Sweep the definition, not the filled values, and judge each field alike at check and composition (issue 231)
The first sweep ran at composition over the resource after settings, bindings and
machine facts were filled, so an operator's value such as ${labels:instance} was
refused as a misspelling its author never wrote, and the whole machine got nothing.
Both points now sweep the resource as the manifest wrote it, against one table of
which fields each pass fills, so the check and composition refuse the same things.
Any ${<known namespace>: its pattern does not take is refused whatever its case or key.
Issue 231's undeclared-setting half is not met here: refusing a key the module does
not declare (ADR 0164) is not built and is handed to issue 398.
This commit is contained in:
@@ -911,6 +911,15 @@ func (r Resolution) compose(with Rendering, owner map[string]string,
|
||||
return nil, err
|
||||
}
|
||||
}
|
||||
// **And every placeholder no pass fills where it stands is refused** (novox/hq issue 231):
|
||||
// judged here, over the definition as written and before any pass, by the function the
|
||||
// catalogue check runs — so a manifest registered by an older binary is judged too, and
|
||||
// what a setting or a binding later puts into a file is its software's text, never swept.
|
||||
for _, own := range m.Resources {
|
||||
if problems := unconsumedPlaceholders(m.Module, own); len(problems) > 0 {
|
||||
return nil, fmt.Errorf("%s", problems[0])
|
||||
}
|
||||
}
|
||||
|
||||
// Which of this module's files carry a secret, for the rule that a container may not read
|
||||
// one of them as its environment without saying so (ADR 0086, issue 041).
|
||||
|
||||
Reference in New Issue
Block a user