Skip to content

scripts: check-cross-plugin-source-drift discover mode word-splits and glob-expands cluster paths #3376

Description

@kyle-sexton

Context

scripts/check-cross-plugin-source-drift.sh:120 iterates cluster keys in discover mode with:

for rel in $(printf '%s\n' "${!cluster_status[@]}" | sort); do

The unquoted command substitution word-splits on all IFS whitespace and glob-expands each resulting word. A cluster rel path containing a space would be split into multiple bogus iterations, and one containing a glob character (*, ?, [) could expand against the working directory. Today's registered cluster paths are safe, so this is latent, but the loop silently mis-iterates the moment a whitespace or glob-char path is registered, and discover mode is the surface humans use to inspect cluster status. Cost of leaving it: wrong or misleading discover output with no error signal.

Proposed work

  • Sort into an array without word-splitting, e.g. mapfile -t sorted < <(printf '%s\n' "${!cluster_status[@]}" | sort) and for rel in "${sorted[@]}".
  • Add a test-suite case registering a cluster path with a space (the suite at scripts/check-cross-plugin-source-drift.test.sh builds fixture repos) to lock the behavior.

Acceptance criteria

  • Discover mode iterates each cluster key exactly once regardless of spaces or glob characters in the path.
  • A test covers a cluster rel path containing a space and passes.

References

  • scripts/check-cross-plugin-source-drift.sh:120
  • Found by the batch-simplify sweep on branch claude/code-tidying-batch-simplify-s7ljbi; deliberately not fixed there because the sweep was behavior-preserving.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    priority: highSignificant impact, or blocks an imminent release; staff this cycle.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions