Repository navigation
Fix: redact shell-snapshot credential leak on relay auth path - #196
SaraAbidHussain wants to merge 1 commit into
Conversation
features.shell_snapshot=false was only applied for the ChatGPT subscription auth path. The relay/API-key path never got this override, so Codex's shell-snapshot capture stayed enabled while the raw provider key sat in the process env — leaking it into run_dir/.../shell_snapshots/*.sh. Fixes sapientinc#84
|
Thank you, @SaraAbidHussain, for this fix and the clear root-cause analysis. We have reproduced the leak and confirmed your diagnosis. Our maintenance process is described here: The branch now goes to the maintainers' real-task validation stage, required here We are closing this source PR only because the change has moved into validation; this is not a rejection. |
|
Update: this shipped. Your change is on One finding from validation: openai-codex 0.147.0 ignores Thank you for your contribution, @SaraAbidHussain |
|
Thanks for the update, @Glen-SP. Glad to know it’s merged! I really appreciate the validation and the extra check around the codex 0.147.0 behavior. Good catch, and thanks again for the contribution credit! |
Summary
Fixes #84.
features.shell_snapshot=falsewas only applied on theChatGPT subscription auth path (
_SUBSCRIPTION_RUNTIME_OVERRIDES,gated behind
if subscription:inpraxist/plugins/agent_runtimes/codex_sdk/adapter.py). The relay/API-key path (
needs_relay(provider)) never picked it up, soCodex's shell-snapshot capture stayed on while the raw provider key
sat in that path's process env (
_client_process_env) — leaking itinto
runtime_state/.../shell_snapshots/*.sh.The smallest fix is to split
features.shell_snapshot=falseinto anew
_ALWAYS_ON_SAFETY_OVERRIDEStuple applied unconditionally,rather than extending the whole subscription-only bundle (which
also sets
mcp_servers={}— that would break MCP tools on therelay path, since they're actively used there via
mcp_configuration).Scope
praxist/plugins/agent_runtimes/codex_sdk/adapter.pyonly — no public contract changes.Verification
uv run python -m unittest discover -s tests -q— 3081 tests, 2 pre-existing unrelated failures (test_signal_set_records_permission_errors_and_process_lookup,test_all_praxist_modules_reload_under_coverage), no new failures.uv run python scripts/run_test_coverage.py unit --fail-under 90 --fail-under-statements 95— 92.29% total / 94.03% statement. The statement threshold isn't met, but only becausetests/product_usage/*fails to collect due to missing optional deps (fastapi,sqlalchemy) not installed by the default dev sync — a pre-existing environment gap unrelated to this change.uv run python scripts/run_test_coverage.py integration— ran clean.uv run python -m compileall -q praxist tests templates examples scripts— clean.uv run python scripts/build_docs_site.py— clean.git diff --check— clean.test_deepseek_uses_private_relay_configuration_and_closes_bothto assertfeatures.shell_snapshot=falseis present for the relay path. Verified the test catches the regression: reverted the fix locally, confirmed the test failed withAssertionError: 'features.shell_snapshot=false' not found in (...), then reapplied the fix and confirmed it passes.Checklist
.github/CONTRIBUTING.mdand the contribution terms inLICENSE.md.This addresses the root cause only. The run-completion scrub pass suggested in the issue is a reasonable defense-in-depth addition, happy to follow up with that as a separate PR if useful.