Adversarial review and fix (run c6c486) - #134
Merged
Merged
Conversation
Code-grounded P0 review + skeptic freeze for adversarial-review-and-fix. 21 confirmed findings (15 Lane A, 6 Lane B); SEC-006 DO_NOT_FIX. Schema-verified findings under .fleet/runs/.../p0-*-findings.json. Co-authored-by: Ravindra Kumar <ravidsrk@gmail.com>
Execute gstack/mattpocock installs via discrete argv (no eval), allowlist --host to cursor|claude|grok|codex, reject shell metacharacters in GSTACK_REPO_URL/GSTACK_SKILLS_DIR, and pin mattpocock to skills@1.5.12 (SEC-008). Co-authored-by: Ravindra Kumar <ravidsrk@gmail.com>
Co-authored-by: Ravindra Kumar <ravidsrk@gmail.com>
Co-authored-by: Ravindra Kumar <ravidsrk@gmail.com>
…E (c6c486) Co-authored-by: Ravindra Kumar <ravidsrk@gmail.com>
…(c6c486) Co-authored-by: Ravindra Kumar <ravidsrk@gmail.com>
…c486) Co-authored-by: Ravindra Kumar <ravidsrk@gmail.com>
Co-authored-by: Ravindra Kumar <ravidsrk@gmail.com>
…rd (SEC-007) Co-Authored-By: Cursor Agent <cursoragent@cursor.com> Co-authored-by: Ravindra Kumar <ravidsrk@gmail.com>
Co-Authored-By: Cursor Agent <cursoragent@cursor.com> Co-authored-by: Ravindra Kumar <ravidsrk@gmail.com>
…rrors (ARCH-002,BUG-002) Co-Authored-By: Cursor Agent <cursoragent@cursor.com> Co-authored-by: Ravindra Kumar <ravidsrk@gmail.com>
Co-Authored-By: Cursor Agent <cursoragent@cursor.com> Co-authored-by: Ravindra Kumar <ravidsrk@gmail.com>
…(ARCH-001) Co-Authored-By: Cursor Agent <cursoragent@cursor.com> Co-authored-by: Ravindra Kumar <ravidsrk@gmail.com>
…c6c486) Co-authored-by: Ravindra Kumar <ravidsrk@gmail.com>
…SE (c6c486) Co-authored-by: Ravindra Kumar <ravidsrk@gmail.com>
…E (c6c486) Co-authored-by: Ravindra Kumar <ravidsrk@gmail.com>
…c6c486) Co-authored-by: Ravindra Kumar <ravidsrk@gmail.com>
… (c6c486) Resolve substrate-manifest.json by regenerating hashes after merge. Co-authored-by: Ravindra Kumar <ravidsrk@gmail.com>
Co-authored-by: Ravindra Kumar <ravidsrk@gmail.com>
Co-authored-by: Ravindra Kumar <ravidsrk@gmail.com>
Co-authored-by: Ravindra Kumar <ravidsrk@gmail.com>
Co-authored-by: Ravindra Kumar <ravidsrk@gmail.com>
…G-004) Co-authored-by: Ravindra Kumar <ravidsrk@gmail.com>
Co-authored-by: Ravindra Kumar <ravidsrk@gmail.com>
…(c6c486) Co-authored-by: Ravindra Kumar <ravidsrk@gmail.com>
…c6c486) Co-authored-by: Ravindra Kumar <ravidsrk@gmail.com>
…(c6c486) Co-authored-by: Ravindra Kumar <ravidsrk@gmail.com>
…BASE (c6c486) Co-authored-by: Ravindra Kumar <ravidsrk@gmail.com>
…(c6c486) Co-authored-by: Ravindra Kumar <ravidsrk@gmail.com>
Co-authored-by: Ravindra Kumar <ravidsrk@gmail.com>
Lane A findings closed; Lane B human-gated; fleet-outcome validates; run archive written under .fleet/runs/<run_id>/ (gitignored). Co-authored-by: Ravindra Kumar <ravidsrk@gmail.com>
Dry-run prints unquoted human-readable command lines; tests no longer require shell-quoted argv tokens. Co-authored-by: Ravindra Kumar <ravidsrk@gmail.com>
…-run Comment-aware no-eval coverage remains in test_script_has_no_eval. Co-authored-by: Ravindra Kumar <ravidsrk@gmail.com>
Co-authored-by: Ravindra Kumar <ravidsrk@gmail.com>
ravidsrk
marked this pull request as ready for review
July 8, 2026 19:27
Substrate syncs from the adversarial-review fix wave drifted the core skill content hash; registry-lint failed CI until the lock and version moved together. Co-authored-by: Ravindra Kumar <ravidsrk@gmail.com>
Keep substrate-manifest.json core_version aligned with SKILL.md after the lock refresh so sync_substrate_assets --check and content_hash stay consistent. Co-authored-by: Ravindra Kumar <ravidsrk@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Full-app adversarial review + remediation for
autonomous-fleet(missionadversarial-review-and-fix, runc6c486).Phase 0
docs/adversarial-review-fresh.md.fleet/docs/arch-build-progress.mdPhase 1 — Lane A closed (15 findings)
Merged into this BASE via merge-commits (fix PRs #135–#147):
evalfrominstall-community.sh; pinskills@1.5.12--run-idbefore sandbox mounts--unshare-netSECURITY.mdclassifier examples to DENY/ASKfleet-verifygains sha-pin + reviewer-sandbox layers|| trueon blocked parsecreated_utc≤ file mtimes; stamp at run startnamespace._RUN_ID_REtofleet_run.RUN_ID_PATTERNincrement_resume_countupdates markdown table rowsmission_promotionhonorsFLEET_LEDGER_DIRLane B (HUMAN_GATED)
SEC-004, SEC-005, SEC-009, ARCH-004, ARCH-005, SEC-010 — draft-both variants in
.fleet/docs/DECISIONS.md.CI fix
Substrate sync drifted
autonomous-fleet-corecontent under version1.3.0. Bumped to 1.3.1, refreshedskills-lock.jsoncomputedHash, and syncedsubstrate-manifest.jsoncore_version.Test plan
python3 scripts/registry_lint.py .passessync_substrate_assets.py --checkOKvalidatejob green on this PRGreptile Summary
This PR applies the adversarial-review fix set across the fleet scripts, substrate assets, docs, and tests. The main changes are:
eval, validating hosts, rejecting shell metacharacters, and pinning the skills CLI.bwrapnetwork isolation.created_utc, SHA pins, reviewer sandbox manifests, findings size caps, and run identity.Confidence Score: 5/5
This PR appears safe to merge from the reviewed changed-code paths.
The executable changes match the documented fix intent and have targeted tests for the affected flows. No new actionable bugs were identified in the reviewed changes.
No new files require special attention beyond the already-discussed historical
fleet_verifySHA-pin behavior.What T-Rex did
Important Files Changed
created_utcagainst artifact mtimes.Sequence Diagram
%%{init: {'theme': 'neutral'}}%% sequenceDiagram participant Operator participant Installer as install-community.sh participant Sandbox as run-sandboxed.sh participant Headless as run-mission-headless.sh / run-campaign.sh participant Archive as fleet_run.py participant Verify as fleet_verify.py Operator->>Installer: choose community bundle Installer->>Installer: validate host + reject shell metacharacters Installer-->>Operator: dry-run display or argv-based execution Operator->>Sandbox: reviewer role with run_id Sandbox->>Sandbox: validate RUN_ID_PATTERN + contain path under .fleet/runs Sandbox->>Sandbox: create read-only reviewer sandbox Sandbox-->>Operator: reviewer output under run dir Operator->>Headless: run mission/campaign Headless->>Archive: emit trace/archive for real run Archive->>Archive: stamp created_utc at run start and validate mtimes Headless->>Verify: validate run artifacts Verify->>Verify: run archive, findings, outcome, trace, identity, sha-pin, reviewer-sandbox layers Verify-->>Operator: PASS/FAIL layer report%%{init: {'theme': 'base', 'themeVariables': {"darkMode": true, "background": "#0d1117", "primaryColor": "#21262d", "primaryTextColor": "#e6edf3", "primaryBorderColor": "#8b949e", "lineColor": "#8b949e", "textColor": "#e6edf3", "edgeLabelBackground": "#161b22", "actorBkg": "#21262d", "actorBorder": "#8b949e", "actorTextColor": "#e6edf3", "actorLineColor": "#8b949e", "signalColor": "#8b949e", "signalTextColor": "#e6edf3", "noteBkgColor": "#373320", "noteBorderColor": "#d4a72c", "noteTextColor": "#f0e6c0", "labelBoxBkgColor": "#21262d", "labelBoxBorderColor": "#8b949e", "labelTextColor": "#e6edf3", "loopTextColor": "#e6edf3", "activationBkgColor": "#30363d", "activationBorderColor": "#8b949e"}}}%% sequenceDiagram participant Operator participant Installer as install-community.sh participant Sandbox as run-sandboxed.sh participant Headless as run-mission-headless.sh / run-campaign.sh participant Archive as fleet_run.py participant Verify as fleet_verify.py Operator->>Installer: choose community bundle Installer->>Installer: validate host + reject shell metacharacters Installer-->>Operator: dry-run display or argv-based execution Operator->>Sandbox: reviewer role with run_id Sandbox->>Sandbox: validate RUN_ID_PATTERN + contain path under .fleet/runs Sandbox->>Sandbox: create read-only reviewer sandbox Sandbox-->>Operator: reviewer output under run dir Operator->>Headless: run mission/campaign Headless->>Archive: emit trace/archive for real run Archive->>Archive: stamp created_utc at run start and validate mtimes Headless->>Verify: validate run artifacts Verify->>Verify: run archive, findings, outcome, trace, identity, sha-pin, reviewer-sandbox layers Verify-->>Operator: PASS/FAIL layer reportReviews (4): Last reviewed commit: "fix(ci): sync substrate-manifest core_ve..." | Re-trigger Greptile