CLI crashes (unhandled rejection) when a shell command contains a literal ${} — shell-quote parse throws in classifyShellCommand
Personne n'a encore pris cette issue.
Évaluation
- Difficulté
- 3/5
- Temps estimé
- 1-2 jours
- Accessibilité débutants
- 72/100
- Type d'issue
- Bug
- Clarté
- Plutôt claire
- Activité
- Active
- Stack technique
- javascript, node.js, shell
Piste de recherche
Suivez classifyShellCommand à travers shellPermissionRulesForCommand, getShellPermissionChoices et ShellPermissionPrompt, puis reproduisez l’échec avec shell-quote's parse('echo ${}'). Veillez à ce qu’une commande impossible à analyser ne mette plus fin à la session, utilise un comportement d’approbation conservateur et affiche l’erreur d’analyse dans le prompt.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Description
Summary
The CLI dies with an unhandled promise rejection when it builds the shell-permission prompt for a command whose text contains a literal ${}. shell-quote's parse() throws Bad substitution: ${}, and classifyShellCommand → shellPermissionRulesForCommand → getShellPermissionChoices → ShellPermissionPrompt does not catch it, so the whole session exits.
This is not a "bad command" problem: the command is never run, and the user never sees a prompt. The process is gone, and with it the conversation context of a long-running session.
Environment
| command-code | 1.54.1 |
| node | v24.1.0 |
| OS | macOS 27.0, arm64 (Apple Silicon, Homebrew install at /opt/homebrew) |
| shell-quote (bundled) | 1.10.0 |
| Session | running inside tmux, driven by an automation harness (messages sent programmatically), auto-yes enabled |
Stack trace (as printed)
✖ CRITICAL: Unhandled Promise Rejection!
✖ ERROR → Error
ℹ REASON → Bad substitution: ${}
ℹ ERROR STACK ↓
Error: Bad substitution: ${}
at parseEnvVar (/opt/homebrew/lib/node_modules/command-code/node_modules/shell-quote/parse.js:157:12)
at /opt/homebrew/lib/node_modules/command-code/node_modules/shell-quote/parse.js:236:14
at Array.map (<anonymous>)
at parseInternal (/opt/homebrew/lib/node_modules/command-code/node_modules/shell-quote/parse.js:113:17)
at parse (/opt/homebrew/lib/node_modules/command-code/node_modules/shell-quote/parse.js:309:15)
at classify (file:///opt/homebrew/lib/node_modules/command-code/dist/cli.mjs:2:382298)
at classifyShellCommand (file:///opt/homebrew/lib/node_modules/command-code/dist/cli.mjs:2:383445)
at shellPermissionRulesForCommand (file:///opt/homebrew/lib/node_modules/command-code/dist/cli.mjs:2:1075519)
at getShellPermissionChoices (file:///opt/homebrew/lib/node_modules/command-code/dist/cli.mjs:2:1083719)
at ShellPermissionPrompt (file:///opt/homebrew/lib/node_modules/command-code/dist/cli.mjs:16:21387)
ℹ Trace ID: 2bf510fd5bd624f90b2282f692816b84
Minimal repro of the throwing dependency
shell-quote throws on a literal ${} (empty substitution), while every other ${...} form parses fine:
const { parse } = require('shell-quote'); // 1.10.0
parse('echo ${VAR}'); // ok
parse('echo ${#a[@]}'); // ok
parse('echo ${PIPESTATUS[0]}');// ok
parse('echo ${!v}'); // ok
parse('echo $(( 1 + 2 ))'); // ok
parse('echo ${}'); // throws: Bad substitution: ${}
parse('echo "${}"'); // throws: Bad substitution: ${}
parse('printf %s ${}'); // throws: Bad substitution: ${}
Source: shell-quote/parse.js parseEnvVar() throws when ${ is immediately followed by }.
How it happens in practice
The model writes a shell command whose text happens to contain ${} — for example when echoing or heredoc-ing documentation/templates that mention ${} literally, or when a variable name is interpolated into an empty string while composing the command. The CLI then tries to classify that command for the permission prompt and crashes before showing anything.
Expected behaviour
Classification of a command that cannot be parsed should degrade, not kill the process. Something like:
- wrap the
shell-quoteparse()call intry/catchinsideclassify/classifyShellCommand, - on a parse error, fall back to the most conservative classification (treat the command as unrecognised and require explicit approval), and
- surface the parse error in the prompt instead of throwing.
A global unhandledRejection guard around the prompt path would also prevent a single classification bug from ending the session.
Impact
- The CLI exits mid-run. In an orchestrated, multi-session setup the managing session dies and its conversation context is lost; recovery has to be done by hand from the run artifacts.
- Because the crash is in the permission prompt path,
--trust/ auto-yes settings do not help: the process dies while building the prompt.
- Langage dominant
- Aucune donnée de langage
- Étoiles
- 4k
- Forks
- 350
- Métriques de merge des PR
- Aucune PR mergée en 30 j
Guide de contribution
Aucun guide de contribution indexé pour ce dépôt
Par où commencer
- Lisez l'issue en entier, puis le guide de contribution du projet.
- Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
- Forkez le dépôt et travaillez sur une branche.
- Ouvrez une pull request qui référence le numéro de l'issue.
Autres issues de CommandCodeAI/command-code
-
Difficulté 2/5 1-3 heures Accessibilité débutants 68/100
CommandCodeAI/command-code#855 ·
-
Difficulté 2/5 1-3 heures Accessibilité débutants 78/100
CommandCodeAI/command-code#841 · 1 commentaire ·
-
Difficulté 2/5 1-3 heures Accessibilité débutants 68/100
CommandCodeAI/command-code#655 · 1 commentaire ·
-
Difficulté 2/5 1-3 heures Accessibilité débutants 68/100
CommandCodeAI/command-code#608 ·
-
Difficulté 3/5 1-2 jours Accessibilité débutants 70/100
CommandCodeAI/command-code#893 ·
Toutes les issues de CommandCodeAI/command-code
Issues similaires
-
Difficulté 2/5 1-3 heures Accessibilité débutants 65/100
qgis/QGIS-Documentation#11275 ·
-
Difficulté 1/5 Moins d'une heure Accessibilité débutants 92/100
milvus-io/birdwatcher#545 ·
-
Difficulté 2/5 1-3 heures Accessibilité débutants 88/100
-
area:tools bug good first issue help wanted priority:P2
Difficulté 2/5 1-3 heures Accessibilité débutants 90/100
TaewoooPark/Motifcode#14 ·
-
bug
Difficulté 2/5 1-3 heures Accessibilité débutants 84/100
newrelic-experimental/preflight#793 · 1 commentaire ·