Skip to content

[bug] Keep direct WorkloadSpec operator validation fail-closed #504

Description

@Anionix

Trigger

Merged PR #501 review thread: #501 (comment)

Merged head: 63140f9ac77cb4732819c44d865f421ea310fce5
Merge commit: 6804f19bcbb69c006374005b14e18c1b6fab5f52

Expected

WorkloadSpec.validate() rejects every filter operator outside the supported ComparisonOperator set, including specs constructed directly rather than through from_mapping().

Actual

The typed field narrows normal callers, but runtime callers can still construct WorkloadSpec(..., operator="contains"). validate() now checks only operator is None, allowing the invalid spec to reach _predicate() and fail later with KeyError.

Impact

The runtime contract is bypassable at a public direct-construction boundary, producing a late implementation error instead of a clear validation error.

Acceptance

  • Centralize supported-operator membership without widening the public Literal type.
  • Keep from_mapping() and direct validate() fail-closed.
  • Add a direct-construction regression test.
  • Reply to and resolve the source review thread after verified merge.

Lifecycle

DISCOVERED -> ENCODED -> ROUNDTRIP_VERIFIED -> BENCHMARKED -> REPORTED; invalid predicates must fail during ENCODED boundary validation.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions