Skip to content

Parse Boolean action inputs as data - #76

Open
Kewe63 wants to merge 1 commit into
related-sciences:mainfrom
Kewe63:fix/74-parse-boolean-inputs
Open

Kewe63 wants to merge 1 commit into
related-sciences:mainfrom
Kewe63:fix/74-parse-boolean-inputs

Conversation

@Kewe63

@Kewe63 Kewe63 commented Sep 19, 2026

Copy link
Copy Markdown

Summary

Parse Boolean action inputs as data and reject malformed values before any external command runs.

Changes

  • Validate all Boolean-like inputs as exactly true or false.
  • Treat an omitted maintenance_policy_terminate as false and make its default explicit.
  • Replace command-position checks for actions_preinstalled and arm with quoted string comparisons.
  • Enable maintenance termination only when its value is exactly true.
  • Pass Boolean inputs through quoted environment variables instead of rendering GitHub expressions directly into shell source.
  • Add regression coverage for valid values, empty/mixed/malformed values, flag behavior, and a benign marker executable that proves malformed input is never run.
  • Run the regression test in a dedicated pull-request workflow.

Verification

  • tests/boolean_input_validation_test.sh
  • Sabotage check: the regression test fails against upstream/main, executes the benign marker there, and passes with this change without executing it.
  • pre-commit run --all-files
  • git diff --check

Compatibility and risk

Documented true and false values keep their intended behavior. Previously accepted malformed values now fail early; maintenance_policy_terminate: false no longer enables termination merely because the string is non-empty.

Fixes #74

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Parse Boolean action inputs as data instead of executing them

1 participant