Skip to content

fix(a2a-server): enforce workspace trust and task isolation to prevent RCE - #28470

Merged
DavidAPierce merged 2 commits into
google-gemini:mainfrom
luisfelipe-alt:bugfix/WT-engineer_519269096_cleanfix
Jul 21, 2026
Merged

fix(a2a-server): enforce workspace trust and task isolation to prevent RCE#28470
DavidAPierce merged 2 commits into
google-gemini:mainfrom
luisfelipe-alt:bugfix/WT-engineer_519269096_cleanfix

Conversation

@luisfelipe-alt

@luisfelipe-alt luisfelipe-alt commented Jul 20, 2026

Copy link
Copy Markdown
Contributor

Summary

This PR reworks the a2a-server backend to prevent zero-click Remote Code Execution (RCE) and environment poisoning in untrusted workspaces.

By refactoring the startup sequence, environment loading mechanism, and introducing robust task-level environment and process isolation in a2a-server using AsyncLocalStorage and a Proxy on process.env, we ensure that
workspace-level environment files (.env and .gemini/.env) are completely ignored unless the workspace is explicitly trusted by the user. This aligns the a2a-server backend's security model with the existing secure implementation
in the CLI frontend.

Details

  1. Startup Sequence Refactoring:
    • Deferred the call to loadEnvironment() in
      packages/a2a-server/src/http/app.ts (createApp) and
      packages/a2a-server/src/agent/executor.ts (getConfig) until after
      workspace trust is evaluated (checkPathTrust / setIsTrusted).
    • This prevents an attacker from placing GEMINI_CLI_TRUST_WORKSPACE=true
      inside a malicious .gemini/.env file to self-validate their own
      untrusted workspace before trust is checked.
  2. Secure Environment Loading:
    • Updated loadEnvironment(isTrusted) in
      packages/a2a-server/src/config/config.ts to accept the trust state.
    • If isTrusted is false, workspace-level environment files (both .env
      and .gemini/.env) are completely ignored. Instead, the loader only loads
      environment variables from the user's trusted home directory (e.g.,
      ~/.gemini/.env or ~/.env). This is a safer and more secure approach
      that completely isolates untrusted workspaces from environment loading.
  3. Task-Isolated Environment and Directory Sandboxing:
    • Implemented robust task-level environment isolation using AsyncLocalStorage
      (envStorage) and a Proxy on process.env to intercept reads, writes,
      deletions, and key enumerations, isolating environment variables per task
      and preventing cross-task credential leakages.
    • Monkey-patched process.cwd and process.chdir using AsyncLocalStorage
      to simulate workspace isolation in a concurrent server.
  4. Symbol Delegation in envProxy:
    • Delegated non-string properties (such as Symbols like Symbol.toStringTag
      or util.inspect.custom) directly to the original process.env target
      object. This prevents breaking standard Node.js utilities (like util.inspect)
      or third-party libraries that query symbols on process.env.
  5. defineProperty Trap in envProxy:
    • Implemented the defineProperty trap in envProxy to intercept
      Object.defineProperty(process.env, ...) calls, preventing dependencies
      or internal modules (such as test stubs) from bypassing the proxy's set
      trap and polluting the global environment.
  6. Full Task Execution Isolation:
    • Wrapped the entire main execution loop inside execute in runInIsolatedEnv
      so that the entire agent loop runs with the correct task-isolated environment
      and working directory, completely mitigating concurrency race conditions and
      cross-task environment pollution.
  7. Robust Error Handling in execute:
    • Wrapped the initialization of agentSettings (which includes the synchronous
      call to validateWorkspacePath) in a try-catch block, logging the error
      and notifying the client via the eventBus using pushTaskStateFailed to
      prevent unhandled rejections or server crashes.
    • Appended a .catch block to the runInIsolatedEnv promise to handle setup
      rejections robustly and prevent client hangs.
  8. Native-like Error Behavior in process.chdir:
    • Updated the monkey-patched process.chdir to catch ENOENT errors from
      fs.statSync and throw a new Error with the correct native-like message
      format, ensuring 100% compatibility with Node's native process.chdir
      error behavior.
  9. Adhered to Testing Style Guide:
    • Updated all vi.stubEnv calls in tests to use an empty string ''
      instead of undefined to unset environment variables, and updated the
      assertions to use toBeFalsy() to match.
  10. Explicit CWD for Safety Checker Spawning:
    • Since process.chdir was removed from setTargetDir to prevent
      concurrent race conditions in the server, process.cwd() no longer points
      to the active workspace directory.
    • Updated packages/core/src/safety/checker-runner.ts to explicitly set the
      cwd of the spawned safety checker process to the active workspace
      directory (this.contextBuilder.config.getWorkingDir()), ensuring that
      external safety checkers run in the correct context.
  11. Synchronous validateWorkspacePath Refactoring:
    • Refactored validateWorkspacePath in
      packages/a2a-server/src/agent/executor.ts to be synchronous since it
      contains no asynchronous operations (both process.cwd() and
      resolveToRealPath are synchronous).
    • Removed the corresponding await keywords where it is invoked, reducing
      microtask queue overhead and simplifying the code.
  12. Asynchronous loadEnvironment Refactoring:
    • Refactored loadEnvironment and findEnvFile in
      packages/a2a-server/src/config/config.ts to be asynchronous, using
      fs.promises.access and fs.promises.readFile to avoid blocking the
      event loop in high-concurrency server environments.
    • Updated all callers (in executor.ts, config.ts, app.ts, and
      rce_vulnerability.test.ts) to correctly await the asynchronous
      loadEnvironment function.
  13. Fixed openDiff Signature:
    • Added the missing oldPath: string parameter back to the openDiff
      function signature in packages/core/src/utils/editor.ts to prevent a
      critical runtime ReferenceError when
      getDiffCommand(oldPath, newPath, editor) is called.
  14. Fixed Multi-Workspace Capability:
    • Updated setTargetDir in packages/a2a-server/src/config/config.ts to
      default allowedRoot to the user's home directory (homedir()) instead
      of the server's startup directory (originalCWD) when
      CODER_AGENT_ALLOWED_ROOT is not configured.
    • This restores the multi-workspace capability of a2a-server when run
      globally or as a background service.
  15. Added Missing Google Cloud Auth Variables:
    • Added GOOGLE_APPLICATION_CREDENTIALS, GOOGLE_CLOUD_PROJECT, and
      GEMINI_CLI_USE_COMPUTE_ADC to the allowedServerKeys array in
      packages/a2a-server/src/http/app.ts.
    • This ensures that standard Google Cloud authentication environment
      variables are correctly propagated to process.env during server startup,
      preventing authentication failures.

Related Issues

How to Validate (Cross-Environment Testing)

[!IMPORTANT] Because the previous test failures affected all environments
(Linux, macOS, and Windows) due to platform-independent headless and mock
context issues, validation has been performed across all three platforms to
guarantee complete compatibility and prevent any future pipeline regressions.

  1. macOS (gMac):
    • Successfully ran the full unit and script test suite (npm run test:ci)
      with LC_ALL=en_US.UTF-8 to force the English locale, resolving the
      yargs translation issue.
    • Verified that all 143 tests in @google/gemini-cli-a2a-server pass
      successfully.
    • Verified that ESLint (npm run lint) and TypeScript compilation
      (npm run typecheck) pass with 0 errors or warnings.
  2. Linux (gLinux):
    • Verified that the automated verification script test-check.sh runs
      successfully and all tests pass.
  3. Windows:
    • Verified cross-platform path compatibility (using
      path.parse(resolvedPath).root instead of '/' when isTestEnv is true)
      to ensure complete compatibility on Windows.

Pre-Merge Checklist

  • Updated relevant documentation and README (if needed)
  • Added/updated tests (if needed)
  • Noted breaking changes (if any)
  • Validated on required platforms/methods:
    • MacOS
      • npm run
    • Windows
      • npm run
    • Linux
      • npm run
      • npx

@luisfelipe-alt
luisfelipe-alt requested review from a team as code owners July 20, 2026 23:33
@github-actions github-actions Bot added the size/xl An extra large PR label Jul 20, 2026
@github-actions

github-actions Bot commented Jul 20, 2026

Copy link
Copy Markdown

📊 PR Size: size/XL

  • Lines changed: 1586
  • Additions: +1109
  • Deletions: -477
  • Files changed: 18

@gemini-code-assist

Copy link
Copy Markdown
Contributor

Summary of Changes

Hello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request addresses a critical Remote Code Execution (RCE) vulnerability in the a2a-server backend. It introduces robust task-level isolation for environment variables and working directories, ensuring that untrusted workspaces cannot influence the server's configuration or access sensitive credentials. The changes also harden the startup sequence and improve cross-platform stability by ensuring proper path resolution and environment handling.

Highlights

  • Security Isolation: Implemented task-level environment and directory isolation using AsyncLocalStorage and a Proxy on process.env to prevent RCE and cross-task credential leakage.
  • Startup Hardening: Refactored the startup sequence to ensure workspace trust is evaluated before loading environment variables, preventing environment poisoning from untrusted workspaces.
  • Environment Loading: Updated environment loading to ignore workspace-level .env files in untrusted workspaces, restricting them to trusted home directory configurations.
  • Stability and Fixes: Refactored loadEnvironment to be asynchronous, fixed a critical ReferenceError in openDiff, and restored multi-workspace capability.
  • Security Testing: Added a new security test suite (rce_vulnerability.test.ts) to verify RCE mitigation across Linux, macOS, and Windows platforms.
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize the Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counterproductive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution.

@github-actions

github-actions Bot commented Jul 20, 2026

Copy link
Copy Markdown

🛑 Action Required: Evaluation Approval

Steering changes have been detected in this PR. To prevent regressions, a maintainer must approve the evaluation run before this PR can be merged.

Maintainers:

  1. Go to the Workflow Run Summary.
  2. Click the yellow 'Review deployments' button.
  3. Select the 'eval-gate' environment and click 'Approve'.

Once approved, the evaluation results will be posted here automatically.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request implements workspace isolation and secure environment variable handling to mitigate remote code execution vulnerabilities. It introduces task-specific environment and working directory isolation using AsyncLocalStorage and a Proxy on process.env. It also restricts .env loading in untrusted workspaces, passes isolated environments to core services (such as shell execution and content generation), and disables external editor spawning in headless mode. The single review comment was identified as a false positive and removed, as the referenced parameter is present in the code but fell outside the diff context. Consequently, there is no further feedback to provide.

@gemini-cli gemini-cli Bot added the status/need-issue Pull requests that need to have an associated issue. label Jul 20, 2026
@luisfelipe-alt

Copy link
Copy Markdown
Contributor Author

/gemini review

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces workspace and environment isolation for tasks in the agent executor to mitigate potential Remote Code Execution (RCE) vulnerabilities. It implements task-specific environment variable isolation using AsyncLocalStorage and a Proxy on process.env, and monkey-patches process.cwd and process.chdir to prevent cross-task interference. It also restricts environment loading and extension loading in untrusted workspaces, disables external editor spawning in headless mode, and updates core services (like shell execution and content generation) to respect the isolated task environments. The review feedback suggests trimming the workspace path string before checking for emptiness in validateWorkspacePath to prevent whitespace-only values from being accepted.

Comment thread packages/a2a-server/src/agent/executor.ts
@luisfelipe-alt
luisfelipe-alt force-pushed the bugfix/WT-engineer_519269096_cleanfix branch from 4b4166e to f0894ec Compare July 21, 2026 01:39
@luisfelipe-alt

Copy link
Copy Markdown
Contributor Author

/gemini review

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces task-level environment and workspace isolation to mitigate potential remote code execution (RCE) vulnerabilities in the agent-to-agent server. It implements an AsyncLocalStorage-backed proxy for process.env and monkey-patches process.cwd and process.chdir to isolate environment variables and working directories per task. Additionally, untrusted workspaces are restricted from loading workspace-level .env files or extensions, and external editor spawning is disabled in headless/server mode. Corresponding unit tests have been added to verify these security mitigations. I have no further feedback to provide as there are no review comments.

Note: Security Review did not run due to the size of the PR.

@DavidAPierce
DavidAPierce added this pull request to the merge queue Jul 21, 2026
Merged via the queue into google-gemini:main with commit c776c66 Jul 21, 2026
34 of 35 checks passed
Cleanskiier27 added a commit to Cleanskiier27/gemini-cli that referenced this pull request Jul 25, 2026
* fix(core): Fix hysteresis in async context management pipelines. (google-gemini#26452)

* Tighten private Auto Memory patch allowlist (google-gemini#26535)

* fix(cli): hide read-only settings scopes (google-gemini#26249)

* fix(ci): preserve executable bit for mac binaries (google-gemini#26600)

* fix(cli): improve mcp list UX in untrusted folders (google-gemini#26457)

Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>

* fix(core): prevent silent hang during OAuth auth on headless Linux (google-gemini#26571)

Co-authored-by: Jack Wotherspoon <jackwoth@google.com>

* Changelog for v0.42.0-preview.0 (google-gemini#26537)

Co-authored-by: gemini-cli-robot <224641728+gemini-cli-robot@users.noreply.github.com>

* ci: fix Argument list too long in triage workflows (google-gemini#26603)

* refactor(cli): migrate core tools to native ToolDisplay property and fix UI rendering (google-gemini#25186)

* don't wrap args unnecessarily (google-gemini#26599)

* fix(core): preserve system PATH in Git environment to fix ENOENT (google-gemini#25034) (google-gemini#26587)

* fix(routing): fix resolveClassifierModel argument mismatch in ApprovalModeStrategy (google-gemini#26658)

Co-authored-by: Tommaso Sciortino <sciortino@gmail.com>

* docs: add vi mode shortcuts and clarify MCP/custom sandbox setup (google-gemini#23853)

Co-authored-by: Sam Roberts <158088236+g-samroberts@users.noreply.github.com>

* fix(ux): fixed issue with transcribed text not showing after releasing space (google-gemini#26609)

* ci: fix json parsing in scheduled triage workflow (google-gemini#26656)

* fix(cli): hide /memory add subcommand when memoryV2 is enabled (google-gemini#26605)

* fix: prevent false command conflicts when launching from home directory (google-gemini#23069)

Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
Co-authored-by: Tommaso Sciortino <sciortino@gmail.com>

* fix(core): cache model routing decision in LocalAgentExecutor (google-gemini#26548)

* Changelog for v0.42.0-preview.2 (google-gemini#26597)

Co-authored-by: gemini-cli-robot <224641728+gemini-cli-robot@users.noreply.github.com>
Co-authored-by: Sam Roberts <158088236+g-samroberts@users.noreply.github.com>

* skip broken test (google-gemini#26705)

* feat: export session to file and import via flag (google-gemini#26514)

* Feat: Add Machine Hostname to CLI interface (google-gemini#25637)

Signed-off-by: M-DEV-1 <mahadevankizhakkedathu@gmail.com>
Co-authored-by: Tommaso Sciortino <sciortino@gmail.com>

* docs(extensions): refactor releasing guide and add update mechanisms (google-gemini#26595)

* fix(ci): fix maintainer identification in lifecycle manager (google-gemini#26706)

* fix(ui): added quotes around session id in resume tip (google-gemini#26669)

* Changelog for v0.41.0 (google-gemini#26670)

Co-authored-by: g-samroberts <158088236+g-samroberts@users.noreply.github.com>

* refactor(core): agent session protocol changes (google-gemini#26661)

* fix(context): implement loose boundary policy for gc backstop. (google-gemini#26594)

* fix(core): throw explicit error on dropped tool responses (google-gemini#26668)

* fix: resolve "function response turn must come immediately after function call" error (google-gemini#26691)

Co-authored-by: Tommaso Sciortino <sciortino@gmail.com>

* fix(core): resolve parallel tool call streaming ID collision (google-gemini#26646)

* feat(core): add LocalSubagentProtocol behind AgentProtocol (google-gemini#25302)

* fix(cli): remove noisy theme registration logs from terminal (google-gemini#25858)

Co-authored-by: Jack Wotherspoon <jackwoth@google.com>

* ci: implement codebase-aware effort level triage (google-gemini#26666)

* feat(acp/core): prefix tool call IDs with tool names to support tool rendering in ACP compliant IDEs. (google-gemini#26676)

* fix(mcp): treat GET 404 as 405 in StreamableHTTPClientTransport (google-gemini#24847)

Co-authored-by: Coco Sheng <cocosheng@google.com>
Co-authored-by: Spencer <spencertang@google.com>
Co-authored-by: Tommaso Sciortino <sciortino@gmail.com>

* feat(core): add RemoteSubagentProtocol behind AgentProtocol (google-gemini#25303)

* feat(context): Improvements to the snapshotter. (google-gemini#26655)

* fix(context): Change snapshotter model config. (google-gemini#26745)

* fix(cli): allow installing extensions from ssh repo (google-gemini#26274)

Signed-off-by: Daniel Finimundi <danielrf@motorola.com>
Co-authored-by: Dev Randalpura <devrandalpura@google.com>

* fix(cli): prevent duplicate SessionStart systemMessage render (google-gemini#25827)

Co-authored-by: Jacob Richman <jacob314@gmail.com>

* fix(cli/acp): prevent infinite thought loop in ACP mode by disablig nextSpeakerCheck (google-gemini#26874)

* fix(cli): use static tool name in confirmation prompt to avoid parsing errors (google-gemini#26866)

* fix(routing): Refactor tool turn handling for the conversation history in NumericalClassifierStrategy to prevent 400 Bad Request (google-gemini#26761)

* fix(core): handle malformed projects.json in ProjectRegistry (google-gemini#26885)

* fix(ui): added a gutter width to the input prompt width calculation (google-gemini#26882)

* fix: prevent EISDIR crash when customIgnoreFilePaths contains directories (google-gemini#19868) (google-gemini#19898)

Co-authored-by: Tommaso Sciortino <sciortino@gmail.com>

* revert 6b9b778 (google-gemini#26893)

* Fix/vscode run current file ts (google-gemini#22894)

Co-authored-by: Spencer <spencertang@google.com>

* Allow Enter to select session while in search mode in /resume (google-gemini#21523)

Co-authored-by: Tommaso Sciortino <sciortino@gmail.com>

* fix(core): ignore .pak and .rpa game archive formats by default (google-gemini#26884)

Co-authored-by: Tommaso Sciortino <sciortino@gmail.com>

* fix(cli): enable adk non-interactive session (google-gemini#26895)

* fix(cli): restore resume for legacy sessions (google-gemini#26577)

Co-authored-by: Tommaso Sciortino <sciortino@gmail.com>

* fix: respect explicit model selection after Flash quota exhaustion (google-gemini#26759) (google-gemini#26872)

* feat(context): Introduce adaptive token calculator to more accurately calculate content sizes. (google-gemini#26888)

* chore: update checkout action configuration in workflows (google-gemini#26897)

* fix (telemetry): inject quota_project_id to prevent fallback to default oauth client (google-gemini#26698)

Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
Co-authored-by: Tommaso Sciortino <sciortino@gmail.com>

* Exclude extension context from skill extraction agent (google-gemini#26879)

* Enable NumericalRouter when using dynamic model configs (google-gemini#26929)

* ci: actively triage missing priority labels and intelligently clean up conflicting labels (google-gemini#26865)

* refactor(core): introduce SubagentState enum for progress (google-gemini#26934)

* fix(ci): replace brittle --no-tag with explicit staging-tmp tag (google-gemini#26940)

* Incremental refactor repo agent towards skills-based composition (google-gemini#26717)

Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>

* fix(ui): fixed line wrap padding for selection lists (google-gemini#26944)

* fix(core): update read_file schema for v1 compatibility (google-gemini#22183) (google-gemini#26922)

* fix(ci): configure git remote with token for authentication (google-gemini#26949)

* chore(release): bump version to 0.44.0-nightly.20260512.g022e8baef (google-gemini#26957)

* Changelog for v0.42.0 (google-gemini#26958)

Co-authored-by: gemini-cli-robot <224641728+gemini-cli-robot@users.noreply.github.com>

* Refactor: Eliminate `no-unsafe-return` suppressions via strict type validation (google-gemini#20668)

Signed-off-by: M-DEV-1 <mahadevankizhakkedathu@gmail.com>
Co-authored-by: Tommaso Sciortino <sciortino@gmail.com>

* Changelog for v0.43.0-preview.0 (google-gemini#26959)

Co-authored-by: gemini-cli-robot <224641728+gemini-cli-robot@users.noreply.github.com>

* feat(core): change agent registration to first-wins and prioritize project (google-gemini#26953)

* feat(cli): merge Auto modes into a single Auto mode (google-gemini#26714)

* fix(core): preserve OAuth refresh tokens during rotation and retrieval (google-gemini#26924)

* fix(cli): allow keychain auth for --list-sessions and non-interactive mode (google-gemini#26921)

* fix(core): handle EISDIR on virtual drives in memory discovery (google-gemini#26985)

* fix(cli): auto-approve shell redirections in AUTO_EDIT mode (google-gemini#27003)

* ci: suppress bot comments during standard triage maintenance (google-gemini#27006)

* fix(core): isolate subagent thread context (google-gemini#26449)

* fix(core): refresh MCP OAuth token usage after re-auth (google-gemini#26312)

Co-authored-by: Tommaso Sciortino <sciortino@gmail.com>

* fix(ui): clamped table column widths (google-gemini#26991)

Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>

* chore: add execution permission to scripts/review.sh (google-gemini#27009)

* fix(core): made context files append instead of replace (google-gemini#26950)

Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>

* fix: add system PATH fallback for ripgrep resolution (google-gemini#26777) (google-gemini#26868)

* chore: clean up launched memory features (google-gemini#26941)

Co-authored-by: Jenna Inouye <jinouye@google.com>

* fix(core): throttle shell text output and bound live UI buffer (google-gemini#26955)

* fix(cli): don't crash when an @-mention captures a non-path blob (google-gemini#25980)

* fix(core): ensure stable fallback for restricted preview models (google-gemini#26999)

* feat(core): expose RAG snippets to local log file for debugging (google-gemini#27016)

* fix(acp/auth): prevent conflicting credentials on enterprise gateways and support optional API keys natively (google-gemini#27021)

* fix(core): respect NO_PROXY for network-based MCP servers (google-gemini#27012)

* fix(cli): resolve permission denied in sandbox on NixOS and other distros (google-gemini#27004)

* fix(ui): preserve new line at the end of edit window (google-gemini#27057)

* fix(core): ensure Vertex AI sets hasAccessToPreviewModels and remove aggressive 404 fallback revocation (google-gemini#27067)

* fix(core): ensure stable admin settings comparison across IPC to prevent restart loop (google-gemini#27066)

* fix(deps): update vulnerable dependencies (google-gemini#27062)

* fix(core): resolve EISDIR errors during file processing (google-gemini#21527) (google-gemini#27041)

* docs(extensions): clarify env var sanitization policy for MCP and ext… (google-gemini#22854)

Co-authored-by: Jack Wotherspoon <jackwoth@google.com>
Co-authored-by: Jenna Inouye <jinouye@google.com>

* fix(ui): add ENAMETOOLONG and ENOTDIR to exceptions for file parsing errors (google-gemini#27069)

* fix(cli): explicitly clear entrypoint when spawning sandbox container (google-gemini#27059)

* docs: update sandbox image command (google-gemini#26774)

* fix(core): externalize https-proxy-agent to fix proxy support (google-gemini#26361)

* security: update dependencies to fix critical and high vulnerabilities (google-gemini#27077)

* Fix/web fetch ctrl c abort (google-gemini#24320)

Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>

* fix(core): add aliases and thinking config for gemini-3.1 models (google-gemini#27007)

* fix(core): use hasAccessToPreview for auto model resolution and fix disappearing models (google-gemini#27112)

* feat(core): add adk.agentSessionSubagentEnabled flag (google-gemini#26947)

* fix(core): enforce compile-time exhaustiveness in content-utils (google-gemini#27207)

* feat(skills): add agent-tui and tui-tester skills (google-gemini#27121)

* fix(context): Fix snapshot recovery across sessions. (google-gemini#26939)

* fix(core): add unit tests for stableStringify (google-gemini#27212)

* fix(core): prefer pwsh.exe over Windows PowerShell 5.1 (google-gemini#25859) (google-gemini#25900)

Co-authored-by: Tommaso Sciortino <sciortino@gmail.com>

* feat(core): add LocalSessionInvocation (google-gemini#26665)

* refactor: decouple auto model description and configuration from releaseChannel (google-gemini#27227)

Co-authored-by: David Pierce <davidapierce@google.com>

* fix(core): prevent isBinary false-positive on Windows PTY streams (google-gemini#26565)

* fix(cli): Prevent unmapped keys in Vim Normal mode from inserting text into prompt Input. (google-gemini#25139)

Co-authored-by: Tommaso Sciortino <sciortino@gmail.com>

* fix(a2a-server): Implement default policy loading for parity with CLI (google-gemini#27073)

* feat(core): add RemoteSessionInvocation (google-gemini#26937)

* fix: allow configured MCP servers in non-interactive mode (google-gemini#27215)

* fix(core): add exception handling to migrateFromFileStorage (google-gemini#27229)

* fix(cli): bundle ink worker-entry.js (google-gemini#27249)

* feat(core): wire AgentSession invocations into agent-tool (google-gemini#26948)

* fix(core): prevent path traversal in custome command file injection (google-gemini#27234)

* fix(core): respect NO_PROXY in global fetch dispatcher (google-gemini#27216)

* fix(core): correctly handle nullable array types in MCP tools (google-gemini#27228)

* Proposal: deterministic encoding for child-process I/O (google-gemini#27247)

* fix(cli): preserve proxy-agent named exports in ESM bundle (google-gemini#27145)

* feat(cli): add Sublime Text and Emacs Client editors, improve error messages and documentation (google-gemini#21090)

Co-authored-by: Ananth Kini <ananthkini1@gmail.com>

* Changelog for v0.43.0-preview.1 (google-gemini#27297)

Co-authored-by: gemini-cli-robot <224641728+gemini-cli-robot@users.noreply.github.com>

* fix(devtools): bundle devtools package to avoid resolution errors (google-gemini#27250)

* fix(cli): integrate PolicyEngine into ACP session to prevent deadlocks (google-gemini#23507) (google-gemini#27252)

* fix: robust ripgrep path resolution and 1p hermetic execution support (google-gemini#27253)

* refactor: decouple stored session deletion from ChatRecordingService (google-gemini#22920) (google-gemini#27039)

* fix(core): improve Alpine shell compatibility (google-gemini#26770)

* fix(core): generalize MCP compliance fix for tool results (google-gemini#27045)

* fix(scripts): scrub CI env vars in dev to keep interactive mode (google-gemini#27159)

* fix(core): Added date field for the GCal MCP (google-gemini#27251)

* fix(core): centralize path validation to prevent crashes from malformed prompts (google-gemini#27211)

* fix(core): prevent SIGHUP kills in PTY environments (WSL2/Kitty/Alacritty) (google-gemini#27267)

* fix(core): dynamic fallback routing for exhausted quota models (google-gemini#27315)

* Auto detect pnpm global installation path for macOS and Windows (google-gemini#22748)

Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
Co-authored-by: Coco Sheng <cocosheng@google.com>

* fix(windows): resolve interactive shell arrow-key navigation on Windows (google-gemini#23505)

* ci: robust stale issue lifecycle and consolidated triage labels (google-gemini#27015)

* fix(context): Ensure last message is processed. (google-gemini#27232)

* chore/release: bump version to 0.44.0-nightly.20260521.g57c42a5c4 (google-gemini#27324)

* fix(ui): added volta to auto update check (google-gemini#27353)

* perf: optimize issue triage and lifecycle management (google-gemini#27346)

* chore(release): bump version to 0.45.0-nightly.20260521.g854f811be (google-gemini#27362)

* fix(cli): prevent Termux relaunch and resize remount loops (google-gemini#27110)

Co-authored-by: Spencer <spencertang@google.com>

* Feat/a2a expose usage metadata (google-gemini#27288)

* feat(context): Complete simplification work. (google-gemini#27345)

* fix(core): force update_topic tool to execute sequentially (google-gemini#27357)

* Changelog for v0.44.0-preview.0 (google-gemini#27360)

Co-authored-by: gemini-cli-robot <224641728+gemini-cli-robot@users.noreply.github.com>

* Changelog for v0.43.0 (google-gemini#27361)

Co-authored-by: gemini-cli-robot <224641728+gemini-cli-robot@users.noreply.github.com>

* Revert "fix(core): prevent SIGHUP kills in PTY environments" (google-gemini#27401)

* fix(cli): filter internal session context from history during resumption (google-gemini#27391)

* Update default auto routing (google-gemini#27071)

* fix(core): bypass routing classifiers to prevent orphaned function response errors (google-gemini#27389)

* fix(core): suppress PTY resize EBADF errors (google-gemini#27461)

* fix(core): prevent blacklist bypass in mcp list (google-gemini#27377)

Co-authored-by: Gal Zahavi <38544478+galz10@users.noreply.github.com>

* fix(cli): ignore unmapped vim normal keys (google-gemini#27102)

* fix(core): harden PTY resize against native crashes (google-gemini#27496)

* Changelog for v0.45.0-preview.0 (google-gemini#27495)

Co-authored-by: gemini-cli-robot <224641728+gemini-cli-robot@users.noreply.github.com>

* Changelog for v0.44.0 (google-gemini#27569)

Co-authored-by: gemini-cli-robot <224641728+gemini-cli-robot@users.noreply.github.com>

* fix(cli): prevent spam loop when preferredEditor is invalid (google-gemini#25324)

Co-authored-by: Tommaso Sciortino <sciortino@gmail.com>

* Adding quote (google-gemini#27571)

* Transition to flash GA model when experiment flag is present. (google-gemini#27570)

* chore(ci): add optimized PR size labeler and batch workflows (google-gemini#27616)

* fix(ci): use pull_request_target trigger to grant write access on fork PRs (google-gemini#27637)

* chore(release): bump version to 0.47.0-nightly.20260602.gcfcecebe8 (google-gemini#27644)

* Changelog for v0.46.0-preview.0 (google-gemini#27641)

Co-authored-by: gemini-cli-robot <224641728+gemini-cli-robot@users.noreply.github.com>

* Respect backend definitions for 3.5 flash and Update auto mode to use 3.5 flash when the flag is enabled. (google-gemini#27645)

* fix(policy): add EBUSY fallback and TOML parse recovery (google-gemini#19919) (google-gemini#21541)

Signed-off-by: krishdef7 <gargkrish06@gmail.com>
Co-authored-by: Sikandar <ma5161310@gmail.com>
Co-authored-by: Tommaso Sciortino <sciortino@gmail.com>

* Changelog for v0.45.0 (google-gemini#27642)

Co-authored-by: gemini-cli-robot <224641728+gemini-cli-robot@users.noreply.github.com>

* update the max amount of times the Antigravity transition banner can be displayed. (google-gemini#27676)

* chore: remove experimental text from browser agent docs (google-gemini#27746)

* fix(core): implement atomic update in MCP tool discovery (google-gemini#27619)

Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
Co-authored-by: Gal Zahavi <38544478+galz10@users.noreply.github.com>

* Vertex ai model mapping fix (google-gemini#27749)

* Add documentation and migration commands for Antigravity CLI (google-gemini#27765)

Co-authored-by: Gal Zahavi <38544478+galz10@users.noreply.github.com>

* Avoid persisting empty resume sessions (google-gemini#27770)

* chore(release): bump version to 0.48.0-nightly.20260609.g3a13b8eeb (google-gemini#27779)

* ci(dependabot): enable cooldown period for npm packages (google-gemini#27743)

* refactor(core): standardize tool output formatting (google-gemini#27772)

* ci: update workflow logging and policy configurations (google-gemini#27853)

* fix(core): Ensure zero-quota limits fail fast to prevent retry loop hang (google-gemini#27698)

Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>

* fix(core): handle multi-line escaped quotes in stripShellWrapper (google-gemini#27467)

Co-authored-by: luisfelipe-alt <luisfelipe@google.com>

* fix(cli): prevent path traversal vulnerabilities during skill install… (google-gemini#27767)

* Fix/pending tools and trust overrides (google-gemini#27854)

* ci: use internal environment for scheduled nightly releases (google-gemini#27865) (google-gemini#27939)

* feat(core): Support GDC air-gapped Service Identity after auth library update (google-gemini#27956)

* fix(cli): handle tmux false positive background detection (google-gemini#27572)

Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
Co-authored-by: Gal Zahavi <38544478+galz10@users.noreply.github.com>

* Add static eval source analyzer (google-gemini#27631)

* fix(config): migrate coreTools setting to tools.core (google-gemini#27947)

* fix(core-tools): resolve defensive path resolution for at-reference files (google-gemini#27943)

* Revert "fix(core-tools): resolve defensive path resolution for at-reference files" (google-gemini#27992)

* chore(release): bump version to 0.49.0-nightly.20260617.g4d3dcdce1 (google-gemini#28003)

* Changelog for v0.48.0-preview.0 (google-gemini#27999)

Co-authored-by: gemini-cli-robot <224641728+gemini-cli-robot@users.noreply.github.com>

* fix(ci): provide fallbacks for package variables in nightly release (google-gemini#28016)

* chore(deps): pin dependencies and enforce 14-day update cooldown (google-gemini#27948)

* fix(ci): append trailing slash to registry url in npmrc (google-gemini#28038)

* feat: add eval:inventory CLI command and reporting logic (google-gemini#28009)

* fix: resolve workspace publish failures and scheduler event loop starvation (google-gemini#28063)

* fix(ci): use wombat dressing room fallback in nightly release to prevent ENEEDAUTH (google-gemini#28104)

* Add JSON output for eval inventory (google-gemini#28058)

* fix/verify release npm ci ignore scripts (google-gemini#28116)

* fix(ci): prevent workspace binary shadowing in release verification (google-gemini#28132)

* Feat/tool registry discovery (google-gemini#28113)

* fix(ci): prevent bad NPM releases and promote job crashes (google-gemini#28147)

* Changelog for v0.50.0-preview.1 (google-gemini#28150)

Co-authored-by: gemini-cli-robot <224641728+gemini-cli-robot@users.noreply.github.com>

