Skip to content

Read Both Heredocs Around a Matching Arithmetic Shift in the Guard #2202

Description

@ptr727

Problem

The #2112 fix (handoff #2123) reads a line holding (( or $[ as opening nothing, plus each << alone and each together with every later one whose body closes. Where the arithmetic shift's own operand matches a later line, as Z in $((1 << Z)), no reading matches bash's, which skips the shift and reads the two real heredocs in order. Develop allows the command below too, so this is a gap the fix left rather than a regression.

Reproduce (constructed)

cat <<A; echo $((1 << Z)); cat <<B
B
A
cat <<X
B
while [ ! -f /x ]; do sleep 1; done
X
Z

Bash reads A's body as B and B's body as cat <<X, then runs the loop. The guard allows the command on the branch and on develop, since every reading it builds hides the loop.

Done looks like

The command above is denied, and a self-test row pins it.

Found by the local strict review of the #2112 fix, and filed as a follow-up under decision #2126.

Activity

  1. added
    bugSomething isn't working
    agentsAgents instructions
    on Oct 1, 2026
  2. ptr727 commented on Oct 8, 2026

    @ptr727
    OwnerAuthor

    Declined per #2517, approved by the maintainer, under GOVERNANCE.md "Trust Boundaries and Hardening Effort": The guard backstops an agent's own mistakes, and this is a command shape built to defeat it rather than one an agent session writes, so a miss does not realistically occur. See #2517 for the per-issue reason.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    agentsAgents instructionsbugSomething isn't working

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions