dor send --stdin interprets backslash escapes in piped bytes
- 主要语言
- TypeScript
- 星标
- 5
- 派生
- 1
- 平均合并
- 18 小时 32 分钟
- 30 天内合并 PR
- 216
描述
## `dor send --stdin` interprets backslash escapes in piped bytes, corrupting the documented use case
`dor send --stdin` reads standard input and forwards it as a **text** input:
```ts
if (flags.stdin === true) {
if (!readStdin) return { ok: false, message: 'stdin is not available' };
return { ok: true, value: [{ kind: 'text', text: await readStdin() }] };
}
```
([send.ts:183-186](https://github.com/diffplug/dormouse/blob/a1782f19b7d8363997eb37c440d1cbc8dfe13829/dor/src/commands/send.ts#L183-L186))
Text inputs then run through `interpretTextEscapes` unless `--raw` is set:
```ts
input += raw ? item.text : interpretTextEscapes(item.text);
```
([send.ts:227-228](https://github.com/diffplug/dormouse/blob/a1782f19b7d8363997eb37c440d1cbc8dfe13829/dor/src/commands/send.ts#L227-L228), converting `\n \r \t \\` at [send.ts:238-253](https://github.com/diffplug/dormouse/blob/a1782f19b7d8363997eb37c440d1cbc8dfe13829/dor/src/commands/send.ts#L238-L253))
### Why this is a footgun for `--stdin`
The flagship stdin example in the help is:
```
cat script.sh | dor send surface:3 --stdin
```
([send.ts:115](https://github.com/diffplug/dormouse/blob/a1782f19b7d8363997eb37c440d1cbc8dfe13829/dor/src/commands/send.ts#L115))
Bytes arriving on stdin are already literal — they are not a shell-authored string where a two-character `\t` stands in for a tab. Shell scripts routinely contain literal backslash sequences (`printf 'a\tb'`, `sed 's/\n/ /'`, `grep -P '\d'`, Windows paths with `\\`). Piping such a file through `--stdin` silently rewrites every `\n`/`\r`/`\t`/`\\`, so the text typed into the target terminal is not the file's contents.
**Repro:** `printf 'printf "a\\tb\\n"\n' | dor send surface:3 --stdin` types a real TAB and newline into the middle of the line instead of the literal `\t`/`\n` the script source contains.
The escape interpretation is desirable for `--text "echo hi\nthere"` (a human types escapes on the command line), but for `--stdin` the input is already-real bytes.
### Design question (why an issue, not a drive-by PR)
The current behavior is *consistent with* the documented contract — the help says "Text input interprets backslash escapes … unless `--raw` is set" ([send.ts:97](https://github.com/diffplug/dormouse/blob/a1782f19b7d8363997eb37c440d1cbc8dfe13829/dor/src/commands/send.ts#L97)), and `--stdin` is documented as text input — so flipping the default is a contract change that needs a maintainer call. Options:
1. **Make `--stdin` raw by default** — treat piped bytes as literal; keep `--text` interpreting escapes. Most aligned with the `cat script.sh | …` example. Would need an opt-in flag if anyone wants escape interpretation on stdin.
2. **Keep current behavior, document it** — call out at the `--stdin` help that it interprets escapes and that `--raw` is needed for literal file contents.
I lean toward option 1, but it changes documented behavior, so I'm leaving the call to a maintainer. Happy to open the PR (including a regression test that pipes a script containing `\t` and asserts the bytes are preserved) once a direction is chosen.
Surfaced by the nightly code-quality survey.
贡献指南
这个仓库没有索引到贡献指南
调研方向
从 dor/src/commands/send.ts 中 issue 所述的 stdin 处理和文本转义转换开始。使用文档中的 piping 示例确认当前行为,然后等待 maintainer 在默认使用 raw stdin 和记录现有行为之间做出选择。完成的标准是,所选 contract 已实现或记录在文档中,并有一个保留相关字节的 regression test。
由索引模型根据 Issue 内容生成。
评估
- 技术栈
- typescript
- 领域
- cli
- Issue 类型
- 缺陷
- 难度
- 3/5
- 预计耗时
- 1-2 天
- 活跃度
- 冷清
- 描述清晰度
- 基本清楚
- 新手友好度
- 50/100