Add trusted plugin script attribution (#35016)

## What changed

- Build a set of active, verified curated and remote plugin roots from loaded plugins.
- Resolve direct and safely wrapped script commands to a plugin ID and normalized plugin-relative path.
- Leave complex or ambiguous commands, local overrides, missing files, overlapping roots, and symlink escapes unattributed.
- Add a shared validator for the safe cross-platform shape of serialized plugin-relative paths.

## Testing

- Cover trusted-root selection, supported interpreters and shell wrappers, normalized paths, and fail-closed cases.

GitOrigin-RevId: 6e4199a241fd6dfadfec3df0845e7cb615352a49
This commit is contained in:
Kyle Brown
2026-07-23 21:45:42 +00:00
committed by copyberry
parent ceb2ffb793
commit 5bdbd3ee90
7 changed files with 660 additions and 1 deletions

View File

@@ -1747,7 +1747,8 @@ fn cd_target(args: &[String]) -> Option<String> {
target
}
fn is_pathish(s: &str) -> bool {
/// Returns whether a command token has an explicit path shape.
pub fn is_pathish(s: &str) -> bool {
s == "."
|| s == ".."
|| s.starts_with("./")