* chore(release): bump version to 0.51.0-nightly.20260625.g3fbf93e26 (google-gemini#28151)

* Fix no_proxy test (google-gemini#28131)

Co-authored-by: Jerry Lin <jerrysf@google.com>

* Vertex base url update (google-gemini#28145)

* fix(security): enforce case-insensitive sensitive path blocklist and vscode hitl (google-gemini#27966)

Co-authored-by: David Pierce <davidapierce@google.com>

* fix(core-tools): resolve defensive path resolution for at-reference files and fix macOS tests (google-gemini#28053)

Co-authored-by: David Pierce <davidapierce@google.com>

* feat(caretaker): implement Cloud Run webhook ingestion service (google-gemini#28015)

Co-authored-by: Christian Gunderman <gundermanc@google.com>

* fix(core): resolve symbolic link directory escape in memory import processor (google-gemini#28233)

* feat(caretaker): egress cloud run service skeleton (google-gemini#28167)

* fix(sandbox): make ~/.gitconfig read-only in the macOS sandbox (google-gemini#28221)

Co-authored-by: David Pierce <davidapierce@google.com>

* fix(core): preserve escape sequences in string literals for modern models (google-gemini#28299)

Co-authored-by: David Pierce <davidapierce@google.com>

* fix(core): strip thoughts from scrubbed history turns and resolve thought leakage (google-gemini#27971)

Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
Co-authored-by: Gal Zahavi <38544478+galz10@users.noreply.github.com>
Co-authored-by: David Pierce <davidapierce@google.com>

* Refactor: exclude transient CI configuration files from workspace context (google-gemini#28216)

* feat(caretaker): add triage worker core foundational modules (google-gemini#28163)

* feat(caretaker-egress): implement octokit github action handler for egress service (google-gemini#28303)

* chore(release): bump version to 0.52.0-nightly.20260707.g27a3da3e8 (google-gemini#28323)

* Changelog for v0.51.0-preview.0 (google-gemini#28320)

Co-authored-by: gemini-cli-robot <224641728+gemini-cli-robot@users.noreply.github.com>

* Changelog for v0.50.0 (google-gemini#28322)

Co-authored-by: gemini-cli-robot <224641728+gemini-cli-robot@users.noreply.github.com>
Co-authored-by: David Pierce <davidapierce@google.com>

* fix(core-tools): bypass LLM correction for JSON and IPYNB files in write_file and replace (google-gemini#28223)

Co-authored-by: David Pierce <davidapierce@google.com>

* fix(core): use unambiguous previous intent label in fallback summary (google-gemini#28343)

* feat(caretaker-triage): implement main worker execution loop and egress action publisher (google-gemini#28306)

* fix(privacy): show a clear message when the account has no Code Assist tier (google-gemini#28304)

* fix(core): enrich shared project quota limit errors with setup hint (google-gemini#28391)

* fix(a2a-server): ensure task cancellation aborts execution loop (google-gemini#28316)

* fix(core): simplify plan mode write policy to support relative paths (google-gemini#28398)

* feat(core): Bump node google-auth-library version to 10.9.0 (google-gemini#28385)

Co-authored-by: Jerry Lin <jerrysf@google.com>

* chore/release: bump version to 0.52.0-nightly.20260715.gfa975395b (google-gemini#28402)

* fix(core,a2a): group cancelled tool responses and coalesce consecutive roles to prevent 400 Bad Request (google-gemini#28407)

* feat(caretaker-triage): implement LLM triage orchestrator and container build (google-gemini#28345)

* refactor(cli): align macOS permissive Seatbelt profiles with deny-default model (google-gemini#28424)

* fix(core): mitigate infinite ReAct loops and prompt injection loops (google-gemini#28429)

Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>

* fix(a2a-server): enforce workspace trust and task isolation to prevent RCE (google-gemini#28470)

* fix(core): sequentially verify cached credentials and restore GOOGLE_APPLICATION_CREDENTIALS fallback (google-gemini#28472)

Co-authored-by: David Pierce <davidapierce@google.com>

* feat(evals): add eval coverage report command (google-gemini#28169)

* Changelog for v0.53.0-preview.0 (google-gemini#28507)

Co-authored-by: gemini-cli-robot <224641728+gemini-cli-robot@users.noreply.github.com>

* Changelog for v0.52.0 (google-gemini#28508)

Co-authored-by: gemini-cli-robot <224641728+gemini-cli-robot@users.noreply.github.com>

* chore(release): bump version to 0.54.0-nightly.20260722.gf743ab579 (google-gemini#28510)

* fix(caretaker): sanitize and wrap issue title in untrusted_context (google-gemini#28352)

* chore(caretaker): update vitest to v3.2.4 and add package-lock.json files (google-gemini#28409)

* fix(core): rotate session ID on model fallback to prevent stateful API errors (google-gemini#28469)

* feat(caretaker-triage): post comment before auto-closing issues (google-gemini#28411)

* fix(core): enforce HTTPS for GoogleCredentialsAuthProvider to prevent cleartext leakage (google-gemini#28517)

* fix(core): filter out thought parts from getHistoryTurns when context management is disabled (google-gemini#28509)

---------

Signed-off-by: M-DEV-1 <mahadevankizhakkedathu@gmail.com>
Signed-off-by: Daniel Finimundi <danielrf@motorola.com>
Signed-off-by: krishdef7 <gargkrish06@gmail.com>
Co-authored-by: joshualitt <joshualitt@google.com>
Co-authored-by: Sandy Tao <sandytao520@icloud.com>
Co-authored-by: Christian Van <113378434+cvan20191@users.noreply.github.com>
Co-authored-by: ruomeng <ruomeng@google.com>
Co-authored-by: Adib234 <30782825+Adib234@users.noreply.github.com>
Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
Co-authored-by: Rhys Sullivan <39114868+RhysSullivan@users.noreply.github.com>
Co-authored-by: Jack Wotherspoon <jackwoth@google.com>
Co-authored-by: gemini-cli-robot <gemini-cli-robot@google.com>
Co-authored-by: gemini-cli-robot <224641728+gemini-cli-robot@users.noreply.github.com>
Co-authored-by: Coco Sheng <cocosheng@google.com>
Co-authored-by: Michael Bleigh <mbleigh@mbleigh.com>
Co-authored-by: Tommaso Sciortino <sciortino@gmail.com>
Co-authored-by: Daniel Weis <danielweis@users.noreply.github.com>
Co-authored-by: Christopher Thomas <cobekgn@gmail.com>
Co-authored-by: Sam Roberts <158088236+g-samroberts@users.noreply.github.com>
Co-authored-by: Dev Randalpura <devrandalpura@google.com>
Co-authored-by: Br1an <932039080@qq.com>
Co-authored-by: AK <akhilbussiness@gmail.com>
Co-authored-by: mahadevan <135952571+M-DEV-1@users.noreply.github.com>
Co-authored-by: Christian Gunderman <gundermanc@google.com>
Co-authored-by: Adam Weidman <65992621+adamfweidman@users.noreply.github.com>
Co-authored-by: Aishanee Shah <aishaneeshah@google.com>
Co-authored-by: JAYADITYA <96861162+JayadityaGit@users.noreply.github.com>
Co-authored-by: Sri Pasumarthi <111310667+sripasg@users.noreply.github.com>
Co-authored-by: krishdef7 <157892833+krishdef7@users.noreply.github.com>
Co-authored-by: Spencer <spencertang@google.com>
Co-authored-by: Daniel Finimundi <daniel@finimundi.com>
Co-authored-by: Aryan Singh <146713101+dimssu@users.noreply.github.com>
Co-authored-by: Jacob Richman <jacob314@gmail.com>
Co-authored-by: Suhaan Raqeeb Khavas <suhaanrk73@gmail.com>
Co-authored-by: Neil Nair <65729206+Neil-N4@users.noreply.github.com>
Co-authored-by: Franco Pieri <geo22therm@gmail.com>
Co-authored-by: Eswar809 <deevieswar44@gmail.com>
Co-authored-by: Kuroda Kayn <kurodakayn@outlook.com>
Co-authored-by: Gal Zahavi <38544478+galz10@users.noreply.github.com>
Co-authored-by: Yulong Wu <50110323+TNTCompany@users.noreply.github.com>
Co-authored-by: kevinjwang1 <kevinjwang@google.com>
Co-authored-by: David Pierce <davidapierce@google.com>
Co-authored-by: Sahil Kirad <167863755+sahilkirad@users.noreply.github.com>
Co-authored-by: Jenna Inouye <jinouye@google.com>
Co-authored-by: EMERSON BUSSON <93008583+emersonbusson@users.noreply.github.com>
Co-authored-by: ifitisit <90478348+ifitisit@users.noreply.github.com>
Co-authored-by: PROTHAM <155388736+ProthamD@users.noreply.github.com>
Co-authored-by: 7. Sun <jhao.sun@gmail.com>
Co-authored-by: sotokisehiro <101786086+sotokisehiro@users.noreply.github.com>
Co-authored-by: Anish Sabharwal <anishs1207@gmail.com>
Co-authored-by: kaluchi <kaluchi@gmail.com>
Co-authored-by: Tirth Naik <naik.ti@northeastern.edu>
Co-authored-by: Rajesh patel <145205731+Rajeshpatel07@users.noreply.github.com>
Co-authored-by: Keith Schaab <keith.schaab@gmail.com>
Co-authored-by: Ramón Medrano Llamas <45878745+rmedranollamas@users.noreply.github.com>
Co-authored-by: Om Patel <ompatel.aiml@gmail.com>
Co-authored-by: ashishch432 <55024632+ashishch432@users.noreply.github.com>
Co-authored-by: Andrea Alberti <a.alberti82@gmail.com>
Co-authored-by: Ananth Kini <ananthkini1@gmail.com>
Co-authored-by: Yuvraj Angad Singh <36276913+yuvrajangadsingh@users.noreply.github.com>
Co-authored-by: Debasish <90102437+dibyx@users.noreply.github.com>
Co-authored-by: Hashaam Zahid <68606886+Hashaam101@users.noreply.github.com>
Co-authored-by: tison <wander4096@gmail.com>
Co-authored-by: adithya32 <163162210+KumarADITHYA123@users.noreply.github.com>
Co-authored-by: Syed Ayman Quadri <87442765+saymanq@users.noreply.github.com>
Co-authored-by: jvargassanchez-dot <jvargassanchez@google.com>
Co-authored-by: Billy Biggs <bbiggs@google.com>
Co-authored-by: Om Patel <ompatel@google.com>
Co-authored-by: Mukunda Rao Katta <mukunda.vjcs6@gmail.com>
Co-authored-by: nirali <124287834+Niralisj@users.noreply.github.com>
Co-authored-by: Sikandar <ma5161310@gmail.com>
Co-authored-by: Gaurav <39389231+gsquared94@users.noreply.github.com>
Co-authored-by: luisfelipe-alt <luisfelipe@google.com>
Co-authored-by: Cesar Sanchez Coraspe <sanchezcoraspe@google.com>
Co-authored-by: sidhantgoyal-droid <sidhantgoyal@google.com>
Co-authored-by: amelidev <ameliesther@google.com>
Co-authored-by: Vedant Mahajan <vedant.04.mahajan@gmail.com>
Co-authored-by: Jerry Lin <44830071+jerrylin3321@users.noreply.github.com>
Co-authored-by: Jerry Lin <jerrysf@google.com>
Co-authored-by: Chad <chaddiao0@gmail.com>
Co-authored-by: Chad <chaddiao@google.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/xl An extra large PR status/need-issue Pull requests that need to have an associated issue.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants