Skip to content

fix: reject adjacent for-loop items before execution - #438

Merged
tobert merged 1 commit into
mainfrom
fix/loop-word-boundaries
Sep 9, 2026
Merged

fix: reject adjacent for-loop items before execution#438
tobert merged 1 commit into
mainfrom
fix/loop-word-boundaries

Conversation

@tobert

@tobert tobert commented Sep 8, 2026

Copy link
Copy Markdown
Owner

For-loop item parsing accepted adjacent expressions as separate iterations. A command substitution followed immediately by a path suffix ran the substitution and then ran the loop body twice. Apply the existing quote-to-join rule to loop items and reject the complete adjacent run before execution, with a diagnostic pointing at the word to quote.

Write one interpolated item:

for x in "$(echo foo)/b"; do echo "$x"; done

Whitespace-separated items, standalone command-substitution newline splitting, and typed collection iteration keep their existing behavior. The argv diagnostic-rescan tests now use a valid test-condition boundary rather than the former loop exception. The overlay glob test also used that exception and missed an extra iteration; it now uses the explicit glob builtin and checks the exact returned paths.

Validation: regression tests failed before the fix and pass afterward; workspace tests, clippy across all targets with warnings denied, and rustdoc with warnings denied. Added nested diagnostic spans, longer adjacent runs, separate runs, and a test that neither substitution nor body side effects execute on rejection. Help fragments and generated syntax are synchronized.

Reviewed through kaibo by GLM-5.2 with DeepSeek V4 Flash investigation; no blocking findings. Review suggestions for nested spans and longer runs are covered. Built on #437 as the first follow-up layer; no version bump.

Base automatically changed from fix/literal-path-words to main September 9, 2026 12:09
For-loop item parsing accepted adjacent expressions as separate iterations. A command substitution followed immediately by a path suffix ran the substitution and then ran the loop body twice. Apply the existing quote-to-join rule to loop items and reject the complete adjacent run before execution, with a diagnostic pointing at the word to quote.

Write one interpolated item:

```sh
for x in "$(echo foo)/b"; do echo "$x"; done
```

Whitespace-separated items, standalone command-substitution newline splitting, and typed collection iteration keep their existing behavior. The argv diagnostic-rescan tests now use a valid test-condition boundary rather than the former loop exception. The overlay glob test also used that exception and missed an extra iteration; it now uses the explicit glob builtin and checks the exact returned paths.

Validation: regression tests failed before the fix and pass afterward; workspace tests, clippy across all targets with warnings denied, and rustdoc with warnings denied. Added nested diagnostic spans, longer adjacent runs, separate runs, and a test that neither substitution nor body side effects execute on rejection. Help fragments and generated syntax are synchronized.

Reviewed through kaibo by GLM-5.2 with DeepSeek V4 Flash investigation; no blocking findings. Review suggestions for nested spans and longer runs are covered. Built on #437 as the first follow-up layer; no version bump.
@tobert
tobert force-pushed the fix/loop-word-boundaries branch from a693b4e to c53bb20 Compare September 9, 2026 12:09
@tobert
tobert merged commit a2f8bc1 into main Sep 9, 2026
3 checks passed
tobert added a commit that referenced this pull request Sep 9, 2026
The lexer classified prefixes of ordinary literal words as numbers, keywords, or flags, then rejected the pieces as adjacent arguments. Recognize numeric filenames and version strings as whole words, accept embedded plus signs in word classes, and let numeric and keyword prefixes participate in existing colon and glob fusion.

These words now retain their complete spelling:

```sh
echo 123.txt 1.2.3 .123.txt true:foo do:foo a+b 123+b 123@host
echo ~/a:b
ls 1.0* true*
```

A numeric filename can exceed the integer range because it is text. Complete scalar numbers still follow the existing numeric rules: incomplete floats and integer overflow remain errors, leading zeros remain text, and ordinary integers and floats keep their types. Glob fusion slices the original source, so numeric formatting cannot change which filenames match. Standalone keywords, booleans, plus-prefixed flags, collection delimiters, and quote-to-join checks retain their roles.

Validation: numeric and keyword regression suites failed before the fix; the final tests check exact token spans, argument values, assignment and redirect values, actual glob matches with misleading numeric-prefix controls, tilde expansion, and control-flow/record behavior. Workspace tests, clippy across all targets with warnings denied, and rustdoc with warnings denied passed. Help fragments and generated syntax are synchronized.

Reviewed through kaibo's default cast, GLM-5.2 with DeepSeek V4 Flash investigation. Review exposed the numeric prefix followed directly by punctuation; it is fixed with failing-then-passing regression tests rather than preserved as another word-character exception. This layer builds on #438 in the native stack rooted at #437. Tilde assignment and its regex-operator collision are a separate layer.
@tobert
tobert deleted the fix/loop-word-boundaries branch September 9, 2026 13:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant