Skip to content

[plan] Quote COPILOT_API_TARGET value in pre-flight diagnostic step generator #21131

Description

@github-actions

Context

Identified in Sergo Audit Discussion #20993 — YAML Step Generator Audit + Context-Propagation Revisit (2026-03-14, score 8/10). This is Task 2 and depends on Task 1 (the singleQuoteYAML helper).

Problem

generateCopilotPreflightDiagnosticStep introduced in PR #20975 directly concatenates EngineConfig.APITarget into a YAML env: block without any quoting:

// pkg/workflow/copilot_engine_execution.go:498
step = append(step, "          COPILOT_API_TARGET: "+workflowData.EngineConfig.APITarget)

This is inconsistent with how other user-supplied values are handled throughout the step-generation layer (all use formatYAMLValue or pre-validated expressions). A value containing : (colon-space), #, ', or a newline would silently corrupt the generated workflow YAML.

Affected location:

  • pkg/workflow/copilot_engine_execution.go:498

Impact: Malformed workflow YAML if the api-target config value contains YAML-special characters.

Approach

  1. Ensure the singleQuoteYAML helper from the companion issue is available (either move it to a shared location or re-export from runtime_step_generator.go).
  2. Apply it to APITarget:
    // Before
    step = append(step, "          COPILOT_API_TARGET: "+workflowData.EngineConfig.APITarget)
    
    // After
    step = append(step, "          COPILOT_API_TARGET: "+singleQuoteYAML(workflowData.EngineConfig.APITarget))
  3. Add test coverage in the Copilot engine execution test suite.

Files to Modify

  • pkg/workflow/copilot_engine_execution.go — fix line 498
  • pkg/workflow/copilot_engine_execution_test.go — add test cases for APITarget values with :, #, '

Acceptance Criteria

  • COPILOT_API_TARGET value is properly single-quoted in generated YAML
  • Test cases cover APITarget values with : , #, ', and a plain hostname
  • Generated workflow YAML round-trips through gopkg.in/yaml.v3 without error
  • make agent-finish passes (build, test, lint, fmt)

Generated by Plan Command for issue #discussion #20993 · ◷

  • expires on Mar 17, 2026, 11:03 PM UTC

Activity

  1. github-actions commented on Mar 18, 2026

    @github-actions
    ContributorAuthor

    This issue was automatically closed because it expired on 2026-03-17T23:03:40.991Z.

    Closed by Workflow

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions