New Phase 1b in tests/run-tests.fish: catches a bare C1-shadowed-command call in a functions/*.fish body with no matching uses-shadow(name) or self-limiting(name) in that function's own CLASSIFICATION header. This is exactly the check discussed after the rm and cd audits -- runtime auto-unwrapping isn't viable in fish (there's no hook finer than shadowing itself, and rewriting behavior invisibly at runtime is its own footgun); a static lint using the CLASSIFICATION tag as the declared-intentional marker is. Scoped to functions/*.fish only: the one-function-per-file convention there makes body extraction exact with no block-depth parser needed. Added a new self-limiting(name) tag to the schema for the case a bare call is safe not because the caller did anything, but because the shadow's own logic already neutralizes the override: rm's and mkdir's flag checks (verified precisely -- rm falls back to command rm for any flag except a bare -r/-R/--recursive alone, which still routes to trash; mkdir falls back to command mkdir -p for any flag, no exception), and grep/fgrep/egrep/dir/vdir/cat's own tty auto-detection (--color=auto, and bat's default color behavior -- verified byte-identical to stock cat when piped, since bat also auto-disables highlighting on a non-terminal). Explicit and durable rather than a silent lint exemption: if a shadow's bypass condition is ever weakened, every self-limiting site is one grep away instead of silently wrong. Running the first draft of the lint surfaced three more real bugs, none previously audited: - config-help.fish's --man pager path checks `type -q less` (proving it wants the real less binary specifically, for less-only -R/+N flag syntax) then called it bare, routing through our own $PAGER -> ov -> less -> more -> cat fallback chain instead -- which could hand those less-specific flags to a completely different program. Now command less. - _fish_deps_install.fish and _fish_deps_update.fish's binary-upgrade paths cp a freshly downloaded binary over an already-installed one with no existence guard -- the update flow's target is guaranteed to already exist. Our cp shadow forces -i unconditionally (a plain alias, not flag-aware like rm's), so this would hang waiting on a confirmation prompt in any non-interactive run. Now command cp. Same two files' lazydocker install path piped curl output into bare bash, invoking our shell-switch wrapper instead of a plain subshell. Now command bash. - agents-init.fish's AGENTS.md/CLAUDE.md relocation calls mv bare in four places; each is already guarded by a preceding test -f check on the destination, so the -i alias was unlikely to ever fire in practice, but explicit command mv removes the reliance on that guard entirely rather than leaving it as the only thing standing between a file move and an unattended hang. The remaining ~65 flagged call sites across ~24 files were reviewed individually and tagged self-limiting(rm)/self-limiting(mkdir) (verified flagged with -f/-rf or -p) and self-limiting(grep)/ self-limiting(cat) (verified piped, captured, or -q/-c; none display color to a human), plus uses-shadow(ls) for two existence-check-only calls (cffetch.fish, ffetch.fish) whose output is redirected to /dev/null.
75 lines
2.7 KiB
Fish
75 lines
2.7 KiB
Fish
# Copyright (C) 2026 Rootiest
|
|
# SPDX-License-Identifier: AGPL-3.0-or-later
|
|
|
|
# CLASSIFICATION
|
|
# self-limiting(rm,mkdir)
|
|
#
|
|
# SYNOPSIS
|
|
# _agents_repo_ensure_symlink <link> <target>
|
|
#
|
|
# DESCRIPTION
|
|
# Idempotently makes <link> a symlink pointing at the directory <target>.
|
|
#
|
|
# Only directories are ever linked. The agent file-editing tools resolve a
|
|
# symlinked directory transparently but refuse to write through a
|
|
# symlinked file, so linking a file would silently break every later edit;
|
|
# a non-directory target is refused outright.
|
|
#
|
|
# A missing target is refused rather than linked, because a dangling
|
|
# memory/ symlink makes agent memory writes fail -- strictly worse than
|
|
# having no backup at all.
|
|
#
|
|
# When <link> is an existing real directory, its contents are copied into
|
|
# <target> without clobbering (cp -n) before the directory is replaced by
|
|
# the link, so adopting a populated live directory never overwrites the
|
|
# copy already in the vault.
|
|
#
|
|
# ARGUMENTS
|
|
# link Path that should become the symlink
|
|
# target Existing directory the link should point at
|
|
#
|
|
# EXIT STATUS
|
|
# 0 Link is correct (created, repinned, or already right)
|
|
# 1 Refused (non-directory target, missing target, non-directory link) or
|
|
# a copy, remove, or link operation failed
|
|
#
|
|
# RETURNS
|
|
# A single "→ ..." progress line on stdout when something changed;
|
|
# nothing at all when the link was already correct.
|
|
#
|
|
# EXAMPLE
|
|
# _agents_repo_ensure_symlink ~/.claude/projects/-home-u-proj/memory \
|
|
# ~/.local/share/agent-vault/projects/host-user-proj/claude/memory
|
|
function _agents_repo_ensure_symlink --argument-names link target
|
|
test -n "$link" -a -n "$target"; or return 1
|
|
|
|
if test -e "$target"; and not test -d "$target"
|
|
echo "_agents_repo_ensure_symlink: refusing non-directory target: $target" >&2
|
|
return 1
|
|
end
|
|
if not test -d "$target"
|
|
echo "_agents_repo_ensure_symlink: target does not exist: $target" >&2
|
|
return 1
|
|
end
|
|
|
|
if test -L "$link"
|
|
set -l cur (path resolve "$link")
|
|
set -l want (path resolve "$target")
|
|
test "$cur" = "$want"; and return 0
|
|
rm -f "$link"; or return 1
|
|
else if test -d "$link"
|
|
set -l contents (command ls -A "$link" 2>/dev/null)
|
|
if test (count $contents) -gt 0
|
|
command cp -rn "$link/." "$target/"; or return 1
|
|
end
|
|
rm -rf "$link"; or return 1
|
|
else if test -e "$link"
|
|
echo "_agents_repo_ensure_symlink: refusing to replace non-directory: $link" >&2
|
|
return 1
|
|
end
|
|
|
|
mkdir -p (path dirname "$link"); or return 1
|
|
ln -s "$target" "$link"; or return 1
|
|
echo "→ Linked "(path basename "$link")" → $target"
|
|
end
|