diffplug / diffplug/dormouse

dor send --stdin interprets backslash escapes in piped bytes

未关闭
#355 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
主要语言
TypeScript
星标
5
派生
1
平均合并
18 小时 32 分钟
30 天内合并 PR
216

描述

## `dor send --stdin` interprets backslash escapes in piped bytes, corrupting the documented use case

`dor send --stdin` reads standard input and forwards it as a **text** input:

```ts
if (flags.stdin === true) {
if (!readStdin) return { ok: false, message: 'stdin is not available' };
return { ok: true, value: [{ kind: 'text', text: await readStdin() }] };
}
```
([send.ts:183-186](https://github.com/diffplug/dormouse/blob/a1782f19b7d8363997eb37c440d1cbc8dfe13829/dor/src/commands/send.ts#L183-L186))

Text inputs then run through `interpretTextEscapes` unless `--raw` is set:

```ts
input += raw ? item.text : interpretTextEscapes(item.text);
```
([send.ts:227-228](https://github.com/diffplug/dormouse/blob/a1782f19b7d8363997eb37c440d1cbc8dfe13829/dor/src/commands/send.ts#L227-L228), converting `\n \r \t \\` at [send.ts:238-253](https://github.com/diffplug/dormouse/blob/a1782f19b7d8363997eb37c440d1cbc8dfe13829/dor/src/commands/send.ts#L238-L253))

### Why this is a footgun for `--stdin`

The flagship stdin example in the help is:

```
cat script.sh | dor send surface:3 --stdin
```
([send.ts:115](https://github.com/diffplug/dormouse/blob/a1782f19b7d8363997eb37c440d1cbc8dfe13829/dor/src/commands/send.ts#L115))

Bytes arriving on stdin are already literal — they are not a shell-authored string where a two-character `\t` stands in for a tab. Shell scripts routinely contain literal backslash sequences (`printf 'a\tb'`, `sed 's/\n/ /'`, `grep -P '\d'`, Windows paths with `\\`). Piping such a file through `--stdin` silently rewrites every `\n`/`\r`/`\t`/`\\`, so the text typed into the target terminal is not the file's contents.

**Repro:** `printf 'printf "a\\tb\\n"\n' | dor send surface:3 --stdin` types a real TAB and newline into the middle of the line instead of the literal `\t`/`\n` the script source contains.

The escape interpretation is desirable for `--text "echo hi\nthere"` (a human types escapes on the command line), but for `--stdin` the input is already-real bytes.

### Design question (why an issue, not a drive-by PR)

The current behavior is *consistent with* the documented contract — the help says "Text input interprets backslash escapes … unless `--raw` is set" ([send.ts:97](https://github.com/diffplug/dormouse/blob/a1782f19b7d8363997eb37c440d1cbc8dfe13829/dor/src/commands/send.ts#L97)), and `--stdin` is documented as text input — so flipping the default is a contract change that needs a maintainer call. Options:

1. **Make `--stdin` raw by default** — treat piped bytes as literal; keep `--text` interpreting escapes. Most aligned with the `cat script.sh | …` example. Would need an opt-in flag if anyone wants escape interpretation on stdin.
2. **Keep current behavior, document it** — call out at the `--stdin` help that it interprets escapes and that `--raw` is needed for literal file contents.

I lean toward option 1, but it changes documented behavior, so I'm leaving the call to a maintainer. Happy to open the PR (including a regression test that pipes a script containing `\t` and asserts the bytes are preserved) once a direction is chosen.

Surfaced by the nightly code-quality survey.

贡献指南

这个仓库没有索引到贡献指南

调研方向

从 dor/src/commands/send.ts 中 issue 所述的 stdin 处理和文本转义转换开始。使用文档中的 piping 示例确认当前行为,然后等待 maintainer 在默认使用 raw stdin 和记录现有行为之间做出选择。完成的标准是,所选 contract 已实现或记录在文档中,并有一个保留相关字节的 regression test。

由索引模型根据 Issue 内容生成。

评估

技术栈
typescript
领域
cli
Issue 类型
缺陷
难度
3/5
预计耗时
1-2 天
活跃度
冷清
描述清晰度
基本清楚
新手友好度
50/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。