Some checks failed
ClawSweeper Dispatch / dispatch (push) Has been cancelled
CodeQL / Security High (actions) (push) Has been cancelled
CodeQL / Security High (channel-runtime-boundary) (push) Has been cancelled
CodeQL / Security High (core-auth-secrets) (push) Has been cancelled
CodeQL / Security High (mcp-process-tool-boundary) (push) Has been cancelled
CodeQL / Security High (network-ssrf-boundary) (push) Has been cancelled
CodeQL / Security High (plugin-trust-boundary) (push) Has been cancelled
CodeQL / Security High (process-exec-boundary) (push) Has been cancelled
Docs Sync Publish Repo / sync-publish-repo (push) Has been cancelled
Docs / docs (push) Has been cancelled
OpenClaw Stable Main Closeout / Resolve stable release closeout inputs (push) Has been cancelled
OpenClaw Stable Main Closeout / Verify stable main closeout (push) Has been cancelled
Workflow Sanity / no-tabs (push) Has been cancelled
Workflow Sanity / actionlint (push) Has been cancelled
Workflow Sanity / generated-doc-baselines (push) Has been cancelled
CI / runner-admission (push) Has been cancelled
CI / preflight (push) Has been cancelled
CI / security-fast (push) Has been cancelled
CI / pnpm-store-warmup (push) Has been cancelled
CI / build-artifacts (push) Has been cancelled
CI / native-i18n (push) Has been cancelled
CI / ${{ matrix.check_name }} (push) Has been cancelled
CI / ${{ matrix.checkName }} (push) Has been cancelled
CI / checks-node-compat-node22 (push) Has been cancelled
CI / check-bundled-channel-config-metadata (push) Has been cancelled
CI / check-dependencies (push) Has been cancelled
CI / check-guards (push) Has been cancelled
CI / check-lint (push) Has been cancelled
CI / check-prod-types (push) Has been cancelled
CI / check-shrinkwrap (push) Has been cancelled
CI / check-test-types (push) Has been cancelled
CI / check-additional-boundaries-a (push) Has been cancelled
CI / check-additional-boundaries-bcd (push) Has been cancelled
CI / check-additional-extension-bundled (push) Has been cancelled
CI / check-additional-extension-channels (push) Has been cancelled
CI / check-additional-extension-package-boundary (push) Has been cancelled
CI / check-additional-runtime-topology-architecture (push) Has been cancelled
CI / check-session-accessor-boundary (push) Has been cancelled
CI / check-session-transcript-reader-boundary (push) Has been cancelled
CI / check-docs (push) Has been cancelled
CI / skills-python (push) Has been cancelled
CI / macos-swift (push) Has been cancelled
CI / ios-build (push) Has been cancelled
CI / ci-timings-summary (push) Has been cancelled
Native App Locale Refresh / Refresh native fa (push) Has been cancelled
Native App Locale Refresh / Refresh native fr (push) Has been cancelled
Native App Locale Refresh / Refresh native hi (push) Has been cancelled
Native App Locale Refresh / Refresh native id (push) Has been cancelled
Native App Locale Refresh / Refresh native it (push) Has been cancelled
Native App Locale Refresh / Refresh native ja-JP (push) Has been cancelled
Control UI Locale Refresh / plan (push) Has been cancelled
Control UI Locale Refresh / Refresh ${{ matrix.locale }} (push) Has been cancelled
Control UI Locale Refresh / Commit control UI locale refresh (push) Has been cancelled
Live Media Runner Image / Build live media runner image (push) Has been cancelled
Native App Locale Refresh / Refresh native ar (push) Has been cancelled
Native App Locale Refresh / Refresh native de (push) Has been cancelled
Native App Locale Refresh / Refresh native es (push) Has been cancelled
Native App Locale Refresh / Refresh native ko (push) Has been cancelled
Native App Locale Refresh / Refresh native nl (push) Has been cancelled
Native App Locale Refresh / Refresh native pl (push) Has been cancelled
Native App Locale Refresh / Refresh native pt-BR (push) Has been cancelled
Native App Locale Refresh / Refresh native ru (push) Has been cancelled
Native App Locale Refresh / Refresh native sv (push) Has been cancelled
Native App Locale Refresh / Refresh native th (push) Has been cancelled
Native App Locale Refresh / Refresh native tr (push) Has been cancelled
Native App Locale Refresh / Refresh native uk (push) Has been cancelled
Native App Locale Refresh / Refresh native vi (push) Has been cancelled
Native App Locale Refresh / Refresh native zh-CN (push) Has been cancelled
Native App Locale Refresh / Refresh native zh-TW (push) Has been cancelled
Native App Locale Refresh / Commit native locale refresh (push) Has been cancelled
Plugin Init Scaffold Validation / Validate provider scaffold (push) Has been cancelled
