floor: the secret-file check can't see runtime values (globs, expansion side effects, symlinks, code)
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 5/5
- Thời gian dự kiến
- Hơn một tuần
- Mức phù hợp với người mới
- 35/100
- Loại issue
- Tính năng
- Độ rõ ràng
- Khá rõ ràng
- Mức độ hoạt động
- Sôi nổi
- Công nghệ
- python, shell, typescript
- Lĩnh vực
- security
Hướng nghiên cứu
Start with floor.ts and section 4 of docs/plans/2026-09-22-real-shell-parser.md, then review the runtime file resolution described in #67 and spawn interception in the eval kernel from #13. Done means the reviewer sees the files opened at runtime or the argv actually spawned, rather than only source spellings.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
The floor's secret-file check is a check on names, and names don't cover runtime values. PR #96 hit the Codex review cap on this: each of three rounds found a new runtime spelling, and the class doesn't close by adding spellings.
| Passes the floor | Why a name check can't see it |
|---|---|
cat .e* |
the glob matches whatever is on disk |
cat ${x:=key.txt} ${x/txt/pem} |
the first expansion assigns x, the second reads it |
ln -s ~/.aws/credentials notes.txt && cat notes.txt |
a symlink renames any file |
subprocess.run(["o" "p", "read", "op://v/i/c"]) in eval |
Python joins the literals, and the floor doesn't evaluate Python |
What #96 does about it: the floor reads each word as the text it's written as, so *.pem still asks and .e* doesn't. The limit is written down as a decision in docs/plans/2026-09-22-real-shell-parser.md section 4. Every one of these reaches the reviewer.
This issue tracks whether anything below the reviewer should close it. Two ways that would actually work, not more spellings:
- For shell, judge the file the command opens, not its name. That means resolving it at run time, the same move #67 makes for script bodies. Symlinks need this too.
- For code, intercept the spawn in the eval kernel (#13) so the floor sees the argv the kernel runs, not the source text.
Until then, don't add glob samples, expansion simulation, or language-specific string parsing to floor.ts. Rounds 2 and 3 on #96 show where that goes.
Related: #95 (the summary's version of the same limit), #91.
- Ngôn ngữ chính
- TypeScript
- Star
- 0
- Fork
- 1
- Merge trung bình
- 1 giờ 15 phút
- Pull request đã merge (30 ngày)
- 49
Hướng dẫn đóng góp
Chưa lập chỉ mục được hướng dẫn đóng góp cho kho mã nguồn này
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của STRML/omp-classifier
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 80/100
STRML/omp-classifier#111 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
STRML/omp-classifier#107 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
STRML/omp-classifier#88 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 74/100
STRML/omp-classifier#86 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
STRML/omp-classifier#81 ·
Tất cả issue của STRML/omp-classifier
Issue tương tự
-
bug(cli): hapi doctor inline-media prints a fabricated B:\ helper-script path in packaged installs Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100
-
Crush Đang mở
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 85/100
catppuccin/catppuccin#3125 ·
-
Add a SECURITY.md Đang mở
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 90/100
ElementsProject/cln-application#167 · 1 bình luận · 1 reaction ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
Quantco/pnpm-licenses#17 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100