fix(tools): add logging filter to redact secrets from libtmux log output - #4871
Open
all-hands-bot wants to merge 1 commit into
Open
fix(tools): add logging filter to redact secrets from libtmux log output#4871all-hands-bot wants to merge 1 commit into
all-hands-bot wants to merge 1 commit into
Conversation
The libtmux library logs full tmux command strings (including send-keys arguments) to stderr when exceptions occur. This can leak API keys and other secrets that agents send through the terminal. Add a SecretRedactFilter to the libtmux logger that applies redact_api_key_literals() from the SDK's redaction utilities to all log messages before they are emitted. Refs: OpenHands/evaluation#446 Co-authored-by: openhands <openhands@all-hands.dev>
Collaborator
Author
|
👋 This PR needs a couple of things fixed before OpenHands can review it:
Push an update once this is addressed and this check re-runs automatically. This is an automated check - no AI was used to generate this comment. |
Contributor
Python API breakage checks — ✅ PASSEDResult: ✅ PASSED |
Contributor
REST API breakage checks (OpenAPI) — ✅ PASSEDResult: ✅ PASSED |
Contributor
Coverage Report •
|
||||||||||||||||||||
simonrosenberg
approved these changes
Sep 6, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Add a
SecretRedactFilterlogging filter to thelibtmuxlogger to prevent secrets from leaking in tmux command log output.Problem
The
libtmuxlibrary'stmux_cmdclass logs the full tmux command string (includingsend-keysarguments) vialogger.exception()/logger.error()when exceptions occur. When an agent sends a command containing API keys or other secrets through the terminal, those secrets appear unredacted in production stderr logs (observed in Datadog:prod-runtime/runtime-pods/runtime-*).Fix
Install a logging filter on the
libtmuxlogger duringTmuxTerminalinitialization that appliesredact_api_key_literals()fromopenhands.sdk.utils.redactto log messages and extra fields before they're emitted.Refs: OpenHands/evaluation#446, #383
This PR was created by an AI agent (OpenHands) on behalf of the security scan workflow.
🐳 Agent Server images for this PR — GHCR package, pull/run commands, and all pushed tags (click to expand)
• GHCR package: https://github.com/OpenHands/agent-sdk/pkgs/container/agent-server
Variants & Base Images
eclipse-temurin:17-jdknikolaik/python-nodejs:python3.13-nodejs22-slimnikolaik/python-nodejs:python3.13-nodejs22-slimgolang:1.21-bookwormPull (multi-arch manifest)
# Each variant is a multi-arch manifest supporting both amd64 and arm64 docker pull ghcr.io/openhands/agent-server:494251b-pythonRun
All tags pushed for this build
About Multi-Architecture Support
494251b-python) is a multi-arch manifest supporting both amd64 and arm64494251b-python-amd64) are also available if needed