Summary
core/static.awk calls _shellquote(full) when checking files under public/, but the core utility layer does not define _shellquote. As written, static file fallback can fail at runtime as soon as a non-routed GET/HEAD path reaches serve_static().
Evidence
core/static.awk: cmd = "test -f " _shellquote(full) ... inside serve_static().
core/util.awk: shared utility helpers define string/log/time helpers but no _shellquote helper.
core/mailbox.awk has mailbox::shell_quote(), but that is namespaced and not the _shellquote() used by static serving.
Impact
Static assets become fragile or unusable in the default 404 fallback path. This also breaks docs/examples that expect public/ files to be served automatically.
Suggested fix
- Add a core-level
_shellquote() helper, or rename the static call to an existing shared helper.
- Add unit tests for
serve_static() with readable, missing, unsafe, and quoted paths.
- Add an e2e smoke test for serving
public/app.css or similar.
Acceptance criteria
GET /some-existing-static-file works without undefined-function errors.
- Paths with spaces or shell-sensitive characters are safely quoted.
- Path traversal attempts still return 404/400-style failure instead of reading outside
public/.
Priority: P0
Area: static/runtime
Type: bug
Summary
core/static.awkcalls_shellquote(full)when checking files underpublic/, but the core utility layer does not define_shellquote. As written, static file fallback can fail at runtime as soon as a non-routed GET/HEAD path reachesserve_static().Evidence
core/static.awk:cmd = "test -f " _shellquote(full) ...insideserve_static().core/util.awk: shared utility helpers define string/log/time helpers but no_shellquotehelper.core/mailbox.awkhasmailbox::shell_quote(), but that is namespaced and not the_shellquote()used by static serving.Impact
Static assets become fragile or unusable in the default 404 fallback path. This also breaks docs/examples that expect
public/files to be served automatically.Suggested fix
_shellquote()helper, or rename the static call to an existing shared helper.serve_static()with readable, missing, unsafe, and quoted paths.public/app.cssor similar.Acceptance criteria
GET /some-existing-static-fileworks without undefined-function errors.public/.Priority: P0
Area: static/runtime
Type: bug