fix(guardrails): retarget block-noncanonical-commit at shell interpolation in -m, not at newlines
维护者通常 1 天内回复
还没有人认领这个 Issue。
评估
- 难度
- 4/5
- 预计耗时
- 1-2 天
- 新手友好度
- 48/100
- Issue 类型
- 缺陷
- 描述清晰度
- 描述清楚
- 活跃度
- 活跃
- 技术栈
- bash, git, powershell, shell
调研方向
Start from block-noncanonical-commit.sh (header comments around lines 5-10) and the tests that currently fail on newlines in -m. Retarget the check to interpolating quote contexts that contain backtick or $ in Bash and PowerShell, keep the listed exemptions, and rewrite the block message to name git commit -F - --cleanup=verbatim with a quoted heredoc. Add the acceptance cases in both shells, then empirically confirm git log --format=%B in a scratch repo with the guard disabled.
由索引模型根据 Issue 内容生成。
描述
Problem
block-noncanonical-commit.sh blocks git commit -m when the message contains a newline. Its stated reason (lines 5-10) is that a multi-line -m "flattens newlines unpredictably across shells." That claim came from the old commit skill's list of anti-patterns (776bdde81, #72). It became a block in #736 and was narrowed to messages with real newlines in #2058. No reproduced newline failure is cited anywhere.
Tested on 2026-10-05 by passing the message to python -I -c "import sys; print(repr(sys.argv[1]))", which shows the exact argv a program receives:
| Shell | Argument | Received |
|---|---|---|
| Bash tool (Git Bash) | multi-line, double-quoted, with escaped " and $ |
exact: 'subject line\n\nBody … "quotes" and $dollar.\n\nCo-Authored-By: …' |
PowerShell tool (pwsh 7.6.6, $PSNativeCommandArgumentPassing = Windows) |
same | exact |
| PowerShell tool | single-line "fix: rename `foo` and `bar` to `new` for `$total" |
mangled: 'fix: rename \x0coo and \x08ar to \new for $total' |
So the guard:
- blocks a safe case: a multi-line message with no special characters.
- lets the unsafe case through: a double-quoted message containing a backtick or
$.- In PowerShell, a backtick is the escape character (
`fbecomes form feed,`bbackspace,`nnewline) and$interpolates. - In Bash, backticks and
$(…)inside double quotes run as command substitution, and$interpolates. - Commit messages often contain code spans in backticks, so this happens in normal use.
- In PowerShell, a backtick is the escape character (
Windows PowerShell 5.1's legacy argument passing strips embedded quotes, but neither Claude tool runs 5.1.
Proposal
- Block
git commit -m/--messagewhose value sits in an interpolating quote context and contains a backtick or$, single-line or multi-line, in both shells:- Bash: double quotes, or no quotes.
- PowerShell: double quotes, or a double-quoted here-string.
- Allow single-quoted values, single-line or multi-line: Bash
'…', PowerShell'…'and@'…'@. Also allow double-quoted values with neither character. - Keep
git commit -F - --cleanup=verbatimwith a quoted heredoc delimiter (<<'EOF') as the form that is always safe, and name it in the block message. - Rewrite the header comment and the block message to state the real hazard, with the table above as evidence.
- Keep the existing exemptions (
--amend,-C/-c,--fixup/--squash,-F, an in-progress sequencer), the allow-list option and the kill switch.
Acceptance
- Tests in both shells:
- multi-line single-quoted
-m: passes - multi-line double-quoted plain text: passes
- single-line double-quoted with a backtick: blocked
- double-quoted with
$: blocked -F -heredoc: passes
- multi-line single-quoted
- The block message shows the safe form.
- Before merging, an empirical check with real
git commit -min a scratch repo, with the guard disabled through its documented setting, confirmsgit log --format=%Bmatches the test table.
Related: #6463 (pre-merge state guard).
- 主要语言
- Shell
- 星标
- 22
- 派生
- 2
- 平均合并
- 5 小时 11 分钟
- 30 天内合并 PR
- 838
环境准备
- 没有 Dockerfile 或 Docker Compose 文件
- 没有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
melodic-software/claude-code-plugins 的其他 Issue
-
good first issue needs-triage priority: medium
难度 2/5 1-3 小时 新手友好度 72/100
melodic-software/claude-code-plugins#6631 · 1 条评论 ·
维护者通常 1 天内回复
-
needs-triage
难度 2/5 1-3 小时 新手友好度 78/100
melodic-software/claude-code-plugins#6547 ·
维护者通常 1 天内回复
-
needs-triage
难度 2/5 1-3 小时 新手友好度 76/100
melodic-software/claude-code-plugins#6535 ·
维护者通常 1 天内回复
-
test_comment_census.py: SccArgv flag-shaped-filename test errors on Windows (#!/bin/sh scc shim)未关闭good first issue needs-triage priority: low
难度 2/5 1-3 小时 新手友好度 72/100
melodic-software/claude-code-plugins#6532 · 1 条评论 ·
维护者通常 1 天内回复
-
good first issue needs-triage priority: low
难度 2/5 1-3 小时 新手友好度 72/100
melodic-software/claude-code-plugins#6390 · 1 条评论 ·
维护者通常 1 天内回复
查看 melodic-software/claude-code-plugins 的全部 Issue
相似的 Issue
-
Lid close does not lock the session on Apple Silicon (lid-close bind skips omarchy-system-lid-close)未关闭
难度 1/5 1-3 小时 新手友好度 90/100
omacom/omarchy-mac#701 · 1 条评论 ·
维护者通常 1 天内回复
-
A 20.x release after 21.0.0 would move `latest` back to 20.x, and `next` stays on the release candidate可能已有人在做 @armando-navarro 今天认领。 未关闭comp: build/pipeline type: bug version: current (v17+)
难度 2/5 1-3 小时 新手友好度 85/100
angular/angularfire#3790 ·
维护者通常 3 天内回复
-
ready-for-agent
难度 2/5 1-3 小时 新手友好度 85/100
LucasSantana-Dev/Lucky#2698 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 68/100
collabnix/awesome-mcp-lists#179 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 70/100