Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

fix(guardrails): retarget block-noncanonical-commit at shell interpolation in -m, not at newlines

Đang mở
#6,464 1 bình luận 0 reaction 0 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 1 ngày

Chưa có ai nhận issue này.

Đánh giá

Độ khó
4/5
Thời gian dự kiến
1-2 ngày
Mức phù hợp với người mới
48/100
Loại issue
Lỗi
Độ rõ ràng
Đặc tả rõ ràng
Mức độ hoạt động
Sôi nổi
Công nghệ
bash, git, powershell, shell

Hướng nghiên cứu

Start from block-noncanonical-commit.sh (header comments around lines 5-10) and the tests that currently fail on newlines in -m. Retarget the check to interpolating quote contexts that contain backtick or $ in Bash and PowerShell, keep the listed exemptions, and rewrite the block message to name git commit -F - --cleanup=verbatim with a quoted heredoc. Add the acceptance cases in both shells, then empirically confirm git log --format=%B in a scratch repo with the guard disabled.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

needs-human needs-triage

Problem

block-noncanonical-commit.sh blocks git commit -m when the message contains a newline. Its stated reason (lines 5-10) is that a multi-line -m "flattens newlines unpredictably across shells." That claim came from the old commit skill's list of anti-patterns (776bdde81, #72). It became a block in #736 and was narrowed to messages with real newlines in #2058. No reproduced newline failure is cited anywhere.

Tested on 2026-10-05 by passing the message to python -I -c "import sys; print(repr(sys.argv[1]))", which shows the exact argv a program receives:

Shell Argument Received
Bash tool (Git Bash) multi-line, double-quoted, with escaped " and $ exact: 'subject line\n\nBody … "quotes" and $dollar.\n\nCo-Authored-By: …'
PowerShell tool (pwsh 7.6.6, $PSNativeCommandArgumentPassing = Windows) same exact
PowerShell tool single-line "fix: rename `foo` and `bar` to `new` for `$total" mangled: 'fix: rename \x0coo and \x08ar to \new for $total'

So the guard:

  • blocks a safe case: a multi-line message with no special characters.
  • lets the unsafe case through: a double-quoted message containing a backtick or $.
    • In PowerShell, a backtick is the escape character (`f becomes form feed, `b backspace, `n newline) and $ interpolates.
    • In Bash, backticks and $(…) inside double quotes run as command substitution, and $ interpolates.
    • Commit messages often contain code spans in backticks, so this happens in normal use.

Windows PowerShell 5.1's legacy argument passing strips embedded quotes, but neither Claude tool runs 5.1.

Proposal

  • Block git commit -m / --message whose value sits in an interpolating quote context and contains a backtick or $, single-line or multi-line, in both shells:
    • Bash: double quotes, or no quotes.
    • PowerShell: double quotes, or a double-quoted here-string.
  • Allow single-quoted values, single-line or multi-line: Bash '…', PowerShell '…' and @'…'@. Also allow double-quoted values with neither character.
  • Keep git commit -F - --cleanup=verbatim with a quoted heredoc delimiter (<<'EOF') as the form that is always safe, and name it in the block message.
  • Rewrite the header comment and the block message to state the real hazard, with the table above as evidence.
  • Keep the existing exemptions (--amend, -C/-c, --fixup/--squash, -F, an in-progress sequencer), the allow-list option and the kill switch.

Acceptance

  • Tests in both shells:
    • multi-line single-quoted -m: passes
    • multi-line double-quoted plain text: passes
    • single-line double-quoted with a backtick: blocked
    • double-quoted with $: blocked
    • -F - heredoc: passes
  • The block message shows the safe form.
  • Before merging, an empirical check with real git commit -m in a scratch repo, with the guard disabled through its documented setting, confirms git log --format=%B matches the test table.

Related: #6463 (pre-merge state guard).

Ngôn ngữ chính
Shell
Star
22
Fork
2
Merge trung bình
5 giờ 4 phút
Pull request đã merge (30 ngày)
825

Chuẩn bị môi trường

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của melodic-software/claude-code-plugins

Tất cả issue của melodic-software/claude-code-plugins

Issue tương tự

Thêm issue về Shell/Bash

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.