Skip to content

Tighten the Remaining Gaps in configure.sh's Labels Payload Validator #2229

Description

@ptr727

Found by the local review pass on the #1372 fix, all in labels_payload_ok in repo-config/configure.sh, and none introduced by that fix. Each was shown by running the function on a constructed payload, except where marked.

  1. Case folding is ASCII only. The duplicate-name test uses ascii_downcase, so entries named É and é both pass, though GitHub compares names case-insensitively (not confirmed against the API).
  2. Name length is unbounded. An 80-character name passes, and GitHub is believed to cap label names at 50 characters, so apply_labels would fail partway through, after the settings writes. A whitespace-only name also passes (not confirmed rejected by GitHub).
  3. A leading dash is accepted. A name such as -h passes, and gh label create "$lname" would read it as a flag (from flag parsing, not run).
  4. Odd characters pass the character test. A NUL, vertical tab, or U+2028 in a name passes, and a NUL is dropped by the rows substitution, so the label created differs from the one declared. jq also accepts nan as a document.
  5. Parse versus jq failure depends on jq's message text. The split keys on the words parse error, which holds for jq 1.6 to 1.8 and not for gojq or jaq installed as jq.

Needs a decision on how far the contract should grow before it is changed, since each added check is a new place for a defect.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions