Add ln to the bash command denylist so a symlink escape cannot be created from the terminal tool. In the sandboxed (non-bypass) _python_exec path, prepend a one-line guard to the generated temp module that monkeypatches only MUTATING file ops (builtins.open in write/append/x/+ modes, os remove/unlink/rmdir/removedirs/ rename/renames/replace/truncate/chmod/chown/mkdir/makedirs/symlink/link, shutil rmtree/move/copy/copy2/copyfile/copytree, pathlib write_text/write_bytes/unlink/ rename/replace/mkdir/rmdir/chmod/symlink_to/hardlink_to/touch) to resolve the true os.path.realpath of the target and raise PermissionError unless it lands inside the injected session workdir. Reads are left unpatched. The guard runs in its own namespace so helper names never leak into user globals, and it is skipped entirely under disable_sandbox. This catches what the static gate cannot prove: pre-existing symlink escapes and dynamic library-writer paths that funnel through builtins.open. Benign in-workdir relative writes and library imports are unaffected (importlib swallows out-of-workdir bytecode-cache write failures). |
||
|---|---|---|
| .. | ||
| assets | ||
| auth | ||
| core | ||
| hub | ||
| loggers | ||
| models | ||
| plugins | ||
| requirements | ||
| routes | ||
| state | ||
| storage | ||
| tests | ||
| utils | ||
| __init__.py | ||
| _platform_compat.py | ||
| cloudflare_tunnel.py | ||
| colab.py | ||
| main.py | ||
| run.py | ||
| startup_banner.py | ||