fix(seedgo): handler guard allows python3 -c, blocks cross-branch .py imports
Guard was too aggressive — blocked all <string>/<stdin> callers including branches' own agents running python3 -c. Now only blocks when a real .py file from a different branch imports handlers. 13 files updated. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.6
parent
696136e271
commit
a800e7919a
@@ -74,28 +74,7 @@ def _guard_branch_access():
|
||||
stack = inspect.stack()
|
||||
for frame in stack:
|
||||
if frame.filename in ("<string>", "<stdin>"):
|
||||
# Try to get the import line from the frame
|
||||
target_line = "unknown"
|
||||
if frame.code_context:
|
||||
target_line = frame.code_context[0].strip()
|
||||
raise ImportError(
|
||||
f"\n{'='*60}\n"
|
||||
f"ACCESS DENIED: Cross-branch handler import blocked\n"
|
||||
f"{'='*60}\n"
|
||||
f" Caller: interactive/script\n"
|
||||
f" Blocked: {target_line}\n"
|
||||
f"\n"
|
||||
f" Handlers are internal to their branch.\n"
|
||||
f" Use the module API instead:\n"
|
||||
f" from {MY_BRANCH}.apps.modules.<module> import <function>\n"
|
||||
f"\n"
|
||||
f" Example:\n"
|
||||
f" from {MY_BRANCH}.apps.modules.logger import logger\n"
|
||||
f"\n"
|
||||
f" For full standards guide:\n"
|
||||
f" drone @seed handlers\n"
|
||||
f"{'='*60}"
|
||||
)
|
||||
return # Allow command-line Python through
|
||||
return # Allow if truly can't determine
|
||||
|
||||
# Check if caller is from our branch
|
||||
|
||||
@@ -50,20 +50,7 @@ def _guard_branch_access():
|
||||
stack = inspect.stack()
|
||||
for frame in stack:
|
||||
if frame.filename in ("<string>", "<stdin>"):
|
||||
target_line = "unknown"
|
||||
if frame.code_context:
|
||||
target_line = frame.code_context[0].strip()
|
||||
raise ImportError(
|
||||
f"\n{'='*60}\n"
|
||||
f"ACCESS DENIED: Cross-branch handler import blocked\n"
|
||||
f"{'='*60}\n"
|
||||
f" Caller: interactive/script\n"
|
||||
f" Blocked: {target_line}\n\n"
|
||||
f" Handlers are internal to their branch.\n"
|
||||
f" Use the module API instead:\n"
|
||||
f" from {MY_BRANCH}.apps.modules.<module> import <function>\n"
|
||||
f"{'='*60}"
|
||||
)
|
||||
return # Allow command-line Python through
|
||||
return
|
||||
|
||||
if f"/{MY_BRANCH}/" in caller_file:
|
||||
|
||||
@@ -74,28 +74,7 @@ def _guard_branch_access():
|
||||
stack = inspect.stack()
|
||||
for frame in stack:
|
||||
if frame.filename in ("<string>", "<stdin>"):
|
||||
# Try to get the import line from the frame
|
||||
target_line = "unknown"
|
||||
if frame.code_context:
|
||||
target_line = frame.code_context[0].strip()
|
||||
raise ImportError(
|
||||
f"\n{'='*60}\n"
|
||||
f"ACCESS DENIED: Cross-branch handler import blocked\n"
|
||||
f"{'='*60}\n"
|
||||
f" Caller: interactive/script\n"
|
||||
f" Blocked: {target_line}\n"
|
||||
f"\n"
|
||||
f" Handlers are internal to their branch.\n"
|
||||
f" Use the module API instead:\n"
|
||||
f" from {MY_BRANCH}.apps.modules.<module> import <function>\n"
|
||||
f"\n"
|
||||
f" Example:\n"
|
||||
f" from {MY_BRANCH}.apps.modules.logger import logger\n"
|
||||
f"\n"
|
||||
f" For full standards guide:\n"
|
||||
f" drone @seed handlers\n"
|
||||
f"{'='*60}"
|
||||
)
|
||||
return # Allow command-line Python through
|
||||
return # Allow if truly can't determine
|
||||
|
||||
# Check if caller is from our branch
|
||||
|
||||
@@ -95,28 +95,7 @@ def _guard_branch_access():
|
||||
stack = inspect.stack()
|
||||
for frame in stack:
|
||||
if frame.filename in ("<string>", "<stdin>"):
|
||||
# Try to get the import line from the frame
|
||||
target_line = "unknown"
|
||||
if frame.code_context:
|
||||
target_line = frame.code_context[0].strip()
|
||||
raise ImportError(
|
||||
f"\n{'='*60}\n"
|
||||
f"ACCESS DENIED: Cross-branch handler import blocked\n"
|
||||
f"{'='*60}\n"
|
||||
f" Caller: interactive/script\n"
|
||||
f" Blocked: {target_line}\n"
|
||||
f"\n"
|
||||
f" Handlers are internal to their branch.\n"
|
||||
f" Use the module API instead:\n"
|
||||
f" from {MY_BRANCH}.apps.modules.<module> import <function>\n"
|
||||
f"\n"
|
||||
f" Example:\n"
|
||||
f" from {MY_BRANCH}.apps.modules.logger import logger\n"
|
||||
f"\n"
|
||||
f" For full standards guide:\n"
|
||||
f" drone @seed handlers\n"
|
||||
f"{'='*60}"
|
||||
)
|
||||
return # Allow command-line Python through
|
||||
return # Allow if truly can't determine
|
||||
|
||||
# Check if caller is from our branch
|
||||
|
||||
@@ -74,28 +74,7 @@ def _guard_branch_access():
|
||||
stack = inspect.stack()
|
||||
for frame in stack:
|
||||
if frame.filename in ("<string>", "<stdin>"):
|
||||
# Try to get the import line from the frame
|
||||
target_line = "unknown"
|
||||
if frame.code_context:
|
||||
target_line = frame.code_context[0].strip()
|
||||
raise ImportError(
|
||||
f"\n{'='*60}\n"
|
||||
f"ACCESS DENIED: Cross-branch handler import blocked\n"
|
||||
f"{'='*60}\n"
|
||||
f" Caller: interactive/script\n"
|
||||
f" Blocked: {target_line}\n"
|
||||
f"\n"
|
||||
f" Handlers are internal to their branch.\n"
|
||||
f" Use the module API instead:\n"
|
||||
f" from {MY_BRANCH}.apps.modules.<module> import <function>\n"
|
||||
f"\n"
|
||||
f" Example:\n"
|
||||
f" from {MY_BRANCH}.apps.modules.logger import logger\n"
|
||||
f"\n"
|
||||
f" For full standards guide:\n"
|
||||
f" drone @seed handlers\n"
|
||||
f"{'='*60}"
|
||||
)
|
||||
return # Allow command-line Python through
|
||||
return # Allow if truly can't determine
|
||||
|
||||
# Check if caller is from our branch
|
||||
|
||||
@@ -74,28 +74,7 @@ def _guard_branch_access():
|
||||
stack = inspect.stack()
|
||||
for frame in stack:
|
||||
if frame.filename in ("<string>", "<stdin>"):
|
||||
# Try to get the import line from the frame
|
||||
target_line = "unknown"
|
||||
if frame.code_context:
|
||||
target_line = frame.code_context[0].strip()
|
||||
raise ImportError(
|
||||
f"\n{'='*60}\n"
|
||||
f"ACCESS DENIED: Cross-branch handler import blocked\n"
|
||||
f"{'='*60}\n"
|
||||
f" Caller: interactive/script\n"
|
||||
f" Blocked: {target_line}\n"
|
||||
f"\n"
|
||||
f" Handlers are internal to their branch.\n"
|
||||
f" Use the module API instead:\n"
|
||||
f" from {MY_BRANCH}.apps.modules.<module> import <function>\n"
|
||||
f"\n"
|
||||
f" Example:\n"
|
||||
f" from {MY_BRANCH}.apps.modules.logger import logger\n"
|
||||
f"\n"
|
||||
f" For full standards guide:\n"
|
||||
f" drone @seed handlers\n"
|
||||
f"{'='*60}"
|
||||
)
|
||||
return # Allow command-line Python through
|
||||
return # Allow if truly can't determine
|
||||
|
||||
# Check if caller is from our branch
|
||||
|
||||
@@ -74,28 +74,7 @@ def _guard_branch_access():
|
||||
stack = inspect.stack()
|
||||
for frame in stack:
|
||||
if frame.filename in ("<string>", "<stdin>"):
|
||||
# Try to get the import line from the frame
|
||||
target_line = "unknown"
|
||||
if frame.code_context:
|
||||
target_line = frame.code_context[0].strip()
|
||||
raise ImportError(
|
||||
f"\n{'='*60}\n"
|
||||
f"ACCESS DENIED: Cross-branch handler import blocked\n"
|
||||
f"{'='*60}\n"
|
||||
f" Caller: interactive/script\n"
|
||||
f" Blocked: {target_line}\n"
|
||||
f"\n"
|
||||
f" Handlers are internal to their branch.\n"
|
||||
f" Use the module API instead:\n"
|
||||
f" from {MY_BRANCH}.apps.modules.<module> import <function>\n"
|
||||
f"\n"
|
||||
f" Example:\n"
|
||||
f" from {MY_BRANCH}.apps.modules.create_plan import handle_command\n"
|
||||
f"\n"
|
||||
f" For full standards guide:\n"
|
||||
f" drone @seedgo handlers\n"
|
||||
f"{'='*60}"
|
||||
)
|
||||
return # Allow command-line Python through
|
||||
return # Allow if truly can't determine
|
||||
|
||||
# Check if caller is from our branch
|
||||
|
||||
@@ -74,28 +74,7 @@ def _guard_branch_access():
|
||||
stack = inspect.stack()
|
||||
for frame in stack:
|
||||
if frame.filename in ("<string>", "<stdin>"):
|
||||
# Try to get the import line from the frame
|
||||
target_line = "unknown"
|
||||
if frame.code_context:
|
||||
target_line = frame.code_context[0].strip()
|
||||
raise ImportError(
|
||||
f"\n{'='*60}\n"
|
||||
f"ACCESS DENIED: Cross-branch handler import blocked\n"
|
||||
f"{'='*60}\n"
|
||||
f" Caller: interactive/script\n"
|
||||
f" Blocked: {target_line}\n"
|
||||
f"\n"
|
||||
f" Handlers are internal to their branch.\n"
|
||||
f" Use the module API instead:\n"
|
||||
f" from {MY_BRANCH}.apps.modules.<module> import <function>\n"
|
||||
f"\n"
|
||||
f" Example:\n"
|
||||
f" from {MY_BRANCH}.apps.modules.logger import logger\n"
|
||||
f"\n"
|
||||
f" For full standards guide:\n"
|
||||
f" drone @seed handlers\n"
|
||||
f"{'='*60}"
|
||||
)
|
||||
return # Allow command-line Python through
|
||||
return # Allow if truly can't determine
|
||||
|
||||
# Check if caller is from our branch
|
||||
|
||||
@@ -74,28 +74,7 @@ def _guard_branch_access():
|
||||
stack = inspect.stack()
|
||||
for frame in stack:
|
||||
if frame.filename in ("<string>", "<stdin>"):
|
||||
# Try to get the import line from the frame
|
||||
target_line = "unknown"
|
||||
if frame.code_context:
|
||||
target_line = frame.code_context[0].strip()
|
||||
raise ImportError(
|
||||
f"\n{'='*60}\n"
|
||||
f"ACCESS DENIED: Cross-branch handler import blocked\n"
|
||||
f"{'='*60}\n"
|
||||
f" Caller: interactive/script\n"
|
||||
f" Blocked: {target_line}\n"
|
||||
f"\n"
|
||||
f" Handlers are internal to their branch.\n"
|
||||
f" Use the module API instead:\n"
|
||||
f" from {MY_BRANCH}.apps.modules.<module> import <function>\n"
|
||||
f"\n"
|
||||
f" Example:\n"
|
||||
f" from {MY_BRANCH}.apps.modules.logger import logger\n"
|
||||
f"\n"
|
||||
f" For full standards guide:\n"
|
||||
f" drone @seed handlers\n"
|
||||
f"{'='*60}"
|
||||
)
|
||||
return # Allow command-line Python through
|
||||
return # Allow if truly can't determine
|
||||
|
||||
# Check if caller is from our branch
|
||||
|
||||
@@ -74,28 +74,7 @@ def _guard_branch_access():
|
||||
stack = inspect.stack()
|
||||
for frame in stack:
|
||||
if frame.filename in ("<string>", "<stdin>"):
|
||||
# Try to get the import line from the frame
|
||||
target_line = "unknown"
|
||||
if frame.code_context:
|
||||
target_line = frame.code_context[0].strip()
|
||||
raise ImportError(
|
||||
f"\n{'='*60}\n"
|
||||
f"ACCESS DENIED: Cross-branch handler import blocked\n"
|
||||
f"{'='*60}\n"
|
||||
f" Caller: interactive/script\n"
|
||||
f" Blocked: {target_line}\n"
|
||||
f"\n"
|
||||
f" Handlers are internal to their branch.\n"
|
||||
f" Use the module API instead:\n"
|
||||
f" from {MY_BRANCH}.apps.modules.<module> import <function>\n"
|
||||
f"\n"
|
||||
f" Example:\n"
|
||||
f" from {MY_BRANCH}.apps.modules.logger import logger\n"
|
||||
f"\n"
|
||||
f" For full standards guide:\n"
|
||||
f" drone @seed handlers\n"
|
||||
f"{'='*60}"
|
||||
)
|
||||
return # Allow command-line Python through
|
||||
return # Allow if truly can't determine
|
||||
|
||||
# Check if caller is from our branch
|
||||
|
||||
@@ -74,28 +74,7 @@ def _guard_branch_access():
|
||||
stack = inspect.stack()
|
||||
for frame in stack:
|
||||
if frame.filename in ("<string>", "<stdin>"):
|
||||
# Try to get the import line from the frame
|
||||
target_line = "unknown"
|
||||
if frame.code_context:
|
||||
target_line = frame.code_context[0].strip()
|
||||
raise ImportError(
|
||||
f"\n{'='*60}\n"
|
||||
f"ACCESS DENIED: Cross-branch handler import blocked\n"
|
||||
f"{'='*60}\n"
|
||||
f" Caller: interactive/script\n"
|
||||
f" Blocked: {target_line}\n"
|
||||
f"\n"
|
||||
f" Handlers are internal to their branch.\n"
|
||||
f" Use the module API instead:\n"
|
||||
f" from {MY_BRANCH}.apps.modules.<module> import <function>\n"
|
||||
f"\n"
|
||||
f" Example:\n"
|
||||
f" from {MY_BRANCH}.apps.modules.logger import logger\n"
|
||||
f"\n"
|
||||
f" For full standards guide:\n"
|
||||
f" drone @seed handlers\n"
|
||||
f"{'='*60}"
|
||||
)
|
||||
return # Allow command-line Python through
|
||||
return # Allow if truly can't determine
|
||||
|
||||
# Check if caller is from our branch
|
||||
|
||||
@@ -50,20 +50,7 @@ def _guard_branch_access():
|
||||
stack = inspect.stack()
|
||||
for frame in stack:
|
||||
if frame.filename in ("<string>", "<stdin>"):
|
||||
target_line = "unknown"
|
||||
if frame.code_context:
|
||||
target_line = frame.code_context[0].strip()
|
||||
raise ImportError(
|
||||
f"\n{'='*60}\n"
|
||||
f"ACCESS DENIED: Cross-branch handler import blocked\n"
|
||||
f"{'='*60}\n"
|
||||
f" Caller: interactive/script\n"
|
||||
f" Blocked: {target_line}\n\n"
|
||||
f" Handlers are internal to their branch.\n"
|
||||
f" Use the module API instead:\n"
|
||||
f" from aipass.trigger.apps.modules.<module> import <function>\n"
|
||||
f"{'='*60}"
|
||||
)
|
||||
return # Allow command-line Python through
|
||||
return
|
||||
|
||||
if f"/trigger/" in caller_file:
|
||||
|
||||
@@ -62,21 +62,7 @@ def _guard_branch_access():
|
||||
stack = inspect.stack()
|
||||
for frame in stack:
|
||||
if frame.filename in ("<string>", "<stdin>"):
|
||||
target_line = "unknown"
|
||||
if frame.code_context:
|
||||
target_line = frame.code_context[0].strip()
|
||||
raise ImportError(
|
||||
f"\n{'='*60}\n"
|
||||
f"ACCESS DENIED: Cross-branch handler import blocked\n"
|
||||
f"{'='*60}\n"
|
||||
f" Caller: interactive/script\n"
|
||||
f" Blocked: {target_line}\n"
|
||||
f"\n"
|
||||
f" Handlers are internal to their branch.\n"
|
||||
f" Use the module API instead:\n"
|
||||
f" from {MY_BRANCH}.apps.modules.<module> import <function>\n"
|
||||
f"{'='*60}"
|
||||
)
|
||||
return # Allow command-line Python through
|
||||
return
|
||||
|
||||
# IMPORTANT: Commons is at src/commons/, not src/aipass/commons/
|
||||
|
||||
Reference in New Issue
Block a user