Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

floor: the secret-file check can't see runtime values (globs, expansion side effects, symlinks, code)

Abierto
#97 0 comentarios 0 reacciones 0 asignados Ver en GitHub

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
5/5
Tiempo estimado
Más de una semana
Aptitud para principiantes
35/100
Tipo de issue
Nueva funcionalidad
Claridad
Bastante claro
Estado de actividad
Activo
Stack tecnológico
python, shell, typescript
Área
security

Línea de trabajo

Start with floor.ts and section 4 of docs/plans/2026-09-22-real-shell-parser.md, then review the runtime file resolution described in #67 and spawn interception in the eval kernel from #13. Done means the reviewer sees the files opened at runtime or the argv actually spawned, rather than only source spellings.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

The floor's secret-file check is a check on names, and names don't cover runtime values. PR #96 hit the Codex review cap on this: each of three rounds found a new runtime spelling, and the class doesn't close by adding spellings.

Passes the floor Why a name check can't see it
cat .e* the glob matches whatever is on disk
cat ${x:=key.txt} ${x/txt/pem} the first expansion assigns x, the second reads it
ln -s ~/.aws/credentials notes.txt && cat notes.txt a symlink renames any file
subprocess.run(["o" "p", "read", "op://v/i/c"]) in eval Python joins the literals, and the floor doesn't evaluate Python

What #96 does about it: the floor reads each word as the text it's written as, so *.pem still asks and .e* doesn't. The limit is written down as a decision in docs/plans/2026-09-22-real-shell-parser.md section 4. Every one of these reaches the reviewer.

This issue tracks whether anything below the reviewer should close it. Two ways that would actually work, not more spellings:

  • For shell, judge the file the command opens, not its name. That means resolving it at run time, the same move #67 makes for script bodies. Symlinks need this too.
  • For code, intercept the spawn in the eval kernel (#13) so the floor sees the argv the kernel runs, not the source text.

Until then, don't add glob samples, expansion simulation, or language-specific string parsing to floor.ts. Rounds 2 and 3 on #96 show where that goes.

Related: #95 (the summary's version of the same limit), #91.

Lenguaje dominante
TypeScript
Estrellas
0
Forks
1
Merge medio
1 h 15 min
PR fusionados (30 d)
49

Guía de contribución

No hay ninguna guía de contribución indexada para este repositorio

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de STRML/omp-classifier

Todos los issues de STRML/omp-classifier

Issues similares

Más issues de TypeScript

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.