Skip to content

Decide How the Guard's Context Scan for #1910 Proceeds After Review Found Hiding Regressions #1960

Description

@ptr727

How should #1910 proceed, now that each local review round of its context-tracking scan finds new cases where the guard allows a command develop denied?

Context

Branch feature/auto-1910 (handoff #1957, no pull request yet) replaces the guard's comment strip and skip list with a context-tracking scan, as #1910 asks. It fixes every constructed example in #1910 and its comments, including the false deny on a multi-line quote, and the selftest and a mutation run over the new scan are green.

To fix that false deny, the branch drops the union with develop's per-line base tokens, which was the safety net that kept the fallback from ever allowing what develop denied. Without it, every place the scan misreads bash becomes a hidden command. Three strict review rounds found 4, then 8, then 3 such regressions, each a constructed command develop denies, the branch allows, and bash runs. Two rounds of fixes closed the first twelve. The review budget is now spent with three still open:

  • a # right after a subshell ) or an arithmetic )) is read as text, where bash reads it as a comment
  • case and esac are counted inside $(...) even as plain arguments
  • _closes_as_arithmetic takes quadratic time on a long run of (, about 6 s at 4000 parens

Options

  1. Recommended: keep the new scan and restore the union with develop's fallback tokens. The guard then never allows what develop denied, whatever the scan misreads, and it still gains every miss the scan closes (the =~, backslash, $(/${/$'/$", extglob, arithmetic, and A Command Substitution Inside Double Quotes Hides a Loop When a Line's Quoting Does Not Parse #1843 shapes). The multi-line-quote false deny in Read a Multi-Line Quote Whole in the Guard's Token Fallback #1910's body stays open. That costs an over-deny, the safe direction. The three open findings stop being hiding paths and become tokenizing imprecision. The worker restores the union, fixes the quadratic scan, and drives the pull request, and Read a Multi-Line Quote Whole in the Guard's Token Fallback #1910 stays open for the false deny alone.
  2. Keep the branch as it is and continue fixing past the budget. This closes Read a Multi-Line Quote Whole in the Guard's Token Fallback #1910 whole if it converges. The three rounds so far suggest it may not, since each fix to the scan exposed new readings, and any miss that survives ships as a hole in a safety hook that fails open.
  3. Abandon the branch. Develop's fallback stays as it is, and Read a Multi-Line Quote Whole in the Guard's Token Fallback #1910 stays open. A Substitution Nested in an Opaque Word Hides a Command From the Guard's Token Fallback #1958 and Shlex Parsing Successfully but Wrongly Hides a Command From the Guard's Context Scan #1959 track the related pre-existing gaps either way.

Effect on the parked work

The branch holds three commits, and its last local review receipt covers its head. Option 1 adds a commit to it. Option 2 continues it. Option 3 deletes it.

Blocks: handoff #1957, and the pull request from feature/auto-1910 that would close #1910.

Activity

  1. added
    agentsAgents instructions
    decisionA question waiting on the maintainer, alone or beside whatever else the issue carries
    on Sep 28, 2026
  2. ptr727 commented on Sep 28, 2026

    @ptr727
    OwnerAuthor

    Answered by the maintainer in an attended session: option 1, keep the new scan and restore the union with develop's fallback tokens, fix the quadratic scan, and drive the pull request; #1910 stays open for the multi-line-quote false deny. Work continues under handoff #1957.

  3. removed
    decisionA question waiting on the maintainer, alone or beside whatever else the issue carries
    on Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    agentsAgents instructions

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions