Skip to content

fix(terminal): run scripts, $PROFILE, execution policy and chmod modes (THI-353) - #387

Merged
thierryvm merged 1 commit into
mainfrom
fix/scripts-profile-pwsh
Sep 23, 2026
Merged

thierryvm merged 1 commit into
mainfrom
fix/scripts-profile-pwsh

Conversation

@thierryvm

@thierryvm thierryvm commented Sep 23, 2026 •

Copy link
Copy Markdown
Owner

Why

THI-353, step 2. Six lesson × environment cases still validated while the terminal printed an error: the 3 script cases (./script.sh, .\script.sh), cat $PROFILE, (Get-Content f).Count and Set-ExecutionPolicy on Windows.

What

  • Scripts — ./x, bash|sh|zsh x, .\x (Windows) run the file line by line. ./x needs the execute bit (Permission denied otherwise — what the chmod lesson teaches). Child-shell semantics: written files stay; cd, exported variables and the script's lines (history) do not. Depth limit 3 + a shared budget of 500 lines per command.
  • PowerShell — $PROFILE (alone → path; as an argument → the profile file), (Get-Content f).Count, Set-ExecutionPolicy / Get-ExecutionPolicy (new optional executionPolicy state; PowerShell-only). The configuration lesson gets a real profile file via a new powershellProfile setup, with a Windows-only note (noteByEnv).
  • chmod (bug found by the new tests) — +x wrote the bits one position too far (-rw-r--r-- → -rw-xr-xr-x: the owner still could not run the file) and only six octal modes existed. Now: any 3-digit octal, symbolic u+x / go-w / a=r / comma lists, invalid modes rejected.
  • Pipes run their left side in the session environment (was hard-coded 'linux').
  • clear in a script clears the screen and keeps what follows.

Ratchet KNOWN_DESYNCS: 9 → 3 (the 2> cluster, next PR — together with ./script.sh > out.txt, which still ignores the redirection like every non-echo command today).

Gates

  • curriculum-validator: GO (with the ratchet entry removed in the same change — done)
  • test-runner: type-check ✅ lint ✅, every new command tested in terminalEngine.test.ts
  • Full suite: 2558 pass / 3 expected-fail (ratchet) ✅ build ✅. Two Supabase integration files time out when the whole suite runs concurrently; run alone they pass 21/21 — pre-existing, network-bound, not touched here.
  • ui-auditor: clean
  • feature-dev:code-reviewer: FIX FIRST → 4 of 5 findings fixed in this PR (clear, fan-out budget, $PROFILE in .Count, pipe env), each with a test; the 5th (redirecting a script's output) belongs to the redirection PR
  • Chrome (local, Windows env): .\script.sh runs and validates, cat $PROFILE shows the profile, Set-ExecutionPolicy RemoteSigned confirms, (Get-Content documents/rapport.md).Count → 10 — no red line

Refs THI-353

🤖 Generated with Claude Code

Résumé par Sourcery

Activez des workflows réalistes pour les scripts, PowerShell et les permissions dans les environnements de terminal pris en charge, tout en corrigeant les problèmes associés liés à l’exécution et à la validation du programme pédagogique.

Nouvelles fonctionnalités :

  • Prise en charge de l’exécution de scripts shell dans les environnements Linux, macOS et Windows, avec un comportement de shell enfant et des limites de sécurité.
  • Ajout de l’expansion des profils PowerShell, des expressions de comptage de lignes et des commandes de stratégie d’exécution pour les leçons Windows.
  • Prise en charge de notes de configuration des leçons spécifiques à l’environnement et ajout d’un profil PowerShell simulé.
  • Extension de chmod pour accepter des modes octaux arbitraires et des expressions de mode symboliques courantes.

Corrections de bugs :

  • Correction de la gestion du bit d’exécution de chmod afin que les fichiers reçoivent les permissions prévues.
  • Conservation de l’environnement actif lors de l’exécution de commandes à gauche d’un tube.
  • Garantie que les commandes clear exécutées dans des scripts conservent la sortie produite ensuite.

Améliorations :

  • Réduction des désynchronisations de fidélité du terminal du programme pédagogique grâce à la prise en charge de workflows auparavant non pris en charge concernant les scripts, PowerShell et les permissions.

Tests :

  • Ajout de tests du moteur de terminal couvrant l’exécution de scripts, le comportement de PowerShell, les modes de chmod, les limites de sécurité des scripts, la gestion de clear et les tubes tenant compte de l’environnement.
Original summary in English

Summary by Sourcery

Enable realistic script, PowerShell, and permission workflows across supported terminal environments while fixing related execution and curriculum validation issues.

New Features:

  • Support executing shell scripts across Linux, macOS, and Windows environments with child-shell behavior and safety limits.
  • Add PowerShell profile expansion, line-count expressions, and execution-policy commands for Windows lessons.
  • Support environment-specific lesson setup notes and provide a simulated PowerShell profile.
  • Extend chmod to accept arbitrary octal modes and common symbolic mode expressions.

Bug Fixes:

  • Correct chmod execute-bit handling so files receive the intended permissions.
  • Preserve the active environment when executing commands on the left side of a pipe.
  • Ensure clear commands inside scripts retain output produced afterward.

Enhancements:

  • Reduce curriculum terminal fidelity desynchronizations by covering previously unsupported script, PowerShell, and permission workflows.

Tests:

  • Add terminal engine coverage for script execution, PowerShell behavior, chmod modes, script safety limits, clear handling, and environment-aware pipes.

…s (THI-353)

Six lesson x environment cases validated while the terminal printed an
error. They now run for real:

- Scripts: `./script.sh`, `bash|sh|zsh script.sh`, and `.\script.sh` on
  Windows execute the file line by line. `./x` needs the execute bit, as the
  chmod lesson teaches ("Permission denied" otherwise). A script runs in a
  child shell: the files it writes stay, its cd and exported variables do
  not, and its lines stay out of the history. A depth limit stops a script
  that calls itself.
- PowerShell: `$PROFILE` expands to the profile path, and the configuration
  lesson now starts with a real profile file, so `cat $PROFILE` shows it
  (the setup note is Windows-only, via the new `noteByEnv`).
  `(Get-Content f).Count` counts lines. `Set-ExecutionPolicy` records the
  policy that `Get-ExecutionPolicy` reports; both are PowerShell-only.
- chmod: `+x` wrote the bits one position too far (`-rw-r--r--` became
  `-rw-xr-xr-x`, the owner still could not run the file), and only six
  octal modes were known. It now handles any 3-digit octal mode and
  symbolic modes (`u+x`, `go-w`, `a=r`, comma lists), and rejects invalid
  ones. Found by the new script tests.

Code-review follow-ups in the same change: `clear` inside a script now
clears the screen (and keeps what the script prints after it); a shared
budget of 500 script lines per command bounds fan-out (N lines each calling
an N-line script is N^3 runs within the depth limit); `(Get-Content
$PROFILE).Count` expands $PROFILE; pipes run their left side in the session
environment instead of a hard-coded 'linux'.

Not in this change: `./script.sh > out.txt` still ignores the redirection,
like every command except echo today. That is the next THI-353 step
(generic redirection), together with the 3 `2>` cases left in the ratchet.

The THI-353 ratchet shrinks from 9 to 3 known cases.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
@vercel

vercel Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
terminal-learning Ready Ready Preview Sep 23, 2026 10:56pm UTC

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @thierryvm, you've used your own review budget of 250,000 diff characters for the last 7 days.

You can request another review in 2 days and 19 hours by commenting @sourcery-ai review. Upgrade to get a review now.

@sourcery-ai

sourcery-ai Bot commented Sep 23, 2026

Copy link
Copy Markdown

Guide du reviewer

Cette PR aligne le simulateur de terminal sur six cas de leçons/environnements auparavant désynchronisés en ajoutant l’exécution limitée des scripts, la prise en charge du profil Windows PowerShell et de la stratégie d’exécution, une analyse robuste de chmod, des pipes qui préservent l’environnement et la gestion de l’effacement des scripts, ainsi que des mises à jour de la configuration du programme et une couverture ciblée.

