Repository navigation
fix(deps): update noyalib and preserve policy null rejection - #4348
Conversation
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
|
I reviewed up to 75631ab: the duration fix clears the provider test failure (137/137 pass locally), but the new null guard still only covers part of the schema, so I'd hold the merge on that. Verdict: request changes. Side note on exposure: I don't think RUSTSEC-2026-0333 ever reached OpenShell. Major
Each one means the same as writing
Provider profiles get the same coercion through Rather than adding more per-field Minor
Nits
|
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
|
🌿 Preview your docs: https://nvidia-preview-pr-4348.docs.buildwithfern.com/openshell |
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
EmilienM
left a comment
There was a problem hiding this comment.
Thanks Drew, this round covers everything from my last comment. I re-ran my main-vs-branch probe and all 22 null cases now behave exactly like main, including query/params values and empty documents, while null inside middleware config still works. yaml::to_string round-tripped every awkward key and value I threw at it, and the affected crates' tests pass locally.
LGTM. A few follow-ups, none blocking:
- The null path lists in
parse_policy_with_limitsandparse_profile_yamlare complete today, but nothing ties them to the structs, so a new map or struct field would quietly accept null again. A small wrappingDeserializerthat rejects null only indeserialize_map/deserialize_structwould cover every loader without lists, and the per-fielddeserialize_non_null_*helpers could go with it. yaml::from_strdecodes from aValuewithoutserde_path_to_error, so profile and prover errors carry no field path. Same as main, butparse_policyalready shows how to get it back.yaml::to_stringre-parses its output and looks up each quoted string from the root, so large-o yamlexports get a lot slower (about 25x on a 16k-item list). Fine at today's sizes.
Summary
Update noyalib to 0.0.53 to clear the published upstream advisory while preserving OpenShell's authored-YAML input semantics and exported string types.
Related Issue
Published upstream advisory: RUSTSEC-2026-0333.
Release failure: https://github.com/NVIDIA/OpenShell/actions/runs/37836897433/job/113539048121
Compatibility review: #4348 (comment)
This is maintainer-requested remediation for an already-public upstream advisory, not a new OpenShell vulnerability report. No public vulnerability issue was filed, per SECURITY.md.
Changes
Testing
Checklist