quoteCmdArg corrupts arguments containing a literal `"` on cmd surfaces
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Aptitud para principiantes
- 45/100
- Tipo de issue
- Error
- Claridad
- Bastante claro
- Estado de actividad
- Tranquilo
- Stack tecnológico
- typescript
- Área
- cli
Línea de trabajo
Comience en dor/src/commands/shell-quote.ts, en quoteCmdArg, y revise las expectativas existentes en dor/test/cli-output.test.mjs alrededor de las líneas 204-206. Valide el comportamiento elegido para las comillas literales en un host Windows cmd.exe, después añada un caso de regresión con comillas incrustadas y confirme que el programa iniciado recibe el argumento original.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
quoteCmdArg corrupts arguments containing a literal " on cmd surfaces
When dor forwards a command tail (dor split -- …, dor ensure …) to a pane whose shell is cmd.exe, the host renders the argv with quoteCmdArg. For any argument that contains a double-quote, the output is malformed.
Trace
function quoteCmdArg(arg: string): string {
if (arg === '') return '""';
const escaped = arg
.replace(/[%]/g, '%%')
.replace(/([&|<>()^"])/g, '^$1'); // caret-escapes the "
if (WINDOWS_SAFE_ARG.test(arg)) return escaped;
return `"${escaped}"`; // ...then wraps the result in quotes
}
For arg = 'say "hi"' the function:
- caret-escapes each
"→say ^"hi^", then - wraps in surrounding quotes →
"say ^"hi^"".
Inside a cmd double-quoted region, ^ is not an escape character — it is literal. So the embedded ^" does not produce an escaped quote; the first ^" is read as a literal ^ followed by a quote that closes the surrounding quoted region early, and the rest of the argument is re-parsed outside quotes. The argument the launched program receives is not say "hi".
The same belt-and-suspenders pattern (caret-escape and wrap in quotes) is what the existing test pins for a&b → "a^&b" (cli-output.test.mjs:204-206); for &/(/) the caret inside quotes is merely redundant (those chars are already literal inside quotes), so it's harmless-but-odd. For " it is actively wrong, and that case is untested.
Why this needs maintainer input rather than a drive-by fix
Correct cmd-line quoting for a literal " depends on how the receiving program parses its command line (the msvcrt/CommandLineToArgvW convention uses \" and ""; a bare cmd builtin differs). Picking the right escaping is a design decision that should be validated on an actual Windows + cmd.exe host, which this CI environment can't do. Flagging rather than guessing.
Suggested direction (needs Windows verification)
For the cmd kind, escape an embedded " by doubling it ("") or backslash-escaping (\") inside the wrapped form, and don't caret-escape characters that already sit inside the surrounding quotes. Add a cli-output.test.mjs case with an embedded " to pin whatever behavior is chosen.
Surfaced by the nightly code-quality survey.
- Lenguaje dominante
- TypeScript
- Estrellas
- 5
- Forks
- 1
- Merge medio
- 11 h 50 min
- PR fusionados (30 d)
- 353
Preparar el entorno
Este proyecto no incluye contenedor de desarrollo, Dockerfile ni guía de contribución, así que la configuración corre por tu cuenta: empieza por su README y consulta nuestra guía para la primera contribución para los pasos generales.
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de diffplug/dormouse
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 86/100
diffplug/dormouse#912 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Dificultad 4/5 3-5 días Aptitud para principiantes 35/100
diffplug/dormouse#968 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Dificultad 5/5 Más de una semana Aptitud para principiantes 42/100
diffplug/dormouse#910 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
security-audit-failure
Dificultad 5/5 Más de una semana Aptitud para principiantes 35/100
diffplug/dormouse#908 · 4 comentarios ·
Los mantenedores suelen responder en 1 día
-
review-runs-tracking: 2026-10Abiertoreview-runs-tracking
Dificultad 5/5 Más de una semana Aptitud para principiantes 10/100
diffplug/dormouse#881 · 1 comentario ·
Los mantenedores suelen responder en 1 día
Todos los issues de diffplug/dormouse
Issues similares
-
enhancement
Dificultad 2/5 1-3 horas Aptitud para principiantes 86/100
tomjn/coilbox-hub#454 ·
Los mantenedores suelen responder en 1 día
-
enhancement
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
Los mantenedores suelen responder en 1 día
-
api: spanner
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
googleapis/google-cloud-node#9513 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 92/100
Los mantenedores suelen responder en 1 día
-
SegmentedControl calls Math.random() during render, breaking Next.js cacheComponents prerenderingAbierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 76/100
mantinedev/mantine#9244 ·
Los mantenedores suelen responder en 8 días