Error-tolerant parse: recovered commands for unparseable input (deny-only use)
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 5/5
- Thời gian dự kiến
- Hơn một tuần
- Mức phù hợp với người mới
- 35/100
Hướng nghiên cứu
Start by locating ParsedCommand and the existing exact parser projections for Commands, Clauses, IsUnparseable, and Syntax. Review how the parser handles unbalanced quotes, separators, assignments, and wrapper children before designing the recovered projection. Done means adding a clearly non-authoritative RecoveredCommands API that over-reports safely, preserves exact projections, and documents deny-only use.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Problem
When ParsedCommand.IsUnparseable is true, Commands and Clauses are empty. A consumer then has no command words to check. Syntax can contain partial diagnostic evidence, but it has no stable projection that a consumer can use.
A security consumer must still find dangerous commands in input that the parser rejects. For example, a deny list must find rm -rf / in rm -rf / ; echo "unbalanced. Today each consumer must write its own raw-text splitter. Netclaw has one (LegacyShellTextScan, about 300 lines). It splits on whitespace outside quotes, guesses at list separators and wrapper children, and guesses a path style. That code is a second, weaker shell reader, and it drifts from the parser.
Proposal: error-tolerant parse with a separate recovered projection
Add a recovery result for unparseable input, similar to Roslyn error recovery. The parser returns what it could read, marked clearly as not authoritative.
Schematic API (names are open):
public sealed record ParsedCommand
{
// Unchanged: exact, fail-closed projections. Empty when IsUnparseable.
public IReadOnlyList<CommandOccurrence> Commands { get; }
public bool IsUnparseable { get; }
// New: populated only when IsUnparseable is true.
public IReadOnlyList<RecoveredCommand> RecoveredCommands { get; }
}
public sealed record RecoveredCommand(
IReadOnlyList<string> Words, // quote-removed words, best effort
SourceRange Range, // where in Source
RecoveryReason Reason); // unbalanced quote, unknown construct, ...
Contract
CommandsandClauseskeep their current meaning. Recovery never adds to them.RecoveredCommandsis for deny-only use: deny lists, protected-path checks, and audit. The XML docs must say that a consumer must not allow, approve, or grant anything from a recovered command.- Recovery must over-report, not under-report. If the parser cannot decide whether text is one command or two, it returns both readings.
- Recovery includes wrapper children when the wrapper text is readable (
bash -c "...",sh -c '...',pwsh -Command ...). - Recovery uses the same grammar code as the exact parser where it can. A second tokenizer is not the goal.
Examples
Positive (recovered words exist):
rm -rf / ; echo "unbalancedrecoversrm -rf /andecho unbalanced.X=1 Y=2 netclaw daemon stop(until #189 lands) recoversnetclaw daemon stopwith the assignments skipped.bash -c "shutdown now; echo 'xrecoversshutdown nowfrom the wrapper child.
Negative:
- Input that parses exactly has an empty
RecoveredCommands. The exact projection is the only source of truth. - A recovered command never appears in
Commands, sols ; echo "xstays unparseable and does not become an approvedls.
Consumer plan
Netclaw will check recovered commands against its hard-deny list and protected-path hints, and then delete LegacyShellTextScan. Netclaw keeps its policy data (deny lists, path hints). Only the grammar work moves here.
- Ngôn ngữ chính
- C#
- Star
- 15
- Fork
- 0
- Merge trung bình
- 9 giờ 8 phút
- Pull request đã merge (30 ngày)
- 46
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Không có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của Aaronontheweb/ShellSyntaxTree
-
Bash: an assignment in a loop body that reads the loop variable is not listed on later commandsĐang mởbug
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 48/100
Aaronontheweb/ShellSyntaxTree#249 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 57/100
Aaronontheweb/ShellSyntaxTree#244 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 48/100
Aaronontheweb/ShellSyntaxTree#236 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 55/100
Aaronontheweb/ShellSyntaxTree#235 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 38/100
Aaronontheweb/ShellSyntaxTree#227 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của Aaronontheweb/ShellSyntaxTree
Issue tương tự
-
Bug pulumi/pulumi
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
activescott/lessmsi#306 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
Maintainer thường phản hồi trong vòng 1 ngày
-
HTML sitemap lists unpublished pagesCó thể đã có người làm @KrzysztofPajak đã nhận hôm nay. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
grandnode/grandnode2#883 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
[Bug]: `winapp ui <command> --on sandbox --help` starts sandbox setup instead of showing helpĐang mởbug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
Maintainer thường phản hồi trong vòng 1 ngày