script/ files pass the image tag through an inline command substitution, against their own rule #101

Closed
opened 2026-10-06 01:32:35 +02:00 by clawbot · 2 comments
Collaborator

script/cibuild and script/docker say, just above their docker build: "Own line: a failing command substitution inside an argument does not trip set -e, so the inline form degrades silently to an empty constant." The same docker build then passes the tag inline, -t "$("$SCRIPT_DIR/projectname")". script/lint and script/test do the same with -t "$("$SCRIPT_DIR/projectname")-lint" and -test. All four are like this on main and on next.

It fails closed, so it is not a false green: when script/projectname fails, the script carries on and docker build refuses the empty or -lint tag. But a rule stated in a file and broken a few lines later reads as optional to the next editor.

To reproduce: in any checkout of these files, replace script/projectname with a script that only does exit 1, then run script/lint. The script does not stop at the failed call; it runs docker build, which fails with invalid tag "-lint": invalid reference format.

Acceptable: in all four scripts the tag is assigned on its own line before the docker build, so set -e stops the script where script/projectname fails.

Found while checking item 3 of sneak/bsfirehose#50 against the canonical files for sneak/bsfirehose#67.

Model: opus-5-5

`script/cibuild` and `script/docker` say, just above their `docker build`: "Own line: a failing command substitution inside an argument does not trip `set -e`, so the inline form degrades silently to an empty constant." The same `docker build` then passes the tag inline, `-t "$("$SCRIPT_DIR/projectname")"`. `script/lint` and `script/test` do the same with `-t "$("$SCRIPT_DIR/projectname")-lint"` and `-test`. All four are like this on `main` and on `next`. It fails closed, so it is not a false green: when `script/projectname` fails, the script carries on and `docker build` refuses the empty or `-lint` tag. But a rule stated in a file and broken a few lines later reads as optional to the next editor. To reproduce: in any checkout of these files, replace `script/projectname` with a script that only does `exit 1`, then run `script/lint`. The script does not stop at the failed call; it runs `docker build`, which fails with `invalid tag "-lint": invalid reference format`. Acceptable: in all four scripts the tag is assigned on its own line before the `docker build`, so `set -e` stops the script where `script/projectname` fails. Found while checking item 3 of https://git.eeqj.de/sneak/bsfirehose/issues/50 against the canonical files for https://git.eeqj.de/sneak/bsfirehose/issues/67. Model: opus-5-5
Author
Collaborator

Plan. In script/cibuild, script/docker, script/lint and script/test, assign the tag on its own line before the docker build (for example tag="$("$SCRIPT_DIR/projectname")", then -t "$tag" or -t "$tag-lint"), so set -e stops the script where script/projectname fails. The comment in script/cibuild and script/docker then covers both substitutions; reword it so it no longer reads as about the version alone. prompts/REPO_POLICIES.md quotes the inline form in the snippet for script/lint and script/test and in the byte-identical script/docker and script/cibuild snippet; those change the same way.

Done when the reproduction above stops at the failed script/projectname call in all four scripts, nothing under prompts/ or script/ still passes $(…projectname) inline to docker build, and make check passes.

The re-vendor on #78 keeps its source commit: this defect fails closed, and repositories pick up the fix on their next re-vendor.

Model: opus-5-5

Plan. In `script/cibuild`, `script/docker`, `script/lint` and `script/test`, assign the tag on its own line before the `docker build` (for example `tag="$("$SCRIPT_DIR/projectname")"`, then `-t "$tag"` or `-t "$tag-lint"`), so `set -e` stops the script where `script/projectname` fails. The comment in `script/cibuild` and `script/docker` then covers both substitutions; reword it so it no longer reads as about the version alone. `prompts/REPO_POLICIES.md` quotes the inline form in the snippet for `script/lint` and `script/test` and in the byte-identical `script/docker` and `script/cibuild` snippet; those change the same way. Done when the reproduction above stops at the failed `script/projectname` call in all four scripts, nothing under `prompts/` or `script/` still passes `$(…projectname)` inline to `docker build`, and `make check` passes. The re-vendor on https://git.eeqj.de/sneak/prompts/issues/78 keeps its source commit: this defect fails closed, and repositories pick up the fix on their next re-vendor. Model: opus-5-5
clawbot self-assigned this 2026-10-06 01:33:40 +02:00
Author
Collaborator

Done as planned in #102, which also adds the same comment above the tag line in script/lint and script/test.

Model: opus-5-5

Done as planned in https://git.eeqj.de/sneak/prompts/pulls/102, which also adds the same comment above the tag line in `script/lint` and `script/test`. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/prompts#101