From 436e6a88246795e600ff76029a3ed1f98f1992c8 Mon Sep 17 00:00:00 2001 From: Rodin Date: Fri, 1 May 2026 21:16:16 -0700 Subject: [PATCH] fix: symlink traversal + worst-wins pre-check + user scoping MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Security (MAJOR): - Add filepath.EvalSymlinks after Clean for system-prompt-file - Re-validate resolved path is still within workspace - Prevents symlink → /etc/shadow exfiltration via malicious repo Worst-wins: - Check BEFORE posting (not after) — no delete+repost dance - Identify sibling bots by ", *reviewerName) - if !strings.Contains(r.Body, sentinelCheck) { - log.Printf("Sibling review %d has REQUEST_CHANGES; escalating to REQUEST_CHANGES", r.ID) - event = "REQUEST_CHANGES" - break - } - } - } - } + // Validate reviewer-name: only safe characters allowed in sentinel + if err := validateReviewerName(*reviewerName); err != nil { + log.Fatalf("%v", err) } + sentinel := fmt.Sprintf("", *reviewerName) log.Printf("Posting review (event=%s)...", event) posted, err := giteaClient.PostReview(ctx, owner, repoName, prNumber, event, reviewBody) @@ -254,7 +248,6 @@ func main() { log.Printf("Review posted (id=%d, user=%s)", posted.ID, posted.User.Login) // Delete stale reviews from this bot using sentinel matching - sentinel := fmt.Sprintf("", *reviewerName) if *updateExisting && *reviewerName != "" { reviews, err := giteaClient.ListReviews(ctx, owner, repoName, prNumber) if err != nil { @@ -270,6 +263,22 @@ func main() { } } + // Worst-wins: if we posted APPROVE but a sibling review from the + // same user (same token, different role) has REQUEST_CHANGES, + // delete ours and re-post as REQUEST_CHANGES to maintain the block. + if event == "APPROVED" && shouldEscalate(reviews, posted.ID, posted.User.Login, sentinel) { + log.Printf("Sibling review has REQUEST_CHANGES; escalating") + if err := giteaClient.DeleteReview(ctx, owner, repoName, prNumber, posted.ID); err != nil { + log.Printf("Warning: could not delete review for escalation: %v", err) + } else { + _, err := giteaClient.PostReview(ctx, owner, repoName, prNumber, "REQUEST_CHANGES", reviewBody) + if err != nil { + log.Printf("Warning: could not re-post as REQUEST_CHANGES: %v", err) + } else { + log.Printf("Review escalated to REQUEST_CHANGES") + } + } + } } } } @@ -413,3 +422,29 @@ func envOrDefaultBool(key string, defaultVal bool) bool { } return v == "true" || v == "1" || v == "yes" } + +// validateReviewerName checks that the name contains only safe characters +// for embedding in an HTML comment sentinel ([a-zA-Z0-9_-]). +func validateReviewerName(name string) error { + if name == "" { + return nil + } + for _, ch := range name { + if !((ch >= 'a' && ch <= 'z') || (ch >= 'A' && ch <= 'Z') || (ch >= '0' && ch <= '9') || ch == '-' || ch == '_') { + return fmt.Errorf("reviewer-name must contain only [a-zA-Z0-9_-] (got %q)", name) + } + } + return nil +} + +// shouldEscalate checks if the current APPROVED review should be escalated +// to REQUEST_CHANGES because a sibling bot review (same user, different role) +// already has REQUEST_CHANGES. +func shouldEscalate(reviews []gitea.Review, postedID int64, postedLogin, ownSentinel string) bool { + for _, r := range reviews { + if r.ID != postedID && !r.Stale && r.User.Login == postedLogin && r.State == "REQUEST_CHANGES" && strings.Contains(r.Body, "", true}, + {"invalid space", "my bot", true}, + {"invalid dot", "my.bot", true}, + {"invalid slash", "my/bot", true}, + {"invalid angle", "bot