Some checks failed
ClawSweeper Dispatch / dispatch (push) Has been cancelled
CodeQL / Security High (actions) (push) Has been cancelled
CodeQL / Security High (channel-runtime-boundary) (push) Has been cancelled
CodeQL / Security High (core-auth-secrets) (push) Has been cancelled
CodeQL / Security High (mcp-process-tool-boundary) (push) Has been cancelled
CodeQL / Security High (network-ssrf-boundary) (push) Has been cancelled
CodeQL / Security High (plugin-trust-boundary) (push) Has been cancelled
CodeQL / Security High (process-exec-boundary) (push) Has been cancelled
Docs Sync Publish Repo / sync-publish-repo (push) Has been cancelled
Docs / docs (push) Has been cancelled
OpenClaw Stable Main Closeout / Resolve stable release closeout inputs (push) Has been cancelled
OpenClaw Stable Main Closeout / Verify stable main closeout (push) Has been cancelled
Workflow Sanity / no-tabs (push) Has been cancelled
Workflow Sanity / actionlint (push) Has been cancelled
Workflow Sanity / generated-doc-baselines (push) Has been cancelled
CI / runner-admission (push) Has been cancelled
CI / preflight (push) Has been cancelled
CI / security-fast (push) Has been cancelled
CI / pnpm-store-warmup (push) Has been cancelled
CI / build-artifacts (push) Has been cancelled
CI / native-i18n (push) Has been cancelled
CI / ${{ matrix.check_name }} (push) Has been cancelled
CI / ${{ matrix.checkName }} (push) Has been cancelled
CI / checks-node-compat-node22 (push) Has been cancelled
CI / check-bundled-channel-config-metadata (push) Has been cancelled
CI / check-dependencies (push) Has been cancelled
CI / check-guards (push) Has been cancelled
CI / check-lint (push) Has been cancelled
CI / check-prod-types (push) Has been cancelled
CI / check-shrinkwrap (push) Has been cancelled
CI / check-test-types (push) Has been cancelled
CI / check-additional-boundaries-a (push) Has been cancelled
CI / check-additional-boundaries-bcd (push) Has been cancelled
CI / check-additional-extension-bundled (push) Has been cancelled
CI / check-additional-extension-channels (push) Has been cancelled
CI / check-additional-extension-package-boundary (push) Has been cancelled
CI / check-additional-runtime-topology-architecture (push) Has been cancelled
CI / check-session-accessor-boundary (push) Has been cancelled
CI / check-session-transcript-reader-boundary (push) Has been cancelled
CI / check-docs (push) Has been cancelled
CI / skills-python (push) Has been cancelled
CI / macos-swift (push) Has been cancelled
CI / ios-build (push) Has been cancelled
CI / ci-timings-summary (push) Has been cancelled
Native App Locale Refresh / Refresh native fa (push) Has been cancelled
Native App Locale Refresh / Refresh native fr (push) Has been cancelled
Native App Locale Refresh / Refresh native hi (push) Has been cancelled
Native App Locale Refresh / Refresh native id (push) Has been cancelled
Native App Locale Refresh / Refresh native it (push) Has been cancelled
Native App Locale Refresh / Refresh native ja-JP (push) Has been cancelled
Control UI Locale Refresh / plan (push) Has been cancelled
Control UI Locale Refresh / Refresh ${{ matrix.locale }} (push) Has been cancelled
Control UI Locale Refresh / Commit control UI locale refresh (push) Has been cancelled
Live Media Runner Image / Build live media runner image (push) Has been cancelled
Native App Locale Refresh / Refresh native ar (push) Has been cancelled
Native App Locale Refresh / Refresh native de (push) Has been cancelled
Native App Locale Refresh / Refresh native es (push) Has been cancelled
Native App Locale Refresh / Refresh native ko (push) Has been cancelled
Native App Locale Refresh / Refresh native nl (push) Has been cancelled
Native App Locale Refresh / Refresh native pl (push) Has been cancelled
Native App Locale Refresh / Refresh native pt-BR (push) Has been cancelled
Native App Locale Refresh / Refresh native ru (push) Has been cancelled
Native App Locale Refresh / Refresh native sv (push) Has been cancelled
Native App Locale Refresh / Refresh native th (push) Has been cancelled
Native App Locale Refresh / Refresh native tr (push) Has been cancelled
Native App Locale Refresh / Refresh native uk (push) Has been cancelled
Native App Locale Refresh / Refresh native vi (push) Has been cancelled
Native App Locale Refresh / Refresh native zh-CN (push) Has been cancelled
Native App Locale Refresh / Refresh native zh-TW (push) Has been cancelled
Native App Locale Refresh / Commit native locale refresh (push) Has been cancelled
Plugin Init Scaffold Validation / Validate provider scaffold (push) Has been cancelled
Plugin NPM Release / preview_plugins_npm (push) Has been cancelled
Plugin NPM Release / Validate release publish approval (push) Has been cancelled
Plugin NPM Release / preview_plugin_pack (push) Has been cancelled
Plugin NPM Release / publish_plugins_npm (push) Has been cancelled
Sandbox Common Smoke / sandbox-common-smoke (push) Has been cancelled
Website Installer Sync / static (push) Has been cancelled
Website Installer Sync / linux-docker (push) Has been cancelled
Website Installer Sync / macos-installer (push) Has been cancelled
Website Installer Sync / windows-installer (push) Has been cancelled
Website Installer Sync / sync-website (push) Has been cancelled
Adolf is a fork/vendored clone of github.com/openclaw/openclaw (v2026.6.11), free to diverge. Tree copied sans upstream .git; upstream remote added for future syncs. Node pinned to 24 (.nvmrc); engines already require >=22.19. Preserves docs/ARCHITECTURE.md. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LeqyaxJF2nbRXJtae2kNB2
205 lines
7.3 KiB
Swift
205 lines
7.3 KiB
Swift
import Foundation
|
|
|
|
enum ExecShellWrapperParser {
|
|
struct ParsedShellWrapper {
|
|
let isWrapper: Bool
|
|
let command: String?
