Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix inappropriate comparison on the length of a Collection #7125

Conversation

munahaf
Copy link
Contributor

@munahaf munahaf commented Aug 17, 2023

In file: oci_utils.py, there are several places in the code where the comparison of Collection length creates a logical short circuit. The way the Collection length is checked (e.g., len(t) >= 0) always returns true. I suggested that the Collection length comparison should be done without creating a logical short circuit. This should be reviewed to verify that the spirit of the original code has been kept by the change.

Sponsorship and Support:

This work is done by the security researchers from OpenRefactory and is supported by the Open Source Security Foundation (OpenSSF)(https://openssf.org/): Project Alpha-Omega(https://alpha-omega.dev/). Alpha-Omega is a project partnering with open source software project maintainers to systematically find new, as-yet-undiscovered vulnerabilities in open source code - and get them fixed – to improve global software supply chain security.

The bug is found by running the Intelligent Code Repair (iCR) tool by OpenRefactory and then manually triaging the results.

@ansibullbot
Copy link
Collaborator

@ansibullbot ansibullbot added cloud module_utils module_utils new_contributor Help guide this first time contributor plugins plugin (any type) labels Aug 17, 2023
Copy link
Collaborator

@felixfontein felixfontein left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for your contribution! Can you please add a changelog fragment? Thanks.

@felixfontein felixfontein added check-before-release PR will be looked at again shortly before release and merged if possible. backport-6 labels Aug 19, 2023
@ansibullbot

This comment was marked as outdated.

@ansibullbot ansibullbot added merge_commit This PR contains at least one merge commit. Please resolve! needs_rebase https://docs.ansible.com/ansible/devel/dev_guide/developing_rebasing.html labels Aug 21, 2023
@ansibullbot

This comment was marked as outdated.

@ansibullbot ansibullbot added ci_verified Push fixes to PR branch to re-run CI needs_revision This PR fails CI tests or a maintainer has requested a review/revision of the PR labels Aug 21, 2023
@ansibullbot

This comment was marked as outdated.

@ansibullbot ansibullbot added ci_verified Push fixes to PR branch to re-run CI and removed ci_verified Push fixes to PR branch to re-run CI labels Aug 22, 2023
@openrefactorymunawar openrefactorymunawar force-pushed the Inappropriate_Logic-13oci_utils.py15314855678017598354.diff branch from 593f30d to f43d477 Compare August 22, 2023 07:12
@ansibullbot ansibullbot removed ci_verified Push fixes to PR branch to re-run CI merge_commit This PR contains at least one merge commit. Please resolve! needs_rebase https://docs.ansible.com/ansible/devel/dev_guide/developing_rebasing.html labels Aug 22, 2023
@openrefactorymunawar openrefactorymunawar force-pushed the Inappropriate_Logic-13oci_utils.py15314855678017598354.diff branch from f43d477 to 0573bc5 Compare August 22, 2023 07:16
@ansibullbot ansibullbot removed the needs_revision This PR fails CI tests or a maintainer has requested a review/revision of the PR label Aug 22, 2023
@felixfontein felixfontein removed the check-before-release PR will be looked at again shortly before release and merged if possible. label Aug 22, 2023
@felixfontein felixfontein merged commit 7721420 into ansible-collections:main Aug 22, 2023
@patchback
Copy link

patchback bot commented Aug 22, 2023

Backport to stable-6: 💚 backport PR created

✅ Backport PR branch: patchback/backports/stable-6/7721420388aa1d9cf7751fa250754d3419f3a2b1/pr-7125

Backported as #7146

🤖 @patchback
I'm built with octomachinery and
my source is open — https://github.com/sanitizers/patchback-github-app.

patchback bot pushed a commit that referenced this pull request Aug 22, 2023
* Comment: Fixed inappropriate comparison on the length of a Collection. Added changlelog fragment file.

* Comment: Updated the scope of the changelog fragment based on feedback.

Co-authored-by: Felix Fontein <[email protected]>

---------

Co-authored-by: Felix Fontein <[email protected]>
(cherry picked from commit 7721420)
@patchback
Copy link

patchback bot commented Aug 22, 2023

Backport to stable-7: 💚 backport PR created

✅ Backport PR branch: patchback/backports/stable-7/7721420388aa1d9cf7751fa250754d3419f3a2b1/pr-7125

Backported as #7147

🤖 @patchback
I'm built with octomachinery and
my source is open — https://github.com/sanitizers/patchback-github-app.

patchback bot pushed a commit that referenced this pull request Aug 22, 2023
* Comment: Fixed inappropriate comparison on the length of a Collection. Added changlelog fragment file.

* Comment: Updated the scope of the changelog fragment based on feedback.

Co-authored-by: Felix Fontein <[email protected]>

---------

Co-authored-by: Felix Fontein <[email protected]>
(cherry picked from commit 7721420)
@felixfontein
Copy link
Collaborator

@munahaf thanks a lot for your contribution!

felixfontein pushed a commit that referenced this pull request Aug 23, 2023
…n the length of a Collection (#7146)

Fix inappropriate comparison on the length of a Collection (#7125)

* Comment: Fixed inappropriate comparison on the length of a Collection. Added changlelog fragment file.

* Comment: Updated the scope of the changelog fragment based on feedback.

Co-authored-by: Felix Fontein <[email protected]>

---------

Co-authored-by: Felix Fontein <[email protected]>
(cherry picked from commit 7721420)

Co-authored-by: Munawar <[email protected]>
felixfontein pushed a commit that referenced this pull request Aug 23, 2023
…n the length of a Collection (#7147)

Fix inappropriate comparison on the length of a Collection (#7125)

* Comment: Fixed inappropriate comparison on the length of a Collection. Added changlelog fragment file.

* Comment: Updated the scope of the changelog fragment based on feedback.

Co-authored-by: Felix Fontein <[email protected]>

---------

Co-authored-by: Felix Fontein <[email protected]>
(cherry picked from commit 7721420)

Co-authored-by: Munawar <[email protected]>
etrombly pushed a commit to etrombly/community.general that referenced this pull request Oct 25, 2023
…ollections#7125)

* Comment: Fixed inappropriate comparison on the length of a Collection. Added changlelog fragment file.

* Comment: Updated the scope of the changelog fragment based on feedback.

Co-authored-by: Felix Fontein <[email protected]>

---------

Co-authored-by: Felix Fontein <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
cloud module_utils module_utils new_contributor Help guide this first time contributor plugins plugin (any type)
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants