Skip to content

A Heredoc Opener Holding (( Leaves Its Body in the Wait-Loop Check #2059

Description

@ptr727

Problem

_heredoc_opener in gh-write-guard.py refuses to recognise a heredoc on any opener line whose tokens hold ((. When that happens the heredoc body is never stripped. It is then tokenized as part of the command, and requirement 7 can read a comparison in the body as a loop's bound. The docstring says the skip "costs a false deny". Here it costs a false allow.

Reproduce (constructed)

while [ -e /nonexistent ] <<EOF ; : $((0))
[ x -lt 5 ]
EOF
do sleep 1; echo tick; done

This is allowed on develop at dd4ca98e. Run from a file under timeout 3 bash, it prints tick until the timeout kills it. The condition is [ -e /nonexistent ] with a heredoc as its stdin, so the loop has no bound. The [ x -lt 5 ] line is heredoc data that bash never evaluates.

Done looks like

The command above is denied, and a self-test row pins it. The docstring then describes what the (( skip actually costs.

Found by the local strict review of the #1998 fix (handoff #2057). It does not depend on that branch.

Activity

  1. added
    bugSomething isn't working
    agentsAgents instructions
    pre-existingReview finding classed pre-existing per local-strict-review Disposing of Findings
    on Sep 29, 2026
  2. added a commit that references this issue on Sep 30, 2026
    dbdf883
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    agentsAgents instructionsbugSomething isn't workingpre-existingReview finding classed pre-existing per local-strict-review Disposing of Findings

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions