fix: harden task1 workspace output and publication

This commit is contained in:
2026-08-11 03:14:58 +02:00
parent 3564817409
commit ad80180381
9 changed files with 410 additions and 67 deletions
@@ -11,6 +11,7 @@ import (
"errors"
"fmt"
"io"
"path/filepath"
"reflect"
"regexp"
"strings"
@@ -369,7 +370,7 @@ func makeInput(c Command) (inputEnvelope, string, error) {
if total > maxSQLTotal {
return env, "", errors.New("SQL input exceeds limit")
}
base := path[strings.LastIndexAny(path, "/\\")+1:]
base := filepath.Base(path)
env.SQL = append(env.SQL, sqlInput{base, base64.StdEncoding.EncodeToString(b), DigestBytes(b)})
}
case CheckSchemaRequest:
@@ -379,7 +380,7 @@ func makeInput(c Command) (inputEnvelope, string, error) {
if e != nil {
return env, "", errors.New("unsafe annotation input")
}
base := x.Annotations[strings.LastIndexAny(x.Annotations, "/\\")+1:]
base := filepath.Base(x.Annotations)
env.Annotations = &annotationInput{base, base64.StdEncoding.EncodeToString(b), DigestBytes(b)}
}
case IndexSchemaRequest:
@@ -589,7 +590,12 @@ func publishCandidate(x *hostExport, result Result, path string) error {
return errors.New("invalid candidate export")
}
var doc any
if yaml.Unmarshal(b, &doc) != nil {
decoder := yaml.NewDecoder(bytes.NewReader(b))
if decoder.Decode(&doc) != nil {
return errors.New("invalid candidate export")
}
var trailing any
if err := decoder.Decode(&trailing); err != io.EOF {
return errors.New("invalid candidate export")
}
if result.RunID == "" || !runIDPattern.MatchString(result.RunID) {