Skip to content

Detect falsy true arms in actions pseudo-ternaries - #2085

Merged
woodruffw merged 4 commits into
zizmorcore:mainfrom
terror:false-ternary
Jun 2, 2026
Merged

woodruffw merged 4 commits into
zizmorcore:mainfrom
terror:false-ternary

Conversation

@terror

@terror terror commented May 31, 2026 •

Copy link
Copy Markdown
Contributor

Pre-submission checks

Please check these boxes:

  • Mandatory: This PR corresponds to an issue (if not, please create
    one first).
  • Having read the AI policy, I hereby disclose the use of an LLM or other
    AI coding assistant in the creation of this PR. PRs will not be rejected
    for using AI tools, but will be rejected for undisclosed use or
    use that violates the policy.

If a checkbox is not applicable, you can leave it unchecked.

Summary

Resolves #746

This diff adds an obfuscation audit check for GitHub Actions expressions that use the common condition && value || fallback pseudo-ternary pattern when value statically evaluates as falsy. In those cases, GitHub Actions short-circuit semantics return the fallback even when the condition is true, so expressions like foo && '' || 'bar' do not behave like ternaries.

The check reports the falsy true arm directly and handles chained || expressions so later pseudo-ternaries are not missed. It covers falsy constants such as empty strings, 0, false, null, and constant-foldable falsy expressions, while avoiding fine forms like !condition && 'value' || '' and non-falsy true arms.

n.b. This does not add an auto-fix yet. A reasonable follow-up would be to rewrite eligible patterns to the official case(...) form, for example converting condition && true_value || fallback into
case(condition, true_value, fallback). I'm open to getting this in here, but it may make the diff larger than ideal 🤔

Test Plan

cargo test -p zizmor

@woodruffw

Copy link
Copy Markdown
Member

Thanks for opening this @terror. I'm curious what you think about doing this in a new audit (something like unsound-ternary?) -- it's arguably not obfuscation per se, but an expression footgun like the other unsound-* audits.

@woodruffw woodruffw added the enhancement New feature or request label May 31, 2026
@terror

terror commented Jun 1, 2026

Copy link
Copy Markdown
Contributor Author

Thanks for opening this @terror. I'm curious what you think about doing this in a new audit (something like unsound-ternary?) -- it's arguably not obfuscation per se, but an expression footgun like the other unsound-* audits.

I think that makes sense! I put it under obfuscation mostly because of the earlier issue discussion and because the existing audit already walks fenced expressions, but I agree that this is less about obfuscation and more about confusing semantics.

I'll look to scope this into a new unsound-ternary audit.

@woodruffw woodruffw left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for working on this @terror! I did a quick skim of the docs, just a few small nitpicks. I'll do a full review of the audit's logic tomorrow as well.

Comment thread docs/audits.md Outdated
Comment thread docs/audits.md Outdated
Comment thread docs/audits.md Outdated
@woodruffw
woodruffw enabled auto-merge (squash) June 2, 2026 21:55
@woodruffw

Copy link
Copy Markdown
Member

Thanks a ton @terror!

@woodruffw woodruffw added this to the 1.26.0 milestone Jun 2, 2026
@woodruffw
woodruffw merged commit fe59399 into zizmorcore:main Jun 2, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Feature: wrong value in ternary pattern

2 participants