Skip to content

Validate runner startup script inputs - #75

Open
Kewe63 wants to merge 2 commits into
related-sciences:mainfrom
Kewe63:fix/73-validate-script-inputs
Open

Kewe63 wants to merge 2 commits into
related-sciences:mainfrom
Kewe63:fix/73-validate-script-inputs

Conversation

@Kewe63

@Kewe63 Kewe63 commented Sep 19, 2026 •

Copy link
Copy Markdown

Summary

Validate runner_ver and shutdown_timeout before either value is embedded in the generated GCE startup script.

Changes

  • Accept runner_ver only as latest or an exact X.Y.Z version.
  • Validate the version returned by the GitHub releases API before using it.
  • Accept shutdown_timeout only as an integer from 0 through 86400 seconds.
  • Resolve latest before constructing the startup script.
  • Pass both inputs through quoted environment variables so GitHub expressions are not rendered directly into shell source.
  • Add regression coverage for shell syntax, malformed versions, timeout boundaries, oversized integers, and valid explicit/latest versions.
  • Run the regression test in a dedicated pull-request workflow.

Verification

  • tests/runner_input_validation_test.sh
  • Sabotage check: the regression test fails against upstream/main and passes with this change.
  • pre-commit run --all-files
  • git diff --check

Compatibility and risk

Documented defaults remain valid. Explicit runner versions must use the existing release format (X.Y.Z), and shutdown grace periods are capped at 24 hours so they cannot become unbounded startup-script data.

Fixes #73

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Validate runner_ver and shutdown_timeout before generating the GCE startup script

1 participant