Problem
cicd_rules/eval_in_shell (lib/rules/cicd_rules.ex:667) matches ~r/\beval\b/ anywhere on a line. The word eval is not the eval builtin, so the rule flags ordinary identifiers.
Observed on hyperpolymath/standards#1096. There were 6 findings and none of them runs the builtin:
| file:line |
text |
what it is |
provision-lib.sh:17 |
# ai-warmup … eval config-show … |
comment (#883 covers this) |
provision-lib.sh:566 |
logf=".eval/$(date …).txt" |
directory name |
provision-lib.sh:567 |
mkdir -p .eval |
directory name |
provision-lib.sh:576 |
# … eval says N/A. |
comment (#883 covers this) |
provision-lib.sh:637 |
eval) cmd_eval ;; |
case label |
provision-check.sh:23 |
VERBS="… ai-warmup eval config-show …" |
string literal |
Every repo that adopts the estate provisioning canon (just eval, the test+bench report verb) will carry these lines, so the false positives will repeat in every one of those repos.
#883 (skip comment lines) removes 2 of the 6. The other 4 remain.
Fix at source
Match eval only in command position: at the start of a line or after ;, &&, ||, |, (, $(, a backtick, then, do, else, if, while or until, and followed by whitespace or end of line. For example:
~r/(?:^|[;&|(`]|\$\(|\b(?:then|do|else|if|while|until)\b)\s*eval(?:\s|$)/
Acceptance criteria
Found by the estate provisioning campaign. Per the owner ruling, a new scanner finding becomes an issue, not a merge blocker.
Problem
cicd_rules/eval_in_shell(lib/rules/cicd_rules.ex:667) matches~r/\beval\b/anywhere on a line. The wordevalis not theevalbuiltin, so the rule flags ordinary identifiers.Observed on hyperpolymath/standards#1096. There were 6 findings and none of them runs the builtin:
provision-lib.sh:17# ai-warmup … eval config-show …provision-lib.sh:566logf=".eval/$(date …).txt"provision-lib.sh:567mkdir -p .evalprovision-lib.sh:576# … eval says N/A.provision-lib.sh:637eval) cmd_eval ;;caselabelprovision-check.sh:23VERBS="… ai-warmup eval config-show …"Every repo that adopts the estate provisioning canon (
just eval, the test+bench report verb) will carry these lines, so the false positives will repeat in every one of those repos.#883 (skip comment lines) removes 2 of the 6. The other 4 remain.
Fix at source
Match
evalonly in command position: at the start of a line or after;,&&,||,|,(,$(, a backtick,then,do,else,if,whileoruntil, and followed by whitespace or end of line. For example:~r/(?:^|[;&|(`]|\$\(|\b(?:then|do|else|if|while|until)\b)\s*eval(?:\s|$)/Acceptance criteria
eval "$x",eval $cmd,foo && eval "$y",if eval "$z"; then,$(eval echo hi).\beval\bmakes the negative-control test fail.Found by the estate provisioning campaign. Per the owner ruling, a new scanner finding becomes an issue, not a merge blocker.