fix(guardrails): block-root-delete-target skips a PowerShell target holding a literal dollar sign
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 48/100
Research direction
Start by tracing the block-root-delete-target hook and its rdt_place_to operand handling for PowerShell single-quoted words; inspect the related work in #6020 and #6542. Reproduce the reported cases, including the cmd /c rd invocation from Bash, and determine whether that lane is wired or a declared gap. Done means literal $ operands and ::$ stream suffixes are judged safely, and the cmd case is judged or documented as a gap.
Written by the indexing model from the issue text.
Description
Problem
block-root-delete-target leaves a PowerShell target alone when it holds a $, even inside single quotes, where PowerShell expands nothing. rdt_place_to returns "leave alone" for any $ in an operand that is not literal, and a PowerShell single-quoted word goes down that path.
On Win32, <dir>::$INDEX_ALLOCATION names the directory itself, so a spelling like the one below may reach a directory the guard would otherwise refuse.
Repro (hook side confirmed; PowerShell runtime side not verified)
With the key unset and cwd /:
Remove-Item -Recurse -Force 'D:\some\outside\dir'exits 2 (refused).Remove-Item -Recurse -Force 'D:\some\outside\dir::$INDEX_ALLOCATION'exits 0 (allowed).
Also seen in the same review: cmd /c rd /s /q <dir> issued from the Bash tool exits 0 even for a directory outside the allowed roots. Check whether this is a declared gap or a lane that is simply not wired.
Acceptance
- A single-quoted PowerShell operand is judged literally: a
$in it does not skip judgment. - A
::$INDEX_ALLOCATION(or other::$stream) suffix is judged as the directory before it, or refused. - The
cmd /c rdfrom Bash case is either judged or listed as a declared gap.
Related: #6020. Found by the security review of #6542.
- Dominant language
- Shell
- Stars
- 22
- Forks
- 2
- Avg merge
- 5h 18m
- Merged PRs (30d)
- 869
Getting set up
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from melodic-software/claude-code-plugins
-
good first issue needs-triage priority: low
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
melodic-software/claude-code-plugins#6699 · 1 comment ·
Maintainers usually reply within 1 day
-
good first issue needs-triage priority: medium
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
melodic-software/claude-code-plugins#6631 · 1 comment ·
Maintainers usually reply within 1 day
-
needs-triage
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
melodic-software/claude-code-plugins#6547 ·
Maintainers usually reply within 1 day
-
needs-triage
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
melodic-software/claude-code-plugins#6535 ·
Maintainers usually reply within 1 day
-
test_comment_census.py: SccArgv flag-shaped-filename test errors on Windows (#!/bin/sh scc shim)Opengood first issue needs-triage priority: low
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
melodic-software/claude-code-plugins#6532 · 1 comment ·
Maintainers usually reply within 1 day
All issues in melodic-software/claude-code-plugins
Similar issues
-
priority middle
Difficulty 1/5 Under an hour Newbie friendliness 72/100
KATO-Hiro/AtCoderClans#12838 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
heymegabyte/install.doctor#171 ·
-
area:cli bug
Difficulty 1/5 Under an hour Newbie friendliness 78/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
community-scripts/ProxmoxVE#17824 ·
Maintainers usually reply within 1 day
-
agent: ready area: submission priority: high type: docs
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
dkritarth/scopewatch#213 ·
Maintainers usually reply within 1 day