Repository navigation
fix(check): refuse an operator inside an XPath function argument (MDL091) - #1012
Merged
Merged
Conversation
…091) `retrieve … where starts-with(Name, 'MS-' + $Key)` passed `check --references` and `exec`, then failed mx check with CE0161 "Error(s) in XPath constraint." (mendixlabs#1326). MDL091 only matched expression-only function names in the rendered XPath string; it never looked at what a function's arguments are. Walk the retrieve constraint's AST and flag a function argument that is itself a `+` or `-` operation. MDL091 is exec-enforced, so exec now refuses it as well. Measured on mxbuild 11.14.0 with the check stubbed out to force the fault in: starts-with(Name, 'MS-' + $Key) CE0161 not(contains(Name, $Key + $Key)) CE0161 contains(Name, $Key - 'a') CE0161 Name = 'X-' + $Key 0 errors year-from-dateTime(Due) = $N - 1 0 errors starts-with(Name, $P) 0 errors `*`, `div` and `mod` are not flagged: their only possible argument is numeric, and `contains(Name, $N)` is CE0161 with no operator, so no measurement isolates the operator. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015mwKd8LDw9MRoZ8uBbbnAg
…on-argument-operator
…on-argument-operator
…on-argument-operator
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes mendixlabs#1326.
Symptom (verbatim from the issue)
…and mx check then reports CE0161 "Error(s) in XPath constraint."
Cause
MDL091 only matched expression-only function names (
startsWith,endsWith,getKey) by regex over the rendered XPath string. It never looked at what a function's arguments are.Fix
mdl/executor/validate_microflow.go: walk the retrieve constraint's AST and flag a function argument that is itself a+or-operation, after unwrapping parentheses and theSourceExprwrapper. MDL091 is exec-enforced, soexecnow refuses it too. The suggestion tells the user to compute the value into a variable first.The bracketed
[…]form needed no change: its grammar already refuses an operator in a function argument as a parse error.Evidence
Tests
TestValidateMicroflow_XPathFunctionArgumentOperator: 10 shapes, both flagged and clean.TestCheckExecAgree_RetrieveConstraintFunctionArgumentOperator:check -pandexecboth refuse the bad form, and both accept the two shapes the issue reports as clean.Control. With
checkXPathFunctionArgumentOperatorsstubbed out, both tests fail with the reported symptom:mxbuild 11.14.0, both variants. I wrote the faulty constraints with a build that had the check stubbed out, then ran
mxcli docker checkon that project and on a control project:starts-with(Name, 'MS-' + $Key)not(contains(Name, $Key + $Key))contains(Name, $Key - 'a')Name = 'X-' + $Keyyear-from-dateTime(Due) = $N - 1starts-with(Name, $P)The fixed binary refuses the bad script: "Refusing to execute: 2 error(s) above. Nothing was written."
Not flagged on purpose:
*,div,mod. Their only possible argument is a number, and the controlcontains(Name, $N)with an Integer$Nis already CE0161 with no operator at all. No measurement isolates the operator, and because MDL091 blocksexec, I left out anything not shown to fail.Also in this PR
mdl-examples/bug-tests/1326-xpath-function-argument-operator.fail.mdl: the bad microflow plus two clean controls.xpath-constraintsskill.findings/mdl-executor.jsonl.Checks
make build,make test,make lint,make check-mdlandmake check-findingsall pass.🤖 Generated with Claude Code
https://claude.ai/code/session_015mwKd8LDw9MRoZ8uBbbnAg
Generated by Claude Code