Skip to content

Promote develop to main: Refuse an Escaped or Folded python-directories Value Wherever It Starts - #2011

Merged
ptr727 merged 1 commit into
mainfrom
develop
Sep 28, 2026
Merged

ptr727 merged 1 commit into
mainfrom
develop

Conversation

@ptr727

@ptr727 ptr727 commented Sep 28, 2026

Copy link
Copy Markdown
Owner

Summary

Promotes develop to main, carrying #2010.

That PR finishes #1916. The audit's caller check now refuses a python-directories value that is double-quoted and carries a backslash escape, which the runner expands and the audit would read raw. The existing folded (>) refusal and the new one both read the value's own text, past any anchor, tag, or comment, so a value after an anchor or tag, or starting on the next line, no longer slips past either.

#1915 needs no change. #1942 already counts a declared directory's setup.cfg [mypy] section in the validator's type-check step and covers it with a test.

Closes #1916
Closes #1915

🤖 Generated with Claude Code

…ts (#2010)

## Summary

This finishes #1916. The comment-indent half landed in #1919. The half
still open was a double-quoted `python-directories` value carrying a
backslash escape, which the runner expands and the audit read raw, so
the two resolved different directories.

- `spec/audit.py`: `python_directories_caller_findings()` now refuses an
escaped double-quoted value, the same way it already refused a folded
(`>`) scalar, rather than modeling YAML's escapes.
- Both refusals now read the input's own text through
`workflow_input_text(..., raw=True)`, skipping any anchor, tag, or
comment in front of the value. Matching only the key's line missed a
value after an anchor or a tag, a value on the next line, and an escape
on a continuation line. With no directories in the registry, each of
those passed silently. The folded check had the same anchor gap.
- The selftest covers each shape, plus a backslash after the closing
quote, which is not refused. It checks the plain case by the finding's
text, since an unexpanded value also resolves to nothing and would
otherwise pass as an ordinary mismatch. Every new case fails when the
refusal is reverted.

#1915 needs no change here. #1942 already counts a declared directory's
`setup.cfg` `[mypy]` section in the validator's type-check step and
tests it (`declared setup.cfg mypy counts` in
`tests/test_release_guards.py`). The spec's `python.config.placement`
still reports that placement as drift, as it does for `mypy.ini`.

Local strict review: three passes. Passes 1 and 2 each raised one
finding in code this change wrote, both fixed on this branch, and pass 3
found nothing. Pre-existing and contrived, left as is: the non-raw
reader treats a comment between the key and a next-line value as a
directory, and it reads a multi-line value as one line.

Refs #1916, #1915

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Copilot AI lite review requested due to automatic review settings September 28, 2026 19:46
@coderabbitai

coderabbitai Bot commented Sep 28, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Repository: ptr727/ProjectTemplate/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 10a33ed4-3064-415f-aa66-41745fe414a3


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@codecov

codecov Bot commented Sep 28, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 5.26316% with 18 lines in your changes missing coverage. Please review.
✅ Project coverage is 55.29%. Comparing base (a5f3949) to head (b80f3d4).
⚠️ Report is 291 commits behind head on main.

Files with missing lines Patch % Lines
spec/audit.py 5.26% 18 Missing ⚠️
Additional details and impacted files
@@            Coverage Diff             @@
##             main    #2011      +/-   ##
==========================================
- Coverage   55.42%   55.29%   -0.13%     
==========================================
  Files          16       16              
  Lines        7249     7266      +17     
==========================================
  Hits         4018     4018              
- Misses       3231     3248      +17     
Flag Coverage Δ
python-3.13 55.29% <5.26%> (-0.13%) ⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The change is narrowly scoped, preserves the audit’s structural-parsing approach, and adds targeted selftests for the newly refused input shapes.

Review effort: Lite
Findings: None

What changed in this PR

This PR promotes develop to main, carrying the updated audit logic that makes python-directories caller validation robust against YAML shapes that the audit does not (and should not) fully interpret.

Changes:

  • Extend workflow_input_text() with a raw=True mode to return the unprocessed value text (including nested lines) for shape validation.
  • Update python_directories_caller_findings() to refuse folded scalars (>) and double-quoted values that contain backslash escapes, even when preceded by anchors/tags/comments or when the value starts on the next line.
  • Expand spec/audit.py selftests to cover the new refusal cases (anchored/tagged/next-line/continued-line variants).
File Description
spec/​audit.py Strengthens audit parsing of workflow-call with: python-directories inputs and adds selftest coverage for the newly refused YAML shapes.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@ptr727
ptr727 merged commit 24614c6 into main Sep 28, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Read a with: Input Past a Deeper-Indented Comment in the Audit Count a setup.cfg [mypy] Section as a Declared Directory's Type Checker

2 participants