fix(shell-sync): remove interactive shell mode and reduce security false positives - #2403
Open
VitalyMarom wants to merge 6 commits into
Open
VitalyMarom wants to merge 6 commits into
VitalyMarom wants to merge 6 commits into
Conversation
…nly rc files Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…e-zsh Drop -i from the login-shell env sync
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This PR removes the explicit -i (interactive) argument when spawning Fish-like shells during shell environment detection.
Related Issues:
#2377
#2376
Motivation
The interactive flag is not required for environment computation when the shell is already started as a login shell (-l).
Using an interactive shell for environment discovery may also trigger security monitoring and endpoint protection tools. Some EDR and security products can flag this behavior as suspicious shell-spawning activity or reverse shell-like behavior, resulting in false-positive security alerts.
Additionally, shell environment variables intended for GUI applications should generally be configured in login shell initialization files. For example, in Zsh the recommended location is:
~/.zprofileSince .zprofile is evaluated by login shells, running an additional interactive shell should not be necessary for environment synchronization.
Changes
["-l"]instead of["-l", "-i"]Benefits
Testing
Updated the existing test to verify that Fish-like shells are spawned with:
["-l"]and confirmed that environment detection continues to work as expected.