Release 0.3.2: security hardening, --clean-env, project-level fallback, security model - #43
Merged
Merged
Conversation
…iming from the shipped-defaults session Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…s redundant Task.Run When the Roslyn reference walk in dotnet_test_affected runs out of budget or its selection is too large, it used to run the whole solution. Try a cheaper middle ground first: walk the project reference graph (AffectedTestFinder. FindAffectedTestProjects) to find the test projects that can be affected by the change, and run just those (no name filter) when that's a real subset of all test projects. Falls back to the whole solution only when the reachable set is empty or covers every test project. Response now reports RanScope (selection/projects/solution) and TestProjectsRun alongside the existing SelectionComplete/RanWholeSolution fields. WorkflowEngine wrapped already-async parallel step execution in Task.Run for no reason - ExecuteStepAsync already catches its own exceptions, so starting its task directly is enough to run steps concurrently. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…referencing xUnit can't be run) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ath boundary, --clean-env, VSTest filter widening - dotnet and git child processes get ProcessStartInfo.ArgumentList (one value = one argument) in BuildService, GitService and TestRunner; framework/runtime/configuration/MSBuild property names and git refs are validated; MSBuild property values escape ';' and ','; under Microsoft.Testing.Platform the filter may only carry --filter* / --treenode-filter options (no -p:/--property smuggling) - PathBoundary.IsWithin (GetFullPath + GetRelativePath) replaces the StartsWith solution-directory check - --clean-env (opt-in): child processes get an allow-listed environment; logs kept/dropped counts, names at Debug - VSTest name filter widens method -> class -> none past the command-line limit, like the MTP path - Tests for every injection string, path bypass, allow-list and widening case Started by a subagent that hit a usage limit before building or writing tests; completed, reviewed and tested here. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…build loops use argument lists via BuildEachAsync) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Security release. Two external reviews of 0.3.1 were checked claim by claim against the code first: several claims were wrong or outdated, but they led to real findings, fixed here. Upgrade from 0.3.0/0.3.1.
Security
dotnet/gitcommand lines.-p:Version=1.0 -p:CustomBeforeMicrosoftCommonTargets=evil.targetsimported a targets file (code runs during build);gitBase=--output=...made git write a file;framework, branch and remote values could add flagsProcessStartInfo.ArgumentList; framework/runtime/configuration/property names/git refs validated; property values escape;and,; MTPfiltermay only carry--filter*/--treenode-filteroptionsStartsWithon un-normalized paths let..and look-alike sibling folders throughPathBoundary.IsWithin(GetFullPath + GetRelativePath)--clean-env(allow-listed environment; not a sandbox, and says so)Also
dotnet_test_affectedproject-level fallback: out of budget or too large → only the test projects referencing the changed projects (ranScope,testProjectsRun), skipping helper libraries without tests. On Polly every tested change is inPolly.Core, which all test projects use, so it correctly still runs everything there; it pays off in solutions with independent modules.WorkflowEngine: noTask.Runaround async steps.How it was built
Two Sonnet subagents in parallel worktrees (security; fallback + workflow). The security agent hit a usage limit before building or writing tests; I completed it, fixed three gaps found in review (
,as MSBuild separator, proxy/cert variables for--clean-env, MSBuild switches smuggled through the MTP filter incl./p:withC:/paths) and wrote the tests. Merge conflict inRunAffectedresolved; both build loops share one argument-list helper.Verification
dotnet build -c Release0 errors;dotnet test118/118 (new: 21 security tests, 6 runner-argument tests, 5 fallback tests, 2 build-argument tests).--clean-env: framework, gitBase and MTP-filter injection strings all rejected (no file written); a real build + affected run succeeds with the scrubbed environment (5 tests, 27.5 s); fallback decisions checked on 3 real commits.--helplists--clean-env; startup logs kept/dropped counts, names only at Debug, never values.After merge: tag
v0.3.2,mcp-publisher publish, then I refresh the wiki (tool reference regenerated from 0.3.2, "(0.3.2+)" markers removed).🤖 Generated with Claude Code