floor: the secret-file check can't see runtime values (globs, expansion side effects, symlinks, code)
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 5/5
- Tiempo estimado
- Más de una semana
- Aptitud para principiantes
- 35/100
- Tipo de issue
- Nueva funcionalidad
- Claridad
- Bastante claro
- Estado de actividad
- Activo
- Stack tecnológico
- python, shell, typescript
- Área
- security
Línea de trabajo
Start with floor.ts and section 4 of docs/plans/2026-09-22-real-shell-parser.md, then review the runtime file resolution described in #67 and spawn interception in the eval kernel from #13. Done means the reviewer sees the files opened at runtime or the argv actually spawned, rather than only source spellings.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
The floor's secret-file check is a check on names, and names don't cover runtime values. PR #96 hit the Codex review cap on this: each of three rounds found a new runtime spelling, and the class doesn't close by adding spellings.
| Passes the floor | Why a name check can't see it |
|---|---|
cat .e* |
the glob matches whatever is on disk |
cat ${x:=key.txt} ${x/txt/pem} |
the first expansion assigns x, the second reads it |
ln -s ~/.aws/credentials notes.txt && cat notes.txt |
a symlink renames any file |
subprocess.run(["o" "p", "read", "op://v/i/c"]) in eval |
Python joins the literals, and the floor doesn't evaluate Python |
What #96 does about it: the floor reads each word as the text it's written as, so *.pem still asks and .e* doesn't. The limit is written down as a decision in docs/plans/2026-09-22-real-shell-parser.md section 4. Every one of these reaches the reviewer.
This issue tracks whether anything below the reviewer should close it. Two ways that would actually work, not more spellings:
- For shell, judge the file the command opens, not its name. That means resolving it at run time, the same move #67 makes for script bodies. Symlinks need this too.
- For code, intercept the spawn in the eval kernel (#13) so the floor sees the argv the kernel runs, not the source text.
Until then, don't add glob samples, expansion simulation, or language-specific string parsing to floor.ts. Rounds 2 and 3 on #96 show where that goes.
Related: #95 (the summary's version of the same limit), #91.
- Lenguaje dominante
- TypeScript
- Estrellas
- 0
- Forks
- 1
- Merge medio
- 1 h 15 min
- PR fusionados (30 d)
- 49
Guía de contribución
No hay ninguna guía de contribución indexada para este repositorio
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de STRML/omp-classifier
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 80/100
STRML/omp-classifier#111 ·
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
STRML/omp-classifier#107 ·
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
STRML/omp-classifier#88 ·
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 74/100
STRML/omp-classifier#86 ·
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 85/100
STRML/omp-classifier#81 ·
Todos los issues de STRML/omp-classifier
Issues similares
-
bug(cli): hapi doctor inline-media prints a fabricated B:\ helper-script path in packaged installs Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
-
Crush Abierto
Dificultad 1/5 Menos de una hora Aptitud para principiantes 85/100
catppuccin/catppuccin#3125 ·
-
Add a SECURITY.md Abierto
Dificultad 1/5 Menos de una hora Aptitud para principiantes 90/100
ElementsProject/cln-application#167 · 1 comentario · 1 reacción ·
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
Quantco/pnpm-licenses#17 ·
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100