feat(gatorwalk-factory): check that CEL product references name declared products (swamp-club #2680) #400

Merged
seth merged 1 commit from cue/2680-gatorwalk-factory-check into main 2026-10-01 00:10:18 +00:00
Owner

Closes swamp-club #2680.

A fixed product name in a factory's CEL must now name a declared product of the kind its map holds. This covers work.bindings, cel gates and a human-approval gate's when. A typo now fails when the definition is checked, not as a binding that fails at dispatch or a gate that never passes.

  • Checked: reads (artifacts.x, evidence["x"], validations.artifacts.x, validations["evidence"]["x"]) and presence tests (has(...) at any depth, "x" in artifacts). A stage's resultEvidence counts as evidence. A name of the other kind gets its own message.
  • Not checked: lookups by variable (artifacts[k]), macros on a map, in on a payload, and payload field paths against payload schemas.
  • Reusable for #2792: the new _lib/engine/cel_refs.ts has productRefs(ast), which lists { map, name, use: read | test }. celExpressions(doc) in definition_schema.ts lists every CEL expression by path from CEL_POSITIONS, so the ${{ check and this one share one list.
  • The outdated "apply renames products" comment on CEL_VOCABULARY is fixed. README and DESIGN are updated.
  • A dispatch test's fixture read an undeclared artifact to make a binding fail at runtime. It now declares the artifact and never records it.

All bundled examples and testdata factories pass: the check found 107 references across them, all valid. 604 unit tests pass. The verification attestation is posted for d5220400. Both reviews passed; their one low finding (optional access .?) doesn't apply, because cel-js 7.6.1 can't parse it.

🤖 Generated with Claude Code

Closes swamp-club #2680. A fixed product name in a factory's CEL must now name a declared product of the kind its map holds. This covers `work.bindings`, cel gates and a human-approval gate's `when`. A typo now fails when the definition is checked, not as a binding that fails at dispatch or a gate that never passes. - **Checked:** reads (`artifacts.x`, `evidence["x"]`, `validations.artifacts.x`, `validations["evidence"]["x"]`) and presence tests (`has(...)` at any depth, `"x" in artifacts`). A stage's `resultEvidence` counts as evidence. A name of the other kind gets its own message. - **Not checked:** lookups by variable (`artifacts[k]`), macros on a map, `in` on a payload, and payload field paths against payload schemas. - **Reusable for #2792:** the new `_lib/engine/cel_refs.ts` has `productRefs(ast)`, which lists `{ map, name, use: read | test }`. `celExpressions(doc)` in `definition_schema.ts` lists every CEL expression by path from `CEL_POSITIONS`, so the `${{` check and this one share one list. - The outdated "apply renames products" comment on `CEL_VOCABULARY` is fixed. README and DESIGN are updated. - A dispatch test's fixture read an undeclared artifact to make a binding fail at runtime. It now declares the artifact and never records it. All bundled examples and testdata factories pass: the check found 107 references across them, all valid. 604 unit tests pass. The verification attestation is posted for d5220400. Both reviews passed; their one low finding (optional access `.?`) doesn't apply, because cel-js 7.6.1 can't parse it. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
feat(gatorwalk-factory): check that CEL product references name declared products (swamp-club #2680)
All checks were successful
CI / Review Integrity (pull_request) Successful in 1m45s
CI / Validate Attestation (pull_request) Successful in 1m16s
d52204000a
A fixed product name in a factory's CEL (work.bindings, cel gates, a
human-approval gate's when) must now name a declared product of the kind its
map holds, so a typo fails when the definition is checked rather than at
dispatch or as a gate that never passes. Reads (artifacts.x, evidence["x"],
validations.artifacts.x, validations["evidence"]["x"]) and presence tests
(has(...), "x" in artifacts) are both checked; lookups by variable are not.

The walk is productRefs in the new _lib/engine/cel_refs.ts, which tells
reads from tests, and celExpressions lists every CEL expression by path from
CEL_POSITIONS, so the ${{ check and this one share one list. Both are the
entry point #2792 will use.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
seth merged commit cf33c80ce9 into main 2026-10-01 00:10:18 +00:00
seth deleted branch cue/2680-gatorwalk-factory-check 2026-10-01 00:10:19 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
swamp-club/swamp-extensions!400
No description provided.