Repository navigation
fix(pkgid): avoid panic on malformed protocol URLs - #17548
Conversation
Add a regression test for a malformed `git++://` package ID specification that currently causes `PackageIdSpec::parse` to panic. Signed-off-by: rabindra789 <rabindrameher116@gmail.com>
|
Thanks for the pull request, and welcome! The Rust Project has assigned @Muscraft (or someone else) to review your changes, you should hear from them (or someone else) within the next two weeks. Please see the contribution instructions and our LLM policy for more information. Why was this reviewer chosen?The reviewer was selected based on:
|
| let (_, rest) = raw | ||
| .split_once('+') | ||
| .ok_or_else(|| ErrorKind::MalformedProtocolUrl(raw.clone()))?; | ||
| rest.parse() |
There was a problem hiding this comment.
Why does the parsing part also return malformed protocol error? URL parse error is not always caused by malformed protocol, no? Also, it would be great to also have tests for missing protocol + part, if needed
There was a problem hiding this comment.
Good catch. you are right. I changed the error to InvalidPkgIdUrl so caees like git+https:// are not reported as malformed protocol. I also added tests for it.
Update cargo submodule 11 commits in f3865b2a4d1acc5276f6b3c67d0e057f4dab3928..45c3aacf0e8dabdcdb6b7b518db100061d6367a7 2026-09-29 19:58:08 +0000 to 2026-10-06 16:29:08 +0000 - feat(pkgid-spec): Builtin package spec parsing and formatting (rust-lang/cargo#17539) - feat(hints): support minimum optimization levels (rust-lang/cargo#17368) - Use trusted publishing for Cargo crates (rust-lang/cargo#17426) - feat(trim-paths): stabilize `profile.trim-paths` (rust-lang/cargo#17488) - fix(pkgid): avoid panic on malformed protocol URLs (rust-lang/cargo#17548) - fix(git)!: Default to net.git-fetch-with-cli if git is present (rust-lang/cargo#17329) - Improved testsuite file permissions cleanup (rust-lang/cargo#17547) - docs(guide): Give an example of checking for stale lockfile (rust-lang/cargo#17546) - Add new peak memory table to cargo timings enabled via `-Zmem-stats` (rust-lang/cargo#17531) - docs(changlog): Update 1.100.0 to reflect a beta backport (rust-lang/cargo#17542) - feat(lint): Making the lint name a terminal hyperlink to docs (rust-lang/cargo#17538)
Update cargo submodule 11 commits in f3865b2a4d1acc5276f6b3c67d0e057f4dab3928..45c3aacf0e8dabdcdb6b7b518db100061d6367a7 2026-09-29 19:58:08 +0000 to 2026-10-06 16:29:08 +0000 - feat(pkgid-spec): Builtin package spec parsing and formatting (rust-lang/cargo#17539) - feat(hints): support minimum optimization levels (rust-lang/cargo#17368) - Use trusted publishing for Cargo crates (rust-lang/cargo#17426) - feat(trim-paths): stabilize `profile.trim-paths` (rust-lang/cargo#17488) - fix(pkgid): avoid panic on malformed protocol URLs (rust-lang/cargo#17548) - fix(git)!: Default to net.git-fetch-with-cli if git is present (rust-lang/cargo#17329) - Improved testsuite file permissions cleanup (rust-lang/cargo#17547) - docs(guide): Give an example of checking for stale lockfile (rust-lang/cargo#17546) - Add new peak memory table to cargo timings enabled via `-Zmem-stats` (rust-lang/cargo#17531) - docs(changlog): Update 1.100.0 to reflect a beta backport (rust-lang/cargo#17542) - feat(lint): Making the lint name a terminal hyperlink to docs (rust-lang/cargo#17538)
Update cargo submodule 15 commits in f3865b2a4d1acc5276f6b3c67d0e057f4dab3928..29c5daa1afc262323364e039bb70c83372cc702c 2026-09-29 19:58:08 +0000 to 2026-10-07 22:13:48 +0000 - test: mark requiring ssh for tests shelling out to it (rust-lang/cargo#17563) - chore(deps): update msrv (rust-lang/cargo#17532) - fix(rustdoc): suppress edition unspecified warnings (rust-lang/cargo#17557) - chore(deps): update cargo-semver-checks to v0.51.0 (rust-lang/cargo#17553) - feat(pkgid-spec): Builtin package spec parsing and formatting (rust-lang/cargo#17539) - feat(hints): support minimum optimization levels (rust-lang/cargo#17368) - Use trusted publishing for Cargo crates (rust-lang/cargo#17426) - feat(trim-paths): stabilize `profile.trim-paths` (rust-lang/cargo#17488) - fix(pkgid): avoid panic on malformed protocol URLs (rust-lang/cargo#17548) - fix(git)!: Default to net.git-fetch-with-cli if git is present (rust-lang/cargo#17329) - Improved testsuite file permissions cleanup (rust-lang/cargo#17547) - docs(guide): Give an example of checking for stale lockfile (rust-lang/cargo#17546) - Add new peak memory table to cargo timings enabled via `-Zmem-stats` (rust-lang/cargo#17531) - docs(changlog): Update 1.100.0 to reflect a beta backport (rust-lang/cargo#17542) - feat(lint): Making the lint name a terminal hyperlink to docs (rust-lang/cargo#17538)
Fixes #17459
Instead of unwrapping the parsed URL i change the
strip_url_protocol()to return aResult. The git, registry and path callers now propagate the error, so malformed protocols return a normal cargo diagnostic instead of panicking. I also added a regression test for the malformed protocol case.I ran
cargo test -p cargo-util-schemas,cargo test -p cargo --test testsuite pkgid,cargo clippy --all-targetsandcargo buildSo the
git++://x:reproducer now returnsmalformed source protocol in pkgid url: ..instead of panicking.🤖LLM disclosure: I use LLM to help me with investigate the issue, reproduce the panic, understand the root cause.