fix(disk-hygiene): accept braces inside quoted words in the engine gate - #5644
Conversation
…ne gate parser
_literal_shell_words rejected '{' and '}' before looking at quoting, so a
quoted GUID path segment could never form an exact engine call. Braces are
literal inside single and double quotes, so they are now accepted only
inside a whole-word quoted span; every other expansion or operator
character stays rejected anywhere, and unquoted braces still fail.
_unparsable_reason no longer blames a quoted brace.
Refs: #5641
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…quoted-braces # Conflicts: # plugins/disk-hygiene/CHANGELOG.md
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Claude finished @kyle-sexton's task in 3m 41s —— View job Security review complete
Scope: No security issues found. This hook is a fail-closed PreToolUse gate for destructive disk-cleanup commands, so I treated it as touching the
GitHub Actions hardening is out of scope for this lane (zizmor's), and this PR doesn't touch any workflow file regardless. |
|
Claude finished @kyle-sexton's task in 6m 54s —— View job Code review complete
SummaryTraced One completeness gap found and adversarially verified against a second, independent reading of the code:
is denied solely because of the quoted Severity-wise this is narrow rather than blocking: the non-bracket spelling of the same trusted command, Suggested fix: scan Everything else — the version bump, CHANGELOG entry, and |
…ted-brace change Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Claude finished @kyle-sexton's task in 1m 54s —— View job Code review complete
SummarySince the last review round (
if any(value in _SHELL_EXPANSION_OR_OPERATOR_CHARS for value in interior):
return Noneversus the fixed call sites at L197-200 and L2193. Concretely: is still denied solely because of the quoted It's narrow rather than blocking — Suggested fix: scan Everything else in this round checked out: the I did not execute the test suite in this sandbox (no tool access to run |
|
Claude finished @kyle-sexton's task in 48s —— View job Security review complete
Skip gate hit (item 3): this head already has a successful security review that still applies. The only commit added since the prior review (
Neither touches the quoted-brace exception logic ( (Unrelated to security: the code-reviewer's completeness-gap finding on |
…belt The /usr/bin/[ ... ] read-only inspection scanned its interior for forbidden characters without the quoted-brace allowance, so a quoted GUID path was still denied there while the /usr/bin/test spelling accepted it. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…quoted-braces Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Claude finished @kyle-sexton's task in 2m 0s —— View job Code review complete
SummarySince the last review round ( The fix at L1678-1680 and L1448-1450 now runs Test coverage added for the previously-missing case: The core quoted-brace machinery ( No blocking findings. The gap identified across both earlier review rounds is now closed, and no new issues were introduced by I did not execute the test suite in this sandbox (no permitted tool access to run |
|
Claude finished @kyle-sexton's task in 2m 23s —— View job Security review complete
No security issues found. Scope: the HEAD moved from
This is the same exception, applied consistently, not a new carve-out — so the earlier instruction-exception-register analysis (quoting makes
GitHub Actions hardening is out of scope for this lane (zizmor's); this PR doesn't touch any workflow file. |
Closes #5641
Summary
The disk-hygiene engine gate refused any command containing
{or}, so a quoted WSL distro path such as'C:/Users/me/AppData/Local/wsl/{673ac4db-...}'could never form an exact engine call. The denial also named the brace as a substitution or expansion.Fix
In
destructive_guard.py,{and}are dropped from whole-word single or double quoted spans before the forbidden-character check (_without_quoted_braces), in both_literal_shell_wordsand_unparsable_reason. Unquoted braces and every other expansion or operator character,$included, are still refused. Version 0.41.3 with a CHANGELOG entry.Verification
python3 -m unittest plugins/disk-hygiene/skills/clean/scripts/test_hygiene.py: 679 tests, OK (1 skipped), including new GUID-path accept and unquoted/$reject cases.scripts/check-changelog-parity.sh --check,--check-order,--check-bump origin/main: pass.scripts/validate-plugins.sh: all manifests validated.Related
Observed in #5228 probe; denial wording from #5519.
🤖 Generated with Claude Code