Repository navigation
fix(android): validate launch component names and guard the executor override - #3366
Conversation
…override Refuse an Android `--activity` value outside the `am start -n` component grammar and a HarmonyOS ability name outside the module.json5 grammar with typed INVALID_ARGS reasons before any device call. Route the provider-scope command executor override through the same device-shell guard as the other adb executors. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The provider-scope executor override now refuses an unminted device-shell argv. Lowering a typed invocation to argv prepends its `-P`/`-s` addressing, so serialization relays the minted command through `relayDeviceShellArgvWithOptions` instead of copying it, and the host route's argv reaches the override still minted. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Size Report
Startup median (7 runs, lower is better):
|
There was a problem hiding this comment.
All reported issues were addressed across 15 files
Reply with feedback, questions, or to request a fix.
View guided diff | Turn on auto-fix | Re-trigger cubic
Both Android launch paths now build the `am start -n` component through one `androidActivityComponent`, so `openAndroidAppWithAdb` refuses a malformed activity the same way `openAndroidApp` does. The grammar checks identifier segments, and an explicitly empty activity or HarmonyOS ability is refused rather than treated as absent. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
This PR is ready at 43cafaa. The change looks correct, and all 19 checks pass on that commit. There are no conflicts, and nothing else needs to happen before merge. Not blocking: no test sends a minted command through The cubic-dev-ai threads on empty or malformed package segments (r4237483992), the HarmonyOS I read the code and did not run it. I did not run a mutation, so the revert claim above comes from reading the tests. There was no live run: valid launches emit the same bytes as before, and the one new failure mode on the override route is mint propagation, which I checked by reading. A leased Limrun run would confirm it end to end. Two behavior changes may deserve a CHANGELOG line, which I did not check for: an empty |
|
Summary
Defense-in-depth hardening for Android and HarmonyOS app launch. Device-shell words were already quoted; this adds input validation and closes the one adb executor that skipped the device-shell guard.
am start -ngrammar:<package>/<Class>,.<Class>, or<Class>. Package segments start with a letter; class segments are Java identifiers. Anything else, empty included, is refused withINVALID_ARGS/invalid-android-activity-componentbefore any adb call.openAndroidAppandopenAndroidAppWithAdbshare oneandroidActivityComponent.--activitymust be a module.json5 ability name; otherwiseinvalid-harmony-ability-namebefore any hdc call.guardDeviceShell. To support this,serializeAndroidAdbInvocationkeeps a checked command recognised when it prepends-P/-s, using the new kernel helperrelayDeviceShellArgvWithOptions.--activityhelp lists the accepted forms.17 files. Scope extends to
@agent-device/kernel(the relay helper) and five test recorders adjusted for thereadonlyargv.Validation
pnpm check:affected --runon43cafaa7e: passed (735 files, 6290 tests).app-controltests.🤖 Generated with Claude Code