create_or_update_file writes to the wrong file when the path contains # or ?
Los mantenedores suelen responder en 4 días
Evaluación
- Dificultad
- 2/5
- Tiempo estimado
- 1-3 horas
- Aptitud para principiantes
- 84/100
Línea de trabajo
Empieza en pkg/github/repositories.go en CreateOrUpdateFile (v1.14.0 / 71ef8266), donde la llamada a CreateFile pasa path sin escapar, y lee escapeGitTreeish como el patrón existente para el escapado por segmento. Compara con las comprobaciones de existencia y symlink basadas en GetContents, que ya escapan correctamente. El resultado se ve como PUT /repos/{owner}/{repo}/contents/docs/C%23/intro.md en un servidor simulado, más una prueba de regresión (amplía el archivo de pruebas de repositories existente) que verifique que las rutas # y ? se escriben en el archivo correcto.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Describe the bug
create_or_update_file with path: "docs/C#/intro.md" commits the content to a file named docs/C and reports success. A ? does the same (notes/what?.md is written as notes/what).
The path goes into the request URL unescaped: go-github's RepositoriesService.CreateFile builds repos/{owner}/{repo}/contents/{path} with no escaping, so everything from # on becomes a URL fragment and everything from ? on becomes a query string. The checks that run first (the existing-file / SHA lookup and the symlink check) go through GetContents, which does escape the path, so they look at the right file while the write goes to another.
Affected version
v1.14.0 and main at 71ef8266 (pkg/github/repositories.go, the CreateFile call in CreateOrUpdateFile).
Steps to reproduce the behavior
- Call
create_or_update_fileon a test repository:{"owner":"<you>","repo":"<test repo>","path":"docs/C#/intro.md","content":"# Intro","message":"Add intro","branch":"main"} - Look at the commit.
Expected vs actual behavior
Expected: a file at docs/C#/intro.md (the request goes to PUT /repos/<you>/<test repo>/contents/docs/C%23/intro.md).
Actual: the request goes to PUT /repos/<you>/<test repo>/contents/docs/C, the commit creates a file named docs/C, and the tool result reports success with "path": "docs/C". If docs/C already exists as a file, it is overwritten.
Logs
Request seen by a mock server for the call above:
GET /repos/owner/repo/contents/docs/C%23/intro.md -> 404 (existence check, escaped)
PUT /repos/owner/repo/contents/docs/C (the write, unescaped)
I have a small fix with a regression test ready and can open a PR: escape each path segment before calling CreateFile, the same way escapeGitTreeish already does for tree lookups.
- Lenguaje dominante
- Go
- Estrellas
- 33.4k
- Forks
- 5.1k
- Merge medio
- 3 d 1 h
- PR fusionados (30 d)
- 35
Preparar el entorno
- Incluye un Dockerfile o un archivo de Docker Compose
- Tiene una plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de github/github-mcp-server
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 76/100
github/github-mcp-server#3450 ·
Los mantenedores suelen responder en 4 días
-
request ai review
Dificultad 2/5 1-3 horas Aptitud para principiantes 74/100
github/github-mcp-server#3439 ·
Los mantenedores suelen responder en 4 días
-
get_job_logs with failed_only misses failed jobs after the first 30 jobs of a runPosiblemente ocupada @jayhemnani9910 la tomó hace 4 días. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 74/100
github/github-mcp-server#3428 ·
Los mantenedores suelen responder en 4 días
-
pull_request_read drops merge_commit_shaPosiblemente ocupada @thejdubb02 la tomó hace 32 días. Abiertobug
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
github/github-mcp-server#3235 · 1 comentario ·
Los mantenedores suelen responder en 4 días
-
Add guidance on GitHub autolinked reference formatting for AI agentsQuizá libre de nuevo Un pull request para esta issue se cerró sin fusionarse. Abiertoenhancement
Dificultad 1/5 Menos de una hora Aptitud para principiantes 88/100
github/github-mcp-server#3042 · 2 comentarios ·
Los mantenedores suelen responder en 4 días
Todos los issues de github/github-mcp-server
Issues similares
-
bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
open-telemetry/opentelemetry-go-compile-instrumentation#1467 ·
Los mantenedores suelen responder en 3 días
-
Python 3.15 supportPosiblemente ocupada @amnesiaof la tomó hoy. AbiertoL: python L: python:uv
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
dependabot/dependabot-core#16524 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
Los mantenedores suelen responder en 1 día
-
duplication
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
openvibely/openvibely#1443 ·
Los mantenedores suelen responder en 2 días
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 60/100
canonical/service-mesh#845 ·
Los mantenedores suelen responder en 1 día