Skip to content

Refuse a Commented or Multi-Line python-directories Value in the Audit #2013

Description

@ptr727

Problem

workflow_input_text() in spec/audit.py reads a caller's python-directories value by indentation, and its non-raw path, the one that produces the declared directories, misreads two shapes. The local strict review of #2010 found both, and neither is new with that change.

  • A comment between the key and a value on the next line. With python-directories: # the gated projects followed by an indented Tools line, the non-raw path takes # the gated projects as the value, since its comment strip needs whitespace before the #. The audit then reports a mismatch naming a directory that does not exist. The same comment on a line of its own at the key's column ends the block read, so the value reads as none.
  • A multi-line plain or quoted value. python-directories: "Tools followed by an indented Other" line is one scalar that YAML folds to Tools Other. The audit reads only the first line, Tools, which matches a registry declaring Tools, so no finding is raised. The validator refuses Tools Other at merge, because no tracked pyproject.toml exists at that path, so the gap is in the audit's report rather than in the gate.

No fleet caller writes either shape. Both of this repository's callers pass a plain single value.

Fix

Refuse both shapes, as #2010 does for a folded or escaped value, rather than modeling YAML: a value line that starts with #, and a plain or quoted value whose nested lines continue it. Add selftest cases for each.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions