fix(review): address PR #1713 review findings
- base-commit-capture.ts: shell-quote integration branch with a real
single-quoted POSIX literal instead of JSON.stringify (not shell-safe).
- TaskCard.tsx: memo compares full workspaceWorktrees values, not just key
sets, so a same-key worktreePath/branch change re-renders.
- TaskDetailModal.tsx: gate/render workspace summary off hydrated workingTask.
- worktree-acquisition.ts: null the singular worktree/branch columns in the
workspaceWorktrees write so isWorkspaceTask stays true; wrap non-fatal
post-acquire observability so logEntry/audit can't re-escalate to fatal.
- agent-tools.ts: register sub-repo worktree via onAcquired unconditionally
(idempotent) so a resumed/already-acquired path is tracked after restart.
- executor.ts: DB liveness fallback also checks task.workspaceWorktrees paths.
- executor-workspace.test.ts: root non-git assertion runs in fx.rootDir (".").
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -39,10 +39,19 @@ export async function resolveCapturedBaseCommitSha(
|
||||
integrationBranch: string = "main",
|
||||
): Promise<string | undefined> {
|
||||
const branch = integrationBranch.trim() || "main";
|
||||
// Shell-quote defensively; integration branch names are normalized upstream
|
||||
// but may carry slashes (e.g. "release/2026-06") that are valid in refs.
|
||||
const localRef = JSON.stringify(branch);
|
||||
const originRef = JSON.stringify(`origin/${branch}`);
|
||||
/*
|
||||
FNXC:Workspace 2026-06-22-09:00:
|
||||
Shell-quote with a real single-quoted POSIX literal, NOT JSON.stringify. A
|
||||
JSON double-quoted string still lets bash expand `$(...)`, backticks, and `$VAR`
|
||||
inside it; JSON.stringify is not a shell-quoting function. Git ref names can't
|
||||
legally contain backticks so there's no live injection path today, but
|
||||
single-quoting is the idiomatic safe form and stays correct if a caller ever
|
||||
passes a less-constrained string. A single quote inside the value is escaped as
|
||||
the standard `'\''` close-reopen sequence.
|
||||
*/
|
||||
const shellSingleQuote = (value: string): string => `'${value.replace(/'/g, "'\\''")}'`;
|
||||
const localRef = shellSingleQuote(branch);
|
||||
const originRef = shellSingleQuote(`origin/${branch}`);
|
||||
let baseCommitSha: string | undefined;
|
||||
try {
|
||||
const { stdout } = await execAsync(
|
||||
|
||||
Reference in New Issue
Block a user