Problem
A line that opens two heredocs, such as cat <<A <<B, has two bodies in sequence, and bash reads both as data before the next command. gh-write-guard.py's heredoc strip takes only the first << on a line and strips only its body. The second body's lines are then read as commands, and one of them that looks like a heredoc opener swallows the real commands after it, so rule 7 never judges a wait loop there.
Reproduce (constructed)
Allowed on develop at 4c9087d and on feature/auto-2059, although bash runs the loop:
cat <<A <<B
a
A
cat <<X
B
while [ ! -f /nonexistent ]; do sleep 1; done
X
Piping the same shape with echo ran-after in place of the loop into bash prints ran-after, so the loop line is a real command.
On a line holding ((, each fork strips one << body starting right after the opener, which covers both bodies only by accident, so : $((0)) <<EOF <<EOF and : $((0)) <<A <<B with a line B inside A's body also allow.
Done looks like
A line opening several heredocs strips each body in order, and a self-test row pins the command above as a deny.
Found by the local strict review of the #2059 fix.
Problem
A line that opens two heredocs, such as
cat <<A <<B, has two bodies in sequence, and bash reads both as data before the next command.gh-write-guard.py's heredoc strip takes only the first<<on a line and strips only its body. The second body's lines are then read as commands, and one of them that looks like a heredoc opener swallows the real commands after it, so rule 7 never judges a wait loop there.Reproduce (constructed)
Allowed on develop at 4c9087d and on
feature/auto-2059, although bash runs the loop:Piping the same shape with
echo ran-afterin place of the loop intobashprintsran-after, so the loop line is a real command.On a line holding
((, each fork strips one<<body starting right after the opener, which covers both bodies only by accident, so: $((0)) <<EOF <<EOFand: $((0)) <<A <<Bwith a lineBinside A's body also allow.Done looks like
A line opening several heredocs strips each body in order, and a self-test row pins the command above as a deny.
Found by the local strict review of the #2059 fix.