fix(config): charset-validate dispatch_input names and choice options - #454
Merged
Merged
Conversation
Dispatch-input names reach the generated workflow_dispatch as raw YAML
keys (and as ${{ inputs.<name> }} references), and choice options are
emitted verbatim as block-sequence items, yet neither was charset-checked
while every sibling identifier is. A name or option carrying a space,
dot, colon, or ${{ }} fragment produced a workflow that failed actionlint
or GitHub's parser at run time with no cascade-side error.
Hold dispatch-input names to the same identifier-safe charset used for
environment, build, and deploy names via validateJobIDSafeName, and reject
choice options that are not safe to emit verbatim (letters, digits, dots,
hyphens, underscores), keeping version-like values expressible.
Signed-off-by: Joshua Temple <joshua.temple@stablekernel.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Dispatch-input names and choice options were emitted verbatim into generated workflow YAML without charset validation, unlike every peer identifier (environment, build, deploy, and component names, and repository_dispatch types, which all go through the shared validators). A manifest dispatch input whose name or option contained a space, a dot, a colon, or a template fragment produced a workflow that fails actionlint or GitHub's parser at run time, with no cascade-side validation error.
Fix
Validate dispatch-input names and choice options against the same identifier charset rule used by the sibling fields, so a malformed name or option is rejected at manifest-validation time with a clear error instead of reaching raw YAML.
Verification
go build ./..., go test ./... -race -count=1, and golangci-lint run ./... all clean locally, including new table cases for rejected and accepted dispatch-input names and options. Documentation updated in docs/src/content/docs/configuration.md.