fix(executor): block shell startup hooks from project env - #3862
Open
timothyanderson096-ocdealcheck wants to merge 1 commit into
Open
Conversation
Remove shell startup environment variables at the final command boundary so project .env files cannot cause repository-controlled scripts to run before Forge commands. Add an end-to-end BASH_ENV marker regression and verify all supported startup variables are explicitly removed. Co-Authored-By: ForgeCode <noreply@forgecode.dev>
timothyanderson096-ocdealcheck
marked this pull request as ready for review
September 1, 2026 05:27
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Prevent project-controlled
.envfiles from configuring shell startup hooks for Forge subprocesses.BASH_ENV,ENV, andZDOTDIRat the final command boundaryprepare_commandpathBASH_ENVscript is not sourcedSecurity impact
Forge loads project
.envvalues into its process environment. A repository can setBASH_ENVto a repository-controlled script, and non-interactive Bash will source that script before executing Forge's requested command. This reaches internal commands such as project-instruction discovery before any model-selected shell action or shell-tool permission check.The removal happens after optional environment forwarding, so a protected variable cannot be reintroduced through that path.
Why this boundary
This patch leaves normal project environment support intact while blocking the interpreter startup controls that create the code-execution path. Centralizing the removal in
prepare_commandcovers both executor entry points and keeps the policy adjacent to process creation.This is intentionally scoped to shell startup hooks. It does not claim to redesign or establish trust for all project-loaded environment variables.
Regression coverage
The Unix regression:
BASH_ENVForgeCommandExecutorServiceA separate command-construction test verifies explicit removal of all three protected variables.
Verification
cargo test -p forge_infra— 78 passedcargo clippy -p forge_infra --all-targets -- -D warningscargo fmt -p forge_infra -- --checkgit diff --checkFixes #3841
AI-assisted tools were used for investigation, implementation, and verification. I reviewed the resulting change and take responsibility for this contribution.
Co-Authored-By: ForgeCode noreply@forgecode.dev