Hserver Failure Notes: Safe Automation · advanced
shell=False Is a Small Setting with a Large Security Boundary
Passing an argument array directly to exec avoids an entire class of shell expansion and injection behavior.
Avoiding unnecessary interpreters is a classic secure-execution principle. Data should remain data instead of being re-parsed as code by an extra language layer. The dedicated ops runner executes approved host commands with parameters supplied through controlled portal requests. Introducing a shell between the runner and command would make quoting rules and metacharacters part of the security model.
A shell interprets strings; an exec-style process launch passes arguments. The former expands the space of possible behavior far beyond the reviewed command structure.
The runner uses shell=False, validates parameters and restricts executable interpreters to reviewed paths. Represent commands as arrays, validate every parameter against the job schema and reject any feature that requires concatenating untrusted input into a shell command line. The concrete hserver evidence is commit 9e6f8a5, so this note is tied to an actual production change rather than a hypothetical failure.