fix(guardrails): retarget block-noncanonical-commit at shell interpolation in -m, not at newlines
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 4/5
- Tiempo estimado
- 1-2 días
- Aptitud para principiantes
- 48/100
- Tipo de issue
- Error
- Claridad
- Bien especificado
- Estado de actividad
- Activo
- Stack tecnológico
- bash, git, powershell, shell
- Área
- cli, developer-experience, tooling
Línea de trabajo
Start from block-noncanonical-commit.sh (header comments around lines 5-10) and the tests that currently fail on newlines in -m. Retarget the check to interpolating quote contexts that contain backtick or $ in Bash and PowerShell, keep the listed exemptions, and rewrite the block message to name git commit -F - --cleanup=verbatim with a quoted heredoc. Add the acceptance cases in both shells, then empirically confirm git log --format=%B in a scratch repo with the guard disabled.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Problem
block-noncanonical-commit.sh blocks git commit -m when the message contains a newline. Its stated reason (lines 5-10) is that a multi-line -m "flattens newlines unpredictably across shells." That claim came from the old commit skill's list of anti-patterns (776bdde81, #72). It became a block in #736 and was narrowed to messages with real newlines in #2058. No reproduced newline failure is cited anywhere.
Tested on 2026-10-05 by passing the message to python -I -c "import sys; print(repr(sys.argv[1]))", which shows the exact argv a program receives:
| Shell | Argument | Received |
|---|---|---|
| Bash tool (Git Bash) | multi-line, double-quoted, with escaped " and $ |
exact: 'subject line\n\nBody … "quotes" and $dollar.\n\nCo-Authored-By: …' |
PowerShell tool (pwsh 7.6.6, $PSNativeCommandArgumentPassing = Windows) |
same | exact |
| PowerShell tool | single-line "fix: rename `foo` and `bar` to `new` for `$total" |
mangled: 'fix: rename \x0coo and \x08ar to \new for $total' |
So the guard:
- blocks a safe case: a multi-line message with no special characters.
- lets the unsafe case through: a double-quoted message containing a backtick or
$.- In PowerShell, a backtick is the escape character (
`fbecomes form feed,`bbackspace,`nnewline) and$interpolates. - In Bash, backticks and
$(…)inside double quotes run as command substitution, and$interpolates. - Commit messages often contain code spans in backticks, so this happens in normal use.
- In PowerShell, a backtick is the escape character (
Windows PowerShell 5.1's legacy argument passing strips embedded quotes, but neither Claude tool runs 5.1.
Proposal
- Block
git commit -m/--messagewhose value sits in an interpolating quote context and contains a backtick or$, single-line or multi-line, in both shells:- Bash: double quotes, or no quotes.
- PowerShell: double quotes, or a double-quoted here-string.
- Allow single-quoted values, single-line or multi-line: Bash
'…', PowerShell'…'and@'…'@. Also allow double-quoted values with neither character. - Keep
git commit -F - --cleanup=verbatimwith a quoted heredoc delimiter (<<'EOF') as the form that is always safe, and name it in the block message. - Rewrite the header comment and the block message to state the real hazard, with the table above as evidence.
- Keep the existing exemptions (
--amend,-C/-c,--fixup/--squash,-F, an in-progress sequencer), the allow-list option and the kill switch.
Acceptance
- Tests in both shells:
- multi-line single-quoted
-m: passes - multi-line double-quoted plain text: passes
- single-line double-quoted with a backtick: blocked
- double-quoted with
$: blocked -F -heredoc: passes
- multi-line single-quoted
- The block message shows the safe form.
- Before merging, an empirical check with real
git commit -min a scratch repo, with the guard disabled through its documented setting, confirmsgit log --format=%Bmatches the test table.
Related: #6463 (pre-merge state guard).
- Lenguaje dominante
- Shell
- Estrellas
- 22
- Forks
- 2
- Merge medio
- 5 h 11 min
- PR fusionados (30 d)
- 838
Preparar el entorno
- Sin Dockerfile ni archivo de Docker Compose
- Sin plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de melodic-software/claude-code-plugins
-
good first issue needs-triage priority: medium
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
melodic-software/claude-code-plugins#6631 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
needs-triage
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
melodic-software/claude-code-plugins#6547 ·
Los mantenedores suelen responder en 1 día
-
needs-triage
Dificultad 2/5 1-3 horas Aptitud para principiantes 76/100
melodic-software/claude-code-plugins#6535 ·
Los mantenedores suelen responder en 1 día
-
test_comment_census.py: SccArgv flag-shaped-filename test errors on Windows (#!/bin/sh scc shim)Abiertogood first issue needs-triage priority: low
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
melodic-software/claude-code-plugins#6532 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
good first issue needs-triage priority: low
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
melodic-software/claude-code-plugins#6390 · 1 comentario ·
Los mantenedores suelen responder en 1 día
Todos los issues de melodic-software/claude-code-plugins
Issues similares
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
gnosis/gnosis_vpn#540 ·
Los mantenedores suelen responder en 1 día
-
bug milestone-qa
Dificultad 2/5 1-3 horas Aptitud para principiantes 74/100
lognorman20/monaco#3901 ·
-
Lid close does not lock the session on Apple Silicon (lid-close bind skips omarchy-system-lid-close)Abierto
Dificultad 1/5 1-3 horas Aptitud para principiantes 90/100
omacom/omarchy-mac#701 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
A 20.x release after 21.0.0 would move `latest` back to 20.x, and `next` stays on the release candidatePosiblemente ocupada @armando-navarro la tomó hoy. Abiertocomp: build/pipeline type: bug version: current (v17+)
Dificultad 2/5 1-3 horas Aptitud para principiantes 85/100
angular/angularfire#3790 ·
Los mantenedores suelen responder en 3 días