fix: set PipelineURL for cached pipelines to resolve relative task paths#2416
fix: set PipelineURL for cached pipelines to resolve relative task paths#2416mathur07 merged 1 commit intotektoncd:mainfrom
Conversation
Summary of ChangesHello @mathur07, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed! This pull request addresses a bug where PipelineRuns referencing a cached remote pipeline with relative task paths would fail after the initial run. The core problem stemmed from the PipelineURL not being propagated when a pipeline was retrieved from the cache, preventing the correct resolution of relative task paths. The fix ensures that the PipelineURL is always set for cached pipelines, thereby enabling proper path resolution for all subsequent PipelineRuns and improving the reliability of remote pipeline execution. Highlights
Using Gemini Code AssistThe full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips. Invoking Gemini You can request assistance from Gemini at any point by creating a comment using either
Customization To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a Limitations & Feedback Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for Github and other Google products, sign up here. You can also get AI-powered code generation, chat, as well as code reviews directly in the IDE at no cost with the Gemini Code Assist IDE Extension. Footnotes
|
There was a problem hiding this comment.
Code Review
This pull request aims to fix a bug where relative task paths failed to resolve for cached pipelines by correctly setting the PipelineURL. However, a security analysis revealed critical vulnerabilities: a task hijacking vulnerability due to improper PipelineURL handling when falling back to local pipelines, and a high-severity issue involving the corruption of shared cached pipeline objects. These could allow an attacker to influence PipelineRuns or hijack tasks via malicious annotations. Additionally, there's a suggestion to refactor a small piece of duplicated code to improve maintainability.
martindbrv
left a comment
There was a problem hiding this comment.
Hey, that's a good catch. I left a suggestion that might be useful.
2760eb1 to
b0fb382
Compare
When multiple PipelineRuns reference the same remote pipeline with relative task paths, the second PipelineRun fails because the PipelineURL is not set when retrieving the pipeline from cache. This causes assembleTaskFQDNs to receive an empty PipelineURL, which returns relative paths unchanged (e.g., '../../common/tasks/hello.yaml'). The go-github library then rejects these paths with 'path must not contain ..' error. The fix sets PipelineURL when using cached pipelines, ensuring relative task paths are resolved correctly for all PipelineRuns. Fixes: SRVKP-10604 Signed-off-by: Shubham Mathur <shumathu@redhat.com>
b0fb382 to
441d367
Compare
📝 Description of the Change
When multiple PipelineRuns reference the same remote pipeline with relative task paths, the second PipelineRun fails because the PipelineURL is not set when retrieving the pipeline from cache.
This causes assembleTaskFQDNs to receive an empty PipelineURL, which returns relative paths unchanged (e.g., '../../common/tasks/hello.yaml'). The go-github library then rejects these paths with 'path must not contain ..' error.
The fix sets PipelineURL when using cached pipelines, ensuring relative task paths are resolved correctly for all PipelineRuns.
Fixes: SRVKP-10604
👨🏻 Linked Jira
https://issues.redhat.com/browse/SRVKP-10604
🔗 Linked GitHub Issue
Fixes #
🚀 Type of Change
fix:)feat:)feat!:,fix!:)docs:)chore:)refactor:)enhance:)deps:)🧪 Testing Strategy
🤖 AI Assistance
If you have used AI assistance, please provide the following details:
Which LLM was used?
Extent of AI Assistance:
Important
If the majority of the code in this PR was generated by an AI, please add a
Co-authored-bytrailer to your commit message.For example:
Co-authored-by: Gemini gemini@google.com
Co-authored-by: ChatGPT noreply@chatgpt.com
Co-authored-by: Claude noreply@anthropic.com
Co-authored-by: Cursor noreply@cursor.com
Co-authored-by: Copilot Copilot@users.noreply.github.com
**💡You can use the script
./hack/add-llm-coauthor.shto automatically addthese co-author trailers to your commits.
✅ Submitter Checklist
fix:,feat:) matches the "Type of Change" I selected above.make testandmake lintlocally to check for and fix anyissues. For an efficient workflow, I have considered installing
pre-commit and running
pre-commit installtoautomate these checks.