Skip to content

refactor(ci): swap uuid for getrandom in the GHA heredoc delimiter#1446

Open
jd wants to merge 1 commit into
devs/jd/worktree-rust-port/drop-indexmap-group-scope-returns-vec-k-v--7085cf29from
devs/jd/worktree-rust-port/swap-uuid-getrandom-gha-heredoc-delimiter--b6599e9b
Open

refactor(ci): swap uuid for getrandom in the GHA heredoc delimiter#1446
jd wants to merge 1 commit into
devs/jd/worktree-rust-port/drop-indexmap-group-scope-returns-vec-k-v--7085cf29from
devs/jd/worktree-rust-port/swap-uuid-getrandom-gha-heredoc-delimiter--b6599e9b

Conversation

@jd
Copy link
Copy Markdown
Member

@jd jd commented May 19, 2026

ci queue-info::write_github_output formatted a unique
ghadelimiter_<uuid-v4> to guard against a metadata payload that
happens to contain its own heredoc delimiter. The actual contract
is "32 unpredictable hex chars", not "a UUID per RFC 4122" — the
delimiter is never parsed by anyone, only matched as a string.

Pull 16 random bytes straight from getrandom::fill and hex-encode
them. Drops uuid from the direct deps (it stays unreferenced and
disappears from Cargo.lock), with getrandom taking its place —
which uuid was already pulling in transitively, so the net add
is zero new code shipped to the binary.

The local helper is six lines. Same blast radius for a
maintainer-attack story, smaller surface to read.

Co-Authored-By: Claude Opus 4.7 noreply@anthropic.com

Depends-On: #1445

@jd
Copy link
Copy Markdown
Member Author

jd commented May 19, 2026

This pull request is part of a Mergify stack:

# Pull Request Link
1 test(freeze): add live smoke test for freeze create/update/delete #1436
2 feat(rust): port freeze create/update/delete to native Rust #1437
3 refactor(rust): dedupe emit-helper boilerplate across command crates #1438
4 refactor(rust): share test scaffolding via mergify-test-support crate #1439
5 refactor(core): introduce CommandContext for the queue+freeze prelude #1441
6 refactor(ci): consolidate the CI-env scrubber into a shared testing module #1442
7 refactor: drop stale Phase X.Y doc markers and one inline color branch #1443
8 refactor(tui): share StyledGlyph across queue show/status renderers #1444
9 refactor(queue): drop indexmap, group_by_scope returns a Vec<(K, V)> #1445
10 refactor(ci): swap uuid for getrandom in the GHA heredoc delimiter #1446 👈
11 refactor(config): standardize the workspace on serde_yaml_ng for YAML parsing #1447

@mergify
Copy link
Copy Markdown
Contributor

mergify Bot commented May 19, 2026

Merge Protections

Your pull request matches the following merge protections and will not be merged until they are valid.

🔴 ⛓️ Depends-On Requirements

Waiting for

This rule is failing.

Requirement based on the presence of Depends-On in the body of the pull request

🔴 👀 Review Requirements

Waiting for

  • #approved-reviews-by>=2
This rule is failing.
  • any of:
    • #approved-reviews-by>=2
    • author = dependabot[bot]
    • author = mergify-ci-bot
    • author = renovate[bot]

🔴 🔎 Reviews

Waiting for

  • #review-requested = 0
This rule is failing.
  • #review-requested = 0
  • #changes-requested-reviews-by = 0
  • #review-threads-unresolved = 0

🟢 🤖 Continuous Integration

Wonderful, this rule succeeded.
  • all of:
    • check-success=ci-gate

🟢 Enforce conventional commit

Wonderful, this rule succeeded.

Make sure that we follow https://www.conventionalcommits.org/en/v1.0.0/

  • title ~= ^(fix|feat|docs|style|refactor|perf|test|build|ci|chore|revert|ui)(?:\(.+\))?:

🟢 📕 PR description

Wonderful, this rule succeeded.
  • body ~= (?ms:.{48,})

@mergify mergify Bot requested a review from a team May 19, 2026 15:32
@jd jd marked this pull request as ready for review May 20, 2026 07:26
sileht
sileht previously approved these changes May 20, 2026
@mergify mergify Bot requested a review from a team May 20, 2026 07:42
@jd jd force-pushed the devs/jd/worktree-rust-port/swap-uuid-getrandom-gha-heredoc-delimiter--b6599e9b branch from 2cd6b4f to 5cd88c9 Compare May 20, 2026 08:42
@jd jd force-pushed the devs/jd/worktree-rust-port/drop-indexmap-group-scope-returns-vec-k-v--7085cf29 branch from e31730b to 57559b2 Compare May 20, 2026 08:42
@jd jd temporarily deployed to func-tests-live May 20, 2026 08:42 — with GitHub Actions Inactive
@jd jd temporarily deployed to func-tests-live May 20, 2026 08:42 — with GitHub Actions Inactive
@jd
Copy link
Copy Markdown
Member Author

jd commented May 20, 2026

Revision history

# Type Changes Reason Date
1 initial 2cd6b4f 2026-05-20 08:42 UTC
2 rebase 2cd6b4f → 5cd88c9 (rebase only) 2026-05-20 08:42 UTC
3 rebase 5cd88c9 → 8468caf (rebase only) 2026-05-20 09:05 UTC
4 rebase 8468caf → 73811d4 (rebase only) 2026-05-21 07:25 UTC
5 rebase 73811d4 → d61afc0 (rebase only) 2026-05-21 07:56 UTC
6 rebase d61afc0 → 637e6a8 (rebase only) 2026-05-21 12:39 UTC

@mergify mergify Bot dismissed sileht’s stale review May 20, 2026 08:43

Pull request has been modified.

@mergify mergify Bot had a problem deploying to Mergify Merge Protections May 20, 2026 08:43 Failure
@jd jd force-pushed the devs/jd/worktree-rust-port/swap-uuid-getrandom-gha-heredoc-delimiter--b6599e9b branch from 5cd88c9 to 8468caf Compare May 20, 2026 09:05
@jd jd temporarily deployed to func-tests-live May 20, 2026 09:05 — with GitHub Actions Inactive
@mergify mergify Bot had a problem deploying to Mergify Merge Protections May 20, 2026 09:06 Failure
@jd jd force-pushed the devs/jd/worktree-rust-port/drop-indexmap-group-scope-returns-vec-k-v--7085cf29 branch from 1d374a9 to a5fc066 Compare May 21, 2026 07:24
@jd jd force-pushed the devs/jd/worktree-rust-port/swap-uuid-getrandom-gha-heredoc-delimiter--b6599e9b branch from 8468caf to 73811d4 Compare May 21, 2026 07:24
@jd jd temporarily deployed to func-tests-live May 21, 2026 07:25 — with GitHub Actions Inactive
@jd jd temporarily deployed to func-tests-live May 21, 2026 07:25 — with GitHub Actions Inactive
@mergify mergify Bot had a problem deploying to Mergify Merge Protections May 21, 2026 07:25 Failure
@jd jd force-pushed the devs/jd/worktree-rust-port/swap-uuid-getrandom-gha-heredoc-delimiter--b6599e9b branch from 73811d4 to d61afc0 Compare May 21, 2026 07:55
@jd jd force-pushed the devs/jd/worktree-rust-port/drop-indexmap-group-scope-returns-vec-k-v--7085cf29 branch from a5fc066 to a6e2beb Compare May 21, 2026 07:56
@jd jd temporarily deployed to func-tests-live May 21, 2026 07:56 — with GitHub Actions Inactive
@jd jd temporarily deployed to func-tests-live May 21, 2026 07:56 — with GitHub Actions Inactive
@mergify mergify Bot had a problem deploying to Mergify Merge Protections May 21, 2026 07:56 Failure
`ci queue-info::write_github_output` formatted a unique
`ghadelimiter_<uuid-v4>` to guard against a metadata payload that
happens to contain its own heredoc delimiter. The actual contract
is "32 unpredictable hex chars", not "a UUID per RFC 4122" — the
delimiter is never parsed by anyone, only matched as a string.

Pull 16 random bytes straight from `getrandom::fill` and hex-encode
them. Drops `uuid` from the direct deps (it stays unreferenced and
disappears from `Cargo.lock`), with `getrandom` taking its place —
which `uuid` was already pulling in transitively, so the net add
is zero new code shipped to the binary.

The local helper is six lines. Same blast radius for a
maintainer-attack story, smaller surface to read.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Change-Id: Ib6599e9b6fca49281186b726a63e4641fa32596e
@jd jd force-pushed the devs/jd/worktree-rust-port/drop-indexmap-group-scope-returns-vec-k-v--7085cf29 branch from a6e2beb to c99237a Compare May 21, 2026 12:39
@jd jd force-pushed the devs/jd/worktree-rust-port/swap-uuid-getrandom-gha-heredoc-delimiter--b6599e9b branch from d61afc0 to 637e6a8 Compare May 21, 2026 12:39
@jd jd temporarily deployed to func-tests-live May 21, 2026 12:39 — with GitHub Actions Inactive
@mergify mergify Bot had a problem deploying to Mergify Merge Protections May 21, 2026 12:40 Failure
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants