Repository navigation
fix: report malformed BoxList bracket indices - #335
Open
arindamsikder wants to merge 1 commit into
Open
arindamsikder wants to merge 1 commit into
arindamsikder wants to merge 1 commit into
Conversation
Guard unmatched index expressions in dotted reads, writes and deletes. Add regressions for nested paths, default/frozen modes and YAML loading. Independent review: passed (security and logic). AI-assisted contribution prepared with Hermes DEV.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Raise a clear
BoxTypeErrorwhen a dotted BoxList path has no numeric bracket index, instead of leakingAttributeErrorfrom a failed regex match.Problem
With
box_dots=True, reads, assignments and deletions such asitems["[x]"]callgroups()onNone. The regex-shaped YAML key in the maintainer's comment on #265 reaches the same assignment path when loaded withdefault_box=True.This addresses the requested diagnostic for that case. I did not reproduce the original segfault and am not claiming to resolve the entire issue.
Solution
develop.Testing
Executed offline in a credential-free Bubblewrap sandbox on Linux, CPython 3.11.15, Cython 3.3.0. Optional TOON dependency loaded from
toon-format/toon-pythoncommit6034550ceec432adba37480c82839d8428a80361.python -m pytest -q -p no:cacheprovider --basetemp=/tmp/pytest test/: 191 passed in pure Python and again with freshly built Cython modules; pristine base: 159 passed in each mode.python -m pytest -q -p no:cacheprovider --basetemp=/tmp/pytest test/test_box_list.py test/test_box.py -k invalidwith final tests and original runtime: 29 expected failures / 3 passing controls in each mode. Restored fix: full suites pass.python -m pytest --cov=box -vv -p no:cacheprovider --basetemp=/tmp/pytest test/: 191 passed in each mode. Pure-Python coverage: 92%; the compiled build is not line-traced (1% reported), so compiled coverage is not claimed.python -m black --check --config=.black.toml box test setup.py(24.10.0): passed.python -m mypy --cache-dir=/tmp/mypy box(1.13.0): passed, eight source files.CC=/usr/bin/x86_64-linux-gnu-gcc-15 python setup.py build_ext --inplaceandpython setup.py sdist bdist_wheel: passed.python -m twine check --strict dist/python_box-7.4.1-cp311-cp311-linux_x86_64.whl dist/python_box-7.4.1.tar.gz: passed. Installed the built wheel offline and reran the full suite with imports verified from that installation: 191 passed.box.py/.pyd, disabled byte-compilation and git-file listing in the disposable non-git build copy).git diff --check, added-line security scan and independent agent diff review: passed.Other interpreters, Windows/macOS and manylinux wheel jobs were not run locally; upstream CI remains authoritative for those platforms.
Related Issue
Refs #265 — the malformed-bracket diagnostic remainder only, not an automatic issue closure.
AI disclosure: implemented and validated autonomously with Hermes DEV; independent review was by a separate agent, not a claim of human pre-review.