From c8e558c72cedcfe2f614366de869df5c2ab10279 Mon Sep 17 00:00:00 2001 From: kshitij <82637225+kshitijk4poor@users.noreply.github.com> Date: Sat, 8 Aug 2026 14:53:41 +0530 Subject: [PATCH] fix(tools): keep non-bash -c invocations covered by the shell guard MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The _bash_exec_payload delegation rejected short-option bundles with letters outside bash's alphabet, so 'zsh -yc', 'dash -Vc' and 'ksh -Gc' scripts stopped being scanned — a fail-open regression for shells the guard's _SHELL_EXECUTABLES explicitly covers. Try the bash grammar first (catches operand-hidden -c), then fall back to the permissive positional scan; a block-guard fails closed. --- tests/tools/test_self_repo_guard.py | 3 +++ tools/self_repo_guard.py | 24 ++++++++++++++++++------ 2 files changed, 21 insertions(+), 6 deletions(-) diff --git a/tests/tools/test_self_repo_guard.py b/tests/tools/test_self_repo_guard.py index d2738ecc90..c0f9ae9dc0 100644 --- a/tests/tools/test_self_repo_guard.py +++ b/tests/tools/test_self_repo_guard.py @@ -84,6 +84,9 @@ class TestBlocksMutationsInSourceRepo: "bash -lc 'git switch main'", "bash -o pipefail -c 'git checkout main'", "bash +O extglob -c 'git checkout main'", + "zsh -yc 'git checkout main'", + "dash -Vc 'git checkout main'", + "ksh -Gc 'git checkout main'", ], ) def test_wrappers_and_nested_shells(self, repo, command): diff --git a/tools/self_repo_guard.py b/tools/self_repo_guard.py index 6d3f4b4c81..218367adff 100644 --- a/tools/self_repo_guard.py +++ b/tools/self_repo_guard.py @@ -331,14 +331,26 @@ def _cd_target(executable: str, args: list[str], cwd: Path) -> Path | None: def _shell_script_arg(args: list[str]) -> str | None: """Return the script string owned by a shell's ``-c``, if present. - Delegates to approval.py's ``_bash_exec_payload``, which parses bash's - real option grammar (``-O/-o`` consume the next argument, short-option - bundles, ``--init-file``/``--rcfile``). A naive "leading option containing - 'c'" scan fails open on ``bash -o pipefail -c '