feat(config): add cobra-probe-enabled toggle option and safeguard cobra probing (#133)

currently, every command that doesn't have a completion spec is assumed
to be a cobra cli and it gets ran with a `__complete` argument. for non
cobra clis this can cause problems if those non-cobra clis have
sideeffects even when ran with the `__complete` argument, and there is
no way to disable this.
one of these problems was solved at #111, but a full solution would
probably require actual sandboxing which is i think is an overkill just
for attempting to get suggestions for unrecognized commands. instead of
sandboxing, this pr adds a config option for allowing only selected
commands to be probed and disallowing the rest.
currently the default is still allowing all (`["*"]`) so default
behavior is the same, but it might be better to just have a long list of
known cobra clis as the default instead.

here's a demo of a side effect caused by the probing, in this case
"deleting" a file with rmtrash without actually trying to run the
command:

https://github.com/user-attachments/assets/5256d363-5291-42e8-bb4f-cf7467927246

---------

Co-authored-by: shemishtamesh <shemishtamail@gmail.com>
This commit is contained in:
shemishtamesh
2026-08-11 19:24:47 +07:00
committed by GitHub
co-authored by shemishtamesh
parent 0f173f78dc
commit 89fcd6f830
8 changed files with 103 additions and 18 deletions
+10 -9
View File
@@ -292,15 +292,16 @@ iris config show
```toml
[core]
version = 1 # config schema version
shell = "" # "zsh", "bash", "fish", or empty for auto-detect
shell-login = false # run shell as a login shell (also: iris --shell-login)
mode = "last" # "last", "spec", or "history"
debug = false # verbose logging to iris.log (also: iris -d)
expand-alias = true # expand aliases before matching
auto-execute = false # run suggestion immediately instead of inserting it
atuin-history = 0 # 0 = shell history, 1 = atuin, 2 = both
atuin-db-path = "" # path to atuin's history.db, empty = use default
version = 1 # config schema version
shell = "" # "zsh", "bash", "fish", or empty for auto-detect
shell-login = false # run shell as a login shell (also: iris --shell-login)
mode = "last" # "last", "spec", or "history"
debug = false # verbose logging to iris.log (also: iris -d)
expand-alias = true # expand aliases before matching
auto-execute = false # run suggestion immediately instead of inserting it
atuin-history = 0 # 0 = shell history, 1 = atuin, 2 = both
atuin-db-path = "" # path to atuin's history.db, empty = use default
cobra-probe-enabled = true # fall back to probing cobra binaries for completions
[ui]
style = "modern" # "modern" or "classic"