix(capability): detect native and escaped Windows private paths in public-safe-outbound - #6223
Open
JasonBuildAI wants to merge 1 commit into
Conversation
JasonBuildAI
requested review from
huangruiteng and
loopx-agent
as code owners
October 11, 2026 10:02
JasonBuildAI
added a commit
to JasonBuildAI/loopx
that referenced
this pull request
Oct 11, 2026
… for agent-v5r2 claim Signed-off-by: JasonBuildAI <jasonbuildai@gmail.com>
JasonBuildAI
force-pushed
the
codex/public-safe-outbound-windows-path-v5r2
branch
from
October 11, 2026 10:04
1f8b351 to
a5de384
Compare
…ublic-safe-outbound The builtin fail-closed pre-submission scrub only recognized the POSIX spelling of a private absolute path. On a Windows host the same private path written as C:\Users\<name>\... or \\server\Users\<name>\..., and the escaped form a serialized string produces (C:\\Users\\<name>\\...), passed the scan with hit_count 0 while its POSIX spelling was blocked. loopx-project#6161 repaired the same spelling class in the public/private boundary scan and names this rule as its deliberately deferred successor owner. Match a separator run at every junction of private_abs_path, covering the POSIX, native Windows, mixed, rooted and escaped spellings of the same roots, and pin the native, escaped and mixed forms with tests. Closes loopx-project#6220 Follow-up to loopx-project#6161 Signed-off-by: JasonBuildAI <jasonbuildai@gmail.com>
JasonBuildAI
force-pushed
the
codex/public-safe-outbound-windows-path-v5r2
branch
from
October 11, 2026 10:27
a5de384 to
ce83ba9
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Goal And Delivered Outcome
Outcome basis / optional anchor: [Bug]: builtin public-safe-outbound scanner misses native Windows private paths (C:\Users\... and UNC) #6220
Goal/source and gap: The builtin
public-safe-outboundcapability is the fail-closed pre-submission scrub for content headed to an external repository. Itsprivate_abs_pathrule (loopx/capabilities/public_safe_outbound/scanner.py) recognized only one separator spelling of a private absolute path, so a Windows host's own spellings (C:\Users\<name>\...,\\server\Users\<name>\...) and the escaped form a serialized string produces (C:\\Users\\<name>\\...in JSON or a source literal) scanned clean while the POSIX spelling was blocked. fix(contract): block native, mixed and escaped Windows private paths in the boundary scan #6161 repaired the same spelling class in the repository's public/private boundary scan and names this rule as its deliberately deferred successor owner; this PR is that follow-up.Observable before → after, with the validation row that proves it: before, the native and escaped spellings returned
ok=Truewith no hits (CLI exit 0,hit_count 0), including a.jsonfile carrying the escaped path; after, every spelling reportsrule_id: "private_abs_path"and the CLI exits 1, while paths outside the private roots stay clean. See theregression_parityandreal_entrypointrows.Issue/task and intended base: Closes [Bug]: builtin public-safe-outbound scanner misses native Windows private paths (C:\Users\... and UNC) #6220. Base:
main.Author Declaration
Implemented against
loopx/capabilities/public_safe_outbound/scanner.py(private_abs_path)loopx/capabilities/public_safe_outbound/tests/test_scanner.py::test_detects_native_windows_private_pathC:\\Users\\<name>\\...) is a hit...::test_detects_escaped_and_mixed_windows_private_path...::test_native_windows_path_outside_the_private_roots_stay_cleanC:\users\...)/home/<non-ASCII-name>/)ruff checkon the capability, andexamples/capability-extension-registry-smoke.py, and compared the old and new rule on a 16-case matrix (POSIX hits and clean inputs unchanged). An independent review round reproduced one escaped-spelling miss in the first revision; this head fixes it and pins it with tests. Two environment-level issues are disclosed rather than hidden:tests/capabilities/test_capability_extension_registry.py::test_installed_runtime_is_catalog_truth_and_cli_defaultfails identically on the unmodified baseline (entrypoint_missing), and a host route conflict makesloopx checkunavailable in this checkout; neither is touched by this change.Scope And Continuation
private_abs_pathto one separator-run pattern that keeps the existing root keywords and covers the POSIX, native Windows, mixed, rooted and escaped spellings, plus tests; 60 lines added, 2 removed. Remaining: case-insensitive spellings and non-ASCII user names stay out of scope as disclosed above.Validation
ce83ba927ddc27954ba3ae444f0bc452d6d86d29regression_paritypassedok=False+private_abs_pathhit after beingok=True/0 hits on the old rule; all four POSIX spellings and the clean inputs unchanged (16-case matrix). Pre-fix test run: 1 failed / 5 passed (AssertionError: drive); after: 7 passed.real_entrypointpassedscan_cli(python -m loopx.capabilities.public_safe_outbound.scan_cli --scan-root ... --format json): a.jsonfile with the escaped path and a.mdwith the native path exit 0 /hit_count 0→ exit 1 /hit_count 3(escaped + native + POSIX control); a clean file is not hit.unitpassedloopx/capabilities/public_safe_outbound/tests/test_scanner.py: 7 passed.staticpassedruff check loopx/capabilities/public_safe_outbound: clean.integrationpassedexamples/capability-extension-registry-smoke.py: ok (capability registry unchanged).real_backendnot_applicableFrontend / Visual Evidence
Type of Change
LoopX Area
Technical Direction
Shared-authority RFC fixture impact
Boundary Checklist
.loopx/,.codex/goals/, and liveACTIVE_GOAL_STATE.md).none.Signed-off-bytrailer (git commit -s).