Commit eac8a8a
Deimos Agent
fix: safe-env whitelist in LocalInteractiveSession; extra_env parity in SSHInteractiveSession
Addresses two concerns raised by @frdel in PR review:
1. shell_local.py — replace os.environ merge with _SAFE_ENV_KEYS whitelist
Previously: env = {**os.environ, **self.extra_env} if self.extra_env else None
This leaked all framework env vars (API keys, tokens) into the subprocess.
Now: only PATH, HOME, USER, SHELL, TERM, LANG, LC_ALL, TMPDIR, PWD are
forwarded from the host environment; extra_env values are merged on top.
2. shell_ssh.py — add extra_env: dict | None = None parameter to
SSHInteractiveSession.__init__ matching shell_local.py signature.
Extra vars are injected via 'export KEY=VALUE' in the initial_command
block (shlex.quote-escaped) so they are available session-wide.
Paramiko invoke_shell() does not pass env to the server reliably
(AcceptEnv restrictions), so the export-prefix approach is used.
Both classes now have identical extra_env: dict | None = None signatures.
No call-site changes required — extra_env defaults to None (no behaviour
change for existing users).1 parent d357c24 commit eac8a8a
2 files changed
Lines changed: 40 additions & 11 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
1 | 2 | | |
2 | 3 | | |
3 | 4 | | |
| |||
8 | 9 | | |
9 | 10 | | |
10 | 11 | | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
11 | 18 | | |
12 | | - | |
13 | | - | |
| 19 | + | |
| 20 | + | |
14 | 21 | | |
15 | 22 | | |
| 23 | + | |
16 | 24 | | |
17 | 25 | | |
18 | | - | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
19 | 33 | | |
20 | 34 | | |
21 | 35 | | |
| |||
29 | 43 | | |
30 | 44 | | |
31 | 45 | | |
32 | | - | |
| 46 | + | |
33 | 47 | | |
34 | 48 | | |
35 | 49 | | |
| |||
47 | 61 | | |
48 | 62 | | |
49 | 63 | | |
50 | | - | |
| 64 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
| 3 | + | |
3 | 4 | | |
4 | 5 | | |
5 | 6 | | |
| |||
14 | 15 | | |
15 | 16 | | |
16 | 17 | | |
17 | | - | |
| 18 | + | |
| 19 | + | |
18 | 20 | | |
19 | 21 | | |
20 | 22 | | |
| |||
28 | 30 | | |
29 | 31 | | |
30 | 32 | | |
| 33 | + | |
31 | 34 | | |
32 | 35 | | |
33 | 36 | | |
| |||
37 | 40 | | |
38 | 41 | | |
39 | 42 | | |
40 | | - | |
| 43 | + | |
41 | 44 | | |
42 | 45 | | |
43 | 46 | | |
| |||
66 | 69 | | |
67 | 70 | | |
68 | 71 | | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
69 | 83 | | |
70 | 84 | | |
71 | 85 | | |
| |||
104 | 118 | | |
105 | 119 | | |
106 | 120 | | |
107 | | - | |
| 121 | + | |
108 | 122 | | |
109 | 123 | | |
110 | 124 | | |
| |||
138 | 152 | | |
139 | 153 | | |
140 | 154 | | |
141 | | - | |
| 155 | + | |
142 | 156 | | |
143 | 157 | | |
144 | 158 | | |
| |||
212 | 226 | | |
213 | 227 | | |
214 | 228 | | |
| 229 | + | |
215 | 230 | | |
216 | 231 | | |
217 | | - | |
| 232 | + | |
218 | 233 | | |
219 | 234 | | |
220 | 235 | | |
221 | | - | |
| 236 | + | |
222 | 237 | | |
223 | 238 | | |
224 | 239 | | |
| |||
0 commit comments