Plugin NPM Release / preview_plugins_npm (push) Has been cancelled
Plugin NPM Release / Validate release publish approval (push) Has been cancelled
Plugin NPM Release / preview_plugin_pack (push) Has been cancelled
Plugin NPM Release / publish_plugins_npm (push) Has been cancelled
Sandbox Common Smoke / sandbox-common-smoke (push) Has been cancelled
Website Installer Sync / static (push) Has been cancelled
Website Installer Sync / linux-docker (push) Has been cancelled
Website Installer Sync / macos-installer (push) Has been cancelled
Website Installer Sync / windows-installer (push) Has been cancelled
Website Installer Sync / sync-website (push) Has been cancelled
Adolf is a fork/vendored clone of github.com/openclaw/openclaw (v2026.6.11), free to diverge. Tree copied sans upstream .git; upstream remote added for future syncs. Node pinned to 24 (.nvmrc); engines already require >=22.19. Preserves docs/ARCHITECTURE.md. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LeqyaxJF2nbRXJtae2kNB2
101 lines
3.9 KiB
Swift
101 lines
3.9 KiB
Swift
import Foundation
|
|
|
|
enum ExecAllowlistMatcher {
|
|
static func match(entries: [ExecAllowlistEntry], resolution: ExecCommandResolution?) -> ExecAllowlistEntry? {
|
|
guard let resolution, !entries.isEmpty else { return nil }
|
|
let rawExecutable = resolution.rawExecutable
|
|
let resolvedPath = resolution.resolvedPath
|
|
|
|
for entry in entries {
|
|
switch ExecApprovalHelpers.validateAllowlistPattern(entry.pattern) {
|
|
case let .valid(pattern):
|
|
if ExecApprovalHelpers.patternHasPathSelector(pattern) {
|
|
let target = resolvedPath ?? rawExecutable
|
|
if self.matches(pattern: pattern, target: target) { return entry }
|
|
} else if pattern != "*",
|
|
!ExecApprovalHelpers.patternHasPathSelector(rawExecutable),
|
|
self.matchesExecutableBasename(pattern: pattern, resolution: resolution)
|
|
{
|
|
return entry
|
|
}
|
|
case .invalid:
|
|
continue
|
|
}
|
|
}
|
|
return nil
|
|
}
|
|
|
|
static func matchAll(
|
|
entries: [ExecAllowlistEntry],
|
|
resolutions: [ExecCommandResolution]) -> [ExecAllowlistEntry]
|
|
{
|
|
guard !entries.isEmpty, !resolutions.isEmpty else { return [] }
|
|
var matches: [ExecAllowlistEntry] = []
|
|
matches.reserveCapacity(resolutions.count)
|
|
for resolution in resolutions {
|
|
guard let match = self.match(entries: entries, resolution: resolution) else {
|
|
return []
|
|
}
|
|
matches.append(match)
|
|
}
|
|
return matches
|
|
}
|
|
|
|
private static func matchesExecutableBasename(
|
|
pattern: String,
|
|
resolution: ExecCommandResolution) -> Bool
|
|
{
|
|
var candidates = Set<String>()
|
|
if !resolution.executableName.isEmpty {
|
|
candidates.insert(resolution.executableName)
|
|
}
|
|
if let resolvedPath = resolution.resolvedPath, !resolvedPath.isEmpty {
|
|
candidates.insert(URL(fileURLWithPath: resolvedPath).lastPathComponent)
|
|
}
|
|
return candidates.contains { self.matches(pattern: pattern, target: $0) }
|
|
}
|
|
|
|
private static func matches(pattern: String, target: String) -> Bool {
|
|
let trimmed = pattern.trimmingCharacters(in: .whitespacesAndNewlines)
|
|
guard !trimmed.isEmpty else { return false }
|
|
let expanded = trimmed.hasPrefix("~") ? (trimmed as NSString).expandingTildeInPath : trimmed
|
|
let normalizedPattern = self.normalizeMatchTarget(expanded)
|
|
let normalizedTarget = self.normalizeMatchTarget(target)
|
|
guard let regex = self.regex(for: normalizedPattern) else { return false }
|
|
let range = NSRange(location: 0, length: normalizedTarget.utf16.count)
|
|
return regex.firstMatch(in: normalizedTarget, options: [], range: range) != nil
|
|
}
|
|
|
|
private static func normalizeMatchTarget(_ value: String) -> String {
|
|
value.replacingOccurrences(of: "\\\\", with: "/").lowercased()
|
|
}
|
|
|
|
private static func regex(for pattern: String) -> NSRegularExpression? {
|
|
var regex = "^"
|
|
var idx = pattern.startIndex
|
|
while idx < pattern.endIndex {
|
|
let ch = pattern[idx]
|
|
if ch == "*" {
|
|
let next = pattern.index(after: idx)
|
|
if next < pattern.endIndex, pattern[next] == "*" {
|
|
regex += ".*"
|
|
idx = pattern.index(after: next)
|
|
} else {
|
|
regex += "[^/]*"
|
|
idx = next
|
|
}
|
|
continue
|
|
}
|
|
if ch == "?" {
|
|
regex += "."
|
|
idx = pattern.index(after: idx)
|
|
continue
|
|
}
|
|
regex += NSRegularExpression.escapedPattern(for: String(ch))
|
|
idx = pattern.index(after: idx)
|
|
}
|
|
regex += "$"
|
|
return try? NSRegularExpression(pattern: regex, options: [.caseInsensitive])
|
|
}
|
|
}
|