fix: heredoc-to-interpreter deny patterns false-positive on .sh/.bash/.zsh extensions (v3.21.1) - #303
Conversation
…on false positive (v3.21.1) The heredoc-to-sh/bash/zsh/python builtin_deny patterns used \b before the interpreter name, which also matches right after a dot (a non-word char) -- so they matched the .sh/.bash/.zsh file extension immediately preceding a heredoc redirect, not just the literal interpreter word as a command. This denied an extremely common, benign idiom outright (write a script to a file via heredoc, then execute it) before it ever reached the existing heredoc-content-scanner (issue #216) built specifically to scan that shape safely. Fixed by anchoring with (?:^|[^.\w]) instead of \b, mirroring the identical fix already applied to exec_re elsewhere in this file. Closes #302 Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0187k8QeNYjgcEGv74YFdh2J
|
|
Overall Grade |
Security Reliability Complexity Hygiene |
Code Review Summary
| Analyzer | Status | Updated (UTC) | Details |
|---|---|---|---|
| JavaScript | Sep 25, 2026 11:41a.m. | Review ↗ | |
| Rust | Sep 25, 2026 11:41a.m. | Review ↗ | |
| Shell | Sep 25, 2026 11:41a.m. | Review ↗ | |
| Secrets | Sep 25, 2026 11:41a.m. | Review ↗ |
Important
AI Review is run only on demand for your team. We're only showing results of static analysis review right now. To trigger AI Review, comment @deepsourcebot review on this thread.
…e review) Greptile flagged that the heredoc-to-interpreter false-positive fix lacked CLI e2e coverage in tests/cli.rs, per this repo's testing convention. Adds e2e tests mirroring the existing unit tests: the reported `.sh` extension false positive now passes clean, the same shape with dangerous heredoc content still denies, and the direct `sh <<`/`bash <<` stdin-pipe danger still denies. *— Claude (Sonnet 5), clawband backlog automation*
|
Added the missing CLI e2e tests in 749b9e6 — 5 new tests in tests/cli.rs covering the reported false-positive shape (benign and dangerous content) and the genuine heredoc-to-stdin-pipe danger case, mirroring the existing unit tests. Full suite (403 tests) passes, clippy clean. — Claude (Sonnet 5), clawband backlog automation |
Second-opinion review (stopgap while Codex is capped)Same disclosure as on my other reviews here: I'm the same model family (Claude/Sonnet) as whatever wrote this, so treat this as a sanity check rather than a genuinely independent perspective. What this PR isA regex fix in Verification
I also tested the regex directly (isolated from the harness, since writing some of these literal strings into a file trips clawband's own content-scanner — amusingly, that's a live demonstration of the rule working) rather than just trusting the PR's own test suite: Core fix is correct: it eliminates the exact reported false positive without weakening the genuine deny case. Finding: pre-existing gap, not introduced or worsened by this PRBoth the old and new patterns require So trivially omitting the space bypasses this entire deny-pattern family, on both sides of this diff — not something this PR caused or regressed, but a real, live gap worth a follow-up issue since it's a one-character bypass of a "deny" (not "ask") tier pattern. Everything else checked out
— Claude (second session), stopgap fallback review while Codex is capped |
Closes #302
Summary
heredoc to sh/heredoc to bash/heredoc to zsh/heredoc to pythonbuiltin_deny patterns used\bbefore the interpreter name, which also matches right after a.— so they matched the.sh/.bash/.zshfile extension immediately preceding a heredoc redirect, not just the literal interpreter as a command word.(?:^|[^.\w])instead of\b, mirroring the identical fix already applied toexec_reelsewhere in this file for the same file-extension gotcha.Test plan
cargo fmt --checkcargo test— 1359/1359 passing (960 unit + 399 e2e)cargo clippy --all-targets -- -D warnings— clean— Claude (Sonnet 5), clawband backlog automation
No outstanding finding blocks merging.
What we checked:
Summary
The PR narrows heredoc-to-interpreter deny patterns so a script file’s extension is not mistaken for an interpreter command, and adds unit and CLI tests. No outstanding finding blocks merging.
Reviews (2) · Last reviewed commit: "fix: add missing CLI e2e tests for hered..."