Close eight follow-up bypasses Codex found on the round-36 git / env work:
- git operand via expansion: a git path operand from a locally-assigned absolute
variable (OUT=/tmp/repo; git init $OUT) was treated as sandbox-local. The git
scan now resolves a $VAR / ${VAR} operand against the command's local bindings
(new _git_operand_escapes); an unknown external expansion is left to the literal
check so git clone $REPO_URL is not a false positive.
- single-assignment env PATH: a non-shell subprocess with an env bound by a single
assignment (e = {'PATH': '.'}; run(['evil'], env=e)) skipped the unsafe-PATH
check because env was a Name, not an inline dict. Resolve the single-assignment
env node to its literal dict before the BASH_ENV / unsafe-PATH scan.
- env -C in argv: the argv-tail git rescan sliced off a preceding env -C /tmp, so
run(['env','-C','/tmp','git','init','repo']) hid the escaping cwd. Reconstruct
from the FULL argv so the git cwd backscan sees the wrapper.
- git exec configs: git -c KEY=CMD / git config KEY CMD run their value in an
unguarded child for execution-capable keys (core.fsmonitor / sshCommand / pager /
editor / credential.helper / filter.*.clean / diff.external / ...); core.hooksPath
/ init.templateDir re-point hooks (undoing the env hook suppression). Block those
configs (alias.*=! was already handled); benign configs (user.name) stay allowed.
- workdir module import vetter: user code may import a sibling .py it wrote, but
that source was never statically analyzed, so a planted workdir/evilmod.py could
run os.system('cat /etc/passwd') at import time in the guarded interpreter. A
meta-path finder now vets a module resolved FROM the workdir and refuses it if it
reaches a command-execution sink or eval/exec/compile; library imports and benign
sibling modules still load. (Direct sinks only; deeper obfuscation is a residual.)
- env -S / --split-string reads: env -S 'cat /etc/passwd' / --split-string= run
the operand as a command, but the READ scanner treated it as inert. Recurse the
split-string payload into the sensitive-read scan (shell-string and argv forms).
- make: make runs shell recipes read from a workdir Makefile in an unguarded child,
the same escape as the pip / pytest launchers. Deny make / gmake.
Regression coverage: TestRound37Bypasses in tests/test_sandbox_tools.py and the
benign/malicious workdir-module import tests in tests/test_sandbox_runtime_backstop.py.