Skip to content

loader: fail-closed allowlist screening on top of the unsupported-attributes check - #2

Merged
glours merged 1 commit into
glours:feat/unsupported-attributes-loader-optionfrom
ndeloof:unsupported-attributes-allowlist
Sep 8, 2026
Merged

glours merged 1 commit into
glours:feat/unsupported-attributes-loader-optionfrom
ndeloof:unsupported-attributes-allowlist

Conversation

@ndeloof

@ndeloof ndeloof commented Sep 8, 2026

Copy link
Copy Markdown

Layered on top of compose-spec#927's API (compose-spec#927), sharing its walk and batch report — the fail-closed half from compose-spec#926:

  • Supported (or the composable WithSupportedAttributes option) declares the attribute paths the runtime implements; anything matching none of them is reported alongside the deny-pattern findings. Deny patterns keep covering the value-dependent cases (ports[].mode: host); the allowlist makes the screening exhaustive: every attribute the specification gains later stays reported until the runtime deliberately wires it in. Extension keys (x-*) and their subtrees are exempt from this rule set.
  • schema.AttributePaths derives the complete attribute-path inventory from the embedded JSON schema, so a runtime declares by subtraction: slices.DeleteFunc(slices.Clone(schema.AttributePaths()), isSwarmOnly).
  • tree.Matcher makes Path pattern-set matching a first-class API (exact Matches + MayContain for walkers). Matching is exact by design: subtree removal reports once at its root, leaf removal reports each leaf, declared siblings keep the descent open.

Combined-usage test included: one load, one report, deny predicate (mode: host) and allowlist findings together.

🤖 Generated with Claude Code

…ributes check

Deny patterns alone reproduce the problem they solve: every attribute
the specification gains later falls through silently until someone adds
a check. This layers the complementary allowlist onto
UnsupportedAttributesCheck, sharing its walk and report:

- Supported (or the composable WithSupportedAttributes option) declares
  the attribute paths the runtime implements; anything matching none of
  them is reported alongside the deny-pattern findings. Extension keys
  (x-*) and everything under them are exempt from this rule set (deny
  patterns still apply below them).

- schema.AttributePaths derives the complete attribute-path inventory
  from the embedded JSON schema (pattern-keyed mappings as '*',
  sequence items as '[]', $ref cycles terminated, '^x-' pattern
  properties excluded, since a wildcard there would blanket-accept
  every undeclared sibling). A runtime builds its declaration by
  removing what it does not implement from the full specification.

- tree.Matcher gives Path pattern sets a first-class matching API:
  exact Matches — declaring a path accepts that node only, so removing
  one leaf reliably surfaces it — plus MayContain for walkers that must
  know when a declared attribute lives deeper.

Matching stays exact by design: subtree removal reports once at its
root, leaf removal reports each leaf, and declared siblings keep the
descent open.

Signed-off-by: Nicolas De Loof <nicolas.deloof@gmail.com>
@ndeloof
ndeloof requested a review from glours as a code owner September 8, 2026 09:04
@glours
glours merged commit b3a5d86 into glours:feat/unsupported-attributes-loader-option Sep 8, 2026
@ndeloof
ndeloof deleted the unsupported-attributes-allowlist branch September 8, 2026 10:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants