Shell-quote source IDs in caseworkctl BReg package recovery commands
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 88/100
Research direction
Start in crates/registry-caseworkctl/src/breg_package.rs, focusing on caseworkctl check --against-breg-package and the existing shell_word uses for project and package paths. Pass the source ID through shell_word in both recovery commands, then add and run a unit test using an ID with whitespace and a shell metacharacter. Done means copied commands preserve the source ID as one literal argument.
Written by the indexing model from the issue text.
Description
Problem
caseworkctl check --against-breg-package builds recovery commands (the recheck command and repin_command) with an unquoted --source-id. CaseworkProject::check only requires a source ID to be non-empty and unique, so an ID containing whitespace or shell metacharacters yields a command that the shell splits or interprets when an operator copies it.
Fix direction
Pass the source ID through the existing shell_word helper, as the project and package paths already are, and add a unit test with a source ID containing a space and a metacharacter.
Raised by the Codex review on #1718 (crates/registry-caseworkctl/src/breg_package.rs).
- Dominant language
- Rust
- Stars
- 2
- Forks
- 0
- Avg merge
- 7h 22m
- Merged PRs (30d)
- 213
Getting set up
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from registrystack/registry-stack
-
Difficulty 1/5 1-3 hours Newbie friendliness 90/100
registrystack/registry-stack#1748 ·
Maintainers usually reply within 1 day
-
area:breg bug criticality:p3 triage:needs-implementation
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
registrystack/registry-stack#1682 ·
Maintainers usually reply within 1 day
-
area:casework bug criticality:p3 triage:needs-implementation
Difficulty 1/5 Under an hour Newbie friendliness 88/100
registrystack/registry-stack#1669 ·
Maintainers usually reply within 1 day
-
agent-ready area:platform criticality:p3 documentation triage:needs-implementation
Difficulty 1/5 Under an hour Newbie friendliness 90/100
registrystack/registry-stack#1639 ·
Maintainers usually reply within 1 day
-
area:evidence bug criticality:p3 triage:needs-implementation
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
registrystack/registry-stack#1620 ·
Maintainers usually reply within 1 day
All issues in registrystack/registry-stack
Similar issues
-
type/bug
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
stackabletech/kafka-operator#1033 · 1 comment ·
Maintainers usually reply within 1 day
-
bug good first issue needs testing
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
Maintainers usually reply within 3 days
-
Difficulty 2/5 1-3 hours Newbie friendliness 90/100
farion1231/cc-switch#7744 · 1 comment ·
Maintainers usually reply within 1 day
-
datafusion
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
apache/iceberg-rust#3297 ·
Maintainers usually reply within 1 day