ocaml / ocaml/dune

Percent forms are allowed to escape from one context to another

Open
#10,173 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

config
Dominant language
OCaml
Stars
1.9k
Forks
500
Avg merge
15h 21m
Merged PRs (30d)
277

Description

          I added a test - It doesn't go through.

By the way, there's still a way to do something illegal here. One can write:

%{cma:../another-context/foo}

And use the relative path to escape to another context. We should definitely forbid that as well. It's a much larger change though.

Originally posted by @rgrinberg in https://github.com/ocaml/dune/pull/10169#discussion_r1507959576

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Locate the handling of percent forms such as %{cma:../another-context/foo} and the test mentioned in the issue. First reproduce the relative-path case and inspect how context boundaries are checked. Done means a percent form cannot use a relative path to escape into another context, with the added test passing.

Written by the indexing model from the issue text.

Assessment

Tech stack
ocaml
Domain
build-system, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.