Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions src/wardline/install/block.py
Original file line number Diff line number Diff line change
Expand Up @@ -31,6 +31,7 @@

_BLOCK_VERSION = "1"


def _compose_body(grant_suffix: str = "", grant_sentence: str = "") -> str:
return (
"This project uses **wardline** as its trust-boundary gate. Before handing "
Expand Down Expand Up @@ -81,6 +82,7 @@ def _pack_guidance(project_root: Path) -> tuple[str, str]:
)
return suffix, sentence


_OWN_NS = "wardline"
_END_MARKER = f"<!-- /{_OWN_NS}:instructions -->"
_WRITER_MARKER = f"<!-- {_OWN_NS}:last-writer:wardline install -->"
Expand Down
4 changes: 1 addition & 3 deletions src/wardline/mcp/server.py
Original file line number Diff line number Diff line change
Expand Up @@ -5103,9 +5103,7 @@ def _grants_merged_arguments(self, arguments: dict[str, Any]) -> dict[str, Any]:
if caller_packs is None or (
isinstance(caller_packs, list) and all(isinstance(p, str) for p in caller_packs)
):
merged["trust_packs"] = list(
dict.fromkeys([*(caller_packs or []), *self._default_trusted_packs])
)
merged["trust_packs"] = list(dict.fromkeys([*(caller_packs or []), *self._default_trusted_packs]))
if self._default_trust_local_packs:
caller_local = merged.get("trust_local_packs")
# Identity checks, not equality: 0 == False, and masking a caller's
Expand Down
6 changes: 6 additions & 0 deletions src/wardline/scanner/taint/variable_level.py
Original file line number Diff line number Diff line change
Expand Up @@ -67,6 +67,12 @@
"tomllib.load",
"tomli_w.dumps",
"tomli_w.dump",
"shelve.open",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Exempt newly created shelves from raw-source taint

When shelve.open(..., flag="n") is used, the underlying database is always created empty rather than opened for reading existing serialized data. Classifying every shelve.open result as UNKNOWN_RAW therefore taints a fresh shelf and all subsequent reads even when the program stores only clean values, producing false trusted-return or downstream-sink findings. Handle the literal fresh-create mode separately instead of applying this unconditional entry.

Useful? React with πŸ‘Β / πŸ‘Ž.

"dill.load",
"dill.loads",
"jsonpickle.decode",
"joblib.load",
"torch.load",
}
)

Expand Down
4 changes: 1 addition & 3 deletions tests/unit/install/test_doctor_pack_grants.py
Original file line number Diff line number Diff line change
Expand Up @@ -66,9 +66,7 @@ def test_project_mcp_check_accepts_grant_flags(tmp_path: Path, monkeypatch: pyte
assert check.ok, check.message


def test_project_mcp_check_names_divergence_not_missing(
tmp_path: Path, monkeypatch: pytest.MonkeyPatch
) -> None:
def test_project_mcp_check_names_divergence_not_missing(tmp_path: Path, monkeypatch: pytest.MonkeyPatch) -> None:
# A present-but-noncanonical entry is a different failure than an absent one;
# "missing wardline server" for a visibly present entry sent the operator
# chasing the wrong problem.
Expand Down
8 changes: 2 additions & 6 deletions tests/unit/install/test_mcp_json.py
Original file line number Diff line number Diff line change
Expand Up @@ -549,9 +549,7 @@ def test_repair_preserves_trust_pack_grant_flags(tmp_path: Path, monkeypatch: py
"--allow-custom-packs",
]
(tmp_path / ".mcp.json").write_text(
json.dumps(
{"mcpServers": {"wardline": {"type": "stdio", "command": "/bin/wardline", "args": list(args)}}}
),
json.dumps({"mcpServers": {"wardline": {"type": "stdio", "command": "/bin/wardline", "args": list(args)}}}),
encoding="utf-8",
)
assert merge_mcp_entry(tmp_path) == "unchanged"
Expand Down Expand Up @@ -581,9 +579,7 @@ def test_repair_preserves_repeated_trust_pack_grants(tmp_path: Path, monkeypatch
assert merge_mcp_entry(tmp_path) == "unchanged"


def test_repair_drops_dangling_trust_pack_but_keeps_bare_grant(
tmp_path: Path, monkeypatch: pytest.MonkeyPatch
) -> None:
def test_repair_drops_dangling_trust_pack_but_keeps_bare_grant(tmp_path: Path, monkeypatch: pytest.MonkeyPatch) -> None:
# A --trust-pack with a missing or flag-shaped value is malformed: it must be
# dropped cleanly, and must never swallow the following --allow-custom-packs.
monkeypatch.setattr("wardline.install.mcp_json._find_wardline_command", lambda: "/bin/wardline")
Expand Down
4 changes: 1 addition & 3 deletions tests/unit/mcp/test_server_trust_grants.py
Original file line number Diff line number Diff line change
Expand Up @@ -24,9 +24,7 @@
def _pack_project(tmp_path: Path) -> Path:
proj = tmp_path / "proj"
(proj / "scripts").mkdir(parents=True)
(proj / "scripts" / "grantpack.py").write_text(
'config = {"exclude": ["skipped_by_pack.py"]}\n', encoding="utf-8"
)
(proj / "scripts" / "grantpack.py").write_text('config = {"exclude": ["skipped_by_pack.py"]}\n', encoding="utf-8")
(proj / "weft.toml").write_text(f'[wardline]\npacks = ["{PACK_NAME}"]\n', encoding="utf-8")
(proj / "kept.py").write_text("def kept():\n return 1\n", encoding="utf-8")
(proj / "skipped_by_pack.py").write_text("def skipped():\n return 1\n", encoding="utf-8")
Expand Down