Context
scripts/check-cross-plugin-source-drift.sh:120 iterates cluster keys in discover mode with:
for rel in $(printf '%s\n' "${!cluster_status[@]}" | sort); do
The unquoted command substitution word-splits on all IFS whitespace and glob-expands each resulting word. A cluster rel path containing a space would be split into multiple bogus iterations, and one containing a glob character (*, ?, [) could expand against the working directory. Today's registered cluster paths are safe, so this is latent, but the loop silently mis-iterates the moment a whitespace or glob-char path is registered, and discover mode is the surface humans use to inspect cluster status. Cost of leaving it: wrong or misleading discover output with no error signal.
Proposed work
- Sort into an array without word-splitting, e.g.
mapfile -t sorted < <(printf '%s\n' "${!cluster_status[@]}" | sort) and for rel in "${sorted[@]}".
- Add a test-suite case registering a cluster path with a space (the suite at
scripts/check-cross-plugin-source-drift.test.sh builds fixture repos) to lock the behavior.
Acceptance criteria
References
scripts/check-cross-plugin-source-drift.sh:120
- Found by the batch-simplify sweep on branch
claude/code-tidying-batch-simplify-s7ljbi; deliberately not fixed there because the sweep was behavior-preserving.
Context
scripts/check-cross-plugin-source-drift.sh:120iterates cluster keys in discover mode with:The unquoted command substitution word-splits on all IFS whitespace and glob-expands each resulting word. A cluster rel path containing a space would be split into multiple bogus iterations, and one containing a glob character (
*,?,[) could expand against the working directory. Today's registered cluster paths are safe, so this is latent, but the loop silently mis-iterates the moment a whitespace or glob-char path is registered, and discover mode is the surface humans use to inspect cluster status. Cost of leaving it: wrong or misleading discover output with no error signal.Proposed work
mapfile -t sorted < <(printf '%s\n' "${!cluster_status[@]}" | sort)andfor rel in "${sorted[@]}".scripts/check-cross-plugin-source-drift.test.shbuilds fixture repos) to lock the behavior.Acceptance criteria
References
scripts/check-cross-plugin-source-drift.sh:120claude/code-tidying-batch-simplify-s7ljbi; deliberately not fixed there because the sweep was behavior-preserving.