Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

docs(cookbook): engine-verified path idioms — membership, at-least-one, and the traps

Đang mở
#324 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 1 ngày

Chưa có ai nhận issue này.

Đánh giá

Độ khó
4/5
Thời gian dự kiến
3-5 ngày
Mức phù hợp với người mới
48/100
Loại issue
Tài liệu
Độ rõ ràng
Khá rõ ràng
Mức độ hoạt động
Sôi nổi
Công nghệ
kubernetes, python, terraform
Lĩnh vực
documentation

Hướng nghiên cứu

Bắt đầu bằng cách xác định tài liệu cookbook và các entry point để xác minh engine đang chạy, sau đó so sánh từng recipe giữa engine json/kubernetes dùng chung và terraform_plan. Dùng eval_expression cho hành vi của guard và giữ nguyên các edge case được liệt kê, các giới hạn của engine và cách xử lý kiểu; trang hoàn thiện phải gắn nhãn cho từng idiom cùng với các engine hỗ trợ nó. Giữ traceback của utils.sort_collections như một bug riêng.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

documentation

A cookbook page of zero-code recipes, each verified against the running engine. House rule: every
path idiom names which of the two path engines it holds for
— the shared json/kubernetes engine
and terraform_plan disagree more often than they agree, and "true idiom, wrong engine" fails
silently.

  • Collection membership: drop the trailing .* and the provider emits the whole collection as
    one value per resource; Contains with an element dict is membership. Limit: exact element
    equality (fails where elements carry extra keys, e.g. aws_db_parameter_group.parameter with
    apply_method).
  • At-least-one via guard && !none: !id is existential in eval_expression, so De Morgan
    applies — an IsNotEmpty guard on the collection, a Not* condition on
    <collection>.*.<field>, and eval_expression: "guard && !none". Verified across matching /
    non-matching / empty-array / absent-key / empty-document cases. The guard is load-bearing:
    without it an absent collection satisfies the negation vacuously. Caveat, measured: on
    terraform_plan this is plan-wide, not per-resource (the provider flattens instances into one
    stream — two resources where only one matches returns true); sound for single-instance json
    documents and genuinely plan-wide intent only. It cannot bind two attributes of the same element,
    and the negated condition cannot be a regex.
  • Scalar-or-list: a trailing .* unwraps a scalar on the shared json/kubernetes engine, so one
    path covers a scalar-or-list union (Statement.*.Action.*). It does not hold on
    terraform_plan, where a scalar under .* is a severity-2 miss.
  • * iterates dict values, so CloudFormation's Resources map addresses exactly like ARM's
    array.
  • An empty list pads None at inner wildcard levels; only the outermost segment is a severity-2
    miss — this decides error_tolerance for nested-block-inside-repeated-block checks.
  • When every id is deleted from the AST the result is null, not true — the trap for
    all-absence policies, whose compliant case is exactly "every path misses".
  • The type-guard idiom is polarity-specific: type present + attribute absent FAILS at every inner
    tolerance, so omit the guard when upstream passes on absence; use !selected || check for
    sibling-attribute scoping.
  • nullable.TypeNullableBool provider arguments arrive in the plan as the strings
    "true"/"false", so Equals: true silently never fires — use ContainedIn: [true, "true"].

Related bug, fileable separately: a mixed-type list in ContainedIn/Equals evaluates correctly
but logs a full traceback from utils.sort_collections — cosmetic, noisy, ~2-line fix.

Ngôn ngữ chính
Python
Star
167
Fork
47
Merge trung bình
2 ngày 9 giờ
Pull request đã merge (30 ngày)
12

Chuẩn bị môi trường

Mở trong Codespaces

Khởi chạy dev container của dự án ngay trên trình duyệt, bằng tài khoản GitHub của bạn.

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của StackGuardian/tirith

Tất cả issue của StackGuardian/tirith

Issue tương tự

Thêm issue về Python

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.