fix(cli): reject unsafe plugin archive links#1043
Merged
shiyiyue1102 merged 1 commit intoJul 17, 2026
Merged
Conversation
shiyiyue1102
approved these changes
Jul 17, 2026
shiyiyue1102
left a comment
Collaborator
There was a problem hiding this comment.
LGTM. The extraction guard now rejects symlinks, hard links, and special-file members before tar extraction, and the regression test covers the symlink escape path. The scoped required check is green.
nattiini45
added a commit
to nattiini45/AgentTeams
that referenced
this pull request
Jul 23, 2026
* fix: align AgentTeams runtime naming defaults (agentscope-ai#1041) * fix: prepare beta release workflow (agentscope-ai#1054) * fix: harden beta release gates (agentscope-ai#1056) * fix(cli): reject unsafe plugin archive links (agentscope-ai#1043) * fix(scripts): redact complete Matrix events (agentscope-ai#1047) * fix(migrate): analyze current cron job format (agentscope-ai#1049) * fix(migrate): print runnable ZIP import command (agentscope-ai#1048) * fix(replay): capture immediate manager replies (agentscope-ai#1045) * fix(hack): persist containerized skopeo auth (agentscope-ai#1050) * chore: archive changelog for v1.2.0-beta.1 (agentscope-ai#1058) Co-authored-by: shiyiyue1102 <20452676+shiyiyue1102@users.noreply.github.com> * fix(copaw): route Team Leader assignments to Team Room (agentscope-ai#1060) * fix(install): user can specify which docker.sock to mount when run install script (agentscope-ai#553) * docs: clarify Element homeserver port (agentscope-ai#978) Co-authored-by: Ziyang Guo <121015044+RunMarshal@users.noreply.github.com> * docs: clarify Higress AI route matching (agentscope-ai#980) Co-authored-by: Ziyang Guo <121015044+RunMarshal@users.noreply.github.com> * docs: clarify OpenAI-compatible provider setup (agentscope-ai#1013) * refactor: complete AgentTeams runtime rename (agentscope-ai#1063) * refactor: complete the AgentTeams hard-cut rename (agentscope-ai#1065) * docs: add v1.2.0-beta.1 release news (agentscope-ai#1066) * feat(sync): restore fork-only product trees on agentteams paths Replay dashboard Helm templates under helm/agentteams, dashboard values and helpers, qwenpaw worker image defaults, and path-adapted remediation-gates (agentteams-controller / helm/agentteams). Root dashboard/, shared/python/, openwiki/, and Gastown skills already survived the merge baseline. Co-authored-by: Cursor <cursoragent@cursor.com> * feat(controller): port fork Project CRD, health, APIs, and status CLI Replay fork-only agentteams-controller features onto the upstream rename baseline: Project CRD/reconciler/Helm, health monitor, message and manager-tasks APIs, worker health probes, managerstate CLI, enhanced agt status overview, SoloOperator/QwenPaw/docker resource wiring, and related tests. Co-authored-by: Cursor <cursoragent@cursor.com> * feat(runtimes): restore quiet-rooms and Higress extra-provider prefix strip Keep upstream CoPaw Team Leader DM-to-Team-Room routing while replaying fork AGENTTEAMS_QUIET_ROOMS bridge/channel wiring. Restore OPT-IN AGENTTEAMS_EXTRA_LLM_PROVIDERS setup with modelMapping prefix strip in setup-higress.sh (route names agentteams-*-route). Co-authored-by: Cursor <cursoragent@cursor.com> * docs(sync): truth-up migration doc, merge changelog, agt naming sweep Rewrite upstream-integration-migration.md for rename acceptance + fork overlay DoD (drop dual-CRD/HICLAW_* claims). Merge changelog entries from both sides. Point pre-commit and openwiki paths at agentteams-controller / helm/agentteams. Align agent-facing CLI examples to agt. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(qwenpaw): resolve Windows file:// agent package refs urlparse puts file://C:\path entirely in netloc with an empty path; Path('') became cwd and silently copied the repo instead of the package archive. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(ci): purge brand leftovers and restore fork runtime bridge/sync Clear remaining retired-brand strings/paths so helm-lint rename gate passes, restore CoPaw fork bridge/worker APIs and Hermes thin sync semantics, and harden installer prompt helpers with printf -v. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(copaw): restore Matrix channel APIs and thin sync wrapper Bring back fork Matrix channel behavior needed by worker tests, switch sync back to the agentteams_sync wrapper, and share filesync helpers via _toolhelpers. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(sync): restore agentteams- bucket prefix stripping for team storage The rename pass incorrectly shortened the hiclaw- bucket prefix check to agt-, breaking team path derivation for agentteams-* buckets. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(security): remediate Kilo review findings on sync/upstream-main Harden appservice token compare, proxy body limits, lifecycle error logging, Helm image/RBAC/CRD alignment, OpenHuman TOML escaping, and storage alias safety. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(helm): avoid retired brand in storage.bucket comment Rename gate rejects hiclaw tokens even in comments; keep migration note brand-free. Co-authored-by: Cursor <cursoragent@cursor.com> --------- Co-authored-by: shiyiyue1102 <zunfei.lzf@alibaba-inc.com> Co-authored-by: Ziyang Guo <121015044+RerankerGuo@users.noreply.github.com> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: shiyiyue1102 <20452676+shiyiyue1102@users.noreply.github.com> Co-authored-by: Daniel Qian <chanjarster@gmail.com> Co-authored-by: Ziyang Guo <121015044+RunMarshal@users.noreply.github.com> Co-authored-by: Cursor <cursoragent@cursor.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Root cause
_safe_extract_tarvalidated every member path before callingextractall, but a link member can change how a later, otherwise valid member path resolves during extraction. A crafted plugin package could therefore write outside the temporary extraction directory.The plugin package contract only needs regular files and directories, so rejecting all other member types closes this path without changing normal TeamHarness packages.
Validation
origin/main: fails after creatingoutside/pwned.txtgit apply --checkconfirms fix(teamharness): align QwenPaw and AgentSpec contracts #1035 remains independently applicablegit diff --check