Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

Error-tolerant parse: recovered commands for unparseable input (deny-only use)

オープン
#190 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 1 日以内に返信

まだ誰も着手していません。

評価

難易度
5/5
見積もり時間
1週間以上
初心者へのやさしさ
35/100
issue の種類
機能追加
明瞭さ
おおむね明確
活発さ
活発
技術スタック
csharp
領域
cli

調査の方向性

Start by locating ParsedCommand and the existing exact parser projections for Commands, Clauses, IsUnparseable, and Syntax. Review how the parser handles unbalanced quotes, separators, assignments, and wrapper children before designing the recovered projection. Done means adding a clearly non-authoritative RecoveredCommands API that over-reports safely, preserves exact projections, and documents deny-only use.

索引モデルが issue の本文から書いたものです。

説明

enhancement

Problem

When ParsedCommand.IsUnparseable is true, Commands and Clauses are empty. A consumer then has no command words to check. Syntax can contain partial diagnostic evidence, but it has no stable projection that a consumer can use.

A security consumer must still find dangerous commands in input that the parser rejects. For example, a deny list must find rm -rf / in rm -rf / ; echo "unbalanced. Today each consumer must write its own raw-text splitter. Netclaw has one (LegacyShellTextScan, about 300 lines). It splits on whitespace outside quotes, guesses at list separators and wrapper children, and guesses a path style. That code is a second, weaker shell reader, and it drifts from the parser.

Proposal: error-tolerant parse with a separate recovered projection

Add a recovery result for unparseable input, similar to Roslyn error recovery. The parser returns what it could read, marked clearly as not authoritative.

Schematic API (names are open):

public sealed record ParsedCommand
{
    // Unchanged: exact, fail-closed projections. Empty when IsUnparseable.
    public IReadOnlyList<CommandOccurrence> Commands { get; }
    public bool IsUnparseable { get; }

    // New: populated only when IsUnparseable is true.
    public IReadOnlyList<RecoveredCommand> RecoveredCommands { get; }
}

public sealed record RecoveredCommand(
    IReadOnlyList<string> Words,     // quote-removed words, best effort
    SourceRange Range,               // where in Source
    RecoveryReason Reason);          // unbalanced quote, unknown construct, ...

Contract

  • Commands and Clauses keep their current meaning. Recovery never adds to them.
  • RecoveredCommands is for deny-only use: deny lists, protected-path checks, and audit. The XML docs must say that a consumer must not allow, approve, or grant anything from a recovered command.
  • Recovery must over-report, not under-report. If the parser cannot decide whether text is one command or two, it returns both readings.
  • Recovery includes wrapper children when the wrapper text is readable (bash -c "...", sh -c '...', pwsh -Command ...).
  • Recovery uses the same grammar code as the exact parser where it can. A second tokenizer is not the goal.

Examples

Positive (recovered words exist):

  • rm -rf / ; echo "unbalanced recovers rm -rf / and echo unbalanced.
  • X=1 Y=2 netclaw daemon stop (until #189 lands) recovers netclaw daemon stop with the assignments skipped.
  • bash -c "shutdown now; echo 'x recovers shutdown now from the wrapper child.

Negative:

  • Input that parses exactly has an empty RecoveredCommands. The exact projection is the only source of truth.
  • A recovered command never appears in Commands, so ls ; echo "x stays unparseable and does not become an approved ls.

Consumer plan

Netclaw will check recovered commands against its hard-deny list and protected-path hints, and then delete LegacyShellTextScan. Netclaw keeps its policy data (deny lists, path hints). Only the grammar work moves here.

主要言語
C#
スター
15
フォーク
0
平均マージ
9時間 54分
マージ済み PR(30日)
40

環境構築

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

Aaronontheweb/ShellSyntaxTree のほかの issue

Aaronontheweb/ShellSyntaxTree の issue をすべて見る

似ている issue

C# の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。