Repository navigation
Store objects for an upstream key with a dot in it, such as gitlab.com [patch] - #109
Open
matt-edmondson wants to merge 1 commit into
Open
matt-edmondson wants to merge 1 commit into
matt-edmondson wants to merge 1 commit into
Conversation
…m [patch] ObjectStore accepted only upstream keys made of [A-Za-z0-9_-] and threw ArgumentException for anything else, though startup validation, the registry and the route parser all accept such a key. With an upstream named gitlab.com the batch call worked and then every object download and upload returned 500. The store now maps a key to its directory name instead of rejecting it. A plain key is its own name, so existing stores stay readable. Any other key has each UTF-8 byte outside that set written as %XX, which is deterministic and reversible, cannot collide with a plain name since it always contains a %, and leaves no separator or parent reference that could reach outside the root. Enumerate maps the name back to the key. Only an empty key is still refused. Fixes #56 Co-Authored-By: Claude Opus 5.5 <[email protected]> Claude-Session: https://claude.ai/code/session_01WY7QGzbH6kE2oceF1hP8fh
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Fixes #56
What was wrong
ObjectStoreonly accepted upstream keys made of[A-Za-z0-9_-](IsValidUpstream/IsUpstreamCharacter) and threwArgumentExceptionfor anything else. Startup validation,UpstreamRegistryandLfsRouteParserall accept such a key. So with an upstream namedgitlab.com, the batch call succeeded and then every object download and every upload returned 500.Change
This follows the maintainer decision on the issue: map the key to a safe directory name in
ObjectStore, and don't reject dotted keys at startup.ObjectStore.DirectoryNameFormaps a key to its directory name:-and_is its own name. That is the layout existing stores already have, so they stay readable.%XX, sogitlab.combecomesgitlab%2Ecom. The mapping is deterministic and reversible, so it is collision-free. An escaped name always contains a%, which a plain name never does. It leaves no separator or..that could reach outside the store root.ObjectPathandStagingDirectoryuse the mapped name. That coversOpenStaging,OpenRead,PublishAsync,TouchandExists.Enumeratemaps the name back to the key (UpstreamFor).Tests
ProxyFlowTests.DottedUpstreamKey_DownloadsAndUploadsAreStoredruns aProxyFixturewith agitlab.comupstream. It checks that a download and an upload both return 200 and both land in the store, which is the test the decision asked for.ObjectStoreTests:AnyNonEmptyUpstream_IsStoredInOneDirectoryUnderTheRootAndReadBackcoversgitlab.com,../escape,with/slash, a backslash,..and a non-ASCII key. Each must store and read back, sit in exactly one directory directly under the root, and enumerate under its original key.DirectoryNameFor_PlainKey_IsTheKeyItselfchecks that existing layouts are unchanged.DirectoryNameFor_DottedKey_EscapesOnlyTheDotandDirectoryNameFor_KeysThatLookAlikeOnceEscaped_StayDistinctcovergitlab.com,gitlab%2Ecom,gitlab%252Ecom,gitlab_comandgitlab-com.OpenStaging_MalformedUpstream_ThrowsbecomesOpenStaging_EmptyUpstream_Throws. Its../escapeandwith/slashrows are now stored safely, which the test above checks, rather than refused.With the fix reverted, 8 cases fail, including the
ProxyFixturetest. The full suite passes locally: 363 tests, 0 failed. The branch merges cleanly with #101, #102, #103, #104, #107 and #108.🤖 Generated with Claude Code
https://claude.ai/code/session_01WY7QGzbH6kE2oceF1hP8fh
Generated by Claude Code