Conversation
Allow-always could store powershell.exe /c and bash -l -c as reusable rules because those spellings were not treated as inline shells. - Treat PowerShell /c, /command, and colon-attached forms as wrappers - Treat POSIX -c, --command, and -lc in any argument after the shell name - Keep bash script.sh and bash -l script.sh bindable Signed-off-by: Sebastien Tardif <SebTardif@ncf.ca>
|
🦞👀 Pull request received. I will update this pull request when review starts. ClawSweeper review completeClawSweeper finished reviewing this revision. The review result is being finalized. |
|
Codex review: needs real behavior proof before merge. Reviewed October 1, 2026, 4:47 PM ET / 20:47 UTC (Revision 23). ClawSweeper reviewWhat this changesThe branch expands PowerShell, Bash, and fish command detection so inline shell commands require individual approval while direct script invocations remain reusable. Merge readiness⛔ Blocked before merge - 4 items remain This PR remains useful: current main and the latest release retain the older classifier. The pinned head resolves the concrete earlier parser findings, but production-boundary approval proof remains incomplete. Priority: P1 Review scores
Verification
How this fits togetherWindows execution approvals classify incoming command arguments before matching saved rules or presenting an approval dialog. The resulting authorization is rechecked before the Windows node launches a process. flowchart TD
A[Gateway command arguments] --> B[Shell command classification]
B --> C{Reusable command?}
C -->|Yes| D[Saved approval rules]
C -->|No| E[Individual approval]
D --> F[Policy revalidation]
E --> F
F --> G[Windows process execution]
Before merge
Agent review detailsSecurityNone. Review metrics
Merge-risk optionsMaintainer options:
Technical reviewBest possible solution: Keep classification in the existing approval binder, preserve direct-script reuse, and verify the accepted inert-rule upgrade behavior through the real execution boundary. Do we have a high-confidence way to reproduce the issue? Yes, source establishes that current main misses PowerShell /c and Bash -l -c before reusable binding; supplied native traces corroborate host semantics. This review did not execute a current-main reproduction. Is this the best way to solve the issue? Yes, repairing the existing classifier is the narrowest maintainable path, and the concrete earlier findings are resolved. Production-boundary and upgrade proof are still needed to establish merge readiness. AGENTS.md: found and applied where relevant. Codex review notes: model internal, reasoning medium; reviewed against 76ab839973aa. LabelsLabel changes: No label changes. Label justifications:
EvidenceWhat I checked:
Likely related people:
Rank-up movesOptional improvements that raise the rating; they are not merge blockers.
Rating scale
Overall follows the weaker of proof and patch quality. Workflow
HistoryReview history (22 earlier review cycles; latest 8 shown)
|
Signed-off-by: Sebastien Tardif <SebTardif@ncf.ca>
|
Global triage: HOLD_FOR_AUTHOR. Take confidence 5%; recommendation confidence 99%; effort medium; risk high. Three verified parsing gaps block this security-boundary change:
Please implement operand-aware, shell-specific option parsing and add saved-rule replay coverage for combined flags, post-script arguments, PowerShell The PR must declare and run The red hosted lanes are not linked to this patch: Core failed an unrelated bounded-cancellation test, the E2E shards failed during shared setup initialization, and CI Gate is derivative. They do not replace the missing MXC proof. |
bash script.sh -c value and pwsh -File script.ps1 /c value are direct script invocations. Scanning past the script operand classified those arguments as inline shell commands and blocked reusable approval. Inline -c and /c before the script operand still stay one-time. Shared tests: 4125 passed, 32 skipped. Tray tests: 3067 passed, 5 failed on the LF source-contract mismatch tracked in openclaw#1518. Signed-off-by: Sebastien Tardif <SebTardif@ncf.ca>
A single-dash letter cluster that contains c, such as -ec or -ce, is an inline shell command. The next argument is the payload. Scanning still stops at the script name, so bash script.sh -ec value stays a direct script. Shared tests: 4128 passed, 32 skipped. Tray tests: 3067 passed, 5 failed on the LF source-contract mismatch tracked in openclaw#1518. Signed-off-by: Sebastien Tardif <SebTardif@ncf.ca>
A combined flag is inline only when it contains a lowercase c. Uppercase C is noclobber, so bash -C and bash -eC script.sh stay direct scripts. bash -ec remains inline. Exact POSIX flags are case-sensitive, so -C does not match -c. Shared tests: 4129 passed, 32 skipped. Tray tests: 3067 passed, 5 failed on the LF source-contract mismatch tracked in openclaw#1518. Signed-off-by: Sebastien Tardif <SebTardif@ncf.ca>
|
HOLD_FOR_AUTHOR at I ran harmless native commands with profiles disabled, bounded completion and task-owned scripts/directories. In an owned working directory containing a directory literally named The old scanner reached Both independent reviewers used the same prompt and agree:
Single-reviewer findings and scope disposition:
The last two are portability/adjacent-contract follow-up evidence, not a request to expand this lane. The reported WSL proxy, Unicode dash, log-only upgrade explanation and unused payload-tail findings are also preexisting or outside the live changed boundary, so no speculative redesign or patches were made for them. Additional native controls: One separate introduced cross-shell regression is source-backed, not native-fish proof: the case-sensitive flag set applies to Please keep the repair in this PR's classifier owner, with shell-specific switch position, operand arity, termination and PowerShell prefix rules backed by actual CLI semantics, rather than another special-case token patch. Add binder/saved-rule regressions for the newly weakened case and direct-script controls. I confirmed that a missed Bash wrapper allows slash/backslash-normalized argument patterns to match two payloads with different actual semicolon behavior. That observation is native shell plus helper-level matching evidence, not Gateway-to-node final-I/O proof. The intended upgrade behavior enforces the existing documented one-time shell policy: recognized inline wrappers have no reusable identity or saved-rule matches. Existing records remain untouched; this is not permission to delete, rewrite or keep unsafe rules. Validation is green but does not override these source blockers. Original head: full build passed, Shared 4129 passed / 32 skipped, Tray 3072 passed, focused exec 339 passed. Unpushed normal integration Live MXC 0.8.0 probe still reports |
A PowerShell option value named -File stopped classification before a later -c, so the binder could save that inline command. A positional script made a later /c look like a host switch. fish -C is an init command and stays a wrapper. bash -C stays noclobber. Validation: ./build.ps1 exit 0. Shared 4132 passed, 32 skipped. ExecApprovalV2NormalizationTests 120 passed. Tray 3067 passed and 5 failed, the LF source-contract mismatch in openclaw#1518. Signed-off-by: Sebastien Tardif <SebTardif@ncf.ca>
Core and CLI failed only RunAsync_OutputDrainIsBoundedAndPreservesFinalFragments_WhenDescendantRetainsHandles. The drain took 1547 ms against a 1 second bound. That test is not in this change. Signed-off-by: Sebastien Tardif <SebTardif@ncf.ca>
pwsh binds -wd as the WorkingDirectory alias and unique prefixes such as -wo and -wor the same way. An operand named -File was classified as file mode, so a later -c could be saved as an allow-always rule. Consume those forms, and the other documented value aliases, before the file check. Normalization tests cover -wd, -wo, -wor, /wd, -w, and -ep, including the binder and the allow-always identity. Native pwsh -wd -File -c and -wo -File -c still print the inline command. Signed-off-by: Sebastien Tardif <SebTardif@ncf.ca>
-i and -in match Interactive, which takes no argument. The value-option prefix matcher treated them as InputFormat and skipped the following -c, so the inline command could be saved as an allow-always rule. A prefix that also matches a no-value switch stays a switch. -inp still consumes its format value. Normalization tests cover -i, -in, and -int with the binder and the allow-always identity, and -inp Text -c still stays inline. Signed-off-by: Sebastien Tardif <SebTardif@ncf.ca>
Signed-off-by: Sebastien Tardif <SebTardif@ncf.ca>
Signed-off-by: Sebastien Tardif <SebTardif@ncf.ca>
Signed-off-by: Sebastien Tardif <SebTardif@ncf.ca>
pwsh --InputFormat and --c still hid a later command. Windows PowerShell -i and -in are InputFormat, not Interactive, and a positional token with more arguments is command text rather than a script. A lone powershell script.ps1 stays a script. EncodedCommand operands stay consumed so they are not resolved as executables. Signed-off-by: Sebastien Tardif <SebTardif@ncf.ca>
Signed-off-by: Sebastien Tardif <SebTardif@ncf.ca>
|
October 1 reassessment of frozen head The long The current repair still introduces these two concrete regressions. I ran the real installed PowerShell hosts with profiles disabled, harmless markers, bounded completion and task-owned files: The previous flat PowerShell scan reached the later These are explicit File-mode invocations, not positional command text. Recognize the actual host's File prefixes before positional handling. The full Two already-reported affected grammar gaps also remain and are not newly attributed to this delta: Bash Keep the repair in the classifier's host-specific operand/termination contract, with binder/normalization regression cases and allowed direct-script controls. No maintainer parser patch, branch push, storage migration or speculative downstream authorization redesign was made. Both models agree: HIGH consensus (actual returned model metadata, identical frozen prompt):
One-model severity findings: LOW consensus:
The Bash native/helper result is independently reproduced, but no persisted-rule Gateway/process-I/O authority proof was run, so the CRITICAL model label is not repeated as a newly verified production exposure. Extra proposed token-table entries, Unicode/unknown-dash cases and attached fish forms are not accepted as new blockers without scoped evidence, and are not permission for a speculative parser or storage rewrite. This was a direct Current main is
Test projects were built/restored first; these are complete floor results, not focused retries. The local floor had no global-MCP capture or FileStream failures. The immediate prior hosted Shipped MXC |
pwsh strips one dash before alias lookup, so --wd is -wd and must be consumed before -File. Windows PowerShell accepts -fi and -fil as -File. Those prefixes stay script invocations, including when another argument follows. Signed-off-by: Sebastien Tardif <SebTardif@ncf.ca>
|
Narrow native follow-up at current
The already-identified Windows PowerShell positional branch also still reproduces: That false-negative predates the PR, but the newly authored branch/comment still infers script mode from one remaining argument. One argument can be command text. The unchanged Bash Positive controls on this exact head: Please finish the remaining classifier-owned alias/default-command repair and post a stable candidate for the next validation/proof pass. No downstream authorization or stored-rule redesign is requested. This comment replaces those repaired c470 findings as current status rather than competing with your active branch edits. Only |
of is the OutputFormat alias and is not a prefix of OutputFormat. pwsh -of Text -c runs the inline command, but the scanner stopped at Text and allowed a reusable identity. Consume -of and --of before the next token. Signed-off-by: Sebastien Tardif <SebTardif@ncf.ca>
|
Narrow current-head check at
Exact-head fixed controls: Please finish this classifier-owned default-command boundary and provide a stable candidate for the next floor/proof pass. No Bash/fish expansion, stored-rule redesign or downstream authorization changes are requested. This pass ran only the Shared dependency build (exit 0) and six harmless native/binder controls, with profiles disabled, task-owned files/cwd and bounded completion. Runtime used normal unpushed integration |
|
I am preparing one local, uncommitted correction against 13441c6 for the sole Windows PowerShell implicit-command argument-count guard, with explicit File and pwsh positional-script controls. No alias grammar, Bash/fish, storage or protocol expansion, and no branch push or fixture launch. Please keep this candidate stable while I validate an applyable two-file patch; if you are already repairing this boundary, reply and I will stop rather than compete. Native Windows PowerShell treats implicit positional text as evaluated Command mode; explicit File mode remains the reusable script control. |
Signed-off-by: Sebastien Tardif <SebTardif@ncf.ca>
|
Validated two-file maintainer patch for the sole Windows PowerShell positional-command guard. No commit or push was made. The patch is against The only production change removes the second-argument requirement. Native Windows PowerShell 5.1 evaluates a single positional command string, including an implicit script-path string. Both now remain runnable one-time but cannot obtain durable approval. Explicit Windows PowerShell Validation of uncommitted patch SHA-256
The first full Shared run failed Apply the following patch locally with diff --git a/src/OpenClaw.Shared/ExecApprovals/ExecShellWrapperNormalizer.cs b/src/OpenClaw.Shared/ExecApprovals/ExecShellWrapperNormalizer.cs
index 14d0f2c4..ac0a1c48 100644
--- a/src/OpenClaw.Shared/ExecApprovals/ExecShellWrapperNormalizer.cs
+++ b/src/OpenClaw.Shared/ExecApprovals/ExecShellWrapperNormalizer.cs
@@ -190,9 +190,9 @@ internal static class ExecShellWrapperNormalizer
if (!t.StartsWith('-') && !t.StartsWith('/'))
{
- // Windows PowerShell joins a positional token and everything
- // after it into command text. A lone positional stays a script.
- if (windowsPowerShell && i + 1 < command.Count)
+ // Windows PowerShell evaluates positional input as command text,
+ // even one token. Explicit File mode was handled above.
+ if (windowsPowerShell)
return t;
return null;
}
diff --git a/tests/OpenClaw.Shared.Tests/ExecApprovalV2NormalizationTests.cs b/tests/OpenClaw.Shared.Tests/ExecApprovalV2NormalizationTests.cs
index 5fe408b2..cc0ac650 100644
--- a/tests/OpenClaw.Shared.Tests/ExecApprovalV2NormalizationTests.cs
+++ b/tests/OpenClaw.Shared.Tests/ExecApprovalV2NormalizationTests.cs
@@ -235,6 +235,51 @@ public class ExecApprovalV2NormalizationTests
Assert.NotNull(bound);
}
+ [Theory]
+ [InlineData("Write-Output marker")]
+ [InlineData("Write-Output marker; Write-Output second")]
+ [InlineData("script.ps1")]
+ public void Normalizer_WindowsPowerShellSinglePositional_IsOneTimeCommand(string command)
+ {
+ string[] argv = ["powershell.exe", "-NoProfile", command];
+ AssertWrapper(argv, command);
+ Assert.Null(ExecReusableCommandBinder.TryBind(argv, cwd: null, env: null, out var failure));
+ Assert.Equal(ExecReusableCommandBinder.BindFailure.ShellWrapper, failure);
+
+ var outcome = ExecApprovalV2Normalizer.Normalize(Req(argv));
+ Assert.True(outcome.IsResolved);
+ Assert.Null(outcome.Identity!.ReusableCommand);
+ Assert.Empty(outcome.Identity.AllowAlwaysPatterns);
+ Assert.Empty(outcome.Identity.AllowlistResolutions);
+ }
+
+ [Theory]
+ [InlineData("powershell.exe", "-File")]
+ [InlineData("powershell.exe", "-fi")]
+ [InlineData("powershell.exe", "-InputFormat", "Text", "-File")]
+ [InlineData("pwsh.exe")]
+ public void Normalizer_SingleScriptInFileMode_RemainsReusable(string executable, params string[] options)
+ {
+ var directory = Directory.CreateTempSubdirectory("exec-single-script");
+ try
+ {
+ var tool = Path.Combine(directory.FullName, executable);
+ File.WriteAllBytes(tool, [0x4D, 0x5A]);
+ var argv = new List<string> { tool, "-NoProfile" };
+ argv.AddRange(options);
+ argv.Add("script.ps1");
+
+ Assert.False(ExecShellWrapperNormalizer.Extract(argv).IsWrapper);
+ var bound = ExecReusableCommandBinder.TryBind(argv, cwd: null, env: null, out var failure);
+ Assert.Equal(ExecReusableCommandBinder.BindFailure.None, failure);
+ Assert.NotNull(bound);
+ }
+ finally
+ {
+ directory.Delete(recursive: true);
+ }
+ }
+
[Fact]
public void Normalizer_FishInitCommand_IsWrapper()
{
@@ -1078,15 +1123,14 @@ public class ExecApprovalV2NormalizationTests
}
[Fact]
- public void ResolveForAllowlist_DirectPowerShellScriptFile_NotFailClosed()
+ public void ResolveForAllowlist_WindowsPowerShellPositionalScript_ResolvesCommandText()
{
- // Direct exec path: ["powershell", "script.ps1"] — no inline flag, no -EncodedCommand.
- // DirectExecUsesEncodedCommand must not trigger; must resolve as a single resolution.
+ // This historical resolver inspects the command text, not durable eligibility.
var resolutions = ExecCommandResolver.ResolveForAllowlist(
["powershell", "script.ps1"],
evaluationRawCommand: null, cwd: null, env: null);
Assert.Single(resolutions);
- Assert.Contains("powershell", resolutions[0].ExecutableName, StringComparison.OrdinalIgnoreCase);
+ Assert.Equal("script.ps1", resolutions[0].ExecutableName);
}
[Fact] |
powershell Get-Date runs as command text, but a lone positional was saved as a script. Command text is now inline, including when nothing follows it. A lone script.ps1 path stays a script. Signed-off-by: Sebastien Tardif <SebTardif@ncf.ca>
A lone script name is still implicit -Command. Guessing from a .ps1 suffix left that command bindable. Explicit -File remains the reusable script form. Signed-off-by: Sebastien Tardif <SebTardif@ncf.ca>
What Problem This Solves
Fixes: Allow always can save PowerShell
/c, Bash-l -cand combined-ecinline commands as reusable rules, allowing later commands to run without a fresh prompt.User Impact
Intended impact: inline commands stay one-time, while direct programs, direct scripts and Bash noclobber
-Cremain reusable. Previously saved rules for newly recognized inline commands remain on disk but no longer authorize those runs; operators must approve them individually.October 1 assessment at
c470a0c2: HOLD_FOR_AUTHOR for current reproduced regressions, not the old September 30 literal cases. The long WorkingDirectory/File-value case, positional pwsh scripts, Command prefixes and literal fish init commands are repaired. Double-dash value aliases and-ofstill hide inline pwsh commands; explicit Windows PowerShell-fi/-filscripts are newly misclassified. The affected Windows PowerShell positional branch also still misses a sole command-string argument.Why This Change Was Made
The classifier is the existing reusable-command binder's shell eligibility gate. Correct classification enforces the already-documented one-time shell policy without changing stored records. The literal Bash cluster, post-script and explicit PowerShell File cases identified on September 25 are addressed in this head.
This head repairs those three classifier holes. A value of
-WorkingDirectorynamed-Fileis an operand, so a later-cstays inline. A positional script stops switch scanning, sopwsh script.ps1 /c valuestays a direct script.fish -Candfish --init-commandstay init commands.bash -Cstays noclobber.Follow-up
53014a78c4b4c9116117e9d9121ca99b63d5374balso consumes PowerShell working-directory aliases and unique prefixes before the file check.pwsh -wd -File -c,-wo -File -c, and-wor -File -cstay inline. A real directory followed by-File script.ps1stays a script. Documented value aliases-wand-epconsume their operand the same way.Evidence
Frozen contributor head assessed:
c470a0c2ae53047b764704f48de26d33c7ad8aac. It is source-identical toc562cad9956f7924d30a9b242f715ee2ac2992c8; the last commit only retriggered CI.Normal unpushed candidate
799090aa4a6fd1ede0b51479a383b195d1ce0926integrates this author head with mainf4122a8927e7cd452d166a23c0d5e30299f94368. Classifier and tests match the frozen author head exactly. Originale2d175c0and earlier unpushed integration6559a590are preserved in local history; their September 30 evidence is historical, not proof for this update. No contributor push, force-push, supersession or merge was performed.Native PowerShell 5.1/7 and Git Bash probes re-ran the exact prior cases and the new alias/File-prefix cases. The repaired literals pass;
pwsh --if Text -c,--wd <owned-directory> -cand-of Text -cexecute inline but bind, while Windows PowerShell-fi/-filwith a script argument executes a direct script but returns ShellWrapper.The authoritative current-project identical-prompt pair returned actual model metadata
claude-opus-5.5andgpt-6-astra(long_context). Both identify the alias regression, lone Windows PowerShell positional-command gap and File-prefix compatibility regression. No nested reviewers, model fallback or extra panel ran. Each accepted issue was checked against native host behavior and the live binder/normalizer/matcher/runner chain.Historical September 30 autoreview at
e2d175c0exited 1 for the File-value and implicit-script cases. Those literal cases were rechecked and repaired in this update; that old verdict is not presented as a current review. The current direct pair and native reproductions still do not clear source.Change Type
Scope
winnodeRequired proof pools
windows-wsl-mxc: exec approval eligibility controlssystem.run; non-skipping MXC Gateway-to-node proof is mandatory.windows-wsl-gateway-e2e: prove saved-rule denial before process I/O and an allowed direct-command positive control through the real Gateway.windows-winui-interactive: verify the changed Allow always availability and operator-visible one-time/denial outcome in an isolated current-head app.These declarations replace the invalid prior
nonedeclaration. They schedule proof, not claim execution. No shared lifecycle lane was reserved or started because source review did not clear.Validation
October 1 current-candidate floor:
799090aa, frozen authorc470a0c2integrated with mainf4122a89. Test projects were built/restored before the no-restore runs. Process-local task-owned C: TEMP/TMP and isolated tray data were used; no global environment, source ACL or unrelated process was modified..\build.ps1dotnet test .\tests\OpenClaw.Shared.Tests\OpenClaw.Shared.Tests.csproj --no-restoredotnet test .\tests\OpenClaw.Tray.Tests\OpenClaw.Tray.Tests.csproj --no-restoredotnet test .\tests\OpenClaw.Shared.Tests\OpenClaw.Shared.Tests.csproj --no-restore --filter "FullyQualifiedName~ExecApprovalV2NormalizationTests|FullyQualifiedName~ExecReusableCommandBinderTests|FullyQualifiedName~ExecApprovalsCoordinatorTests|FullyQualifiedName~SystemCapabilityV2|FullyQualifiedName~ExecArgPatternTests".\scripts\validate-mxc-e2e.ps1without-AllowSkipNo local suite failure occurred in this floor, including no global-MCP capture or FileStream failure. The immediate prior hosted c562 run 36906744667 failed
LocalAiApiCredentialStoreTests.ConcurrentCreationConvergesOnOneCredentialwith anIOExceptionon its own credential fixture file; CI Gate was derivative. That is diagnosed historical evidence, not an unexplained flake or current-head pass. The exact c470 run 36909036529 subsequently completed successfully, including Setup/Connect E2E and CI Gate. These green hosted gates do not override the independently reproduced source regressions or satisfy missing custom authority-chain/MXC proof.Historical contributor and September 30 validation, retained for attribution
Windows x64, isolated process-local TEMP/TMP and tray data;
OPENCLAW_REPO_ROOTpoints to this worktree. Shared/Tray were first restored and built before relying on--no-restore.e2d175c0final result6559a590result.\build.ps1dotnet test .\tests\OpenClaw.Shared.Tests\OpenClaw.Shared.Tests.csproj --no-restoredotnet test .\tests\OpenClaw.Tray.Tests\OpenClaw.Tray.Tests.csproj --no-restoredotnet test .\tests\OpenClaw.Shared.Tests\OpenClaw.Shared.Tests.csproj --no-restore --filter "FullyQualifiedName~ExecApprovalV2NormalizationTests|FullyQualifiedName~ExecReusableCommandBinderTests|FullyQualifiedName~ExecApprovalsCoordinatorTests|FullyQualifiedName~SystemCapabilityV2|FullyQualifiedName~ExecArgPatternTests".\scripts\validate-mxc-e2e.ps1without-AllowSkipHead
7b42fe012e17973770fe544e6cbad1f607ebfadf:./build.ps1exit 0. Shared passed 4132, failed 0, skipped 32, total 4164.ExecApprovalV2NormalizationTestspassed 120. Tray passed 3067, failed 5, total 3072. Those five are the LF source-contract checks in #1518 (setup-code SSH fields, diagnostics copy glyph, voice dialog routing, and two capabilities-review checks). This commit does not change those files.Head
53014a78c4b4c9116117e9d9121ca99b63d5374b:./build.ps1exit 0. Shared passed 4133, failed 0, skipped 32, total 4165.ExecApprovalV2NormalizationTestspassed 121. Tray passed 3067, failed 5, total 3072. The same five LF source-contract checks failed. This commit does not change those files..\scripts\validate-mxc-e2e.ps1was not run.One earlier original-head Shared run failed
McpHttpServerTelemetryTests.ShutdownWhileWaitingForHandler_RecordsShutdownNotBusyOrTimeoutat its two-second telemetry observation deadline. Its exact filtered retry passed 1/1, then the entire build/Shared/Tray closeout above passed. No parser change or telemetry workaround was made. The earlier contributor-reported Tray failures did not reproduce here; they are not represented as current failures.Hosted CI at the actual PR head is separate from these local results: run 36278257616 failed Setup/Connect at wizard restart,
