Skip to content

fix(pkgid): avoid panic on malformed protocol URLs - #17548

Merged
weihanglo merged 3 commits into
rust-lang:masterfrom
rabindra789:fix/malformed-pkgid-protocol
Oct 6, 2026
Merged

weihanglo merged 3 commits into
rust-lang:masterfrom
rabindra789:fix/malformed-pkgid-protocol

Conversation

@rabindra789

Copy link
Copy Markdown
Contributor

Fixes #17459

Instead of unwrapping the parsed URL i change the strip_url_protocol() to return a Result. The git, registry and path callers now propagate the error, so malformed protocols return a normal cargo diagnostic instead of panicking. I also added a regression test for the malformed protocol case.

I ran cargo test -p cargo-util-schemas, cargo test -p cargo --test testsuite pkgid, cargo clippy --all-targets and cargo build

So the git++://x: reproducer now returns malformed source protocol in pkgid url: .. instead of panicking.

🤖LLM disclosure: I use LLM to help me with investigate the issue, reproduce the panic, understand the root cause.

Add a regression test for a malformed `git++://` package ID specification that
currently causes `PackageIdSpec::parse` to panic.

Signed-off-by: rabindra789 <rabindrameher116@gmail.com>
@rustbot rustbot added the S-waiting-on-review Status: Awaiting review from the assignee but also interested parties. label Oct 4, 2026
@rustbot

rustbot commented Oct 4, 2026

Copy link
Copy Markdown
Collaborator

Thanks for the pull request, and welcome! The Rust Project has assigned @Muscraft (or someone else) to review your changes, you should hear from them (or someone else) within the next two weeks.

Please see the contribution instructions and our LLM policy for more information.

Why was this reviewer chosen?

The reviewer was selected based on:

  • Owners of files modified in this PR: @Muscraft, @epage, @weihanglo
  • @Muscraft, @epage, @weihanglo expanded to Muscraft, epage, weihanglo
  • Random selection from Muscraft, epage, weihanglo

let (_, rest) = raw
.split_once('+')
.ok_or_else(|| ErrorKind::MalformedProtocolUrl(raw.clone()))?;
rest.parse()

@weihanglo weihanglo Oct 4, 2026 •

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why does the parsing part also return malformed protocol error? URL parse error is not always caused by malformed protocol, no? Also, it would be great to also have tests for missing protocol + part, if needed

View changes since the review

@rabindra789 rabindra789 Oct 5, 2026 •

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good catch. you are right. I changed the error to InvalidPkgIdUrl so caees like git+https:// are not reported as malformed protocol. I also added tests for it.

@weihanglo weihanglo left a comment •

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@weihanglo
weihanglo added this pull request to the merge queue Oct 5, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Oct 5, 2026
@weihanglo
weihanglo added this pull request to the merge queue Oct 5, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Oct 5, 2026
@weihanglo
weihanglo added this pull request to the merge queue Oct 6, 2026
Merged via the queue into rust-lang:master with commit f9b76ee Oct 6, 2026
29 checks passed
@rustbot rustbot removed the S-waiting-on-review Status: Awaiting review from the assignee but also interested parties. label Oct 6, 2026
@rabindra789
rabindra789 deleted the fix/malformed-pkgid-protocol branch October 6, 2026 06:18
rust-bors Bot pushed a commit to rust-lang/rust that referenced this pull request Oct 7, 2026
Update cargo submodule

11 commits in f3865b2a4d1acc5276f6b3c67d0e057f4dab3928..45c3aacf0e8dabdcdb6b7b518db100061d6367a7
2026-09-29 19:58:08 +0000 to 2026-10-06 16:29:08 +0000
- feat(pkgid-spec): Builtin package spec parsing and formatting (rust-lang/cargo#17539)
- feat(hints): support minimum optimization levels (rust-lang/cargo#17368)
- Use trusted publishing for Cargo crates (rust-lang/cargo#17426)
- feat(trim-paths): stabilize `profile.trim-paths` (rust-lang/cargo#17488)
- fix(pkgid): avoid panic on malformed protocol URLs (rust-lang/cargo#17548)
- fix(git)!: Default to net.git-fetch-with-cli if git is present (rust-lang/cargo#17329)
- Improved testsuite file permissions cleanup (rust-lang/cargo#17547)
- docs(guide): Give an example of checking for stale lockfile (rust-lang/cargo#17546)
- Add new peak memory table to cargo timings enabled via `-Zmem-stats` (rust-lang/cargo#17531)
- docs(changlog): Update 1.100.0 to reflect a beta backport (rust-lang/cargo#17542)
- feat(lint): Making the lint name a terminal hyperlink to docs (rust-lang/cargo#17538)
rust-bors Bot pushed a commit to rust-lang/rust that referenced this pull request Oct 7, 2026
Update cargo submodule

11 commits in f3865b2a4d1acc5276f6b3c67d0e057f4dab3928..45c3aacf0e8dabdcdb6b7b518db100061d6367a7
2026-09-29 19:58:08 +0000 to 2026-10-06 16:29:08 +0000
- feat(pkgid-spec): Builtin package spec parsing and formatting (rust-lang/cargo#17539)
- feat(hints): support minimum optimization levels (rust-lang/cargo#17368)
- Use trusted publishing for Cargo crates (rust-lang/cargo#17426)
- feat(trim-paths): stabilize `profile.trim-paths` (rust-lang/cargo#17488)
- fix(pkgid): avoid panic on malformed protocol URLs (rust-lang/cargo#17548)
- fix(git)!: Default to net.git-fetch-with-cli if git is present (rust-lang/cargo#17329)
- Improved testsuite file permissions cleanup (rust-lang/cargo#17547)
- docs(guide): Give an example of checking for stale lockfile (rust-lang/cargo#17546)
- Add new peak memory table to cargo timings enabled via `-Zmem-stats` (rust-lang/cargo#17531)
- docs(changlog): Update 1.100.0 to reflect a beta backport (rust-lang/cargo#17542)
- feat(lint): Making the lint name a terminal hyperlink to docs (rust-lang/cargo#17538)
rust-bors Bot pushed a commit to rust-lang/rust that referenced this pull request Oct 8, 2026
Update cargo submodule



15 commits in f3865b2a4d1acc5276f6b3c67d0e057f4dab3928..29c5daa1afc262323364e039bb70c83372cc702c
2026-09-29 19:58:08 +0000 to 2026-10-07 22:13:48 +0000
- test: mark requiring ssh for tests shelling out to it (rust-lang/cargo#17563)
- chore(deps): update msrv (rust-lang/cargo#17532)
- fix(rustdoc): suppress edition unspecified warnings (rust-lang/cargo#17557)
- chore(deps): update cargo-semver-checks to v0.51.0 (rust-lang/cargo#17553)
- feat(pkgid-spec): Builtin package spec parsing and formatting (rust-lang/cargo#17539)
- feat(hints): support minimum optimization levels (rust-lang/cargo#17368)
- Use trusted publishing for Cargo crates (rust-lang/cargo#17426)
- feat(trim-paths): stabilize `profile.trim-paths` (rust-lang/cargo#17488)
- fix(pkgid): avoid panic on malformed protocol URLs (rust-lang/cargo#17548)
- fix(git)!: Default to net.git-fetch-with-cli if git is present (rust-lang/cargo#17329)
- Improved testsuite file permissions cleanup (rust-lang/cargo#17547)
- docs(guide): Give an example of checking for stale lockfile (rust-lang/cargo#17546)
- Add new peak memory table to cargo timings enabled via `-Zmem-stats` (rust-lang/cargo#17531)
- docs(changlog): Update 1.100.0 to reflect a beta backport (rust-lang/cargo#17542)
- feat(lint): Making the lint name a terminal hyperlink to docs (rust-lang/cargo#17538)
@rustbot rustbot added this to the 1.101.0 milestone Oct 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

cargo panics on crafted Cargo.toml with malformed git URL in profile package override

4 participants