Skip to content

[pull] main from affaan-m:main - #248

Merged
pull[bot] merged 2 commits into
joyshmitz:mainfrom
affaan-m:main
Sep 28, 2026
Merged

pull[bot] merged 2 commits into
joyshmitz:mainfrom
affaan-m:main

Conversation

@pull

@pull pull Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

tpanchal-iclr and others added 2 commits September 27, 2026 19:04
* fix(install): make install.sh robust to sh/dash invocation

Two related portability fixes so `sh install.sh` behaves correctly
even though the script is written for bash:

- The cygpath detection used the bash-only `&>/dev/null` redirection.
  dash misparses `&>`, so `command -v cygpath &>/dev/null` always took
  the true branch and tried to run the nonexistent `cygpath` binary,
  failing with "cygpath: not found". Switched to the POSIX-portable
  `>/dev/null 2>&1` form.

- Some dash builds don't support `set -o pipefail`, so `sh install.sh`
  can fail immediately at that line before even reaching the cygpath
  check (or the `[[ ... ]]` symlink-resolution logic further down).
  Added a guard that re-execs the script under bash when the current
  shell lacks bash capabilities, so the rest of the bash-only syntax
  always runs under a real bash regardless of the invoking shell. The
  guard probes for the `[[` compound command directly (via
  `eval '[[ 1 == 1 ]]'`) rather than trusting the $BASH_VERSION
  environment variable, since that variable could be inherited or
  spoofed under a non-bash shell and cause the guard to be skipped.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019XBaBRjaZgwhrZtYoqcQfp

* test(install): cover the sh install.sh re-exec path

Greptile flagged that the bash re-exec guard added in install.sh has
no automated coverage, since the existing test helper only invoked
the wrapper via `bash`. Adds two regression tests:

- "delegates to the Node installer when invoked via a POSIX sh
  wrapper" — runs the script via `sh` and asserts the args/cwd still
  reach the Node installer correctly.
- "re-execs into bash under sh even when BASH_VERSION is spoofed in
  the environment" — exercises the eval '[[ 1 == 1 ]]' capability
  probe directly, guarding against a regression back to trusting the
  (spoofable) $BASH_VERSION variable.

CodeRabbit then pointed out that the second test used generic `sh`,
which could trivially pass without exercising the re-exec branch at
all if `sh` ever resolves to bash on some system. Added a
findPosixOnlyShell() helper that prefers `dash` (falling back to
checking `sh`, and skipping with an explicit message if neither
genuinely lacks bash's `[[`), so the test reliably exercises the
branch it claims to cover instead of passing vacuously.

CodeRabbit then flagged that the skip path itself was miscounted as
a pass (the callback returned normally, so `test()` reported success
and `passed` was incremented even though nothing executed). Moved
the findPosixOnlyShell() check outside the test() registration, so
the test is only registered — and only counted — when a genuinely
POSIX-only shell is actually available; otherwise it's excluded from
both the passed and failed counts with an explicit skip line.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019XBaBRjaZgwhrZtYoqcQfp

---------

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Bumps [actions/stale](https://github.com/actions/stale) from 10.4.0 to 11.0.0.
- [Release notes](https://github.com/actions/stale/releases)
- [Changelog](https://github.com/actions/stale/blob/main/CHANGELOG.md)
- [Commits](actions/stale@1e223db...4391f3d)

---
updated-dependencies:
- dependency-name: actions/stale
  dependency-version: 11.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
@pull pull Bot locked and limited conversation to collaborators Sep 28, 2026
@pull pull Bot added the ⤵️ pull label Sep 28, 2026
@pull
pull Bot merged commit d3b8a3e into joyshmitz:main Sep 28, 2026
26 of 39 checks passed
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant