Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

Test the floor against a real shell instead of hand-written shell rules

Cerrado
#91 0 comentarios 0 reacciones 0 asignados Ver en GitHub

Los mantenedores suelen responder en 1 día

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
4/5
Tiempo estimado
3-5 días
Aptitud para principiantes
62/100
Tipo de issue
Nueva funcionalidad
Claridad
Bien especificado
Estado de actividad
Activo
Stack tecnológico
bash, typescript
Área
security, testing

Línea de trabajo

Start with floor.ts and evaluateFloor, then inspect how this repository runs tests or scripts. Add a bash-backed fixture with the named command stubs and capture stdout, stderr, file writes, and piped sinks across the listed command shapes. Done means the oracle agrees with evaluateFloor for observable exposures, with file sinks checked against policy, and the test is isolated from the default bun test path if needed.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

floor.ts decides whether a secret reaches a sink by reading the command with hand-written rules. Across four review rounds on #85, every blocking finding was the same mistake: those rules were written from memory of what a shell does, and each fix was right for the case in front of it and wrong for the next spelling.

  • Round 1: the host tokenizer strips quotes, so a quoted capture read as a print.
  • Round 2: the fd digit came off its redirect, so 2>/dev/null read as the allowed sink.
  • Round 3: nohup, command and builtin were listed as assignment prefixes. They are not, and the shell's error message prints the secret.
  • A background review: a backwards scan let a literal env in argument position restore assignment position, so echo env TOKEN=$(op read …) read as a capture.

What eventually worked was asking the shell. Build it into the repo as a fixture.

Shape

For each command shape, run it in a real bash with stub secret sources on PATH, then compare what the shell did to what evaluateFloor answers.

  • Stubs: security (prints the secret only with -w), op, pass, and a pbcopy that appends to a capture file, all in a temp dir prepended to PATH.
  • Oracle: the secret is exposed when it appears in stdout, stderr, a file the command wrote, or a sink process it was piped into. Capture all four, not just stdout: a first draft that watched stdout alone reported four false mismatches.
  • Assertion: evaluateFloor({command}).asks === exposed, for every shape where the oracle can observe. A file sink asks by policy even when the oracle cannot see the write, so those rows are asserted against the policy instead.

A working version ran 24 shapes (captures quoted, unquoted and backticked; every redirect spelling including &>, &>>, >&, 2>, 1>&2; the wrapper prefixes; quoted read commands) and agreed with the shell on 23, the last being an oracle limitation rather than a floor bug.

Why it is worth the fixture

It converts the recurring class from "a reviewer notices a spelling" into a failing test, and it is the only source consulted so far that has not been wrong. It also gives #90 (time misclassified as an exec wrapper) a natural home: add the shape, watch it fail, move the word.

Cost: it shells out, so it belongs behind its own script or a tagged test rather than in the default bun test path if CI images cannot be trusted to have bash.

Lenguaje dominante
TypeScript
Estrellas
0
Forks
1
Merge medio
3 h 35 min
PR fusionados (30 d)
50

Preparar el entorno

Este proyecto no incluye contenedor de desarrollo, Dockerfile ni guía de contribución, así que la configuración corre por tu cuenta: empieza por su README y consulta nuestra guía para la primera contribución para los pasos generales.

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de STRML/omp-classifier

Todos los issues de STRML/omp-classifier

Issues similares

Más issues de TypeScript

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.