feat: CLASSIFICATION function-header field + shadow-classification lint #163

Merged
rootiest merged 7 commits from feat/classification-header-field into main 2026-09-22 02:12:58 +00:00
8 changed files with 28 additions and 9 deletions
Showing only changes of commit 100cb478bc - Show all commits
+7
View File
@@ -72,3 +72,10 @@ schema's own rollout caught several false positives this way: a piped
`read` misread as an interactive prompt, a documented `--yes` flag missed
as an escape hatch, and cleanup of a function's own temp output flagged
as `destructive` despite the explicit exclusion above.
`rm` specifically has its own internal flag check (any flag other than
`-r`/`-R`/`--recursive` falls back to `command rm` *inside the shadow
itself*, before it ever touches trash) — a caller writing plain `rm -f`
or `rm -rf` is not bypassing anything itself, the shadow is. Only tag
`bypasses-shadow(rm)` when the caller explicitly writes `command rm` or
`builtin rm`; a bare `rm -f`/`rm -rf` call gets no shadow tag at all.
+4 -4
View File
@@ -2,7 +2,7 @@
# SPDX-License-Identifier: AGPL-3.0-or-later
# CLASSIFICATION
# bypasses-shadow(cat)
# bypasses-shadow(cat,rm), destructive
#
# SYNOPSIS
# _scrollback_prune_junk [dir]
@@ -29,7 +29,7 @@ function _scrollback_prune_junk --description 'Remove empty, trivial, and Kitty
# Remove any completely empty log file regardless of source
for f in $dir/*.log $dir/*.txt
test -f $f || continue
not test -s $f; and rm $f
not test -s $f; and command rm -f $f
end
# Remove any log with only a single meaningful line (e.g. [exited], a lone prompt, or a trivial error)
@@ -37,7 +37,7 @@ function _scrollback_prune_junk --description 'Remove empty, trivial, and Kitty
test -f $f || continue
set -l line_count (command cat $f | sed 's/\x1b\[[0-9;:]*[a-zA-Z]//g' | grep -cv '^\s*$')
if test $line_count -le 1
rm $f
command rm -f $f
end
end
@@ -45,7 +45,7 @@ function _scrollback_prune_junk --description 'Remove empty, trivial, and Kitty
for f in $dir/scrollback_*.log $dir/scrollback_*.txt
test -f $f || continue
if command cat $f | sed 's/\x1b\[[0-9;:]*[a-zA-Z]//g' | grep -q 'Enter the new title for this tab below'
rm $f
command rm -f $f
end
end
end
+3
View File
@@ -8,6 +8,9 @@
# __fish_palette, __config_settings_state, __config_settings_apply,
# __config_settings_set_value, python3
#
# CLASSIFICATION
# bypasses-shadow(rm)
#
# SYNOPSIS
# config-settings [-h | --help]
#
+1 -1
View File
@@ -119,7 +119,7 @@ function dng2avif --description 'Convert DNG raw to 10-bit HDR AVIF'
end
# Final Cleanup
test -f "$temp_pnm"; and rm "$temp_pnm"
test -f "$temp_pnm"; and rm -f "$temp_pnm"
set -l size (stat -c '%s' "$output" | numfmt --to=iec)
echo (set_color yellow)"Complete: $output ($size)"(set_color normal)
+3
View File
@@ -7,6 +7,9 @@
# COMPONENT
# aliases/dev-tools
#
# CLASSIFICATION
# bypasses-shadow(rm)
#
# SYNOPSIS
# edit [-V|-t] [-e EDITOR] [-c] [-x TEXT] [-n] [-v|-s] [FILE...]
#
+6 -3
View File
@@ -4,6 +4,9 @@
# CATEGORY
# 03-editors-and-viewers
#
# CLASSIFICATION
# bypasses-shadow(rm)
#
# SYNOPSIS
# fc [command_prefix]
#
@@ -50,15 +53,15 @@ function fc --description 'Edit and execute the last command (Bash-style fc)'
# Final check if user cleared the file in the editor
if test -s $tmpfile
set -l command (cat $tmpfile)
rm $tmpfile
command rm -f $tmpfile
commandline -r "$command"
commandline -f execute
else
rm $tmpfile
command rm -f $tmpfile
echo "fc: Aborted (empty file)"
end
else
rm $tmpfile
command rm -f $tmpfile
echo "fc: Could not retrieve history"
end
end
+3
View File
@@ -7,6 +7,9 @@
# DEPENDENCIES
# gpg, tar
#
# CLASSIFICATION
# bypasses-shadow(rm), destructive
#
# SYNOPSIS
# key-crypt [options] <input> [output]
# key-crypt -i <input> -o <output> [options]
+1 -1
View File
@@ -5,7 +5,7 @@
# 01-file-and-directory
#
# CLASSIFICATION
# bypasses-shadow(rm), destructive
# uses-shadow(rm), bypasses-shadow(rm), destructive
#
# SYNOPSIS
# scrub [-a] [-d] [-h]