Skip to content

Commit 19beee3

Browse files
author
SqlRush
committed
Canonicalize PowerShell read-only aliases
1 parent ddf77cc commit 19beee3

4 files changed

Lines changed: 30 additions & 0 deletions

File tree

‎docs/claude-code-go-rewrite-plan.md‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -282,6 +282,7 @@ test/parity/ # golden tests against TS/official behavior
282282
- 本轮补充:slash command 现在有基础 local command result 抽象,`/clear` 不再落入 unsupported 分支,会生成 local text result、保留 command metadata message,并且不会请求模型;完整 REPL conversation reset、local command text/compact/skip 全语义、`/cost`/`/status`/`/compact` 和 local-jsx UI 执行仍未宣称完成。
283283
- 本轮补充:Bash destructive 分类会递归检查未 single-quoted 的 `$()`、backtick 和 subshell `(...)` 内容,嵌套破坏性命令会触发 destructive 标记。
284284
- 本轮补充:PowerShell destructive 分类会递归检查未 single-quoted 的括号表达式、`$()` 子表达式和 scriptblock `{...}`,嵌套 `Remove-Item`/mutating cmdlet 不再只停留在 not-read-only 状态。
285+
- 本轮补充:PowerShell read-only 分类补齐常见 pipeline alias canonicalization,包括 `select`/`sort`/`group`/`where`/`?`、`ft`/`fl`/`fw`/`fc` 和 `measure`,复用现有参数表达式 guard。
285286
- 本轮补充:Bash 文件读取/搜索类 read-only 命令增加基础相对路径 guard,绝对路径、home、父目录、变量路径、Windows drive、UNC 和 URI/provider-like 路径不再自动允许。
286287
- 本轮补充:Bash read-only 分类新增 `sed` 保守只读子集,允许 `-n`/`--quiet`、`-e`/`--expression` 的纯打印/删除/退出/行号脚本读取安全相对路径,同时拒绝 `-i`、`-f`、写文件/执行命令脚本和越界路径。
287288
- 本轮补充:Bash read-only 分类新增 `awk`/`gawk`/`mawk`/`nawk` 极小安全子集,允许 `{print}` 和 `{print $1, $2}` 这类纯输出脚本读取安全相对路径,并拒绝脚本文件、重定向、`system`/复杂表达式和越界路径。

‎docs/first-second-parity-audit.md‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -133,6 +133,7 @@ Covered behavior:
133133
- `Grep` now accepts whole-word matching through `word_regexp`/`wordRegexp`/`word-regexp`/`-w`, applying word-boundary filtering for both regex and fixed-string patterns and preserving quoted boolean coercion.
134134
- `Grep` now accepts ripgrep-style pattern files through `pattern_file`/`--file`/`-f`, reading one pattern per line, combining file patterns with explicit patterns, preserving empty-line matching semantics, and applying fixed-string, smart-case, word-regexp, and line-regexp handling to the combined set.
135135
- `Grep` now accepts inverted matching through `invert_match`/`invertMatch`/`invert-match`/`-v`, applying the inverted line set consistently for files-with-matches, content, count, and multiline span output modes while preserving quoted boolean coercion.
136+
- `PowerShell` read-only classification now canonicalizes common pipeline aliases such as `select`/`sort`/`group`/`where`/`?`, `ft`/`fl`/`fw`/`fc`, and `measure`, while preserving the existing expression/scriptblock guards.
136137
- `Grep` content output now accepts ripgrep-style no-line-number controls such as `--no-line-number` and `-N`, plus snake/camel adjacent aliases, to disable default line-number output with structured state preserved.
137138
- `Grep` content output now accepts `column`/`column_numbers`/`columnNumbers`/`column-number`/`--column`, emitting `path:line:column:text` for matching lines while preserving context-line formatting and structured column metadata.
138139
- `Grep` files-with-matches output now mirrors the official modified-time sort: newest files first, path tie-breaker, and pagination applied after sorting.

‎internal/tools/powershell/tools.go‎

Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1944,6 +1944,24 @@ func canonicalCommand(command string) string {
19441944
return "write-output"
19451945
case "sleep":
19461946
return "start-sleep"
1947+
case "select":
1948+
return "select-object"
1949+
case "sort":
1950+
return "sort-object"
1951+
case "group":
1952+
return "group-object"
1953+
case "where", "?":
1954+
return "where-object"
1955+
case "ft":
1956+
return "format-table"
1957+
case "fl":
1958+
return "format-list"
1959+
case "fw":
1960+
return "format-wide"
1961+
case "fc":
1962+
return "format-custom"
1963+
case "measure":
1964+
return "measure-object"
19471965
default:
19481966
return name
19491967
}

‎internal/tools/powershell/tools_test.go‎

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -137,6 +137,15 @@ func TestPowerShellCommandClassification(t *testing.T) {
137137
"Get-Process | Sort-Object Name",
138138
"Get-Process | Group-Object Name",
139139
"Get-Process | Where-Object Name -EQ go",
140+
"Get-Process | select Name",
141+
"Get-Process | sort Name",
142+
"Get-Process | group Name",
143+
"Get-Process | where Name -EQ go",
144+
"Get-Process | ft Name",
145+
"Get-Process | fl Name",
146+
"Get-Process | fw Name",
147+
"Get-Process | fc Name",
148+
"Get-Process | measure CPU",
140149
"Get-Process | Format-Table -AutoSize Name",
141150
"Get-Process | Format-List Name",
142151
"Get-Process | Format-Wide Name",
@@ -258,6 +267,7 @@ func TestPowerShellCommandClassification(t *testing.T) {
258267
"Start-Sleep -Seconds $env:SECRET",
259268
`Get-ItemProperty HKLM:\Software -Name Path`,
260269
"Get-Process | Select-Object $env:SECRET",
270+
"Get-Process | select $env:SECRET",
261271
"Get-Process | Select-Object @{N='x';E={Remove-Item out.txt}}",
262272
"Get-Process | Where-Object { Remove-Item out.txt }",
263273
"Get-Process | Format-Table -Property:$env:SECRET",

0 commit comments

Comments
 (0)