Skip to content

fix(code-placeholders): reject shell arithmetic placeholders - #8628

Merged
icecrasher321 merged 1 commit into
stagingfrom
codex/shell-arithmetic-guard
Oct 5, 2026
Merged

icecrasher321 merged 1 commit into
stagingfrom
codex/shell-arithmetic-guard

Conversation

@icecrasher321

@icecrasher321 icecrasher321 commented Oct 5, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Reject resolved shell placeholders inside $((...)), $[...], and ((...)) (including arithmetic for headers) before sandbox execution, where Bash recursively evaluates operand text.
  • Track these explicit arithmetic frames and their nested substitutions in the shared placeholder compiler. Preserve literal shell text and analysis-only variable discovery.
  • Scope: this is a defense-in-depth syntax guard, not a complete prohibition on evaluating bound data. let, numeric [[ ... ]] comparisons, array subscripts, integer assignments, and values assigned elsewhere before arithmetic evaluation remain outside this change. The demonstrated path uses environment values available to the shell author; no additional privilege boundary is crossed.

Type of Change

  • Bug fix

Testing

  • All 13 arithmetic rejection cases fail with the guard removed.
  • Compiler, resolver, and Function execution tests: 316 passed on the staging base.
  • bun run lint, bun run type-check, all 58 repository audits, docs-manifest check, and the staging-based block-registry check passed.
  • Full repository test run on Node 24: app suite had 34,713 passes and one timeout in the existing executor/execution/executor.test.ts case "does not run a stale branch inside a loop"; all 18 other test tasks passed. The timeout also reproduces with this patch removed on clean staging.
  • Local compiler-to-Bash reproduction verified before the fix and rejected after it; no hosted sandbox run.

Checklist

  • Code follows project style guidelines
  • Self-reviewed my changes
  • Tests added/updated and passing (new tests pass the test-audit authoring gate)
  • No new warnings introduced
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

@vercel

vercel Bot commented Oct 5, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
docs Skipped Skipped Oct 5, 2026 6:01pm UTC

Request Review

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 2 files

Fix all with cubic | Re-trigger cubic

Comment thread apps/sim/lib/execution/code-placeholders/shell.ts
@greptile-apps

greptile-apps Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

[Medium risk] Adds validation to reject shell arithmetic placeholders.

The PR appears safe to merge within its stated explicit-arithmetic scope.

Summary

The PR rejects resolved shell placeholders in explicit arithmetic expansions and commands while retaining literal-text handling and analysis-only discovery.

  • Adds compiler tests for arithmetic forms, nested substitutions, heredocs, and completed frames.
  • The previously reported broader arithmetic evaluators remain outside this PR’s acknowledged scope.

Reviews (2) · Last reviewed commit: "fix(code-placeholders): reject shell ari..."

Comment thread apps/sim/lib/execution/code-placeholders/shell.ts
@icecrasher321

Copy link
Copy Markdown
Collaborator Author

@greptile

@icecrasher321

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@icecrasher321 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 2 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

@icecrasher321

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@icecrasher321 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 2 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

@icecrasher321
icecrasher321 merged commit 2c8eeaf into staging Oct 5, 2026
60 of 61 checks passed
@waleedlatif1
waleedlatif1 deleted the codex/shell-arithmetic-guard branch October 5, 2026 23:29

This branch was previously deployed

1 inactive deployment
Preview — 4c9ea92e Deployed Oct 5, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant