github / github/copilot-cli

Permission scanner misclassifies git -L arguments and shell command text as directory paths

未关闭
#4,221 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
area:permissions
主要语言
Shell
星标
11.2k
派生
1.9k
平均合并
14 小时 16 分钟
30 天内合并 PR
6

描述

### Describe the bug

Copilot CLI incorrectly flags parts of a shell command as directory access candidates when running `git log -L ...` with a search expression that starts with `/`.

In my case, the permission prompt displayed a synthetic "path" composed of:

- the `git log -L` search expression
- a source file path
- trailing shell text such as `&& printf`

This is not a real filesystem path. It appears the permission scanner is lexically collecting slash-prefixed command arguments and adjacent shell text, then presenting the result as an "Allow directory access" prompt.

### Affected version

GitHub Copilot CLI 1.0.73

### Steps to reproduce the behavior

Run a shell command shaped like this:

```bash
cd /REPO_ROOT && printf '%s\n' '---marker---' && git --no-pager log --oneline -L '/requestMatchers(HttpMethod).GET, "/some-route"/,+1:/project-module/src/main/java/com/example/security/SecurityConfig.java'
```

Then ask Copilot CLI to execute it under normal permissions.

### Actual behavior

Copilot CLI shows an **Allow directory access** prompt and presents a "path" that is actually a mixture of:

- the `-L` search expression
- the Java source path
- trailing shell tokens such as `&& printf`

Example of the misclassified candidate shape:

```text
/requestMatchers(HttpMethod).GET, "/some-route"/,+1:/project-module/src/main/java/com/example/security/SecurityConfig.java && printf
/**
/requestMatchers(HttpMethod).GET,
/\*\*
/,+1:/project-module/src/main/java/com/example/security/SecurityConfig.java
```

This is not a valid directory path and should not be treated as one.

### Expected behavior

Copilot CLI should not interpret `git -L` expressions or adjacent shell command text as filesystem paths.

If path scanning is needed, it should distinguish between:

- actual filesystem arguments
- regex/search expressions
- shell syntax and chained commands

### Impact

This causes unnecessary permission prompts on normal investigation commands and interrupts the workflow.

### Additional context

This looks related to other permission/path misclassification issues, especially cases where slash-prefixed strings or URL-like arguments are treated as local paths.

贡献指南

打开贡献指南

调研方向

使用提供的 shell 命令重现权限提示,然后跟踪 CLI 权限扫描器,该扫描器从 git -L 参数和链接的 shell 文本中收集路径候选项。将候选项列表与实际的文件系统参数进行比较,并验证搜索表达式和末尾的 shell token 不再产生目录访问提示。

由索引模型根据 Issue 内容生成。

评估

技术栈
git, shell
领域
cli, security
Issue 类型
缺陷
难度
3/5
预计耗时
1-2 天
活跃度
冷清
描述清晰度
基本清楚
新手友好度
55/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。