You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Detect falsy true arms in actions pseudo-ternaries - #2085
Mandatory: This PR corresponds to an issue (if not, please create
one first).
Having read the AI policy, I hereby disclose the use of an LLM or other
AI coding assistant in the creation of this PR. PRs will not be rejected
for using AI tools, but will be rejected for undisclosed use or
use that violates the policy.
If a checkbox is not applicable, you can leave it unchecked.
This diff adds an obfuscation audit check for GitHub Actions expressions that use the common condition && value || fallback pseudo-ternary pattern when value statically evaluates as falsy. In those cases, GitHub Actions short-circuit semantics return the fallback even when the condition is true, so expressions like foo && '' || 'bar' do not behave like ternaries.
The check reports the falsy true arm directly and handles chained || expressions so later pseudo-ternaries are not missed. It covers falsy constants such as empty strings, 0, false, null, and constant-foldable falsy expressions, while avoiding fine forms like !condition && 'value' || '' and non-falsy true arms.
n.b. This does not add an auto-fix yet. A reasonable follow-up would be to rewrite eligible patterns to the official case(...) form, for example converting condition && true_value || fallback into case(condition, true_value, fallback). I'm open to getting this in here, but it may make the diff larger than ideal 🤔
Thanks for opening this @terror. I'm curious what you think about doing this in a new audit (something like unsound-ternary?) -- it's arguably not obfuscation per se, but an expression footgun like the other unsound-* audits.
Thanks for opening this @terror. I'm curious what you think about doing this in a new audit (something like unsound-ternary?) -- it's arguably not obfuscation per se, but an expression footgun like the other unsound-* audits.
I think that makes sense! I put it under obfuscation mostly because of the earlier issue discussion and because the existing audit already walks fenced expressions, but I agree that this is less about obfuscation and more about confusing semantics.
I'll look to scope this into a new unsound-ternary audit.
The reason will be displayed to describe this comment to others. Learn more.
Thanks for working on this @terror! I did a quick skim of the docs, just a few small nitpicks. I'll do a full review of the audit's logic tomorrow as well.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Pre-submission checks
Please check these boxes:
one first).
AI coding assistant in the creation of this PR. PRs will not be rejected
for using AI tools, but will be rejected for undisclosed use or
use that violates the policy.
If a checkbox is not applicable, you can leave it unchecked.
Summary
Resolves #746
This diff adds an
obfuscationaudit check for GitHub Actions expressions that use the commoncondition && value || fallbackpseudo-ternary pattern whenvaluestatically evaluates as falsy. In those cases, GitHub Actions short-circuit semantics return the fallback even when the condition is true, so expressions likefoo && '' || 'bar'do not behave like ternaries.The check reports the falsy true arm directly and handles chained
||expressions so later pseudo-ternaries are not missed. It covers falsy constants such as empty strings,0,false,null, and constant-foldable falsy expressions, while avoiding fine forms like!condition && 'value' || ''and non-falsy true arms.n.b. This does not add an auto-fix yet. A reasonable follow-up would be to rewrite eligible patterns to the official
case(...)form, for example convertingcondition && true_value || fallbackintocase(condition, true_value, fallback). I'm open to getting this in here, but it may make the diff larger than ideal 🤔Test Plan
cargo test -p zizmor