Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

fix(guardrails): retarget block-noncanonical-commit at shell interpolation in -m, not at newlines

Abierto
#6,464 1 comentario 0 reacciones 0 asignados Ver en GitHub

Los mantenedores suelen responder en 1 día

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
4/5
Tiempo estimado
1-2 días
Aptitud para principiantes
48/100
Tipo de issue
Error
Claridad
Bien especificado
Estado de actividad
Activo
Stack tecnológico
bash, git, powershell, shell

Línea de trabajo

Start from block-noncanonical-commit.sh (header comments around lines 5-10) and the tests that currently fail on newlines in -m. Retarget the check to interpolating quote contexts that contain backtick or $ in Bash and PowerShell, keep the listed exemptions, and rewrite the block message to name git commit -F - --cleanup=verbatim with a quoted heredoc. Add the acceptance cases in both shells, then empirically confirm git log --format=%B in a scratch repo with the guard disabled.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

needs-human needs-triage

Problem

block-noncanonical-commit.sh blocks git commit -m when the message contains a newline. Its stated reason (lines 5-10) is that a multi-line -m "flattens newlines unpredictably across shells." That claim came from the old commit skill's list of anti-patterns (776bdde81, #72). It became a block in #736 and was narrowed to messages with real newlines in #2058. No reproduced newline failure is cited anywhere.

Tested on 2026-10-05 by passing the message to python -I -c "import sys; print(repr(sys.argv[1]))", which shows the exact argv a program receives:

Shell Argument Received
Bash tool (Git Bash) multi-line, double-quoted, with escaped " and $ exact: 'subject line\n\nBody … "quotes" and $dollar.\n\nCo-Authored-By: …'
PowerShell tool (pwsh 7.6.6, $PSNativeCommandArgumentPassing = Windows) same exact
PowerShell tool single-line "fix: rename `foo` and `bar` to `new` for `$total" mangled: 'fix: rename \x0coo and \x08ar to \new for $total'

So the guard:

  • blocks a safe case: a multi-line message with no special characters.
  • lets the unsafe case through: a double-quoted message containing a backtick or $.
    • In PowerShell, a backtick is the escape character (`f becomes form feed, `b backspace, `n newline) and $ interpolates.
    • In Bash, backticks and $(…) inside double quotes run as command substitution, and $ interpolates.
    • Commit messages often contain code spans in backticks, so this happens in normal use.

Windows PowerShell 5.1's legacy argument passing strips embedded quotes, but neither Claude tool runs 5.1.

Proposal

  • Block git commit -m / --message whose value sits in an interpolating quote context and contains a backtick or $, single-line or multi-line, in both shells:
    • Bash: double quotes, or no quotes.
    • PowerShell: double quotes, or a double-quoted here-string.
  • Allow single-quoted values, single-line or multi-line: Bash '…', PowerShell '…' and @'…'@. Also allow double-quoted values with neither character.
  • Keep git commit -F - --cleanup=verbatim with a quoted heredoc delimiter (<<'EOF') as the form that is always safe, and name it in the block message.
  • Rewrite the header comment and the block message to state the real hazard, with the table above as evidence.
  • Keep the existing exemptions (--amend, -C/-c, --fixup/--squash, -F, an in-progress sequencer), the allow-list option and the kill switch.

Acceptance

  • Tests in both shells:
    • multi-line single-quoted -m: passes
    • multi-line double-quoted plain text: passes
    • single-line double-quoted with a backtick: blocked
    • double-quoted with $: blocked
    • -F - heredoc: passes
  • The block message shows the safe form.
  • Before merging, an empirical check with real git commit -m in a scratch repo, with the guard disabled through its documented setting, confirms git log --format=%B matches the test table.

Related: #6463 (pre-merge state guard).

Lenguaje dominante
Shell
Estrellas
22
Forks
2
Merge medio
5 h 11 min
PR fusionados (30 d)
838

Preparar el entorno

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de melodic-software/claude-code-plugins

Todos los issues de melodic-software/claude-code-plugins

Issues similares

Más issues de Shell/Bash

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.