Repository navigation
fix(analyzer): keep checking command lines inside a word that spans lines - #814
Open
elliottwaves-20 wants to merge 1 commit into
Open
elliottwaves-20 wants to merge 1 commit into
elliottwaves-20 wants to merge 1 commit into
Conversation
…ines
A quote in a heredoc body, a shell comment or Markdown prose can pair with
a quote on a later command line. The command-word scan then parsed one word
across those lines and skipped every candidate inside it, so a runtime
command such as
cat <<E
he said "hi
E
$CMD"" -rf / # "
was reported as completely inspected.
A word that spans a line break now opens a shadow region instead of moving
the parse frontier. Candidates in that region are still checked at command
positions (line start or after ; | & (), but they never own quotes, never
move the frontier, and an unresolved parse there is not charged to the
budget. Python sources keep their AST-proven frontier. Later candidates are
the same as on main, so the result is never less strict than main.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: elliottwaves-20 <pail1217@web.de>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #813.
Problem
A double quote in a heredoc body, a shell comment or Markdown prose can pair with a quote on a later command line.
_has_shell_command_word_exhaustionthen parses one word across those lines and movesparsed_throughpast it. Every candidate inside the word is skipped, including a runtime-selected command such as$CMD"" -rf /, and the file is reported as completely inspected. The reproducers are in #813.Change
The fix does not try to prove shell quote state. It only stops a multi-line word from hiding later command lines.
shadow_through) instead of movingparsed_through.;,|,&or((new helper_is_shell_command_position). That keeps the extra parse work linear in the number of lines, andtest_json_owned_runtime_bounds.pystill passes.parsed_throughorshadow_through. An unresolved parse inside the region is not charged to the command-word budget, because the spanning word already closed that region's quotes.python_source is not None) keep the current frontier, because the AST already proves their string and comment bounds.The candidates after the region are therefore the same as on
main, and the region's candidates can only add checks. No file can move from partial to complete.Tests
tests/nodes/analyzers/test_multiline_word_shadow.py:test_quote_spanning_lines_cannot_hide_a_later_command: comment, heredoc with plain and quoted delimiter,${X},${X}" ",$()"e", a backtick variant, lone-CR line endings, and Markdown prose into a fence. Each runs short and padded. All fail onmain.test_heredoc_quote_cannot_hide_a_runtime_rm_at_scan_level: therun.shfrom Quote in a heredoc body, comment or prose hides a later command line from the command-word scan #813 throughrun_static_patterns_with_ledger, expected to be notCOMPLETED.echo "…$HOME"stays complete, a dynamic multi-line$(…)word behaves as onmain, and Python sources keep their frontier.Verification against main 5edc347
mainand on this branch. Those failures are Windows/environment-specific on my machine (release, git and CLI tests).mainskipped those lines.mainis partial and this branch is complete.🤖 Generated with Claude Code