Repository navigation
Fail closed on an unknown BranchAction - #272
Merged
Merged
Conversation
The on_exit/on_error setters mapped any unrecognized value to Commit, the only action that writes the branch into the workdir, and the build still reported success. A binding passing a bad value had its changes merged with no way to notice. An out-of-range discriminant is a binding-layer programmer error, which the C ABI already signals with a null builder: drop the builder and return null so the setter chain carries it through and the build fails with err = -1, rather than guessing an action on the caller's behalf. Fixes #175 Signed-off-by: Cong Wang <cwang@multikernel.io>
BranchAction is a plain uint8, so Sandbox{OnExit: BranchAction(9)}
compiles and reaches the C ABI. The FFI now fails such a build, but only
with a bare error code; checking up front, before the builder exists,
gives Go callers an error naming the bad value.
Signed-off-by: Cong Wang <cwang@multikernel.io>
The SDK mapped any unrecognized branch action to Commit through a dict.get default, so Sandbox(on_exit="Abort") committed the workdir it was meant to discard. Coerce both fields through BranchAction when the Sandbox is constructed so a bad value raises ValueError immediately, and look the discriminant up strictly when building. Signed-off-by: Cong Wang <cwang@multikernel.io>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #175.
An unrecognized branch action fell through to Commit, the only action that writes the COW branch into the workdir, and the build still reported success. The same fallback existed at three layers:
on_exit/on_errormapped any discriminant outside 0..=3 to Commit. An out-of-range value is a binding-layer programmer error, which the C ABI already signals with a null builder, so the setter now frees the builder and returns null; the setter chain carries it through andsandlock_sandbox_buildfails witherr = -1.BranchActionis a plainuint8, soSandbox{OnExit: BranchAction(9)}reached the C ABI.buildPolicynow rejects it up front with an error naming the value.dict.get(value, 0), soSandbox(on_exit="Abort")committed. Both fields are now coerced throughBranchActionat construction (raisingValueError) and looked up strictly at build.Tests
crates/sandlock-ffi/tests/branch_action.rs: 0..=3 round-trip for both setters; 4, 99, 255 fail the build.TestRunUnknownBranchActionRejected.🤖 Generated with Claude Code