currently, every command that doesn't have a completion spec is assumed
to be a cobra cli and it gets ran with a `__complete` argument. for non
cobra clis this can cause problems if those non-cobra clis have
sideeffects even when ran with the `__complete` argument, and there is
no way to disable this.
one of these problems was solved at #111, but a full solution would
probably require actual sandboxing which is i think is an overkill just
for attempting to get suggestions for unrecognized commands. instead of
sandboxing, this pr adds a config option for allowing only selected
commands to be probed and disallowing the rest.
currently the default is still allowing all (`["*"]`) so default
behavior is the same, but it might be better to just have a long list of
known cobra clis as the default instead.
here's a demo of a side effect caused by the probing, in this case
"deleting" a file with rmtrash without actually trying to run the
command:
https://github.com/user-attachments/assets/5256d363-5291-42e8-bb4f-cf7467927246
---------
Co-authored-by: shemishtamesh <shemishtamail@gmail.com>
run the `__complete` probe subprocess in its own session so that a
cobra-incompatible binary that ignores `__complete` can't mess with the
user's controlling terminal.
tested on both macos and nixos.
encountered the problem while trying to use
[visidata](https://www.visidata.org/).
---------
Co-authored-by: shemishtamesh <shemishtamail@gmail.com>