Diagramme de séquence pour l’exécution limitée des scripts

sequenceDiagram
    participant User
    participant TerminalEngine
    participant ScriptFile
    participant ChildShell
    User->>TerminalEngine: processCommand ./script.sh
    TerminalEngine->>ScriptFile: read and validate executable bit
    alt executable and within limits
        TerminalEngine->>ChildShell: runScript(script)
        loop each script line
            ChildShell->>TerminalEngine: processCommand(line, env)
            TerminalEngine-->>ChildShell: output and state
        end
        ChildShell-->>TerminalEngine: preserve file changes only
        TerminalEngine-->>User: script output
    else permission, depth, or line limit failure
        TerminalEngine-->>User: error
    end
Loading

Diagramme de séquence pour les commandes de profil PowerShell et de stratégie d’exécution

sequenceDiagram
    participant User
    participant TerminalEngine
    participant PowerShellState
    participant ProfileFile
    User->>TerminalEngine: $PROFILE
    TerminalEngine-->>User: profile path
    User->>TerminalEngine: cat $PROFILE
    TerminalEngine->>ProfileFile: read profile
    ProfileFile-->>TerminalEngine: profile contents
    TerminalEngine-->>User: profile contents
    User->>TerminalEngine: Set-ExecutionPolicy RemoteSigned
    TerminalEngine->>PowerShellState: store executionPolicy
    TerminalEngine-->>User: policy confirmation
    User->>TerminalEngine: Get-ExecutionPolicy
    TerminalEngine->>PowerShellState: read executionPolicy
    PowerShellState-->>TerminalEngine: RemoteSigned
    TerminalEngine-->>User: RemoteSigned
Loading

Diagramme de flux pour l’application du mode chmod

flowchart TD
    A["chmod mode path"] --> B{mode format}
    B -->|3-digit octal| C["convert digits to rwx bits"]
    B -->|symbolic or comma list| D["apply u/g/o changes"]
    B -->|invalid| E["return invalid mode error"]
    C --> F["update permission string"]
    D --> F
    F --> G["file can be executed when x is set"]
Loading

Modifications au niveau des fichiers

Modification Détails Fichiers
Ajout de l’exécution des scripts shell avec le comportement d’un shell enfant et des limites de sécurité dans les environnements pris en charge.
  • Reconnaître les invocations de ./, .\, bash, sh et zsh.
  • Appliquer les vérifications du bit d’exécution lorsque cela s’applique et préserver les modifications de fichiers tout en isolant le répertoire de travail courant, les variables et l’historique.
  • Limiter la profondeur d’exécution récursive et le nombre total de lignes ; prendre en charge l’effacement de la sortie des scripts.
src/app/data/terminalEngine.ts
src/app/components/TerminalEmulator.tsx
src/test/terminalEngine.test.ts
Implémentation du comportement du profil PowerShell et de la stratégie d’exécution pour les leçons Windows.
  • Développer $PROFILE vers son chemin simulé ou le contenu du fichier, et compter les résultats de Get-Content.
  • Suivre et exposer l’état de Set-/Get-ExecutionPolicy avec validation.
  • Fournir un fichier de profil réel et des messages de configuration spécifiques à l’environnement.
src/app/data/terminalEngine.ts
src/app/data/commands/types.ts
src/app/data/commands/windows.ts
src/app/data/lessonSetup.ts
src/app/data/curriculum.ts
src/app/components/LessonPage.tsx
src/test/lessonSetup.test.ts
src/test/terminalEngine.test.ts
Refonte de l’analyse de chmod pour prendre en charge les modes symboliques corrects et les modes octaux arbitraires.
  • Corriger le positionnement du bit d’exécution pour les modes symboliques.
  • Prendre en charge tous les modes octaux à trois chiffres, les clauses symboliques, les listes séparées par des virgules et les erreurs de mode invalide, tout en préservant les marqueurs de type de fichier.
src/app/data/terminalEngine.ts
src/test/terminalEngine.test.ts
Adaptation de l’exécution des pipes afin qu’elle respecte l’environnement actif du terminal.
  • Transmettre l’environnement courant au traitement du côté gauche du pipe afin de préserver le comportement spécifique aux commandes et scripts Windows.
src/app/data/terminalEngine.ts
src/test/terminalEngine.test.ts
Suppression des désynchronisations résolues de fidélité du programme et ajout de notes de configuration tenant compte de l’environnement.
  • Supprimer les entrées relatives aux scripts, à PowerShell et à la stratégie d’exécution de KNOWN_DESYNCS.
  • Valider l’immuabilité de la configuration et les nouveaux scénarios de leçons pris en charge.
src/test/lessonFidelity.test.ts
src/test/lessonSetup.test.ts
src/app/data/lessonSetup.ts
src/app/components/LessonPage.tsx

Conseils et commandes

Interagir avec Sourcery

  • Déclencher une nouvelle review : commentez @sourcery-ai review sur la pull request.
  • Poursuivre les discussions : répondez directement aux commentaires de review de Sourcery.
  • Générer une issue GitHub à partir d’un commentaire de review : demandez à Sourcery de créer une issue à partir d’un commentaire de review en y répondant. Vous pouvez également répondre à un commentaire de review avec @sourcery-ai issue pour créer une issue à partir de celui-ci.
  • Générer un titre de pull request : écrivez @sourcery-ai n’importe où dans le titre de la pull request pour générer un titre à tout moment. Vous pouvez également commenter @sourcery-ai title sur la pull request pour générer ou régénérer le titre à tout moment.
  • Générer un résumé de pull request : écrivez @sourcery-ai summary n’importe où dans le corps de la pull request pour générer un résumé de PR à tout moment, exactement à l’endroit souhaité. Vous pouvez également commenter @sourcery-ai summary sur la pull request pour générer ou régénérer le résumé à tout moment.
  • Générer le guide du reviewer : commentez @sourcery-ai guide sur la pull request pour générer ou régénérer le guide du reviewer à tout moment.
  • Résoudre tous les commentaires de Sourcery : commentez @sourcery-ai resolve sur la pull request pour résoudre tous les commentaires de Sourcery. Utile si vous avez déjà traité tous les commentaires et ne souhaitez plus les voir.
  • Ignorer toutes les reviews de Sourcery : commentez @sourcery-ai dismiss sur la pull request pour ignorer toutes les reviews de Sourcery existantes. Particulièrement utile si vous souhaitez repartir de zéro avec une nouvelle review — n’oubliez pas de commenter @sourcery-ai review pour déclencher une nouvelle review !

Personnaliser votre expérience

Accédez à votre tableau de bord pour :

  • Activer ou désactiver des fonctionnalités de review telles que le résumé de pull request généré par Sourcery, le guide du reviewer, etc.
  • Modifier la langue de review.
  • Ajouter, supprimer ou modifier les instructions de review personnalisées.
  • Ajuster d’autres paramètres de review.

Obtenir de l’aide

Original review guide in English

Reviewer's Guide

This PR brings the terminal simulator in line with six previously desynchronized lesson/environment cases by adding bounded script execution, Windows PowerShell profile and execution-policy support, robust chmod parsing, environment-preserving pipes, and script clear handling, with curriculum setup updates and focused coverage.

Sequence diagram for bounded script execution

sequenceDiagram
    participant User
    participant TerminalEngine
    participant ScriptFile
    participant ChildShell
    User->>TerminalEngine: processCommand ./script.sh
    TerminalEngine->>ScriptFile: read and validate executable bit
    alt executable and within limits
        TerminalEngine->>ChildShell: runScript(script)
        loop each script line
            ChildShell->>TerminalEngine: processCommand(line, env)
            TerminalEngine-->>ChildShell: output and state
        end
        ChildShell-->>TerminalEngine: preserve file changes only
        TerminalEngine-->>User: script output
    else permission, depth, or line limit failure
        TerminalEngine-->>User: error
    end
Loading

Sequence diagram for PowerShell profile and execution policy commands

sequenceDiagram
    participant User
    participant TerminalEngine
    participant PowerShellState
    participant ProfileFile
    User->>TerminalEngine: $PROFILE
    TerminalEngine-->>User: profile path
    User->>TerminalEngine: cat $PROFILE
    TerminalEngine->>ProfileFile: read profile
    ProfileFile-->>TerminalEngine: profile contents
    TerminalEngine-->>User: profile contents
    User->>TerminalEngine: Set-ExecutionPolicy RemoteSigned
    TerminalEngine->>PowerShellState: store executionPolicy
    TerminalEngine-->>User: policy confirmation
    User->>TerminalEngine: Get-ExecutionPolicy
    TerminalEngine->>PowerShellState: read executionPolicy
    PowerShellState-->>TerminalEngine: RemoteSigned
    TerminalEngine-->>User: RemoteSigned
Loading

Flow diagram for chmod mode application

flowchart TD
    A["chmod mode path"] --> B{mode format}
    B -->|3-digit octal| C["convert digits to rwx bits"]
    B -->|symbolic or comma list| D["apply u/g/o changes"]
    B -->|invalid| E["return invalid mode error"]
    C --> F["update permission string"]
    D --> F
    F --> G["file can be executed when x is set"]
Loading

File-Level Changes

Change Details Files
Added shell-script execution with child-shell behavior and safety limits across supported environments.
  • Recognize ./, ., bash, sh, and zsh invocations.
  • Enforce execute-bit checks where applicable and preserve file changes while isolating cwd, variables, and history.
  • Limit recursive execution depth and total lines; support clear output from scripts.
src/app/data/terminalEngine.ts
src/app/components/TerminalEmulator.tsx
src/test/terminalEngine.test.ts
Implemented PowerShell profile and execution-policy behavior for Windows lessons.
  • Expand $PROFILE to its simulated path or file content and count Get-Content results.
  • Track and expose Set-/Get-ExecutionPolicy state with validation.
  • Provision a real profile file and environment-specific setup messaging.
src/app/data/terminalEngine.ts
src/app/data/commands/types.ts
src/app/data/commands/windows.ts
src/app/data/lessonSetup.ts
src/app/data/curriculum.ts
src/app/components/LessonPage.tsx
src/test/lessonSetup.test.ts
src/test/terminalEngine.test.ts
Reworked chmod parsing to support correct symbolic and arbitrary octal modes.
  • Fix execute-bit placement for symbolic modes.
  • Support all three-digit octal modes, symbolic clauses, comma lists, and invalid-mode errors while preserving file type markers.
src/app/data/terminalEngine.ts
src/test/terminalEngine.test.ts
Made pipe execution honor the active terminal environment.
  • Pass the current environment into left-side pipe processing so Windows-specific command and script behavior is retained.
src/app/data/terminalEngine.ts
src/test/terminalEngine.test.ts
Removed resolved curriculum fidelity desyncs and added environment-aware setup notes.
  • Remove script, PowerShell, and execution-policy entries from KNOWN_DESYNCS.
  • Validate setup immutability and newly supported lesson scenarios.
src/test/lessonFidelity.test.ts
src/test/lessonSetup.test.ts
src/app/data/lessonSetup.ts
src/app/components/LessonPage.tsx

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@thierryvm
thierryvm merged commit 06ce4dd into main Sep 23, 2026
4 checks passed
@thierryvm
thierryvm deleted the fix/scripts-profile-pwsh branch September 23, 2026 23:05
thierryvm added a commit that referenced this pull request Sep 24, 2026
- CHANGELOG: entries for 23 and 24 September (#383-#387) and for the
  18-19 August fixes that had none (#377-#379)
- STORY: "Le bug était dans la police" section (23-24 September)
- plan.md / ROADMAP.md / docs/README.md banners moved off 6 June
- README: test count 1000+ -> 2500+
- security-audit-log: gates of #383-#387, #380 gate debt status

Co-authored-by: Claude Opus 5.5 <[email protected]>

This branch was successfully deployed

1 active deployment
Preview — 39d70b8c Deployed Sep 23, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant