P0-8 sh:// path fix + P0-1/P0-3/P0-4/P0-5 follow-ups, README reduction (P1-5) - #98
Merged
Merged
Conversation
…r and absent from case dir Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RhG7KcNHxMhoJrsZJFtC4Y
…f the old resolver) Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RhG7KcNHxMhoJrsZJFtC4Y
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RhG7KcNHxMhoJrsZJFtC4Y
…fix failing version_cmd - cache:// warns once per campaign when it ignores a legacy (v1) cache entry - README Threat Model lists version_cmd as executed code - version_cmd exiting non-zero no longer yields its error message as code_id - Telemac example alias declares a version_cmd; tests cover it Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RhG7KcNHxMhoJrsZJFtC4Y
…che warning, threat model Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RhG7KcNHxMhoJrsZJFtC4Y
…S bash) Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RhG7KcNHxMhoJrsZJFtC4Y
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RhG7KcNHxMhoJrsZJFtC4Y
…ata tests Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RhG7KcNHxMhoJrsZJFtC4Y
…ramiko client Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RhG7KcNHxMhoJrsZJFtC4Y
…t URI in version_cmd warning Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RhG7KcNHxMhoJrsZJFtC4Y
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RhG7KcNHxMhoJrsZJFtC4Y
yannrichet
marked this pull request as draft
September 30, 2026 16:50
yannrichet
marked this pull request as ready for review
September 30, 2026 16:52
…able CI matrix versions may be declared); drop redundant test Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RhG7KcNHxMhoJrsZJFtC4Y
…are its classifier Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RhG7KcNHxMhoJrsZJFtC4Y
…and run the captured kill command in bash Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RhG7KcNHxMhoJrsZJFtC4Y
…ad of once per case Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RhG7KcNHxMhoJrsZJFtC4Y
…tent unchanged to doc/guide/ Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RhG7KcNHxMhoJrsZJFtC4Y
…, document sh:// file resolution, add consistency tests Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RhG7KcNHxMhoJrsZJFtC4Y
…doc/guide/ Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RhG7KcNHxMhoJrsZJFtC4Y
…o reference pages), fix documented-but-wrong API statements - fzr(callbacks=...) is a dict of named callbacks, not a list - no 'fz list algorithms/models' CLI nor fz.list_algorithms() - alias without an entry for the model: bare URI is used (no 'does not support model' error) - .fz_hash example shows the v2 format; output structure moved into overview.md Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RhG7KcNHxMhoJrsZJFtC4Y
…nk core-functions to cli-usage; add python-block validity test Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RhG7KcNHxMhoJrsZJFtC4Y
yannrichet
pushed a commit
that referenced
this pull request
Sep 30, 2026
…uctured doc/ Re-applies the unmerged review of claude/fz-docs-skills-review-8xkpgw on top of #98 (doc/ restructuring) and P0-8 (sh:// path resolution), after re-checking every finding against current main by running fz: - doc/limitations.md (new): verified constraints and pitfalls; sh:// part updated for P0-8 (argument appending remains a trap) - fzr examples passing calculators as 4th positional argument (results_dir) - default delimiters (() for variables without delim), no ?var conversion - fzc per-case sub-directories, fzo on case dirs; skill ladder fixed - FZ_RUN_TIMEOUT=0, first Ctrl+C terminates running cases, cache://_ - os.environ after import -> reload_config(); fz.shell imports - funz:// UDP port, SSH auth/host keys, fz list and --global caveats - notebook 02: ?(name) needs varprefix '?' Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012GxLbauyVHBQPCeSow8hdh
8 of 10 tasks
3 of 4 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Audit-plan work stacked on one branch (several tickets in one PR, by the maintainer's choice):
sh://path resolution. The resolver converted every word that looked like a file name into an absolute path in the launch directory without checking existence. Withsh://cat in.txt > out.txtthe calculation read the un-substituted template from the launch directory and wroteout.txtoutside the case directory (shared across parallel cases), with no error: silently wrong results.code_id/version_cmd).CITATION.cff; README reduced from ~3 450 to ~290 lines; all documentation merged and deduplicated intodoc/(one file per topic).skills/fz/) and doc updates for the above.Related Issues
Audit plan tickets P0-8, P0-1 (compléments), P0-3 (gap found during cross-check), P0-4 (affinage), P0-5, P1-5 (partial). No GitHub issue is referenced.
Type of Change
Changes Made
P0-8 (
fz/runners/sh.py): a word is resolved to the launch directory only if it exists there and not in the case directory (compiled inputs win); targets of>,>>,2>… are never resolved (stricter than the ticket); each resolved word is logged at info level;sh://bash script.shwith the script only in the launch directory still works.tests/test_comprehensive_paths.py: the Windows-only expectationfailedfor thetarcase was a symptom of the old resolver; nowdoneeverywhere.P0-1 follow-ups
cache://warns once per campaign when it ignores a legacy v1 cache entry (fz/io.py).version_cmdwith a non-zero exit no longer becomes thecode_id(sh://andssh://); stderr with exit 0 still accepted.version_cmdwas executed with the value ofFZ_SHELL_PATH(a list of directories) as the shell program, so it always failed when that variable was set (e.g. Windows CI). It now usesfz.shell.run_command.version_cmdas executed code;examples/Telemacalias declares aversion_cmd.P0-3 follow-up: the best-effort remote kill on interrupt built
pkill -P $(pgrep -f '<pattern>')with theslurm://partition (from the URI) and thessh://command prefix inside single quotes, unquoted: a'allowed remote shell injection on that path. Nowfz.runners.ssh.build_kill_cmd(shlex.quote). Theversion_cmdwarning no longer prints a URI with an embedded password.P0-4 follow-up: the "No timeout set for ssh:// / slurm:// calculations (unlimited)" warning is logged once per scheme and
fzr()campaign (reset_timeout_warnings()) instead of per case.P0-5:
3.14added to the stable CI matrix on Linux, macOS and Windows (the Ubuntu-only3.14-devjob is removed) and the classifier declared;tests/test_python_version_support.pyrequires the two to match.P1-5 (partial)
CITATION.cff(author confirmed by the maintainer; no version, DOI or ORCID).README.md#<section>links land on a "Former README sections" list (hidden anchors) that points to the new pages.doc/, one file per topic, deduplicated. Each former README section was first moved unchanged, then compared with the existing page of the same topic: content already covered was dropped, only what the page lacked was merged (e.g. factorial vs non-factorial designs and output type casting incore-functions.md; progress callbacks and SSH keepalive inparallel-and-caching.md; calculator-model compatibility incalculators.md; plugin creation ininstalling-models.md; full output structure inoverview.md). Topics without an existing page became new files (cli-usage.md,configuration.md,custom-algorithms.md,installation.md,quick-start.md,interrupt-handling.md,breaking-changes.md,troubleshooting.md,development.md,ai-agents.md,resources.md);doc/INDEX.mdmaps topics to files. Also deduplicated: interrupt handling (single page), shell path and environment variables (configuration.md↔shell-path.md,calculators.md). Editorial judgement was involved (what counts as "already covered"), so this part deserves a human read.fzr(callbacks=...)takes a dict of named callbacks (on_start,on_case_start,on_case_complete,on_progress,on_complete), not a list of functions (a list raisesTypeError); there is nofz list algorithms|modelsCLI command norfz.list_algorithms(); an alias without an entry for the requested model does not raise a "does not support model" error (the bare URI is used, so ansh://case fails with "Permission denied"); the.fz_hashexample now shows the v2 format.tests/test_readme_structure.py(README <= 300 lines, links),tests/test_docs_consistency.py(everyFZ_*variable cited in the docs exists in the code, relative links indoc/resolve, former-README content present, no leftover "Guide:" sections, callbacks documented as a dict, legacy TOC anchors kept).cli-usage.mdstill partly overlaps the per-function CLI snippets ofcore-functions.md; a few pre-existing doc code blocks are not valid Python as written (elided arguments, Jupyter magics).Skill / docs:
skills/fz/documents thesh://resolution rule,version_cmdsemantics/trust, the legacy-cache warning and the executed-code threat model;NEWS.md,CLAUDE.md,llms.txtupdated (and a brokenllms.txtlink fixed).Testing Performed
test_p0_8_sh_path_resolution.py(5),test_cache_code_id.py(+5),test_version_cmd_ssh_exit_status.py(3, mocked paramiko),test_p0_3_kill_cmd_quoting.py(9),test_run_timeout.py(+1),test_project_metadata.py(1),test_readme_structure.py(2),test_docs_consistency.py(6). Regression tests were checked to fail without their fix where applicable._execute_remote_commandand_execute_remote_slurm_commandare driven with a mocked SSH client and a simulated interrupt; the captured kill command is executed in a real bash with fakepgrep/pkill. With the old interpolation both tests create the injectedPWNEDfile; withbuild_kill_cmdthey pass. Skipped on Windows..fz_hashformat and the alias/model behaviour documented in this PR were verified by running fz.mcpinstalled).da4dcaf(Linux/macOS/Windows 3.9–3.14, MSYS2, CLI, examples, SSH localhost, SLURM, Funz Calculator, lint, docs, wheels). Commits since then (kill tests, timeout warning, README reduction, docs consolidation and deduplication,6205d14) await the next CI run. The headless Claude Code e2e job is skipped, sotests/test_skill_e2e.pyis not exercised.version_cmdand the kill command (mocked client only); GitHub's handling of the hidden legacy anchors. Local full-suite run (earlier): only environment-related failures (yqflavour in twotest_python_outputstests; one permission test because the sandbox runs as root).Breaking Changes
sh://commands that referenced input/output files by bare name now use the compiled file and write in the case directory. Results obtained earlier with such commands should be re-checked.doc/(oldREADME.md#<section>links land on the "Former README sections" list). No API change.Additional Notes / known, not fixed here
cat in.txt > res.txt in.txt). Pre-existing; changing it affects everysh://command.pgrep -fon a command prefix /srun.*<partition>can match unrelated processes); only its quoting was fixed here.fz.api, P1-x) not re-verified; a corrected audit status document was produced separately.🤖 Generated with Claude Code
https://claude.ai/code/session_01RhG7KcNHxMhoJrsZJFtC4Y