From 385923f0818be44107322ac1c36ee2663c2c1468 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 18 Sep 2026 16:57:50 +0900 Subject: [PATCH 1/4] test(queue-health): reproduce non-canonical repository identities --- ...ctions_queue_health_repository_identity.py | 38 +++++++++++++++++++ 1 file changed, 38 insertions(+) create mode 100644 tests/test_actions_queue_health_repository_identity.py diff --git a/tests/test_actions_queue_health_repository_identity.py b/tests/test_actions_queue_health_repository_identity.py new file mode 100644 index 0000000000..3039e44e54 --- /dev/null +++ b/tests/test_actions_queue_health_repository_identity.py @@ -0,0 +1,38 @@ +"""Regression coverage for queue-health repository identity admission.""" + +import importlib.util +import json +from pathlib import Path + +import pytest + + +ROOT = Path(__file__).resolve().parents[1] +MODULE_PATH = ROOT / "scripts/ci/actions_queue_health_core.py" +SPEC = importlib.util.spec_from_file_location("actions_queue_health_core_identity", MODULE_PATH) +assert SPEC and SPEC.loader +queue_health = importlib.util.module_from_spec(SPEC) +SPEC.loader.exec_module(queue_health) + + +@pytest.mark.parametrize( + "repository", + [ + "ContextualWisdomLab/repository.", + "ContextualWisdomLab/repo..name", + "ContextualWisdomLab/..", + "ContextualWisdomLab/.", + ], +) +def test_load_allowlist_rejects_noncanonical_repository_identity( + tmp_path: Path, repository: str +) -> None: + """Reject non-canonical repository components through the production allowlist path.""" + allowlist = tmp_path / "repositories.json" + allowlist.write_text( + json.dumps({"repositories": [repository]}), + encoding="utf-8", + ) + + with pytest.raises(queue_health.QueueHealthError, match="invalid repository identifier"): + queue_health.load_allowlist(allowlist) From d43c83554581b548003f8a824e54207193e5397f Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 18 Sep 2026 17:52:17 +0900 Subject: [PATCH 2/4] test(queue-health): cover owner identity drift --- tests/test_actions_queue_health_repository_identity.py | 2 ++ 1 file changed, 2 insertions(+) diff --git a/tests/test_actions_queue_health_repository_identity.py b/tests/test_actions_queue_health_repository_identity.py index 3039e44e54..139fcaf55e 100644 --- a/tests/test_actions_queue_health_repository_identity.py +++ b/tests/test_actions_queue_health_repository_identity.py @@ -20,6 +20,8 @@ [ "ContextualWisdomLab/repository.", "ContextualWisdomLab/repo..name", + "ContextualWisdomLab./repository", + "Contextual..WisdomLab/repository", "ContextualWisdomLab/..", "ContextualWisdomLab/.", ], From c754daf771187868bc4273669c44de8ba0a9f10b Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 18 Sep 2026 18:09:21 +0900 Subject: [PATCH 3/4] test(queue-health): preserve canonical repository names --- ...ctions_queue_health_repository_identity.py | 22 +++++++++++++++++++ 1 file changed, 22 insertions(+) diff --git a/tests/test_actions_queue_health_repository_identity.py b/tests/test_actions_queue_health_repository_identity.py index 139fcaf55e..e2d53f3575 100644 --- a/tests/test_actions_queue_health_repository_identity.py +++ b/tests/test_actions_queue_health_repository_identity.py @@ -38,3 +38,25 @@ def test_load_allowlist_rejects_noncanonical_repository_identity( with pytest.raises(queue_health.QueueHealthError, match="invalid repository identifier"): queue_health.load_allowlist(allowlist) + + +@pytest.mark.parametrize( + "repository", + [ + "ContextualWisdomLab/.github", + "ContextualWisdomLab/repository.name", + "ContextualWisdomLab/repository_name", + "ContextualWisdomLab/repository-name", + ], +) +def test_load_allowlist_preserves_canonical_repository_identity( + tmp_path: Path, repository: str +) -> None: + """Keep valid dot-prefixed and punctuation-bearing repository names admissible.""" + allowlist = tmp_path / "repositories.json" + allowlist.write_text( + json.dumps({"repositories": [repository]}), + encoding="utf-8", + ) + + assert queue_health.load_allowlist(allowlist) == [repository] From 142e5b2617778e79f665693be1e6f8c04d7533aa Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 18 Sep 2026 22:46:28 +0900 Subject: [PATCH 4/4] fix(queue-health): reject non-canonical repository identities --- scripts/ci/actions_queue_health_core.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/scripts/ci/actions_queue_health_core.py b/scripts/ci/actions_queue_health_core.py index db3e5570ba..04ded2acc1 100644 --- a/scripts/ci/actions_queue_health_core.py +++ b/scripts/ci/actions_queue_health_core.py @@ -60,7 +60,7 @@ def _repository_name(value: Any) -> str: """Validate and return one owner/repository identifier.""" if not isinstance(value, str) or not REPOSITORY_PATTERN.fullmatch(value): raise QueueHealthError(f"invalid repository identifier: {value!r}") - if any(segment in {".", ".."} for segment in value.split("/")): + if any(".." in segment or segment.endswith(".") for segment in value.split("/")): raise QueueHealthError(f"invalid repository identifier: {value!r}") return value