github / github/copilot-cli

Permission scanner misclassifies git -L arguments and shell command text as directory paths

Abierto
#4,221 0 comentarios 0 reacciones 0 asignados Ver en GitHub
area:permissions
Lenguaje dominante
Shell
Estrellas
11.2k
Forks
1.9k
Merge medio
14 h 16 min
PR fusionados (30 d)
6

Descripción

### Describe the bug

Copilot CLI incorrectly flags parts of a shell command as directory access candidates when running `git log -L ...` with a search expression that starts with `/`.

In my case, the permission prompt displayed a synthetic "path" composed of:

- the `git log -L` search expression
- a source file path
- trailing shell text such as `&& printf`

This is not a real filesystem path. It appears the permission scanner is lexically collecting slash-prefixed command arguments and adjacent shell text, then presenting the result as an "Allow directory access" prompt.

### Affected version

GitHub Copilot CLI 1.0.73

### Steps to reproduce the behavior

Run a shell command shaped like this:

```bash
cd /REPO_ROOT && printf '%s\n' '---marker---' && git --no-pager log --oneline -L '/requestMatchers(HttpMethod).GET, "/some-route"/,+1:/project-module/src/main/java/com/example/security/SecurityConfig.java'
```

Then ask Copilot CLI to execute it under normal permissions.

### Actual behavior

Copilot CLI shows an **Allow directory access** prompt and presents a "path" that is actually a mixture of:

- the `-L` search expression
- the Java source path
- trailing shell tokens such as `&& printf`

Example of the misclassified candidate shape:

```text
/requestMatchers(HttpMethod).GET, "/some-route"/,+1:/project-module/src/main/java/com/example/security/SecurityConfig.java && printf
/**
/requestMatchers(HttpMethod).GET,
/\*\*
/,+1:/project-module/src/main/java/com/example/security/SecurityConfig.java
```

This is not a valid directory path and should not be treated as one.

### Expected behavior

Copilot CLI should not interpret `git -L` expressions or adjacent shell command text as filesystem paths.

If path scanning is needed, it should distinguish between:

- actual filesystem arguments
- regex/search expressions
- shell syntax and chained commands

### Impact

This causes unnecessary permission prompts on normal investigation commands and interrupts the workflow.

### Additional context

This looks related to other permission/path misclassification issues, especially cases where slash-prefixed strings or URL-like arguments are treated as local paths.

Guía de contribución

Abrir la guía de contribución

Línea de trabajo

Reproduce la solicitud de permisos con el comando de shell proporcionado y, a continuación, sigue el escáner de permisos de la CLI que recopila candidatos de rutas a partir de los argumentos de git -L y del texto de shell encadenado. Compara la lista de candidatos con el argumento real del sistema de archivos y verifica que la expresión de búsqueda y los tokens de shell posteriores ya no produzcan solicitudes de acceso a directorios.

Escrito por el modelo de indexación a partir del texto del issue.

Evaluación

Stack tecnológico
git, shell
Área
cli, security
Tipo de issue
Error
Dificultad
3/5
Tiempo estimado
1-2 días
Estado de actividad
Tranquilo
Claridad
Bastante claro
Aptitud para principiantes
55/100

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.