mirror of
https://github.com/SikongJueluo/pi-extensions.git
synced 2026-10-05 11:52:55 +08:00
feat(pi-permission-inner-cmd): defer xargs as a non-transparent wrapper
- add handlers/xargs.ts mirroring env: claim xargs-leading commands and defer - register xargsHandler so leading-xargs commands log and defer instead of falling through silently - add CONTEXT.md xargs example and ADR 0003 (xargs args come from stdin, so even the AI judge cannot know them)
This commit is contained in:
+6
-4
@@ -21,8 +21,10 @@ program that actually runs.
|
||||
_Avoid_: safe wrapper
|
||||
|
||||
**Non-transparent wrapper**:
|
||||
A wrapper whose modifier args change the inner command's resolution or effect
|
||||
(e.g. `env`, whose `PATH=` or `-i` can make the inner name resolve to a
|
||||
different binary). Stripping the modifiers and re-evaluating the inner command
|
||||
is unsound: the verdict may apply to a different program than the one that runs.
|
||||
A wrapper whose modifiers change what the inner command actually does in a way
|
||||
the command string does not capture — e.g. `env` (its `PATH=` / `LD_PRELOAD`
|
||||
make the inner name resolve to or load a different program) or `xargs` (its
|
||||
inner command's arguments are read from stdin). Stripping the modifiers and
|
||||
re-evaluating the inner command is unsound: the verdict applies to inputs that
|
||||
are not knowable from the command string.
|
||||
_Avoid_: unsafe wrapper
|
||||
|
||||
Reference in New Issue
Block a user