`wrap` layer expansion can loop forever when the core content contains `{CORE_TEMPLATE}`
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 84/100
- Issue type
- Bug
- Clarity
- Clearly specified
- Activity status
- Active
- Tech stack
- bash
- Domain
- tooling
Research direction
Start at scripts/bash/common.sh:606 and inspect the wrap strategy's placeholder-expansion loop. Exercise a wrap layer whose core content contains the literal {CORE_TEMPLATE}, then confirm expansion terminates while replacing each layer placeholder and preserving the surrounding content.
Written by the indexing model from the issue text.
Description
Affected: scripts/bash/common.sh:606, confirmed present at tag v0.11.9
(fetched from raw.githubusercontent.com/github/spec-kit/v0.11.9/scripts/bash/common.sh).
The wrap strategy substitutes the core content into the layer at each {CORE_TEMPLATE}
placeholder:
case "$layer_content" in
*'{CORE_TEMPLATE}'*) ;;
*) echo "Error: wrap strategy missing {CORE_TEMPLATE} placeholder" >&2; return 1 ;;
esac
while [[ "$layer_content" == *'{CORE_TEMPLATE}'* ]]; do
local before="${layer_content%%\{CORE_TEMPLATE\}*}"
local after="${layer_content#*\{CORE_TEMPLATE\}}"
layer_content="${before}${content}${after}"
done
The loop condition re-tests the string it just substituted into. If $content itself
contains the literal {CORE_TEMPLATE}, every iteration reintroduces the placeholder, the
condition never goes false, and layer_content grows by ${#content} each pass — an
unbounded loop that ends in memory exhaustion rather than an error message.
The guard above it does not cover this: it rejects a layer that is missing the
placeholder, and says nothing about the content being substituted in.
Suggested fix — scan left to right and never re-scan what was already substituted, which
also preserves the multi-placeholder behaviour the loop exists for:
out=""; rest="$layer_content"
while [[ "$rest" == *'{CORE_TEMPLATE}'* ]]; do
out="${out}${rest%%\{CORE_TEMPLATE\}*}${content}"
rest="${rest#*\{CORE_TEMPLATE\}}"
done
layer_content="${out}${rest}"
Reachability / why we are reporting rather than patching. Found while adopting a
Spec Kit-based plugin in a downstream repo. It is not reachable through that plugin: it
ships nothing that declares {CORE_TEMPLATE}, so $content never carries the placeholder
on that path (grep -rl CORE_TEMPLATE over the plugin returns nothing). It is reachable for
any consumer that authors a wrap template layer whose core content includes the literal
token — which is a normal thing to do by accident when a template documents its own
placeholder syntax.
- Dominant language
- Python
- Stars
- 138k
- Forks
- 12.4k
- Avg merge
- 3d 6h
- Merged PRs (30d)
- 145
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from github/spec-kit
-
enhancement needs-triage
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
-
enhancement needs-triage
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
-
enhancement needs-triage
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
-
enhancement needs-triage triage-can-wait
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
-
triage-can-wait
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
Similar issues
-
enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
canonical/paas-charm#368 · 1 comment ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
-
tech debt
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
-
Difficulty 1/5 Under an hour Newbie friendliness 90/100
StevenBlack/hosts#3256 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 90/100
qualcomm/qai-appbuilder#275 ·