Skip to content

✨ feat(builtin-tool-local-system): skip intervention for safe paths like /tmp#13232

Merged
Innei merged 3 commits into
canaryfrom
fix/skip-intervention-for-safe-paths
Mar 25, 2026
Merged

✨ feat(builtin-tool-local-system): skip intervention for safe paths like /tmp#13232
Innei merged 3 commits into
canaryfrom
fix/skip-intervention-for-safe-paths

Conversation

@Innei

@Innei Innei commented Mar 24, 2026

Copy link
Copy Markdown
Member

πŸ’» Change Type

  • ✨ feat

πŸ”— Related Issue

N/A

πŸ”€ Description of Change

Add a safe-path whitelist (/tmp, /var/tmp) to pathScopeAudit so that file operations targeting these ephemeral directories no longer trigger user intervention confirmation.

Previously, any path outside the working directory required a secondary confirmation dialog. This was unnecessarily disruptive for temporary/scratch paths that pose no security risk.

Key behavior:

  • Operations where all paths target safe directories β†’ no intervention
  • Operations mixing safe and non-safe paths β†’ still requires intervention
  • No change to working-directory-scoped operations

πŸ§ͺ How to Test

  • Added/updated tests
cd packages/builtin-tool-local-system && bunx vitest run src/__tests__/interventionAudit.test.ts

28 tests pass, including new cases for /tmp, /var/tmp, and mixed-path scenarios.

@vercel

vercel Bot commented Mar 24, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
lobehub Ready Ready Preview, Comment Mar 25, 2026 3:46pm

Request Review

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We've reviewed this pull request using the Sourcery rules engine

@lobehubbot

Copy link
Copy Markdown
Member

@arvinxx - This is a tool calling feature (builtin-tool-local-system intervention audit). Please take a look.

@codecov

codecov Bot commented Mar 24, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 69.23077% with 8 lines in your changes missing coverage. Please review.
βœ… Project coverage is 66.91%. Comparing base (a1e91ab) to head (bb7362c).
⚠️ Report is 4 commits behind head on canary.

Additional details and impacted files
@@           Coverage Diff           @@
##           canary   #13232   +/-   ##
=======================================
  Coverage   66.91%   66.91%           
=======================================
  Files        1867     1867           
  Lines      147855   147869   +14     
  Branches    16904    16906    +2     
=======================================
+ Hits        98942    98952   +10     
- Misses      48802    48806    +4     
  Partials      111      111           
Flag Coverage Ξ”
app 58.16% <57.14%> (+<0.01%) ⬆️
database 97.89% <ΓΈ> (ΓΈ)
packages/agent-runtime 89.61% <83.33%> (+<0.01%) ⬆️
packages/context-engine 83.59% <ΓΈ> (ΓΈ)
packages/conversation-flow 92.36% <ΓΈ> (ΓΈ)
packages/file-loaders 87.02% <ΓΈ> (ΓΈ)
packages/memory-user-memory 66.68% <ΓΈ> (ΓΈ)
packages/model-bank 99.85% <ΓΈ> (ΓΈ)
packages/model-runtime 84.53% <ΓΈ> (ΓΈ)
packages/prompts 74.60% <ΓΈ> (ΓΈ)
packages/python-interpreter 92.90% <ΓΈ> (ΓΈ)
packages/ssrf-safe-fetch 0.00% <ΓΈ> (ΓΈ)
packages/utils 90.41% <ΓΈ> (ΓΈ)
packages/web-crawler 88.82% <ΓΈ> (ΓΈ)

Flags with carried forward coverage won't be shown. Click here to find out more.

Components Coverage Ξ”
Store 66.07% <63.63%> (-0.01%) ⬇️
Services 49.57% <33.33%> (-0.01%) ⬇️
Server 68.13% <ΓΈ> (+<0.01%) ⬆️
Libs 43.20% <ΓΈ> (ΓΈ)
Utils 91.01% <ΓΈ> (ΓΈ)
πŸš€ New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • πŸ“¦ JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

πŸ’‘ Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: faedd2f719

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with πŸ‘.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread packages/builtin-tool-local-system/src/interventionAudit.ts Outdated
@arvinxx

arvinxx commented Mar 25, 2026

Copy link
Copy Markdown
Member

Damn, there's a conflict @Innei β€” I already did this in #13234


This comment was translated by Claude.

Original Content

θ‰Ή 冲ηͺδΊ† @Innei ζˆ‘εœ¨ #13234 θΏ™ι‡ŒεšδΊ†

Innei added 3 commits March 25, 2026 23:36
…ike /tmp

Add SAFE_PATH_PREFIXES whitelist to bypass user confirmation for
file operations targeting ephemeral directories (/tmp, /var/tmp).
@Innei

Innei commented Mar 25, 2026

Copy link
Copy Markdown
Member Author

@codex review it

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

πŸ’‘ Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: bb7362c559

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with πŸ‘.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +88 to +89
if (toolScope && !isPathWithinWorkingDirectory(toolScope, workingDirectory, workingDirectory)) {
return true;

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Apply safe-path exemption to scope arguments

The new early return on toolScope forces intervention before the safe-path audit runs, so calls that rely on scope (for example globFiles with scope: '/tmp' and a relative pattern) can never benefit from the /tmp//var/tmp exemption. This is a regression from previous behavior and contradicts the commit’s intended rule that operations targeting only safe paths should skip intervention.

Useful? React with πŸ‘Β / πŸ‘Ž.

@Innei Innei merged commit 84674b1 into canary Mar 25, 2026
34 checks passed
@Innei Innei deleted the fix/skip-intervention-for-safe-paths branch March 25, 2026 17:38
@lobehubbot

Copy link
Copy Markdown
Member

❀️ Great PR @Innei ❀️

The growth of project is inseparable from user feedback and contribution, thanks for your contribution! If you are interesting with the lobehub developer community, please join our discord and then dm @arvinxx or @canisminor1990. They will invite you to our private developer channel. We are talking about the lobe-chat development or sharing ai newsletter around the world.

ONLY-yours added a commit that referenced this pull request Mar 27, 2026
# πŸš€ release: 20260326

This release includes **91 commits**. Key updates are below.


- **Agent can now execute background tasks** β€” Agents can perform
long-running operations without blocking your conversation.
[#13289](#13289)
- **Better error messages** β€” Redesigned error UI across chat and image
generation with clearer explanations and recovery options.
[#13302](#13302)
- **Smoother topic switching** β€” No more full page reloads when
switching topics while an agent is responding.
[#13309](#13309)
- **Faster image uploads** β€” Large images are now automatically
compressed to 1920px before upload, reducing wait times.
[#13224](#13224)
- **Improved knowledge base** β€” Documents are now properly parsed before
chunking, improving retrieval accuracy.
[#13221](#13221)

### Bot Platform

- **WeChat Bot support** β€” You can now connect LobeChat to WeChat, in
addition to Discord.
[#13191](#13191)
- **Richer bot responses** β€” Bots now support custom markdown rendering
and context injection.
[#13294](#13294)
- **New bot commands** β€” Added `/new` to start fresh conversations and
`/stop` to halt generation.
[#13194](#13194)
- **Discord stability fixes** β€” Fixed thread creation issues and Redis
connection drops.
[#13228](#13228)
[#13205](#13205)

### Models & Providers

- **GLM-5** is now available in the LobeHub model list.
[#13189](#13189)
- **Coding Plan providers** β€” Added support for code planning assistant
providers. [#13203](#13203)
- **Tencent Hunyuan 3.0 ImageGen** β€” New image generation model from
Tencent. [#13166](#13166)
- **Gemini content handling** β€” Better handling when Gemini blocks
content due to safety filters.
[#13270](#13270)
- **Claude token limits fixed** β€” Corrected max window tokens for
Anthropic Claude models.
[#13206](#13206)

### Skills & Tools

- **Auto credential injection** β€” Skills can now automatically request
and use required credentials.
[#13124](#13124)
- **Smarter tool permissions** β€” Built-in tools skip confirmation for
safe paths like `/tmp`.
[#13232](#13232)
- **Model switcher improvements** β€” Quick access to provider settings
and visual highlight for default model.
[#13220](#13220)

### Memory

- **Bulk delete memories** β€” You can now delete all memory entries at
once. [#13161](#13161)
- **Per-agent memory control** β€” Memory injection now respects
individual agent settings.
[#13265](#13265)

### Desktop App

- **Gateway connection** β€” Desktop app can now connect to LobeHub
Gateway for enhanced features.
[#13234](#13234)
- **Connection status indicator** β€” See gateway connection status in the
titlebar. [#13260](#13260)
- **Settings persistence** β€” Gateway toggle state now persists across
app restarts. [#13300](#13300)

### CLI

- **API key authentication** β€” CLI now supports API key auth for
programmatic access.
[#13190](#13190)
- **Shell completion** β€” Tab completion for bash/zsh/fish shells.
[#13164](#13164)
- **Man pages** β€” Built-in manual pages for CLI commands.
[#13200](#13200)

### Security

- **XSS protection** β€” Sanitized search result image titles to prevent
script injection.
[#13303](#13303)
- **Workflow hardening** β€” Fixed potential shell injection in release
automation. [#13319](#13319)
- **Dependency update** β€” Updated nodemailer to address security
advisory. [#13326](#13326)

### Bug Fixes

- Fixed skill page not redirecting correctly after import.
[#13255](#13255)
[#13261](#13261)
- Fixed token counting in group chats.
[#13247](#13247)
- Fixed editor not resetting when switching to empty pages.
[#13229](#13229)
- Fixed manual tool toggle not working.
[#13218](#13218)
- Fixed Search1API response parsing.
[#13207](#13207)
[#13208](#13208)
- Fixed mobile topic menus rendering issues.
[#12477](#12477)
- Fixed history count calculation for accurate context.
[#13051](#13051)
- Added missing Turkish translations.
[#13196](#13196)

### Credits

Huge thanks to these contributors:

@bakiburakogun @hardy-one @Zhouguanyang @sxjeru @hezhijie0327 @arvinxx
@cy948 @CanisMinor @Innei @lijian @lobehubbot @neko @rdmclin2
@rivertwilight @tjx666
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants