Skip to content

fix(code-placeholders): reject arithmetic comparisons and heredoc operands - #8760

Merged
waleedlatif1 merged 7 commits into
stagingfrom
fix/code-placeholders-arithmetic-contexts
Oct 8, 2026
Merged

waleedlatif1 merged 7 commits into
stagingfrom
fix/code-placeholders-arithmetic-contexts

Conversation

@waleedlatif1

@waleedlatif1 waleedlatif1 commented Oct 7, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Reject supplied shell placeholders in arithmetic comparisons ([[ ... -eq/-ne/-lt/-le/-gt/-ge ... ]]), including nested substitutions.
  • Carry arithmetic context from heredoc operators into their bodies, including quoted heredocs lowered to private input files.
  • Preserve ordinary strings, regexes, [ ... ] tests, and string comparisons. Brackets and dollar signs remain valid data.

Type of Change

  • Bug fix

Scope

This is a lexical guard for explicit arithmetic delimiters and comparisons. It does not infer variable types or trace later evaluation through let, integer-attributed variables, name-taking builtins, or dynamically selected commands. Scripts must validate data before those evaluations. A global value blacklist cannot make those paths safe without breaking ordinary string inputs. Supplied placeholders in the guarded positions are rejected even when their current value is numeric.

Testing

  • Compiler-to-Bash execution suite: 72 checks on Bash 3.2 and 5.2, using environment bindings, real private input files, and a command-execution sentinel.
  • The suite fails on the staging baseline. Disabling comparison detection or heredoc inheritance independently fails the corresponding cases.
  • CI runs the execution suite and uploads its JSON report on failure.
  • Focused compiler and CLI-service suites: 173 passed, 3 skipped. Lint, all 58 audits, type-checking across 26 workspaces, docs manifest, block registry, and workflow lint passed.
  • Additional comparison probe: 512 source variants, no accepted variant executed the sentinel.
  • Full local verification passed with two workers and unchanged timeouts: 366 script tests plus all workspace suites, including 35,447 app tests passed and 25 skipped.
  • All 25 applicable CI checks passed; Greptile reviewed the current head at 5/5 and all 61 review threads are resolved.

Checklist

  • Code follows project style guidelines
  • Self-reviewed my changes
  • Tests added/updated and passing
  • No new warnings introduced
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

@vercel

vercel Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
docs Skipped Skipped Oct 8, 2026 6:18am UTC

Request Review

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 3 files

Reply with feedback, questions, or to request a fix.

Turn on auto-fix | Re-trigger cubic

Comment thread apps/sim/lib/execution/code-placeholders/shell.ts Outdated
@greptile-apps

greptile-apps Bot commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

[High risk] Adds shell placeholder validation and end-to-end test infrastructure.

The PR appears safe to merge within its stated arithmetic-check scope.

What we checked:

  • Printed arguments stay ordinary text: The scanner opens a separate frame for the substitution. Closing it removes only that frame, leaving the outer command state intact.

Summary

The PR rejects supplied placeholders in explicit shell arithmetic comparisons and carries arithmetic context into heredoc bodies. The latest change gives process substitutions their own scan frames.

  • Input, output, and nested process substitutions preserve the surrounding command state.
  • Added checks cover printed arguments, literal values, and arithmetic comparisons inside process substitutions.
  • waleedlatif1 explicitly deferred checks for later evaluation through integer attributes, let, name-taking builtins, and dynamically selected commands. Those paths need broader tracking and remain outside this PR’s stated scope.
  • All supplied previous threads were unnumbered, so no numbered previous-finding entries are required.

Reviews (18) · Last reviewed commit: "fix(code-placeholders): preserve command..." · Reviewed by Greptile

Comment thread apps/sim/lib/execution/code-placeholders/shell.ts Outdated
Comment thread apps/sim/lib/execution/code-placeholders/shell.ts Outdated
Comment thread apps/sim/lib/execution/code-placeholders/shell.ts Outdated
Comment thread apps/sim/lib/execution/code-placeholders/shell.ts Outdated
Comment thread apps/sim/lib/execution/code-placeholders/shell.ts Outdated
Comment thread apps/sim/lib/execution/code-placeholders/shell.ts
@waleedlatif1
waleedlatif1 force-pushed the fix/code-placeholders-arithmetic-contexts branch from 9dfab5f to 1a74dc6 Compare October 7, 2026 20:40
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 3 files

Reply with feedback, questions, or to request a fix.

Turn on auto-fix | Re-trigger cubic

Comment thread apps/sim/lib/execution/code-placeholders/shell.ts
Comment thread apps/sim/lib/execution/code-placeholders/shell.ts Outdated
Comment thread apps/sim/lib/execution/code-placeholders/shell.ts Outdated
Comment thread apps/sim/lib/execution/code-placeholders/shell.ts Outdated
Comment thread apps/sim/lib/execution/code-placeholders/shell.ts Outdated
Comment thread apps/sim/lib/execution/code-placeholders/shell.ts Outdated
Comment thread apps/sim/lib/execution/code-placeholders/shell.ts Outdated
@waleedlatif1
waleedlatif1 force-pushed the fix/code-placeholders-arithmetic-contexts branch from 1a74dc6 to f0150b8 Compare October 7, 2026 21:09
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 3 files

Reply with feedback, questions, or to request a fix.

Turn on auto-fix | Re-trigger cubic

Comment thread apps/sim/lib/execution/code-placeholders/shell.ts Outdated
Comment thread apps/sim/lib/execution/code-placeholders/shell.ts Outdated
Comment thread apps/sim/lib/execution/code-placeholders/shell.ts Outdated
Comment thread apps/sim/lib/execution/code-placeholders/shell.ts Outdated
Comment thread apps/sim/lib/execution/code-placeholders/shell.ts Outdated
@waleedlatif1
waleedlatif1 force-pushed the fix/code-placeholders-arithmetic-contexts branch from f0150b8 to fbc91c8 Compare October 7, 2026 21:34
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@waleedlatif1
waleedlatif1 force-pushed the fix/code-placeholders-arithmetic-contexts branch from fbc91c8 to 6d07b57 Compare October 7, 2026 21:37
@cubic-dev-ai

cubic-dev-ai Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 3 files

Reply with feedback, questions, or to request a fix.

Turn on auto-fix | Re-trigger cubic

Comment thread apps/sim/lib/execution/code-placeholders/shell.ts Outdated
Comment thread apps/sim/lib/execution/code-placeholders/shell.ts Outdated
Comment thread apps/sim/lib/execution/code-placeholders/shell.ts Outdated
Comment thread apps/sim/lib/execution/code-placeholders/shell.ts Outdated
Comment thread apps/sim/lib/execution/code-placeholders/shell.ts Outdated
@waleedlatif1
waleedlatif1 force-pushed the fix/code-placeholders-arithmetic-contexts branch from 6d07b57 to 0477e23 Compare October 7, 2026 22:04

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 3 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

You've manually re-run cubic several times on this PR. Each manual re-review checks the full PR again and counts toward your usage quota. To preserve your usage limits, we recommend letting cubic automatically review new commits.

Turn on auto-fix | Re-trigger cubic

@waleedlatif1
waleedlatif1 force-pushed the fix/code-placeholders-arithmetic-contexts branch from d234578 to f1893de Compare October 8, 2026 05:43
@waleedlatif1 waleedlatif1 changed the title fix(code-placeholders): harden shell placeholder interpolation in arithmetic contexts fix(code-placeholders): reject arithmetic comparisons and heredoc operands Oct 8, 2026
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 4 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Turn on auto-fix | Re-trigger cubic

Comment thread apps/sim/lib/execution/code-placeholders/shell.ts
@waleedlatif1
waleedlatif1 force-pushed the fix/code-placeholders-arithmetic-contexts branch from f1893de to f4573b3 Compare October 8, 2026 05:58
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 4 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Turn on auto-fix | Re-trigger cubic

Comment thread apps/sim/lib/execution/code-placeholders/shell.ts
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 4 files

Reply with feedback, questions, or to request a fix.

Turn on auto-fix | Re-trigger cubic

Comment thread apps/sim/lib/execution/code-placeholders/shell.ts
@waleedlatif1
waleedlatif1 merged commit e3800f6 into staging Oct 8, 2026
48 checks passed
@waleedlatif1
waleedlatif1 deleted the fix/code-placeholders-arithmetic-contexts branch October 8, 2026 06:29

This branch was previously deployed

1 inactive deployment
Preview — 3d993519 Deployed Oct 8, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant