fix(agent): guard apply_patch with secret-guard and realpath bound - #1259
Open
Conversation
TheGreatAxios
added this pull request to stack #1260
September 30, 2026 16:30
TheGreatAxios
force-pushed
the
cl-9622-apply_patch-re-enforces-secret-guard-and-realpath-workspace
branch
from
September 30, 2026 17:35
d72fdc4 to
b3e1b98
Compare
TheGreatAxios
removed this pull request from stack #1260
September 30, 2026 17:49
TheGreatAxios
added this pull request to stack #1263
September 30, 2026 17:49
TheGreatAxios
force-pushed
the
cl-9622-apply_patch-re-enforces-secret-guard-and-realpath-workspace
branch
from
September 30, 2026 18:04
b3e1b98 to
3e81383
Compare
TheGreatAxios
removed this pull request from stack #1263
September 30, 2026 18:12
TheGreatAxios
added this pull request to stack #1266
September 30, 2026 18:13
TheGreatAxios
removed this pull request from stack #1266
September 30, 2026 20:26
TheGreatAxios
added this pull request to stack #1273
September 30, 2026 20:27
TheGreatAxios
removed this pull request from stack #1273
September 30, 2026 20:41
TheGreatAxios
added this pull request to stack #1277
September 30, 2026 20:42
TheGreatAxios
removed this pull request from stack #1277
September 30, 2026 20:56
TheGreatAxios
added this pull request to stack #1279
September 30, 2026 20:57
TheGreatAxios
removed this pull request from stack #1279
September 30, 2026 23:49
TheGreatAxios
force-pushed
the
cl-9622-apply_patch-re-enforces-secret-guard-and-realpath-workspace
branch
from
September 30, 2026 23:49
3e81383 to
5c96812
Compare
TheGreatAxios
added this pull request to stack #1284
September 30, 2026 23:50
apply_patch is mounted outside the posix plugin stack, so it skipped the secret-guard denylist and checked the workspace bound lexically only. Every patch path now goes through the denylist and the shared realpath resolver, on both the primary and worker mounts.
TheGreatAxios
force-pushed
the
cl-9622-apply_patch-re-enforces-secret-guard-and-realpath-workspace
branch
from
October 2, 2026 00:25
5c96812 to
80a3be0
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
apply_patchpath (add, update, delete, move target) against the secret-guard denylist, including the realpath leg and runtime extra-denied paths.apply_patchto the workspace with the shared realpath resolver, so a symlink inside the workspace cannot lead out of it. Sibling worktrees and yolo mode behave as they do for write and edit.Verification
bun run checkpasses..envpatch and a write through a workspace symlink to an outside directory.Fixes CL-9622