Test the floor against a real shell instead of hand-written shell rules
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Aptitud para principiantes
- 62/100
- Tipo de issue
- Nueva funcionalidad
- Claridad
- Bien especificado
- Estado de actividad
- Activo
- Stack tecnológico
- bash, typescript
Línea de trabajo
Start with floor.ts and evaluateFloor, then inspect how this repository runs tests or scripts. Add a bash-backed fixture with the named command stubs and capture stdout, stderr, file writes, and piped sinks across the listed command shapes. Done means the oracle agrees with evaluateFloor for observable exposures, with file sinks checked against policy, and the test is isolated from the default bun test path if needed.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
floor.ts decides whether a secret reaches a sink by reading the command with hand-written rules. Across four review rounds on #85, every blocking finding was the same mistake: those rules were written from memory of what a shell does, and each fix was right for the case in front of it and wrong for the next spelling.
- Round 1: the host tokenizer strips quotes, so a quoted capture read as a print.
- Round 2: the fd digit came off its redirect, so
2>/dev/nullread as the allowed sink. - Round 3:
nohup,commandandbuiltinwere listed as assignment prefixes. They are not, and the shell's error message prints the secret. - A background review: a backwards scan let a literal
envin argument position restore assignment position, soecho env TOKEN=$(op read …)read as a capture.
What eventually worked was asking the shell. Build it into the repo as a fixture.
Shape
For each command shape, run it in a real bash with stub secret sources on PATH, then compare what the shell did to what evaluateFloor answers.
- Stubs:
security(prints the secret only with-w),op,pass, and apbcopythat appends to a capture file, all in a temp dir prepended toPATH. - Oracle: the secret is exposed when it appears in stdout, stderr, a file the command wrote, or a sink process it was piped into. Capture all four, not just stdout: a first draft that watched stdout alone reported four false mismatches.
- Assertion:
evaluateFloor({command}).asks === exposed, for every shape where the oracle can observe. A file sink asks by policy even when the oracle cannot see the write, so those rows are asserted against the policy instead.
A working version ran 24 shapes (captures quoted, unquoted and backticked; every redirect spelling including &>, &>>, >&, 2>, 1>&2; the wrapper prefixes; quoted read commands) and agreed with the shell on 23, the last being an oracle limitation rather than a floor bug.
Why it is worth the fixture
It converts the recurring class from "a reviewer notices a spelling" into a failing test, and it is the only source consulted so far that has not been wrong. It also gives #90 (time misclassified as an exec wrapper) a natural home: add the shape, watch it fail, move the word.
Cost: it shells out, so it belongs behind its own script or a tagged test rather than in the default bun test path if CI images cannot be trusted to have bash.
- Lenguaje dominante
- TypeScript
- Estrellas
- 0
- Forks
- 1
- Merge medio
- 3 h 35 min
- PR fusionados (30 d)
- 50
Preparar el entorno
Este proyecto no incluye contenedor de desarrollo, Dockerfile ni guía de contribución, así que la configuración corre por tu cuenta: empieza por su README y consulta nuestra guía para la primera contribución para los pasos generales.
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de STRML/omp-classifier
-
Decide whether a coordinator may lift a headless worker's refusal (the trust boundary #68 defers)Abiertoenhancement ready-for-human
Dificultad 5/5 Más de una semana Aptitud para principiantes 25/100
STRML/omp-classifier#142 ·
Los mantenedores suelen responder en 1 día
-
enhancement ready-for-human
Dificultad 4/5 3-5 días Aptitud para principiantes 45/100
STRML/omp-classifier#116 · 8 comentarios ·
Los mantenedores suelen responder en 1 día
-
enhancement ready-for-human
Dificultad 5/5 Más de una semana Aptitud para principiantes 35/100
STRML/omp-classifier#13 · 6 comentarios ·
Los mantenedores suelen responder en 1 día
Todos los issues de STRML/omp-classifier
Issues similares
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
cameri/nostream#811 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
bug p3 triaged
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
Los mantenedores suelen responder en 1 día
-
bug javascript P2-medium python release:v3.1
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
adrirubio/claude-deck#546 ·
Los mantenedores suelen responder en 1 día
-
area: desktop area: website priority: P2 type: feature
Dificultad 2/5 1-3 horas Aptitud para principiantes 62/100
appandflow/stim#3411 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
needs triage
Dificultad 2/5 1-3 horas Aptitud para principiantes 65/100
rjsf-team/react-jsonschema-form#5485 ·
Los mantenedores suelen responder en 2 días