From a800e7919aea45e4c083de9c56f77dc9e6dae84f Mon Sep 17 00:00:00 2001 From: AIOSAI Date: Thu, 19 Mar 2026 22:34:50 -0700 Subject: [PATCH] fix(seedgo): handler guard allows python3 -c, blocks cross-branch .py imports MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Guard was too aggressive — blocked all / callers including branches' own agents running python3 -c. Now only blocks when a real .py file from a different branch imports handlers. 13 files updated. Co-Authored-By: Claude Opus 4.6 (1M context) --- src/aipass/ai_mail/apps/handlers/__init__.py | 23 +------------------- src/aipass/api/apps/handlers/__init__.py | 15 +------------ src/aipass/backup/apps/handlers/__init__.py | 23 +------------------- src/aipass/cli/apps/handlers/__init__.py | 23 +------------------- src/aipass/daemon/apps/handlers/__init__.py | 23 +------------------- src/aipass/drone/apps/handlers/__init__.py | 23 +------------------- src/aipass/flow/apps/handlers/__init__.py | 23 +------------------- src/aipass/memory/apps/handlers/__init__.py | 23 +------------------- src/aipass/prax/apps/handlers/__init__.py | 23 +------------------- src/aipass/seedgo/apps/handlers/__init__.py | 23 +------------------- src/aipass/spawn/apps/handlers/__init__.py | 23 +------------------- src/aipass/trigger/apps/handlers/__init__.py | 15 +------------ src/commons/apps/handlers/__init__.py | 16 +------------- 13 files changed, 13 insertions(+), 263 deletions(-) diff --git a/src/aipass/ai_mail/apps/handlers/__init__.py b/src/aipass/ai_mail/apps/handlers/__init__.py index 469e7134..b1a66134 100755 --- a/src/aipass/ai_mail/apps/handlers/__init__.py +++ b/src/aipass/ai_mail/apps/handlers/__init__.py @@ -74,28 +74,7 @@ def _guard_branch_access(): stack = inspect.stack() for frame in stack: if frame.filename in ("", ""): - # Try to get the import line from the frame - target_line = "unknown" - if frame.code_context: - target_line = frame.code_context[0].strip() - raise ImportError( - f"\n{'='*60}\n" - f"ACCESS DENIED: Cross-branch handler import blocked\n" - f"{'='*60}\n" - f" Caller: interactive/script\n" - f" Blocked: {target_line}\n" - f"\n" - f" Handlers are internal to their branch.\n" - f" Use the module API instead:\n" - f" from {MY_BRANCH}.apps.modules. import \n" - f"\n" - f" Example:\n" - f" from {MY_BRANCH}.apps.modules.logger import logger\n" - f"\n" - f" For full standards guide:\n" - f" drone @seed handlers\n" - f"{'='*60}" - ) + return # Allow command-line Python through return # Allow if truly can't determine # Check if caller is from our branch diff --git a/src/aipass/api/apps/handlers/__init__.py b/src/aipass/api/apps/handlers/__init__.py index f9ca1ae2..a09d46ca 100644 --- a/src/aipass/api/apps/handlers/__init__.py +++ b/src/aipass/api/apps/handlers/__init__.py @@ -50,20 +50,7 @@ def _guard_branch_access(): stack = inspect.stack() for frame in stack: if frame.filename in ("", ""): - target_line = "unknown" - if frame.code_context: - target_line = frame.code_context[0].strip() - raise ImportError( - f"\n{'='*60}\n" - f"ACCESS DENIED: Cross-branch handler import blocked\n" - f"{'='*60}\n" - f" Caller: interactive/script\n" - f" Blocked: {target_line}\n\n" - f" Handlers are internal to their branch.\n" - f" Use the module API instead:\n" - f" from {MY_BRANCH}.apps.modules. import \n" - f"{'='*60}" - ) + return # Allow command-line Python through return if f"/{MY_BRANCH}/" in caller_file: diff --git a/src/aipass/backup/apps/handlers/__init__.py b/src/aipass/backup/apps/handlers/__init__.py index 537f4655..14e5bfeb 100755 --- a/src/aipass/backup/apps/handlers/__init__.py +++ b/src/aipass/backup/apps/handlers/__init__.py @@ -74,28 +74,7 @@ def _guard_branch_access(): stack = inspect.stack() for frame in stack: if frame.filename in ("", ""): - # Try to get the import line from the frame - target_line = "unknown" - if frame.code_context: - target_line = frame.code_context[0].strip() - raise ImportError( - f"\n{'='*60}\n" - f"ACCESS DENIED: Cross-branch handler import blocked\n" - f"{'='*60}\n" - f" Caller: interactive/script\n" - f" Blocked: {target_line}\n" - f"\n" - f" Handlers are internal to their branch.\n" - f" Use the module API instead:\n" - f" from {MY_BRANCH}.apps.modules. import \n" - f"\n" - f" Example:\n" - f" from {MY_BRANCH}.apps.modules.logger import logger\n" - f"\n" - f" For full standards guide:\n" - f" drone @seed handlers\n" - f"{'='*60}" - ) + return # Allow command-line Python through return # Allow if truly can't determine # Check if caller is from our branch diff --git a/src/aipass/cli/apps/handlers/__init__.py b/src/aipass/cli/apps/handlers/__init__.py index e164d47c..5b5bfdc0 100755 --- a/src/aipass/cli/apps/handlers/__init__.py +++ b/src/aipass/cli/apps/handlers/__init__.py @@ -95,28 +95,7 @@ def _guard_branch_access(): stack = inspect.stack() for frame in stack: if frame.filename in ("", ""): - # Try to get the import line from the frame - target_line = "unknown" - if frame.code_context: - target_line = frame.code_context[0].strip() - raise ImportError( - f"\n{'='*60}\n" - f"ACCESS DENIED: Cross-branch handler import blocked\n" - f"{'='*60}\n" - f" Caller: interactive/script\n" - f" Blocked: {target_line}\n" - f"\n" - f" Handlers are internal to their branch.\n" - f" Use the module API instead:\n" - f" from {MY_BRANCH}.apps.modules. import \n" - f"\n" - f" Example:\n" - f" from {MY_BRANCH}.apps.modules.logger import logger\n" - f"\n" - f" For full standards guide:\n" - f" drone @seed handlers\n" - f"{'='*60}" - ) + return # Allow command-line Python through return # Allow if truly can't determine # Check if caller is from our branch diff --git a/src/aipass/daemon/apps/handlers/__init__.py b/src/aipass/daemon/apps/handlers/__init__.py index 84d9adf0..09f37dc6 100644 --- a/src/aipass/daemon/apps/handlers/__init__.py +++ b/src/aipass/daemon/apps/handlers/__init__.py @@ -74,28 +74,7 @@ def _guard_branch_access(): stack = inspect.stack() for frame in stack: if frame.filename in ("", ""): - # Try to get the import line from the frame - target_line = "unknown" - if frame.code_context: - target_line = frame.code_context[0].strip() - raise ImportError( - f"\n{'='*60}\n" - f"ACCESS DENIED: Cross-branch handler import blocked\n" - f"{'='*60}\n" - f" Caller: interactive/script\n" - f" Blocked: {target_line}\n" - f"\n" - f" Handlers are internal to their branch.\n" - f" Use the module API instead:\n" - f" from {MY_BRANCH}.apps.modules. import \n" - f"\n" - f" Example:\n" - f" from {MY_BRANCH}.apps.modules.logger import logger\n" - f"\n" - f" For full standards guide:\n" - f" drone @seed handlers\n" - f"{'='*60}" - ) + return # Allow command-line Python through return # Allow if truly can't determine # Check if caller is from our branch diff --git a/src/aipass/drone/apps/handlers/__init__.py b/src/aipass/drone/apps/handlers/__init__.py index 3a9fc998..f531dd4b 100644 --- a/src/aipass/drone/apps/handlers/__init__.py +++ b/src/aipass/drone/apps/handlers/__init__.py @@ -74,28 +74,7 @@ def _guard_branch_access(): stack = inspect.stack() for frame in stack: if frame.filename in ("", ""): - # Try to get the import line from the frame - target_line = "unknown" - if frame.code_context: - target_line = frame.code_context[0].strip() - raise ImportError( - f"\n{'='*60}\n" - f"ACCESS DENIED: Cross-branch handler import blocked\n" - f"{'='*60}\n" - f" Caller: interactive/script\n" - f" Blocked: {target_line}\n" - f"\n" - f" Handlers are internal to their branch.\n" - f" Use the module API instead:\n" - f" from {MY_BRANCH}.apps.modules. import \n" - f"\n" - f" Example:\n" - f" from {MY_BRANCH}.apps.modules.logger import logger\n" - f"\n" - f" For full standards guide:\n" - f" drone @seed handlers\n" - f"{'='*60}" - ) + return # Allow command-line Python through return # Allow if truly can't determine # Check if caller is from our branch diff --git a/src/aipass/flow/apps/handlers/__init__.py b/src/aipass/flow/apps/handlers/__init__.py index 68453315..fe138553 100644 --- a/src/aipass/flow/apps/handlers/__init__.py +++ b/src/aipass/flow/apps/handlers/__init__.py @@ -74,28 +74,7 @@ def _guard_branch_access(): stack = inspect.stack() for frame in stack: if frame.filename in ("", ""): - # Try to get the import line from the frame - target_line = "unknown" - if frame.code_context: - target_line = frame.code_context[0].strip() - raise ImportError( - f"\n{'='*60}\n" - f"ACCESS DENIED: Cross-branch handler import blocked\n" - f"{'='*60}\n" - f" Caller: interactive/script\n" - f" Blocked: {target_line}\n" - f"\n" - f" Handlers are internal to their branch.\n" - f" Use the module API instead:\n" - f" from {MY_BRANCH}.apps.modules. import \n" - f"\n" - f" Example:\n" - f" from {MY_BRANCH}.apps.modules.create_plan import handle_command\n" - f"\n" - f" For full standards guide:\n" - f" drone @seedgo handlers\n" - f"{'='*60}" - ) + return # Allow command-line Python through return # Allow if truly can't determine # Check if caller is from our branch diff --git a/src/aipass/memory/apps/handlers/__init__.py b/src/aipass/memory/apps/handlers/__init__.py index bb0c3638..f1082d01 100644 --- a/src/aipass/memory/apps/handlers/__init__.py +++ b/src/aipass/memory/apps/handlers/__init__.py @@ -74,28 +74,7 @@ def _guard_branch_access(): stack = inspect.stack() for frame in stack: if frame.filename in ("", ""): - # Try to get the import line from the frame - target_line = "unknown" - if frame.code_context: - target_line = frame.code_context[0].strip() - raise ImportError( - f"\n{'='*60}\n" - f"ACCESS DENIED: Cross-branch handler import blocked\n" - f"{'='*60}\n" - f" Caller: interactive/script\n" - f" Blocked: {target_line}\n" - f"\n" - f" Handlers are internal to their branch.\n" - f" Use the module API instead:\n" - f" from {MY_BRANCH}.apps.modules. import \n" - f"\n" - f" Example:\n" - f" from {MY_BRANCH}.apps.modules.logger import logger\n" - f"\n" - f" For full standards guide:\n" - f" drone @seed handlers\n" - f"{'='*60}" - ) + return # Allow command-line Python through return # Allow if truly can't determine # Check if caller is from our branch diff --git a/src/aipass/prax/apps/handlers/__init__.py b/src/aipass/prax/apps/handlers/__init__.py index deb15203..c2a68bdb 100755 --- a/src/aipass/prax/apps/handlers/__init__.py +++ b/src/aipass/prax/apps/handlers/__init__.py @@ -74,28 +74,7 @@ def _guard_branch_access(): stack = inspect.stack() for frame in stack: if frame.filename in ("", ""): - # Try to get the import line from the frame - target_line = "unknown" - if frame.code_context: - target_line = frame.code_context[0].strip() - raise ImportError( - f"\n{'='*60}\n" - f"ACCESS DENIED: Cross-branch handler import blocked\n" - f"{'='*60}\n" - f" Caller: interactive/script\n" - f" Blocked: {target_line}\n" - f"\n" - f" Handlers are internal to their branch.\n" - f" Use the module API instead:\n" - f" from {MY_BRANCH}.apps.modules. import \n" - f"\n" - f" Example:\n" - f" from {MY_BRANCH}.apps.modules.logger import logger\n" - f"\n" - f" For full standards guide:\n" - f" drone @seed handlers\n" - f"{'='*60}" - ) + return # Allow command-line Python through return # Allow if truly can't determine # Check if caller is from our branch diff --git a/src/aipass/seedgo/apps/handlers/__init__.py b/src/aipass/seedgo/apps/handlers/__init__.py index cc93d5ce..65b2cb17 100644 --- a/src/aipass/seedgo/apps/handlers/__init__.py +++ b/src/aipass/seedgo/apps/handlers/__init__.py @@ -74,28 +74,7 @@ def _guard_branch_access(): stack = inspect.stack() for frame in stack: if frame.filename in ("", ""): - # Try to get the import line from the frame - target_line = "unknown" - if frame.code_context: - target_line = frame.code_context[0].strip() - raise ImportError( - f"\n{'='*60}\n" - f"ACCESS DENIED: Cross-branch handler import blocked\n" - f"{'='*60}\n" - f" Caller: interactive/script\n" - f" Blocked: {target_line}\n" - f"\n" - f" Handlers are internal to their branch.\n" - f" Use the module API instead:\n" - f" from {MY_BRANCH}.apps.modules. import \n" - f"\n" - f" Example:\n" - f" from {MY_BRANCH}.apps.modules.logger import logger\n" - f"\n" - f" For full standards guide:\n" - f" drone @seed handlers\n" - f"{'='*60}" - ) + return # Allow command-line Python through return # Allow if truly can't determine # Check if caller is from our branch diff --git a/src/aipass/spawn/apps/handlers/__init__.py b/src/aipass/spawn/apps/handlers/__init__.py index a3925ada..7a4dab02 100644 --- a/src/aipass/spawn/apps/handlers/__init__.py +++ b/src/aipass/spawn/apps/handlers/__init__.py @@ -74,28 +74,7 @@ def _guard_branch_access(): stack = inspect.stack() for frame in stack: if frame.filename in ("", ""): - # Try to get the import line from the frame - target_line = "unknown" - if frame.code_context: - target_line = frame.code_context[0].strip() - raise ImportError( - f"\n{'='*60}\n" - f"ACCESS DENIED: Cross-branch handler import blocked\n" - f"{'='*60}\n" - f" Caller: interactive/script\n" - f" Blocked: {target_line}\n" - f"\n" - f" Handlers are internal to their branch.\n" - f" Use the module API instead:\n" - f" from {MY_BRANCH}.apps.modules. import \n" - f"\n" - f" Example:\n" - f" from {MY_BRANCH}.apps.modules.logger import logger\n" - f"\n" - f" For full standards guide:\n" - f" drone @seed handlers\n" - f"{'='*60}" - ) + return # Allow command-line Python through return # Allow if truly can't determine # Check if caller is from our branch diff --git a/src/aipass/trigger/apps/handlers/__init__.py b/src/aipass/trigger/apps/handlers/__init__.py index 1bbd77fc..18a55610 100644 --- a/src/aipass/trigger/apps/handlers/__init__.py +++ b/src/aipass/trigger/apps/handlers/__init__.py @@ -50,20 +50,7 @@ def _guard_branch_access(): stack = inspect.stack() for frame in stack: if frame.filename in ("", ""): - target_line = "unknown" - if frame.code_context: - target_line = frame.code_context[0].strip() - raise ImportError( - f"\n{'='*60}\n" - f"ACCESS DENIED: Cross-branch handler import blocked\n" - f"{'='*60}\n" - f" Caller: interactive/script\n" - f" Blocked: {target_line}\n\n" - f" Handlers are internal to their branch.\n" - f" Use the module API instead:\n" - f" from aipass.trigger.apps.modules. import \n" - f"{'='*60}" - ) + return # Allow command-line Python through return if f"/trigger/" in caller_file: diff --git a/src/commons/apps/handlers/__init__.py b/src/commons/apps/handlers/__init__.py index 7684cbeb..68945270 100644 --- a/src/commons/apps/handlers/__init__.py +++ b/src/commons/apps/handlers/__init__.py @@ -62,21 +62,7 @@ def _guard_branch_access(): stack = inspect.stack() for frame in stack: if frame.filename in ("", ""): - target_line = "unknown" - if frame.code_context: - target_line = frame.code_context[0].strip() - raise ImportError( - f"\n{'='*60}\n" - f"ACCESS DENIED: Cross-branch handler import blocked\n" - f"{'='*60}\n" - f" Caller: interactive/script\n" - f" Blocked: {target_line}\n" - f"\n" - f" Handlers are internal to their branch.\n" - f" Use the module API instead:\n" - f" from {MY_BRANCH}.apps.modules. import \n" - f"{'='*60}" - ) + return # Allow command-line Python through return # IMPORTANT: Commons is at src/commons/, not src/aipass/commons/