Files
hermes-agent/tests/hermes_cli
beardthelion 67902dfa9d config: extend env-writer denylist to the full subprocess-execution class
The denylist in save_env_value is the fail-closed gate between the
dashboard's PUT /api/env surface (and every other env writer) and .env,
which lands in os.environ for every subprocess Hermes spawns. It covered
LD_PRELOAD, PYTHONPATH, PATH, EDITOR and GIT_SSH_COMMAND, but missed most
members of the class it states: env-driven git config injection
(GIT_CONFIG_PARAMETERS, GIT_CONFIG_COUNT, GIT_CONFIG_KEY_n/GIT_CONFIG_VALUE_n,
GIT_CONFIG_GLOBAL/SYSTEM), executed git helpers (GIT_SSH, GIT_ASKPASS,
GIT_EDITOR, GIT_SEQUENCE_EDITOR, GIT_PAGER, GIT_EXTERNAL_DIFF,
GIT_PROXY_COMMAND, GIT_TEMPLATE_DIR, GIT_DIR), credential-prompt helpers
(SSH_ASKPASS, SUDO_ASKPASS), shell init files (BASH_ENV, ENV, ZDOTDIR,
PROMPT_COMMAND, VIMINIT, EXINIT, MANPAGER), and interpreter/toolchain
injection (PERL5OPT/PERL5LIB/PERLLIB, RUBYOPT/RUBYLIB, PYTHONBREAKPOINT,
PYTHONCASEOK, CLASSPATH, JAVA_TOOL_OPTIONS/_JAVA_OPTIONS/JDK_JAVA_OPTIONS,
GOFLAGS, RUSTFLAGS).

GIT_CONFIG_KEY_n/GIT_CONFIG_VALUE_n pairs are unbounded, so a new
_ENV_VAR_NAME_DENY_PREFIXES tuple matches whole families by prefix:
LD_, DYLD_, GIT_CONFIG_. The check runs on the Windows-corrected policy
name, so mixed-case spellings are refused there while POSIX's inert
lowercase names stay writable.

git credential helpers and subprocess env construction already null
GIT_CONFIG_GLOBAL/SYSTEM and strip GIT_ASKPASS from child environments
for the same reason, so this closes the write surface those hygiene
paths assume.

Regression tests cover every denied name, the unbounded pairs, near-miss
names that must stay writable (GIT_COMMITTER_NAME, GIT_AUTHOR_NAME,
GIT_TERMINAL_PROMPT, POSIX-lowercase spellings), and Windows mixed-case
denial.
2026-09-20 00:08:36 -07:00
..