Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

fix(guardrails): retarget block-noncanonical-commit at shell interpolation in -m, not at newlines

Aperta
#6,464 1 commento 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
4/5
Tempo stimato
1-2 giorni
Idoneità per principianti
48/100
Tipo di issue
Bug
Chiarezza
Specificata chiaramente
Stato di attività
Attiva
Stack tecnologico
bash, git, powershell, shell

Direzione di ricerca

Start from block-noncanonical-commit.sh (header comments around lines 5-10) and the tests that currently fail on newlines in -m. Retarget the check to interpolating quote contexts that contain backtick or $ in Bash and PowerShell, keep the listed exemptions, and rewrite the block message to name git commit -F - --cleanup=verbatim with a quoted heredoc. Add the acceptance cases in both shells, then empirically confirm git log --format=%B in a scratch repo with the guard disabled.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

needs-human needs-triage

Problem

block-noncanonical-commit.sh blocks git commit -m when the message contains a newline. Its stated reason (lines 5-10) is that a multi-line -m "flattens newlines unpredictably across shells." That claim came from the old commit skill's list of anti-patterns (776bdde81, #72). It became a block in #736 and was narrowed to messages with real newlines in #2058. No reproduced newline failure is cited anywhere.

Tested on 2026-10-05 by passing the message to python -I -c "import sys; print(repr(sys.argv[1]))", which shows the exact argv a program receives:

Shell Argument Received
Bash tool (Git Bash) multi-line, double-quoted, with escaped " and $ exact: 'subject line\n\nBody … "quotes" and $dollar.\n\nCo-Authored-By: …'
PowerShell tool (pwsh 7.6.6, $PSNativeCommandArgumentPassing = Windows) same exact
PowerShell tool single-line "fix: rename `foo` and `bar` to `new` for `$total" mangled: 'fix: rename \x0coo and \x08ar to \new for $total'

So the guard:

  • blocks a safe case: a multi-line message with no special characters.
  • lets the unsafe case through: a double-quoted message containing a backtick or $.
    • In PowerShell, a backtick is the escape character (`f becomes form feed, `b backspace, `n newline) and $ interpolates.
    • In Bash, backticks and $(…) inside double quotes run as command substitution, and $ interpolates.
    • Commit messages often contain code spans in backticks, so this happens in normal use.

Windows PowerShell 5.1's legacy argument passing strips embedded quotes, but neither Claude tool runs 5.1.

Proposal

  • Block git commit -m / --message whose value sits in an interpolating quote context and contains a backtick or $, single-line or multi-line, in both shells:
    • Bash: double quotes, or no quotes.
    • PowerShell: double quotes, or a double-quoted here-string.
  • Allow single-quoted values, single-line or multi-line: Bash '…', PowerShell '…' and @'…'@. Also allow double-quoted values with neither character.
  • Keep git commit -F - --cleanup=verbatim with a quoted heredoc delimiter (<<'EOF') as the form that is always safe, and name it in the block message.
  • Rewrite the header comment and the block message to state the real hazard, with the table above as evidence.
  • Keep the existing exemptions (--amend, -C/-c, --fixup/--squash, -F, an in-progress sequencer), the allow-list option and the kill switch.

Acceptance

  • Tests in both shells:
    • multi-line single-quoted -m: passes
    • multi-line double-quoted plain text: passes
    • single-line double-quoted with a backtick: blocked
    • double-quoted with $: blocked
    • -F - heredoc: passes
  • The block message shows the safe form.
  • Before merging, an empirical check with real git commit -m in a scratch repo, with the guard disabled through its documented setting, confirms git log --format=%B matches the test table.

Related: #6463 (pre-merge state guard).

Lingua principale
Shell
Stelle
22
Fork
2
Merge medio
5h 15m
PR unite (30g)
833

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di melodic-software/claude-code-plugins

Tutte le issue di melodic-software/claude-code-plugins

Issue simili

Altre issue su Shell/Bash

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.