GATEWAY_RESTART_PREPARATION_REFUSED, because another OpenClaw process owned SQLitestate-lifecycle; CI Gate failed derivatively. This was diagnosed from the failed log and setup journal, not classified as an unexplained flake. No hosted gate was bypassed or made green by local validation.Real Behavior Proof
c470a0c2, runtime on identical-parser integration799090aa.pwsh -NoProfile -NonInteractive -NoLogo --if Text -c "Write-Output pr1511-inline"; also-of Textand--wd <owned-directory>before the same-c. For File controls,powershell.exe -NoProfile -NonInteractive -NoLogo -fi <owned-script.ps1> valueand-fil.pr1511-inline, but current Extract returnsIsWrapper=falseand TryBind returns non-null/BindFailure.None. Each abbreviated explicit File case exits 0, printspr1511-direct-scriptand itsvalueargument, but Extract returnsIsWrapper=trueand binder returnsShellWrapper. Full-Fileremains direct.-WorkingDirectory -File -cnow correctly fails binding withShellWrapper; positionalpwsh script.ps1 /c valuenow correctly binds;/coon both PowerShell hosts is now recognized. A sole Windows PowerShell positional command string still executes two markers but binds, so argument count is not a correct mode boundary.-C/-eC,--and post-script operands stay direct. Existing-o/-O/+eand-euo pipefailbefore-cremain missed. The escaped-semicolon/slash-semicolon argument-pattern difference still reproduces at helper/native level. Literal fish init-command classification is repaired, but no native fish run is claimed.wxc-exec.exeversion0.8.0+7dac1a9, fresh--probereturnstier=base-container,needsDaclAugmentation=false, warnings empty. This is host capability only, not non-skipping containment validation.Yes/No/N/A): N/A; bounded copied native output described above, no current UI screenshot or public artifact claimed.Earlier contributor native proof, retained as historical evidence only
53014a78c4b4c9116117e9d9121ca99b63d5374b.pwsh -NoProfile -wd -File -c "Write-Output pr1511-wd"andpwsh -NoProfile -wo -File -c "Write-Output pr1511-wo", then the same argv throughExtract,TryBind, andExecApprovalV2Normalizer.Normalize.Extractreturns a wrapper whose payload isGet-Datefor-wd,-wo,-wor, and/wdwhen the operand is-Fileand-cfollows.TryBindreturnsBindFailure.ShellWrapper.NormalizeleavesReusableCommandnull andAllowAlwaysPatternsempty.pwsh -wd C:\temp -File script.ps1stays a script. The earlier-WorkingDirectorytrace on7b42fe012e17973770fe544e6cbad1f607ebfadfstill applies to the long name.-wdand-worun the inline command in native pwsh, and this head refuses a reusable allow-always identity for that argv. Native fish was not installed. Approval UI, a saved-rule replay through Gatewaysystem.run, and non-skipping MXC were not run.-Cas an init command. This head classifiesfish -Candfish --init-commandas wrappers. Native fish was not installed and was not run.0.8.0+7dac1a9, nativewxc-exec.exe --probe, reportstier=base-container,needsDaclAugmentation=false, no warnings on original and integration output. A capability probe is not containment E2E validation.Yes/No/N/A): N/A, copied bounded native output above; no screenshot or public artifact link claimed.tools/list/tools/callorwinnodediscovery/invocation, real isolated Gateway-to-node saved-rule denial before process I/O/direct positive control, and non-skipping MXC E2E. All remain required after author repair and serialized proof-lane reservation.Security Impact
Yes/No): NoYes/No): NoYes/No): NoYes/No): YesYes/No): NoYes, explain the risk and mitigation: the tested literal WorkingDirectory, fish and positional pwsh-script repairs work, but current alias operands still make inline pwsh reusable and abbreviated explicit WinPS File mode loses direct-script eligibility. Hold for author-owned classifier repair and exact-head authority-chain proof. No saved records are deleted or rewritten.Compatibility and Migration
Yes/No): No for previously saved newly recognized inline-shell rules; those records remain present but inert.Yes/No): NoYes/No): No automatic migration, deletion or rewrite is introduced.Review Conversations