docs(cookbook): engine-verified path idioms — membership, at-least-one, and the traps
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức phù hợp với người mới
- 48/100
- Loại issue
- Tài liệu
- Độ rõ ràng
- Khá rõ ràng
- Mức độ hoạt động
- Sôi nổi
- Công nghệ
- kubernetes, python, terraform
- Lĩnh vực
- documentation
Hướng nghiên cứu
Bắt đầu bằng cách xác định tài liệu cookbook và các entry point để xác minh engine đang chạy, sau đó so sánh từng recipe giữa engine json/kubernetes dùng chung và terraform_plan. Dùng eval_expression cho hành vi của guard và giữ nguyên các edge case được liệt kê, các giới hạn của engine và cách xử lý kiểu; trang hoàn thiện phải gắn nhãn cho từng idiom cùng với các engine hỗ trợ nó. Giữ traceback của utils.sort_collections như một bug riêng.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
A cookbook page of zero-code recipes, each verified against the running engine. House rule: every
path idiom names which of the two path engines it holds for — the shared json/kubernetes engine
and terraform_plan disagree more often than they agree, and "true idiom, wrong engine" fails
silently.
- Collection membership: drop the trailing
.*and the provider emits the whole collection as
one value per resource;Containswith an element dict is membership. Limit: exact element
equality (fails where elements carry extra keys, e.g.aws_db_parameter_group.parameterwith
apply_method). - At-least-one via
guard && !none:!idis existential ineval_expression, so De Morgan
applies — anIsNotEmptyguard on the collection, aNot*condition on
<collection>.*.<field>, andeval_expression: "guard && !none". Verified across matching /
non-matching / empty-array / absent-key / empty-document cases. The guard is load-bearing:
without it an absent collection satisfies the negation vacuously. Caveat, measured: on
terraform_planthis is plan-wide, not per-resource (the provider flattens instances into one
stream — two resources where only one matches returnstrue); sound for single-instance json
documents and genuinely plan-wide intent only. It cannot bind two attributes of the same element,
and the negated condition cannot be a regex. - Scalar-or-list: a trailing
.*unwraps a scalar on the shared json/kubernetes engine, so one
path covers a scalar-or-list union (Statement.*.Action.*). It does not hold on
terraform_plan, where a scalar under.*is a severity-2 miss. *iterates dict values, so CloudFormation'sResourcesmap addresses exactly like ARM's
array.- An empty list pads
Noneat inner wildcard levels; only the outermost segment is a severity-2
miss — this decideserror_tolerancefor nested-block-inside-repeated-block checks. - When every id is deleted from the AST the result is
null, nottrue— the trap for
all-absence policies, whose compliant case is exactly "every path misses". - The type-guard idiom is polarity-specific: type present + attribute absent FAILS at every inner
tolerance, so omit the guard when upstream passes on absence; use!selected || checkfor
sibling-attribute scoping. nullable.TypeNullableBoolprovider arguments arrive in the plan as the strings
"true"/"false", soEquals: truesilently never fires — useContainedIn: [true, "true"].
Related bug, fileable separately: a mixed-type list in ContainedIn/Equals evaluates correctly
but logs a full traceback from utils.sort_collections — cosmetic, noisy, ~2-line fix.
- Ngôn ngữ chính
- Python
- Star
- 167
- Fork
- 47
- Merge trung bình
- 2 ngày 9 giờ
- Pull request đã merge (30 ngày)
- 12
Chuẩn bị môi trường
Khởi chạy dev container của dự án ngay trên trình duyệt, bằng tài khoản GitHub của bạn.
- Không có Dockerfile hay tệp Docker Compose
- Có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của StackGuardian/tirith
-
good first issue hacktoberfest tests
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
StackGuardian/tirith#381 · 2 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
research
Độ khó 1/5 1-3 giờ Mức phù hợp với người mới 78/100
StackGuardian/tirith#356 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
documentation
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
StackGuardian/tirith#302 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
enhancement
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 74/100
StackGuardian/tirith#299 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
fix(providers): dotted keys are addressable from terraform_plan but not from json/kubernetesĐang mởbug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
StackGuardian/tirith#295 ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của StackGuardian/tirith
Issue tương tự
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 83/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 86/100
FuRongJun-1999/dsh-memory#65 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
ci needs-ac
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
Ikalus1988/MisakaNet#2930 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
`FakeBackendV2.run` fails with `NoiseError` on circuits with delays on qubits where T2 > 2·T1Đang mởbug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
Qiskit/qiskit-aer#2466 ·
-
area/cli
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100