Skip to content

fix(capability): enforce valid output path before shifting profiler options - #6795

Open
vaibhavsrv wants to merge 1 commit into
Osmantic:public-betafrom
vaibhavsrv:fix/capability-profile-option-args
Open

vaibhavsrv wants to merge 1 commit into
Osmantic:public-betafrom
vaibhavsrv:fix/capability-profile-option-args

Conversation

@vaibhavsrv

Copy link
Copy Markdown
Contributor

Why this matters

In ods/scripts/build-capability-profile.sh, the --output option reads $2 and executes shift 2 under set -euo pipefail without checking if an argument was provided. Passing --output as the trailing argument crashes the script with an unhandled exit code 1 and an empty standard error, providing operators and automated wrappers with no diagnostic information. Furthermore, passing --output immediately before --env (i.e., build-capability-profile.sh --output --env) causes the parser to swallow --env into OUTPUT_FILE, suppressing --env mode and attempting to write profile output to a file named --env.

This change introduces pre-shift validation for --output. If the argument is missing, empty, or starts with a hyphen indicating an option flag, the script outputs a clear diagnostic (ERROR: --output requires an argument) to standard error and exits with usage status 1. Valid output path specifications and hardware classification profiling contracts remain untouched.

Validation

  • Baseline reproduction: Running bash ods/scripts/build-capability-profile.sh --output halted abruptly with unhandled exit 1 and empty stderr; passing --output --env swallowed --env into OUTPUT_FILE.
  • Post-fix verification: Running python3 ods/tests/test_build_capability_profile_options.py confirms that missing, empty, and option-hijacked invocations fail with exit code 1 and output the ERROR: --output requires an argument diagnostic, while unknown options reject cleanly.
  • Telemetry statement: "Capability profiling suites: 4 passed. New-test PyCompile, ShellCheck, and diff checks pass; new regressions wired into Linux CI."

Overlap check

Risk / AI disclosure

AI-assisted investigation, implementation and CLI regressions. This strengthens a CLI check, not runtime admission. Independent human review and platform/runtime qualification remain gates. No running configuration, deployment or upstream merge changed.

Follow-up integration evidence

Composed with #6794 at 1001730 without conflicts. Production and test diffs passed together; worker pruning checks remain intact.
Backlog composition was local-only (production/test diffs, excluding workflow/Makefile wiring); it is not an upstream merge or independent human approval. Declared live-review gates remain open.

@vaibhavsrv vaibhavsrv changed the title fix(capability): reject missing option argument for output in capability profiler fix(capability): enforce valid output path before shifting profiler options Sep 26, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant