Skip to content

eval_in_shell matches the word "eval" anywhere, not the builtin in command position #892

Description

@hyperpolymath

Problem

cicd_rules/eval_in_shell (lib/rules/cicd_rules.ex:667) matches ~r/\beval\b/ anywhere on a line. The word eval is not the eval builtin, so the rule flags ordinary identifiers.

Observed on hyperpolymath/standards#1096. There were 6 findings and none of them runs the builtin:

file:line text what it is
provision-lib.sh:17 # ai-warmup … eval config-show … comment (#883 covers this)
provision-lib.sh:566 logf=".eval/$(date …).txt" directory name
provision-lib.sh:567 mkdir -p .eval directory name
provision-lib.sh:576 # … eval says N/A. comment (#883 covers this)
provision-lib.sh:637 eval) cmd_eval ;; case label
provision-check.sh:23 VERBS="… ai-warmup eval config-show …" string literal

Every repo that adopts the estate provisioning canon (just eval, the test+bench report verb) will carry these lines, so the false positives will repeat in every one of those repos.

#883 (skip comment lines) removes 2 of the 6. The other 4 remain.

Fix at source

Match eval only in command position: at the start of a line or after ;, &&, ||, |, (, $(, a backtick, then, do, else, if, while or until, and followed by whitespace or end of line. For example:

~r/(?:^|[;&|(`]|\$\(|\b(?:then|do|else|if|while|until)\b)\s*eval(?:\s|$)/

Acceptance criteria

  • Every flagged line in the table above yields no finding.
  • A positive control still fires on each of these: eval "$x", eval $cmd, foo && eval "$y", if eval "$z"; then, $(eval echo hi).
  • Kill the mutant: reverting the pattern to \beval\b makes the negative-control test fail.
  • The rule behaves the same as today on the existing hypatia fixtures, apart from the removed false positives.

Found by the estate provisioning campaign. Per the owner ruling, a new scanner finding becomes an issue, not a merge blocker.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions