Skip to content

fix: reject reserved result names in Task and StepAction validation - #10824

Open
ogulcanaydogan wants to merge 1 commit into
tektoncd:mainfrom
ogulcanaydogan:fix/reserved-result-names
Open

ogulcanaydogan wants to merge 1 commit into
tektoncd:mainfrom
ogulcanaydogan:fix/reserved-result-names

Conversation

@ogulcanaydogan

Copy link
Copy Markdown
Contributor

Changes

Fixes #10631.

entrypointer.go writes internal bookkeeping entries (Key: "ExitCode", Key: "StartedAt", Key: "Reason", with ResultType: InternalTektonResultType) into the same []result.RunResult termination message array as user-declared Task and Step results, distinguished only by ResultType.

If a Task or StepAction author declares a result named ExitCode, StartedAt, or Reason, the user result collides with the internal entry. Depending on ordering, the internal value may be overwritten, causing incorrect status reporting for the Step.

This adds a reserved-name check to TaskResult.Validate() and StepResult.Validate() (pkg/apis/pipeline/v1/result_validation.go), so these names are rejected at webhook validation time rather than silently colliding at runtime.

This is self-inflicted-confusion prevention only (the Task author controls their own result names) — no cross-tenant or security impact, per the issue's linked security advisory triage (closed as not a vulnerability).

Submitter Checklist

As the author of this PR, please check off the items in this checklist:

  • Has Docs if any changes are user facing, including updates to minimum requirements e.g. Kubernetes version bumps
  • Has Tests included if any functionality added or changed
  • pre-commit Passed
  • Follows the commit message standard
  • Meets the Tekton contributor standards (including functionality, content, code)
  • Has a kind label. You can add one by adding a comment on this PR that contains /kind <type>. Valid types are bug, cleanup, design, documentation, feature, flake, misc, question, tep
  • Release notes block below has been updated with any user facing changes (API changes, bug fixes, changes requiring upgrade notices or deprecation warnings). See some examples of good release notes.
  • Release notes contains the string "action required" if the change requires additional action from users switching to the new release

Release Notes

Task and StepAction results can no longer be named `ExitCode`, `StartedAt`, or `Reason`, since those names collide with internal bookkeeping results written by the entrypointer.

@tekton-robot tekton-robot added the release-note Denotes a PR that will be considered when it comes time to generate release notes. label Sep 26, 2026
@ogulcanaydogan

Copy link
Copy Markdown
Contributor Author

/kind bug

@tekton-robot tekton-robot added the kind/bug Categorizes issue or PR as related to a bug. label Sep 26, 2026
@tekton-robot

Copy link
Copy Markdown
Collaborator

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
To complete the pull request process, please assign abayer after the PR has been reviewed.
You can assign the PR to them by writing /assign @abayer in a comment when ready.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@tekton-robot tekton-robot added the size/M Denotes a PR that changes 30-99 lines, ignoring generated files. label Sep 26, 2026
@codecov

codecov Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 90.73%. Comparing base (61e0221) to head (2cd45d5).
⚠️ Report is 1 commits behind head on main.

Additional details and impacted files
@@           Coverage Diff           @@
##             main   #10824   +/-   ##
=======================================
  Coverage   90.73%   90.73%           
=======================================
  Files         297      297           
  Lines       22569    22573    +4     
=======================================
+ Hits        20478    20482    +4     
  Misses       2089     2089           
  Partials        2        2           
Flag Coverage Δ
unit-tests 90.73% <100.00%> (+<0.01%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@tekton-robot tekton-robot added the needs-rebase Indicates a PR cannot be merged because it has merge conflicts with HEAD. label Sep 30, 2026
entrypointer.go writes internal bookkeeping entries (ExitCode,
StartedAt, Reason) into the same result array as user-declared Task
and Step results, distinguished only by ResultType. A Task or
StepAction author declaring a result with one of these names collides
with the internal entry, and depending on ordering the internal value
may be overwritten, causing incorrect status reporting for the step.

Adds a reserved-name check to TaskResult.Validate() and
StepResult.Validate() so these names are rejected at webhook
validation time instead of silently colliding at runtime.

Signed-off-by: Ogulcan Aydogan <ogulcanaydogan@gmail.com>
@ogulcanaydogan
ogulcanaydogan force-pushed the fix/reserved-result-names branch from de4c8b6 to 2cd45d5 Compare September 30, 2026 11:34
@tekton-robot tekton-robot removed the needs-rebase Indicates a PR cannot be merged because it has merge conflicts with HEAD. label Sep 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

kind/bug Categorizes issue or PR as related to a bug. release-note Denotes a PR that will be considered when it comes time to generate release notes. size/M Denotes a PR that changes 30-99 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Validate Task/Step result names against internal reserved names (ExitCode, StartedAt, Reason)

2 participants