|
|
|
|
static let notWrapper = ParsedShellWrapper(isWrapper: false, command: nil)
|
|
static let blockedWrapper = ParsedShellWrapper(isWrapper: true, command: nil)
|
|
}
|
|
|
|
private enum Kind: Equatable {
|
|
case posix
|
|
case cmd
|
|
case powershell
|
|
}
|
|
|
|
private struct WrapperSpec {
|
|
let kind: Kind
|
|
let names: Set<String>
|
|
}
|
|
|
|
private static let posixInlineFlags = Set(["-lc", "-c", "--command"])
|
|
private static let powershellInlineFlags = Set(["-c", "-command", "--command"])
|
|
|
|
private static let wrapperSpecs: [WrapperSpec] = [
|
|
WrapperSpec(kind: .posix, names: ["ash", "sh", "bash", "zsh", "dash", "ksh", "fish"]),
|
|
WrapperSpec(kind: .cmd, names: ["cmd.exe", "cmd"]),
|
|
WrapperSpec(kind: .powershell, names: ["powershell", "powershell.exe", "pwsh", "pwsh.exe"]),
|
|
]
|
|
private static let loginStartupShellNames = Set(["ash", "bash", "dash", "fish", "ksh", "sh", "zsh"])
|
|
|
|
static func extract(command: [String], rawCommand: String?) -> ParsedShellWrapper {
|
|
let trimmedRaw = rawCommand?.trimmingCharacters(in: .whitespacesAndNewlines) ?? ""
|
|
let preferredRaw = trimmedRaw.isEmpty ? nil : trimmedRaw
|
|
return self.extract(
|
|
command: command,
|
|
preferredRaw: preferredRaw,
|
|
failClosedOnStartupWrappers: false,
|
|
depth: 0)
|
|
}
|
|
|
|
static func extractForAllowlist(command: [String], rawCommand: String?) -> ParsedShellWrapper {
|
|
let trimmedRaw = rawCommand?.trimmingCharacters(in: .whitespacesAndNewlines) ?? ""
|
|
let preferredRaw = trimmedRaw.isEmpty ? nil : trimmedRaw
|
|
return self.extract(
|
|
command: command,
|
|
preferredRaw: preferredRaw,
|
|
failClosedOnStartupWrappers: true,
|
|
depth: 0)
|
|
}
|
|
|
|
private static func extract(
|
|
command: [String],
|
|
preferredRaw: String?,
|
|
failClosedOnStartupWrappers: Bool,
|
|
depth: Int) -> ParsedShellWrapper
|
|
{
|
|
guard depth < ExecEnvInvocationUnwrapper.maxWrapperDepth else {
|
|
return .notWrapper
|
|
}
|
|
guard let token0 = command.first?.trimmingCharacters(in: .whitespacesAndNewlines), !token0.isEmpty else {
|
|
return .notWrapper
|
|
}
|
|
|
|
let base0 = ExecCommandToken.basenameLower(token0)
|
|
if base0 == "env" {
|
|
guard let unwrapped = ExecEnvInvocationUnwrapper.unwrap(command) else {
|
|
return .notWrapper
|
|
}
|
|
return self.extract(
|
|
command: unwrapped,
|
|
preferredRaw: preferredRaw,
|
|
failClosedOnStartupWrappers: failClosedOnStartupWrappers,
|
|
depth: depth + 1)
|
|
}
|
|
|
|
guard let spec = self.wrapperSpecs.first(where: { $0.names.contains(base0) }) else {
|
|
return .notWrapper
|
|
}
|
|
if spec.kind == .posix,
|
|
base0 == "fish",
|
|
ExecInlineCommandParser.hasFishAttachedCommandOption(command)
|
|
{
|
|
return .blockedWrapper
|
|
}
|
|
let includeLegacyLoginInlineForm = failClosedOnStartupWrappers &&
|
|
!self.legacyLoginInlinePayloadMatchesRaw(
|
|
command: command,
|
|
spec: spec,
|
|
base0: base0,
|
|
preferredRaw: preferredRaw)
|
|
if self.startupWrapperRequiresFullArgv(
|
|
command: command,
|
|
spec: spec,
|
|
base0: base0,
|
|
includeLegacyLoginInlineForm: includeLegacyLoginInlineForm)
|
|
{
|
|
return .blockedWrapper
|
|
}
|
|
guard let payload = self.extractPayload(command: command, spec: spec) else {
|
|
return .notWrapper
|
|
}
|
|
let normalized = failClosedOnStartupWrappers ? payload : preferredRaw ?? payload
|
|
return ParsedShellWrapper(isWrapper: true, command: normalized)
|
|
}
|
|
|
|
private static func startupWrapperRequiresFullArgv(
|
|
command: [String],
|
|
spec: WrapperSpec,
|
|
base0: String,
|
|
includeLegacyLoginInlineForm: Bool) -> Bool
|
|
{
|
|
guard spec.kind == .posix else {
|
|
return false
|
|
}
|
|
if base0 == "fish",
|
|
ExecInlineCommandParser.hasFishInitCommandOption(command)
|
|
{
|
|
return true
|
|
}
|
|
if self.loginStartupShellNames.contains(base0),
|
|
ExecInlineCommandParser.hasPosixLoginStartupBeforeInlineCommand(
|
|
command,
|
|
flags: self.posixInlineFlags)
|
|
{
|
|
return includeLegacyLoginInlineForm || !self.isLegacyShLoginInlineForm(command, base0: base0)
|
|
}
|
|
return ExecInlineCommandParser.hasPosixInteractiveStartupBeforeInlineCommand(
|
|
command,
|
|
flags: self.posixInlineFlags)
|
|
}
|
|
|
|
private static func isLegacyLoginInlineForm(_ command: [String]) -> Bool {
|
|
guard command.count > 1 else {
|
|
return false
|
|
}
|
|
return command[1].trimmingCharacters(in: .whitespacesAndNewlines) == "-lc"
|
|
}
|
|
|
|
private static func isLegacyShLoginInlineForm(_ command: [String], base0: String) -> Bool {
|
|
base0 == "sh" && self.isLegacyLoginInlineForm(command)
|
|
}
|
|
|
|
private static func legacyLoginInlinePayloadMatchesRaw(
|
|
command: [String],
|
|
spec: WrapperSpec,
|
|
base0: String,
|
|
preferredRaw: String?) -> Bool
|
|
{
|
|
guard let preferredRaw,
|
|
base0 == "sh",
|
|
self.isLegacyLoginInlineForm(command),
|
|
let payload = self.extractPayload(command: command, spec: spec)
|
|
else {
|
|
return false
|
|
}
|
|
return payload == preferredRaw.trimmingCharacters(in: .whitespacesAndNewlines)
|
|
}
|
|
|
|
private static func extractPayload(command: [String], spec: WrapperSpec) -> String? {
|
|
switch spec.kind {
|
|
case .posix:
|
|
self.extractPosixInlineCommand(command)
|
|
case .cmd:
|
|
self.extractCmdInlineCommand(command)
|
|
case .powershell:
|
|
self.extractPowerShellInlineCommand(command)
|
|
}
|
|
}
|
|
|
|
private static func extractPosixInlineCommand(_ command: [String]) -> String? {
|
|
ExecInlineCommandParser.extractInlineCommand(
|
|
command,
|
|
flags: self.posixInlineFlags,
|
|
allowCombinedC: true)
|
|
}
|
|
|
|
private static func extractCmdInlineCommand(_ command: [String]) -> String? {
|
|
guard let idx = command
|
|
.firstIndex(where: { $0.trimmingCharacters(in: .whitespacesAndNewlines).lowercased() == "/c" })
|
|
else {
|
|
return nil
|
|
}
|
|
let tail = command.suffix(from: command.index(after: idx)).joined(separator: " ")
|
|
let payload = tail.trimmingCharacters(in: .whitespacesAndNewlines)
|
|
return payload.isEmpty ? nil : payload
|
|
}
|
|
|
|
private static func extractPowerShellInlineCommand(_ command: [String]) -> String? {
|
|
for idx in 1..<command.count {
|
|
let token = command[idx].trimmingCharacters(in: .whitespacesAndNewlines).lowercased()
|
|
if token.isEmpty { continue }
|
|
if token == "--" { break }
|
|
if self.powershellInlineFlags.contains(token) {
|
|
return ExecInlineCommandParser.extractInlineCommand(
|
|
command,
|
|
flags: self.powershellInlineFlags,
|
|
allowCombinedC: false)
|
|
}
|
|
}
|
|
return nil
|
|
}
|
|
}
|