Actuator validate_params enum screen: consider a safe-char allowlist (parity with invoke-tool composition) #7
Labels
No labels
correctness
coverage
milestone:M4
polish
security
tech-debt
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
public/warden#7
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
From the M4 T1 re-review (out-of-scope observation).
mesh/manifest.py_UNSAFE_RE = [\s\x00-\x1f\x7f](used byvalidate_params, the actuator-side runtime param check) is a whitespace/control-only DENYLIST — it still lets shell metacharacters through in an enum/regex param value. This is a DIFFERENT threat model than M4 T1 (the actuator runs argv with shell=False, so no shell interpolation there), so it is not a live RCE like the composition path was — but: (1) the newremediate.pycomment claims the allowlist "mirrors validate_params", which is INACCURATE (different charset + strategy) — fix the comment; (2) evaluate whether the actuator param screen should also become a positive allowlist for defense-in-depth. Files: src/warden/mesh/manifest.py:164, src/warden/remediate.py:229.Fixed in v0.18.0 (commits
54a0cd9+e8d5348).manifest.validate_paramsnow applies the positive safe-char allowlist [A-Za-z0-9._@:=+/-] to ENUM values (parity with the composition path); regex/int params unchanged. The inaccurate remediate.py comment is corrected.