Reduce panic-driven internal control flow#6
Merged
Conversation
Co-authored-by: AlexandreYang <[email protected]>
Co-authored-by: AlexandreYang <[email protected]>
2 tasks
julesmcrt
added a commit
that referenced
this pull request
May 12, 2026
…cs; close coverage gaps Four review items from @AlexandreYang on PR #237 addressed in one commit: 1. Promote the -P-above-sandbox passthrough invariant from a local comment into the package docstring so callers can reason about when cd -P diverges from bash on container-style sandboxes. 2. Improve the diagnostic emitted when ChangeDir is nil (the RunCommand-child case used by find -exec / -execdir / xargs). Was "cd: not supported in this runner" — generic and opaque to users. Now reads "cd: cannot change directory from inside find -exec/-execdir or xargs (child invocations are isolated)" so the user knows the cause is intentional isolation. 3. Add a scenario for HOME pointing outside the sandbox (errors/home_outside_sandbox.yaml). Existing scenarios only covered HOME unset and HOME empty; the rejection path where resolveOperand succeeds but changeDir rejects was untested. 4. Add four hardening unit tests for the HostPrefix re-prefix logic in resolveSymlinks: unrelated absolute target gets re-prefixed, already-prefixed target is left alone, target exactly equal to hp is left alone, and the /mnt/host vs /mnt/hostile prefix-collision boundary is correctly distinguished by the hp+sep check. P3 review items (#5 Windows ACL test, #6 isCd literal-name defer-skip) are intentionally not addressed — both are flagged as not blocking and are forward-looking notes; replies posted on the threads. Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Converts internal panics in hot paths to explicit fatal errors, reserving panics for truly unrecoverable conditions (public API misuse, user handler crashes).
Changes
interp/vars.go: AddedinternalErrorfhelper that records assertion failures viaexit.fatalinstead of panicking. Converted panics inlookupVar,setVarWithIndex, andassignValto use it.interp/api.go: ConvertedReset()panic for zero-value Runner toexit.fatal+ early return. Added explicit fatal-error check inRun()afterReset()so the error surfaces without relying on the recover wrapper.interp/handler.go: KeptHandlerCtxpanic (public API, genuine programmer error) but clarified the doc comment.interp/allowed_paths_internal_test.go: AddedTestRunZeroValueRunnerReturnsErrorto verify the new explicit error path.The
recover()inRun()is retained as a safety net for panics from user-provided handlers (validated by existingTestRunRecoversPanic).Testing
go test ./...)PR by Bits
View session in Datadog
Comment @DataDog to request changes