Skip to content

fix(config): charset-validate dispatch_input names and choice options - #454

Merged
joshua-temple merged 1 commit into
mainfrom
fix/dispatch-input-validation-land
Jul 5, 2026
Merged

joshua-temple merged 1 commit into
mainfrom
fix/dispatch-input-validation-land

Conversation

@joshua-temple

Copy link
Copy Markdown
Collaborator

Problem

Dispatch-input names and choice options were emitted verbatim into generated workflow YAML without charset validation, unlike every peer identifier (environment, build, deploy, and component names, and repository_dispatch types, which all go through the shared validators). A manifest dispatch input whose name or option contained a space, a dot, a colon, or a template fragment produced a workflow that fails actionlint or GitHub's parser at run time, with no cascade-side validation error.

Fix

Validate dispatch-input names and choice options against the same identifier charset rule used by the sibling fields, so a malformed name or option is rejected at manifest-validation time with a clear error instead of reaching raw YAML.

Verification

go build ./..., go test ./... -race -count=1, and golangci-lint run ./... all clean locally, including new table cases for rejected and accepted dispatch-input names and options. Documentation updated in docs/src/content/docs/configuration.md.

Dispatch-input names reach the generated workflow_dispatch as raw YAML
keys (and as ${{ inputs.<name> }} references), and choice options are
emitted verbatim as block-sequence items, yet neither was charset-checked
while every sibling identifier is. A name or option carrying a space,
dot, colon, or ${{ }} fragment produced a workflow that failed actionlint
or GitHub's parser at run time with no cascade-side error.

Hold dispatch-input names to the same identifier-safe charset used for
environment, build, and deploy names via validateJobIDSafeName, and reject
choice options that are not safe to emit verbatim (letters, digits, dots,
hyphens, underscores), keeping version-like values expressible.

Signed-off-by: Joshua Temple <joshua.temple@stablekernel.com>
@joshua-temple
joshua-temple merged commit dccb396 into main Jul 5, 2026
21 checks passed
@joshua-temple
joshua-temple deleted the fix/dispatch-input-validation-land branch July 5, 2026 03:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant