Skip to content

fix(ci): store regex in variables to fix notify-parent parse error - #8

Merged
mateodelnorte merged 1 commit into
mainfrom
fix/notify-parent-regex
Feb 19, 2026
Merged

mateodelnorte merged 1 commit into
mainfrom
fix/notify-parent-regex

Conversation

@mateodelnorte

@mateodelnorte mateodelnorte commented Feb 18, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Stores regex patterns in bash variables before using them in [[ =~ ]] tests
  • Fixes bash parse error: ( in [:(] character class was interpreted as unmatched subshell opener
  • Error: unexpected EOF while looking for matching ')' (exit code 2)
  • Broken since cascading notification support was added

Root cause

# Broken — bash parses ( as subshell opener before regex engine sees it
if [[ "$MSG" =~ ^feat[:(] ]]; then ...

# Fixed — variable content passes directly to regex engine
re_feat='^feat[:(]'
if [[ "$MSG" =~ $re_feat ]]; then ...

Context

  • Part of [[tasks/meta-64]] / [[incidents/notify-parent-broken]]
  • Same fix applied to all 5 affected child repos

Test plan

  • Workflow passes on next push to main after merge

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Centralized output handling and introduced environment-driven payload variables for workflow runs.
    • Standardized payload handling for both dispatched and local executions while preserving existing behavior.
    • Replaced scattered write operations with a single output interface and added explicit patterns for change-type detection (feat, fix, chore, docs, test, refactor) for clearer, easier maintenance.

@coderabbitai

coderabbitai Bot commented Feb 18, 2026 •

Copy link
Copy Markdown

No actionable comments were generated in the recent review. 🎉


Walkthrough

Centralized payload handling was added to the GitHub Actions workflow: a write_output helper and new environment variables (EVENT_NAME, PAYLOAD_*, GH_REPOSITORY, GH_REPO_NAME, GH_ACTOR) replace multiple direct echo writes; regex patterns for change types were extracted into named variables and used in both branches.

Changes

Cohort / File(s) Summary
GitHub Actions Workflow
.github/workflows/notify-parent.yml
Added an env block (EVENT_NAME, PAYLOAD_*, GH_REPOSITORY, GH_REPO_NAME, GH_ACTOR). Introduced a local write_output helper to emit key/value pairs to GITHUB_OUTPUT with a delimiter and replaced direct echo writes in both repository_dispatch and default paths. Extracted re_feat, re_fix, re_chore, re_docs, re_test, re_refactor regex variables and updated conditional checks to use them; consolidated payload wiring and control flow around the single writer.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Poem

🐰
I hopped through workflows, neat and spry,
Collected values, wrote them by,
A tiny writer, regexes named,
No echo crumbs left to be blamed,
I twitch my nose and wave goodbye.

🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The PR title clearly and specifically describes the main change: fixing a parse error in the CI notify-parent workflow by storing regex patterns in variables.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch fix/notify-parent-regex

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
.github/workflows/notify-parent.yml (1)

36-36: ⚠️ Potential issue | 🟠 Major

Pre-existing risk: potential command injection via client_payload.message.

The ${{ github.event.client_payload.message }} expression is directly interpolated into the shell script. If a malicious actor can trigger a repository_dispatch event with a crafted message containing shell metacharacters (e.g., $(malicious_command) or backticks), arbitrary commands could execute.

Consider using an environment variable to safely pass the value:

🛡️ Suggested safer approach
       - name: Determine source
         id: source
+        env:
+          PAYLOAD_MESSAGE: ${{ github.event.client_payload.message }}
+          PAYLOAD_REPO: ${{ github.event.client_payload.repo }}
+          PAYLOAD_REPO_NAME: ${{ github.event.client_payload.repo_name }}
+          PAYLOAD_SHA: ${{ github.event.client_payload.sha }}
+          PAYLOAD_SHORT_SHA: ${{ github.event.client_payload.short_sha }}
+          PAYLOAD_TYPE: ${{ github.event.client_payload.type }}
+          PAYLOAD_ACTOR: ${{ github.event.client_payload.actor }}
         run: |
           if [ "${{ github.event_name }}" = "repository_dispatch" ]; then
-            echo "repo=${{ github.event.client_payload.repo }}" >> $GITHUB_OUTPUT
-            echo "repo_name=${{ github.event.client_payload.repo_name }}" >> $GITHUB_OUTPUT
-            echo "sha=${{ github.event.client_payload.sha }}" >> $GITHUB_OUTPUT
-            echo "short_sha=${{ github.event.client_payload.short_sha }}" >> $GITHUB_OUTPUT
-            echo "message=${{ github.event.client_payload.message }}" >> $GITHUB_OUTPUT
-            echo "type=${{ github.event.client_payload.type }}" >> $GITHUB_OUTPUT
-            echo "actor=${{ github.event.client_payload.actor }}" >> $GITHUB_OUTPUT
+            echo "repo=$PAYLOAD_REPO" >> $GITHUB_OUTPUT
+            echo "repo_name=$PAYLOAD_REPO_NAME" >> $GITHUB_OUTPUT
+            echo "sha=$PAYLOAD_SHA" >> $GITHUB_OUTPUT
+            echo "short_sha=$PAYLOAD_SHORT_SHA" >> $GITHUB_OUTPUT
+            echo "message=$PAYLOAD_MESSAGE" >> $GITHUB_OUTPUT
+            echo "type=$PAYLOAD_TYPE" >> $GITHUB_OUTPUT
+            echo "actor=$PAYLOAD_ACTOR" >> $GITHUB_OUTPUT

This prevents shell interpretation of the payload contents since environment variables are not subject to shell expansion when referenced.

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In @.github/workflows/notify-parent.yml at line 36, The echo line directly
interpolates github.event.client_payload.message allowing shell metacharacter
injection; instead capture the payload into a dedicated environment variable
(using the workflow's env/context or set-env style safely) and then write that
variable to GITHUB_OUTPUT without re-evaluating it, e.g., assign
github.event.client_payload.message to a safe variable and reference the
variable when appending to $GITHUB_OUTPUT (avoid direct ${ {
github.event.client_payload.message } } in the shell command).
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Outside diff comments:
In @.github/workflows/notify-parent.yml:
- Line 36: The echo line directly interpolates
github.event.client_payload.message allowing shell metacharacter injection;
instead capture the payload into a dedicated environment variable (using the
workflow's env/context or set-env style safely) and then write that variable to
GITHUB_OUTPUT without re-evaluating it, e.g., assign
github.event.client_payload.message to a safe variable and reference the
variable when appending to $GITHUB_OUTPUT (avoid direct ${ {
github.event.client_payload.message } } in the shell command).

@mateodelnorte
mateodelnorte force-pushed the fix/notify-parent-regex branch 2 times, most recently from 4e218e3 to 37558de Compare February 19, 2026 00:27

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Inline comments:
In @.github/workflows/notify-parent.yml:
- Around line 43-49: The write_output function uses a fixed delimiter "__EOF__"
which allows output injection/truncation; change write_output to generate a
per-call random delimiter (e.g., using a short random token from
openssl/sha1/LC_CTYPE + date or mktemp -u), check/regenerate if the random
delimiter appears inside the value, then use that delimiter variable in the
here-doc writes to GITHUB_OUTPUT (use the same variable name in the printf lines
and the closing marker) so each call uses a unique delimiter and cannot be
prematurely terminated by the value content; update the function name
write_output and its use sites accordingly.

Comment thread .github/workflows/notify-parent.yml
Bash interprets `(` in `[:(]` character classes as an unmatched
subshell opener, causing "unexpected EOF while looking for matching ')'"
(exit code 2). Storing the regex in a variable avoids this because bash
passes variable content directly to the regex engine without shell parsing.

Resolves [[incidents/notify-parent-broken]]
Implements [[tasks/meta-64]]

Co-authored-by: Claude <claude@anthropic.com>
@mateodelnorte
mateodelnorte force-pushed the fix/notify-parent-regex branch from 37558de to 2e0c281 Compare February 19, 2026 03:23
@mateodelnorte
mateodelnorte merged commit 30e1e4d into main Feb 19, 2026
7 checks passed
@mateodelnorte
mateodelnorte deleted the fix/notify-parent-regex branch February 19, 2026 04:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant