Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

Test the floor against a real shell instead of hand-written shell rules

クローズ
#91 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 1 日以内に返信

まだ誰も着手していません。

評価

難易度
4/5
見積もり時間
3〜5日
初心者へのやさしさ
62/100
issue の種類
機能追加
明瞭さ
明確に書かれている
活発さ
活発
技術スタック
bash, typescript
領域
security, testing

調査の方向性

Start with floor.ts and evaluateFloor, then inspect how this repository runs tests or scripts. Add a bash-backed fixture with the named command stubs and capture stdout, stderr, file writes, and piped sinks across the listed command shapes. Done means the oracle agrees with evaluateFloor for observable exposures, with file sinks checked against policy, and the test is isolated from the default bun test path if needed.

索引モデルが issue の本文から書いたものです。

説明

floor.ts decides whether a secret reaches a sink by reading the command with hand-written rules. Across four review rounds on #85, every blocking finding was the same mistake: those rules were written from memory of what a shell does, and each fix was right for the case in front of it and wrong for the next spelling.

  • Round 1: the host tokenizer strips quotes, so a quoted capture read as a print.
  • Round 2: the fd digit came off its redirect, so 2>/dev/null read as the allowed sink.
  • Round 3: nohup, command and builtin were listed as assignment prefixes. They are not, and the shell's error message prints the secret.
  • A background review: a backwards scan let a literal env in argument position restore assignment position, so echo env TOKEN=$(op read …) read as a capture.

What eventually worked was asking the shell. Build it into the repo as a fixture.

Shape

For each command shape, run it in a real bash with stub secret sources on PATH, then compare what the shell did to what evaluateFloor answers.

  • Stubs: security (prints the secret only with -w), op, pass, and a pbcopy that appends to a capture file, all in a temp dir prepended to PATH.
  • Oracle: the secret is exposed when it appears in stdout, stderr, a file the command wrote, or a sink process it was piped into. Capture all four, not just stdout: a first draft that watched stdout alone reported four false mismatches.
  • Assertion: evaluateFloor({command}).asks === exposed, for every shape where the oracle can observe. A file sink asks by policy even when the oracle cannot see the write, so those rows are asserted against the policy instead.

A working version ran 24 shapes (captures quoted, unquoted and backticked; every redirect spelling including &>, &>>, >&, 2>, 1>&2; the wrapper prefixes; quoted read commands) and agreed with the shell on 23, the last being an oracle limitation rather than a floor bug.

Why it is worth the fixture

It converts the recurring class from "a reviewer notices a spelling" into a failing test, and it is the only source consulted so far that has not been wrong. It also gives #90 (time misclassified as an exec wrapper) a natural home: add the shape, watch it fail, move the word.

Cost: it shells out, so it belongs behind its own script or a tagged test rather than in the default bun test path if CI images cannot be trusted to have bash.

主要言語
TypeScript
スター
0
フォーク
1
平均マージ
3時間 35分
マージ済み PR(30日)
50

環境構築

このプロジェクトには開発コンテナ、Dockerfile、コントリビューションガイドがありません。まず README を読み、一般的な手順ははじめてのコントリビューションガイドを参照してください。

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

STRML/omp-classifier のほかの issue

STRML/omp-classifier の issue をすべて見る

似ている issue

TypeScript の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。