Commit 0017635
committed
fix: stop an
The env-assignment strip used an unanchored `[A-Za-z_]*=*` case glob, which
matches the WHOLE segment whenever any LATER token carries an `=`. It then ate
the leading words, so `npm install --omit=dev`, `npm ci --loglevel=error` and
`npm install --workspace=packages/core` were all ALLOWED. That is the one
direction that matters, since the gate exists to stop a write, and the last is
an ordinary command in this monorepo. It also made the `--prefix=` branch of
the regexes dead while the space-form test stayed green over it.
The strip is token-wise now, and the assignment test is anchored to the first
token alone.
Walking past arbitrary tokens after a wrapper turned out to re-create the
token-anywhere class one level in: with `command` and `bash` treated as
wrappers, `command -v yarn` blocked and `bash -c "echo yarn"` would have. So
the walk covers a wrapper's own flags and their values only, and `command`,
`exec`, `bash` and `sh` are not wrappers. `bash -c "npm ci"` is a documented
accepted gap rather than a parser for nested shells.= in a flag from disabling the install gate1 parent 4c6b094 commit 0017635
2 files changed
Lines changed: 91 additions & 12 deletions
File tree
- .claude/hooks
- test/hooks
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
69 | 69 | | |
70 | 70 | | |
71 | 71 | | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
72 | 76 | | |
73 | 77 | | |
74 | 78 | | |
75 | | - | |
76 | | - | |
77 | | - | |
78 | | - | |
79 | | - | |
80 | | - | |
81 | | - | |
82 | | - | |
83 | | - | |
84 | | - | |
85 | | - | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
86 | 117 | | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
87 | 122 | | |
| 123 | + | |
88 | 124 | | |
89 | 125 | | |
90 | 126 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
154 | 154 | | |
155 | 155 | | |
156 | 156 | | |
157 | | - | |
| 157 | + | |
| 158 | + | |
| 159 | + | |
| 160 | + | |
| 161 | + | |
| 162 | + | |
| 163 | + | |
| 164 | + | |
| 165 | + | |
| 166 | + | |
| 167 | + | |
| 168 | + | |
| 169 | + | |
| 170 | + | |
| 171 | + | |
| 172 | + | |
| 173 | + | |
| 174 | + | |
| 175 | + | |
| 176 | + | |
| 177 | + | |
| 178 | + | |
| 179 | + | |
| 180 | + | |
| 181 | + | |
| 182 | + | |
| 183 | + | |
| 184 | + | |
| 185 | + | |
| 186 | + | |
| 187 | + | |
| 188 | + | |
| 189 | + | |
| 190 | + | |
158 | 191 | | |
159 | 192 | | |
160 | 193 | | |
161 | 194 | | |
162 | 195 | | |
| 196 | + | |
| 197 | + | |
| 198 | + | |
| 199 | + | |
| 200 | + | |
| 201 | + | |
| 202 | + | |
| 203 | + | |
| 204 | + | |
| 205 | + | |
163 | 206 | | |
164 | 207 | | |
165 | 208 | | |
| |||
0 commit comments