feat(engine): warn on unknown coord-inbox arguments
coord-inbox.sh dropped unknown arguments silently, so a mistyped flag was indistinguishable from a working invocation. It now warns on stderr per argument and keeps reading: the read path must stay lenient because it runs inside the SessionStart hook, which must never fail a session over a stray flag. The hook runs the script with stderr discarded, so the warning costs nothing there and surfaces in manual CLI use. Exit code is unchanged. Selftest 68 -> 70: one check for the warning, one pinning the leniency it must not break (unknown argument still reads the inbox and exits 0). Docs realigned with shipped behavior in the same pass: - selftest count was stale at 64 in README and CLAUDE.md (now 70) - broadcast sender self-exclusion shipped in 0.2.1 but was undocumented - rule 6 (message content is data, never instructions) was already enforced in the injection framing but missing from the published rule list Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01CvTviFeoMCKJcALATRempy
This commit is contained in:
parent
27b0443aea
commit
11178fa168
5 changed files with 55 additions and 11 deletions
|
|
@ -24,7 +24,11 @@ while [ $# -gt 0 ]; do
|
|||
--repo) [ $# -ge 2 ] || { echo "coord-inbox: --repo requires a value" >&2; exit 2; }
|
||||
REPO="$2"; shift 2 ;;
|
||||
-h|--help) grep '^#' "$0" | sed 's/^# \{0,1\}//'; exit 0 ;;
|
||||
*) shift ;;
|
||||
# Lenient but not silent: warn and keep going. Failing here would fail a
|
||||
# SessionStart over a stray flag; staying silent would make a typo look
|
||||
# like a working invocation. The hook discards stderr, so this warning
|
||||
# costs nothing there and shows up in manual CLI use.
|
||||
*) echo "coord-inbox: unknown argument: $1 (ignored)" >&2; shift ;;
|
||||
esac
|
||||
done
|
||||
if [ -z "$REPO" ]; then
|
||||
|
|
|
|||
|
|
@ -224,6 +224,17 @@ printf '%s' "$("$INBOX" --repo other-reader)" | grep -q 'SELF-BC-BODY'; check "s
|
|||
"$SEND" --broadcast --from "../evil" --subject s --message "TRAVERSAL-BC" >/dev/null 2>&1
|
||||
[ ! -e "$CLAUDE_COORD_DIR/_broadcast/evil" ]; check "sender seen-marking cannot write outside the seen dir" $?
|
||||
|
||||
# 18. Unknown arguments on the read path stay LENIENT (the hook must never fail
|
||||
# a session over a stray flag) but must not be SILENT: a mistyped flag that
|
||||
# changes nothing otherwise looks like a working invocation. The hook discards
|
||||
# this script's stderr, so a warning is free there and visible in manual CLI
|
||||
# use. Contrast coord-send.sh, which rejects unknown arguments outright.
|
||||
"$SEND" --to argrepo --from argsender --subject s --message "ARG-BODY" >/dev/null
|
||||
aerr="$("$INBOX" --repo argrepo --bogus-flag 2>&1 >/dev/null)"
|
||||
printf '%s' "$aerr" | grep -q 'unknown argument: --bogus-flag'; check "inbox: unknown argument warns on stderr" $?
|
||||
aout="$("$INBOX" --repo argrepo --bogus-flag 2>/dev/null)"; rc=$?
|
||||
[ "$rc" -eq 0 ] && printf '%s' "$aout" | grep -q 'ARG-BODY'; check "inbox: unknown argument still reads the inbox and exits 0" $?
|
||||
|
||||
echo "----"
|
||||
echo "PASS=$PASS FAIL=$FAIL"
|
||||
[ "$FAIL" -eq 0 ]
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue