@@ -1053,6 +1053,37 @@ describe('code placeholder compiler', () => {
10531053 'total=$(( $(( 1 + 1 )) + {{KEY}} ))' ,
10541054 'cat <<PAYLOAD\n$(( {{KEY}} * 2 ))\nPAYLOAD' ,
10551055 'cat <<PAYLOAD\n$[ {{KEY}} * 2 ]\nPAYLOAD' ,
1056+ 'echo $(( $(cat <<EOF\n{{KEY}}\nEOF\n) + 1 ))' ,
1057+ "echo $(( $(cat <<'EOF'\n{{KEY}}\nEOF\n) + 1 ))" ,
1058+ "echo $(( $(cat <<-'EOF'\n\t{{KEY}}\n\tEOF\n) + 1 ))" ,
1059+ '[[ {{KEY}} -eq 0 ]] && echo zero' ,
1060+ '[[ "{{KEY}}" -eq 0 ]] && echo zero' ,
1061+ 'if [[ 0 -lt {{KEY}} ]]; then echo positive; fi' ,
1062+ '[[ -n x && ( "{{KEY}}" -ge 1 ) ]]' ,
1063+ '[[ $(printf "%s" "{{KEY}}") -ne 0 ]]' ,
1064+ '[[ $(printf "%s" "{{KEY}}"; echo 1) -le 0 ]]' ,
1065+ '[[ $(cat <<EOF\n{{KEY}}\nEOF\n) -gt 0 ]]' ,
1066+ 'let "x={{KEY}}"' ,
1067+ 'let x={{KEY}}+1' ,
1068+ 'declare -i x="{{KEY}}"' ,
1069+ 'typeset -i x={{KEY}}' ,
1070+ 'f() { local -i x="{{KEY}}"; }' ,
1071+ 'declare -ai values=("{{KEY}}")' ,
1072+ 'declare -x -i x="{{KEY}}"' ,
1073+ // biome-ignore lint/suspicious/noTemplateCurlyInString: shell parameter expansion, not a JS template
1074+ 'a=(1 2); echo "${a[{{KEY}}]}"' ,
1075+ // biome-ignore lint/suspicious/noTemplateCurlyInString: shell parameter expansion, not a JS template
1076+ 's=abc; echo "${s:{{KEY}}}"' ,
1077+ // biome-ignore lint/suspicious/noTemplateCurlyInString: shell parameter expansion, not a JS template
1078+ 's=abc; echo "${s:0:{{KEY}}}"' ,
1079+ // biome-ignore lint/suspicious/noTemplateCurlyInString: shell parameter expansion, not a JS template
1080+ 's=abc; echo "${s: -1:{{KEY}}}"' ,
1081+ // biome-ignore lint/suspicious/noTemplateCurlyInString: shell parameter expansion, not a JS template
1082+ 'set -- a b; echo "${@:{{KEY}}}"' ,
1083+ // biome-ignore lint/suspicious/noTemplateCurlyInString: shell parameter expansion, not a JS template
1084+ 'cat <<PAYLOAD\n${a[{{KEY}}]}\nPAYLOAD' ,
1085+ // biome-ignore lint/suspicious/noTemplateCurlyInString: shell parameter expansion, not a JS template
1086+ 'cat <<PAYLOAD\n${s:{{KEY}}}\nPAYLOAD' ,
10561087 ] ) ( 'rejects shell placeholders whose values enter arithmetic: %s' , async ( code ) => {
10571088 await expect (
10581089 compileCodePlaceholders ( {
@@ -1087,6 +1118,41 @@ describe('code placeholder compiler', () => {
10871118 )
10881119 } )
10891120
1121+ it ( 'compiles shell placeholders beside arithmetic that never evaluates them' , async ( ) => {
1122+ const value = 'values[$(printf injected >&2)]'
1123+ const compiled = await compileCodePlaceholders ( {
1124+ code : [
1125+ '[ "{{KEY}}" -eq 0 ] 2>/dev/null || printf "%s\\n" not-zero' ,
1126+ '[[ "{{KEY}}" == values* && 1 -eq 1 ]] && printf "%s\\n" matched' ,
1127+ 'let total=1+1; printf "%s\\n" "{{KEY}}"' ,
1128+ 'f() { local copy="{{KEY}}"; printf "%s\\n" "$copy"; }; f' ,
1129+ 'declare copy="{{KEY}}"; printf "%s\\n" "$copy"' ,
1130+ // biome-ignore lint/suspicious/noTemplateCurlyInString: shell parameter expansion, not a JS template
1131+ 'printf "%s\\n" "${missing:-{{KEY}}}"' ,
1132+ // biome-ignore lint/suspicious/noTemplateCurlyInString: shell parameter expansion, not a JS template
1133+ 'a=(x y); printf "%s\\n" "${a[1]}{{KEY}}"' ,
1134+ 'printf "%s\\n" "let {{KEY}}"' ,
1135+ 'printf "%s\\n" "items[{{KEY}}]"' ,
1136+ '# declare -i n' ,
1137+ 'n="{{KEY}}"; printf "%s\\n" "$n"' ,
1138+ 'let total=1 <<EOF' ,
1139+ '{{KEY}}' ,
1140+ 'EOF' ,
1141+ 'printf "%s\\n" "$total"' ,
1142+ 'cat <<PAYLOAD' ,
1143+ '{{KEY}} $(( 1 + 1 ))' ,
1144+ 'PAYLOAD' ,
1145+ ] . join ( '\n' ) ,
1146+ language : CodeLanguage . Shell ,
1147+ environmentVariables : { KEY : value } ,
1148+ } )
1149+
1150+ expect ( executeShell ( `{\n${ compiled . code } \n} 2>&1` , compiled . bindings ) ) . toBe (
1151+ `not-zero\nmatched\n${ value } \n${ value } \n${ value } \n${ value } \ny${ value } \n` +
1152+ `let ${ value } \nitems[${ value } ]\n${ value } \n1\n${ value } 2\n`
1153+ )
1154+ } )
1155+
10901156 it ( 'discovers shell arithmetic placeholders without compiling missing values' , async ( ) => {
10911157 const code = 'total=$(( {{MISSING}} + {{KEY}} ))'
10921158 await expect ( analyzeCodePlaceholders ( code , CodeLanguage . Shell ) ) . resolves . toEqual ( [
0 commit comments