Skip to content

Reject NUL bytes in Git paths and consolidate validation tests - #60043

Merged
pelikhan merged 2 commits into
mainfrom
copilot/testify-expert-improve-test-quality
Sep 10, 2026
Merged

pelikhan merged 2 commits into
mainfrom
copilot/testify-expert-improve-test-quality

Conversation

Copilot AI commented Sep 10, 2026 •

Copy link
Copy Markdown
Contributor

ValidateGitPath accepted NUL bytes, and its coverage duplicated cases across two test files.

  • Path validation
    • Reject NUL bytes before paths reach Git subprocesses.
if strings.ContainsRune(path, '\x00') {
    return fmt.Errorf("invalid git path %q: paths must not contain NUL bytes", path)
}
  • Test organization
    • Consolidate Git ref/path cases into table-driven tests.
    • Add a shared validation-error assertion helper.
    • Remove duplicate sibling tests while retaining distinct edge cases.

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Copilot AI changed the title [WIP] Improve test quality for pkg/gitutil/gitutil_ctr_formal_test.go Reject NUL bytes in Git paths and consolidate validation tests Sep 10, 2026
Copilot AI requested a review from pelikhan September 10, 2026 20:11
@github-actions

Copy link
Copy Markdown
Contributor

Great work! 👋 This PR looks ready for review. The fix correctly rejects NUL bytes in Git paths (addressing the security concern from #60027), and the test consolidation is solid—you have modernized the validation tests into table-driven form and removed duplicate coverage across test files while keeping distinct edge cases intact. The implementation is focused, well-tested, and clearly documented. This looks good to merge once the draft status is addressed and CI passes.

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • github.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com"

See Network Configuration for more information.

Generated by ✅ Contribution Check · copilot · auto · 58.3 AIC · ⌖ 9.2 AIC · ⊞ 9.4K · ◷

@pelikhan
pelikhan marked this pull request as ready for review September 10, 2026 21:12
Copilot AI balanced review requested due to automatic review settings September 10, 2026 21:12
@github-actions

github-actions Bot commented Sep 10, 2026 •

Copy link
Copy Markdown
Contributor

✅ Ponytail Reviewer completed successfully!

Lean already. Ship.

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • ab.chatgpt.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "ab.chatgpt.com"

See Network Configuration for more information.

Generated by Ponytail Reviewer for #60043

@github-actions

github-actions Bot commented Sep 10, 2026 •

Copy link
Copy Markdown
Contributor

🧠 Matt Pocock Skills Reviewer has completed the skills-based review. ✅

🧠 Reviewed using Matt Pocock's skills by Matt Pocock Skills Reviewer

@github-actions

github-actions Bot commented Sep 10, 2026 •

Copy link
Copy Markdown
Contributor

⚠️ Security scanning failed for Design Decision Gate 🏗️. Review the logs for details.

No ADR enforcement needed: PR does not have the 'implementation' label and has <=100 new lines of code in business logic directories.

🏗️ ADR gate enforced by Design Decision Gate 🏗️

@github-actions

github-actions Bot commented Sep 10, 2026 •

Copy link
Copy Markdown
Contributor

✅ Test Quality Sentinel completed test quality analysis.

Test Quality Sentinel skipped because pre-fetch PR data was unavailable: unable to fetch test file diff

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • github.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com"

See Network Configuration for more information.

🧪 Test quality analysis by Test Quality Sentinel

@github-actions

github-actions Bot commented Sep 10, 2026 •

Copy link
Copy Markdown
Contributor

⚠️ PR Code Quality Reviewer failed during code quality review.

Warning

Threat Detection Engine Failure — The analysis engine could not complete. This is a tooling failure, not a security finding.

What happened

The threat detection engine failed to produce results.

Review the workflow run logs for details.

🔎 Code quality review by PR Code Quality Reviewer

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The focused validation fix is correct and retains comprehensive consolidated coverage.

Pull request overview

Rejects NUL bytes in Git paths and consolidates validation coverage.

Changes:

  • Adds NUL-byte validation for Git paths.
  • Consolidates ref/path cases into table-driven tests.
  • Adds a shared validation-error assertion helper.
File summaries
File Description
pkg/gitutil/gitutil.go Rejects NUL bytes in Git paths.
pkg/gitutil/gitutil_test.go Removes duplicate validation tests.
pkg/gitutil/gitutil_ctr_formal_test.go Centralizes validation cases and assertions.
Review details
  • Files reviewed: 3/3 changed files
  • Comments generated: 0
  • Review effort level: Balanced

💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Skills-Based Review 🧠

Applied /diagnosing-bugs and /tdd — no blocking issues found.

📋 Analysis

/diagnosing-bugs

The NUL-byte fix in ValidateGitPath mirrors the existing ValidateGitRef check exactly (same strings.ContainsRune(path, '\x00') pattern, same error message style), addressing the root cause (unsanitized paths reaching the git subprocess) rather than a symptom. Placement before the IsAbs/traversal checks is correct since NUL can terminate C-string parsing in some git internals before those checks would matter.

/tdd

The table-driven consolidation is a genuine improvement:

  • All previously distinct test cases (safe paths/refs, hyphen-prefix, absolute path, traversal, empty, NUL byte) are preserved — verified none were silently dropped when merging gitutil_test.go into gitutil_ctr_formal_test.go.
  • The new assertValidationError helper removes duplicated require.Error/ErrorContains boilerplate across both TestValidateGitRef and TestValidateGitPath.
  • Test names read as clear specifications (e.g. "leading double dash is rejected", "nested path traversal is rejected").
  • A new case (--output=/etc/passwd, --upload-pack=malicious) strengthens double-dash-prefix coverage beyond the original single-dash case.

Minor observation (non-blocking)

No test exercises a NUL byte combined with another violation (e.g. -evil\x00) to confirm check ordering, but this is low value given the checks are independent and already well covered individually.

Nice cleanup — consolidating duplicate test files into one table-driven suite with a shared assertion helper is exactly the kind of maintainability win /tdd calls for.

🧠 Reviewed using Matt Pocock's skills by Matt Pocock Skills Reviewer · copilot · sonnet50 · 25.9 AIC · ⌖ 13.8 AIC · ⊞ 10.4K
Comment /matt to run again

@github-actions

Copy link
Copy Markdown
Contributor

Test Quality Sentinel Report - PR #60043

Summary

PR: Reject NUL bytes in Git paths and consolidate validation tests
Files: 2 Go test files analyzed
Tests: 2 validation functions (TestValidateGitRef, TestValidateGitPath)

Key Findings

Strengths

  • Security-focused design tests for both validation functions
  • NUL byte coverage added for both ValidateGitRef and ValidateGitPath
  • Table-driven consolidation removes duplicate code
  • Helper function provides consistent error validation
  • Proper build tags and parallel test execution
  • Comprehensive edge case coverage

Test Quality Score: 88/100 (Excellent)

Verdict

✅ APPROVE

This PR demonstrates excellent test quality:

  • All tests verify design contracts and security boundaries
  • Consolidation improves maintainability (net -46 lines)
  • No violations or code quality issues
  • Implementation test ratio: 0% (threshold: 30%)

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • github.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com"

See Network Configuration for more information.

🧪 Test quality analysis by Test Quality Sentinel · copilot · haiku45 · 24 AIC · ⌖ 9.3 AIC · ⊞ 8.4K · ◷
Comment /review to run again

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Test Quality Sentinel: 88/100. All tests verify design contracts and security boundaries (0% implementation tests, threshold 30%). Consolidation improves maintainability with net -46 lines. No violations.

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the NUL-byte validation fix in ValidateGitPath and the test consolidation in pkg/gitutil.

  • The new NUL-byte check mirrors the existing ValidateGitRef check and is placed consistently with the other validations.
  • Test consolidation into table-driven TestValidateGitRef/TestValidateGitPath preserves all prior coverage (dash-injection, traversal, absolute path, empty, NUL byte) and adds new cases (double-dash injection, nested traversal, NUL byte for paths) without duplication.
  • Verified locally: go build ./pkg/gitutil/... and go test ./pkg/gitutil/... both pass.

No blocking issues found.

🧵 Reviewed using Impeccable skills by Impeccable Skills Reviewer · copilot · sonnet50 · 32.4 AIC · ⌖ 12.5 AIC · ⊞ 8.4K

@pelikhan
pelikhan merged commit bdc29d9 into main Sep 10, 2026
95 of 107 checks passed
@pelikhan
pelikhan deleted the copilot/testify-expert-improve-test-quality branch September 10, 2026 21:22
@github-actions

Copy link
Copy Markdown
Contributor

🎉 This pull request is included in a new release.

Release: v0.89.3

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[testify-expert] Improve Test Quality: pkg/gitutil/gitutil_ctr_formal_test.go

3 participants