Skip to content

Fix E1018 false positive on Fn::Split over Fn::GetStackOutput - #439

Merged
satyakigh merged 2 commits into
mainfrom
e1018
Sep 30, 2026
Merged

satyakigh merged 2 commits into
mainfrom
e1018

Conversation

@satyakigh

@satyakigh satyakigh commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Fn::Split whose source is Fn::GetStackOutput was reported as E1018 (Fn::Split source must be a string or a string-producing intrinsic), but CloudFormation accepts that nesting. The AWS CDK synthesizes exactly this shape for weak string-list cross-stack references (Fn::Split("||", Fn::GetStackOutput ...)), so every such consumer stack tripped the rule, and the CDK's CloudFormationValidatePlugin currently suppresses E1018 outright to work around it.

The allowed Fn::Split sources mirrored the published Fn::Split operand list, which predates Fn::GetStackOutput and still omits it. This change adds Fn::GetStackOutput to SPLIT_SOURCE_FUNCTIONS in template-model, the shared layer both engines use, so the fix applies to Rego and CEL identically.

  • src/template-model/src/intrinsic_arg_shapes.rs: add FN_GET_STACK_OUTPUT to SPLIT_SOURCE_FUNCTIONS; new unit test split_source_get_stack_output_is_allowed.
  • src/resources/templates/good/functions/split_get_stack_output.yaml: good-corpus fixture in the deploy-verified shape (split used as a list property, re-joined into a string with Fn::Join, and indexed with Fn::Select).
  • src/resources/expected/validation_reports{6,7,8}.json: regenerated; the only new entries are the fixture's three I9040 (INFO, missing Tags) findings, the rest is chunk-boundary movement. No existing template's diagnostics changed.

With this fix released, the E1018 entry in the CDK plugin's IGNORE_RULES becomes unnecessary.

  • Documentation: the Fn::Split reference lists the same ten source functions as the previous allowlist and predates Fn::GetStackOutput. The Fn::GetStackOutput reference enumerates supported positions (direct property value, Fn::Join, Fn::If, Fn::Select) and known limitations (Fn::Sub variable map, Fn::Base64, Outputs, Fn::Equals, Fn::ImportValue); Fn::Split appears in neither list, and the deployment shows it is accepted.
  • CDK: aws-cdk-lib emits this nesting for weak string-list cross-stack references (@aws-cdk/core:defaultCrossStackReferences=weak), and its CloudFormationValidatePlugin lists E1018 in IGNORE_RULES for that reason.

Checklist

  • For validation behavior changes, expected behavior is supported by CloudFormation evidence and all three engine
    selectors agree.
  • My code adheres to the [CONTRIBUTING GUIDE][contributing-guide] and DESIGN GUIDELINES.

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license.

CloudFormation accepts Fn::GetStackOutput as the source of Fn::Split (confirmed by deploying a template in the CDK weak cross-stack string-list shape), but the published Fn::Split operand list predates the function and omits it, so the validator reported E1018 on every such template.

Add Fn::GetStackOutput to the allowed Split sources in template-model so both engines inherit the fix, add a unit test and a good-corpus fixture in the deploy-verified shape, and regenerate the snapshots (engine parity verified: rego == cel == composite on all 718 templates).
@satyakigh
satyakigh merged commit ff783d2 into main Sep 30, 2026
14 checks passed
@satyakigh
satyakigh deleted the e1018 branch September 30, 2026 15:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant