Files
fish-config/functions/_agents_init_ensure_gitignore.fish
T
rootiest 3414f81cb6 feat(tests): add shadow-classification lint; fix real cp/mv/less bugs
New Phase 1b in tests/run-tests.fish: catches a bare C1-shadowed-command
call in a functions/*.fish body with no matching uses-shadow(name) or
self-limiting(name) in that function's own CLASSIFICATION header. This
is exactly the check discussed after the rm and cd audits -- runtime
auto-unwrapping isn't viable in fish (there's no hook finer than
shadowing itself, and rewriting behavior invisibly at runtime is its
own footgun); a static lint using the CLASSIFICATION tag as the
declared-intentional marker is. Scoped to functions/*.fish only: the
one-function-per-file convention there makes body extraction exact
with no block-depth parser needed.

Added a new self-limiting(name) tag to the schema for the case a bare
call is safe not because the caller did anything, but because the
shadow's own logic already neutralizes the override: rm's and mkdir's
flag checks (verified precisely -- rm falls back to command rm for any
flag except a bare -r/-R/--recursive alone, which still routes to
trash; mkdir falls back to command mkdir -p for any flag, no
exception), and grep/fgrep/egrep/dir/vdir/cat's own tty auto-detection
(--color=auto, and bat's default color behavior -- verified
byte-identical to stock cat when piped, since bat also auto-disables
highlighting on a non-terminal). Explicit and durable rather than a
silent lint exemption: if a shadow's bypass condition is ever
weakened, every self-limiting site is one grep away instead of
silently wrong.

Running the first draft of the lint surfaced three more real bugs,
none previously audited:

- config-help.fish's --man pager path checks `type -q less` (proving
  it wants the real less binary specifically, for less-only -R/+N
  flag syntax) then called it bare, routing through our own
  $PAGER -> ov -> less -> more -> cat fallback chain instead -- which
  could hand those less-specific flags to a completely different
  program. Now command less.
- _fish_deps_install.fish and _fish_deps_update.fish's binary-upgrade
  paths cp a freshly downloaded binary over an already-installed one
  with no existence guard -- the update flow's target is guaranteed to
  already exist. Our cp shadow forces -i unconditionally (a plain
  alias, not flag-aware like rm's), so this would hang waiting on a
  confirmation prompt in any non-interactive run. Now command cp.
  Same two files' lazydocker install path piped curl output into bare
  bash, invoking our shell-switch wrapper instead of a plain
  subshell. Now command bash.
- agents-init.fish's AGENTS.md/CLAUDE.md relocation calls mv bare in
  four places; each is already guarded by a preceding test -f check on
  the destination, so the -i alias was unlikely to ever fire in
  practice, but explicit command mv removes the reliance on that guard
  entirely rather than leaving it as the only thing standing between a
  file move and an unattended hang.

The remaining ~65 flagged call sites across ~24 files were reviewed
individually and tagged self-limiting(rm)/self-limiting(mkdir)
(verified flagged with -f/-rf or -p) and self-limiting(grep)/
self-limiting(cat) (verified piped, captured, or -q/-c; none display
color to a human), plus uses-shadow(ls) for two existence-check-only
calls (cffetch.fish, ffetch.fish) whose output is redirected to
/dev/null.
2026-09-21 21:26:55 -04:00

87 lines
3.4 KiB
Fish

# Copyright (C) 2026 Rootiest
# SPDX-License-Identifier: AGPL-3.0-or-later
# CLASSIFICATION
# self-limiting(grep)
#
# SYNOPSIS
# _agents_init_ensure_gitignore <root> <label> <pattern>...
#
# DESCRIPTION
# Appends any patterns not already covered by the project's .gitignore.
# Uses git check-ignore for accurate rule matching (catches wildcards
# and parent-dir globs). Falls back to a whole-line string search when the
# root is not a git repository. Leading / is stripped from each pattern
# before the path-based check so root-anchored patterns (e.g. /AGENTS.md)
# are matched correctly.
#
# Missing patterns are written as a single labeled block:
#
# # ──────────────── Added by agents-init ──────────────────
# # <label>
# <pattern>
# # ────────────────────────────────────────────────────────
#
# ARGUMENTS
# root Absolute path to the project root containing .gitignore
# label Short description used in the block comment header
# pattern One or more gitignore patterns to ensure are present
#
# EXIT STATUS
# 0 All patterns already ignored or successfully appended
# 1 Could not write to .gitignore
#
# EXAMPLE
# _agents_init_ensure_gitignore /home/user/myproject "agents-init" "AGENTS/" "/AGENTS.md"
function _agents_init_ensure_gitignore
__fish_palette
if test (count $argv) -lt 3
echo (set_color red)"_agents_init_ensure_gitignore: requires <root> <label> <pattern>..."(set_color normal) >&2
return 1
end
set -l root $argv[1]
set -l label $argv[2]
set -l patterns $argv[3..]
set -l gitignore "$root/.gitignore"
set -l in_git 0
git -C "$root" rev-parse --git-dir >/dev/null 2>&1
and set in_git 1
# Collect patterns not already covered
set -l missing
for pattern in $patterns
# Strip leading / so git check-ignore receives a repo-relative path,
# not an absolute filesystem path (which it cannot match against rules).
set -l check_path (string replace -r '^/' '' "$pattern")
set -l already 0
if test $in_git -eq 1
git -C "$root" check-ignore -q --no-index "$check_path" 2>/dev/null
and set already 1
else if test -f "$gitignore"
# Whole-line match: a substring match treats a negation line
# such as "!AGENTS/foo" as covering the pattern "AGENTS/".
grep -qxF "$pattern" "$gitignore"
and set already 1
end
if test $already -eq 0
set -a missing "$pattern"
end
end
test (count $missing) -eq 0; and return 0
# Write missing patterns as a labeled block
set -l header "# ──────────────── Added by agents-init ──────────────────"
set -l footer "# ────────────────────────────────────────────────────────"
printf '\n%s\n# %s\n' "$header" "$label" >>"$gitignore"
for p in $missing
printf '%s\n' "$p" >>"$gitignore"
end
printf '%s\n' "$footer" >>"$gitignore"
echo "$c_ok→ Added "(count $missing)" pattern(s) to .gitignore$c_reset"
end