Skip to content

fix: validate capability version dates - #50

Open
horaceewang-TT wants to merge 1 commit into
Universal-Commerce-Protocol:mainfrom
horaceewang-TT:fix/validate-capability-versions
Open

fix: validate capability version dates#50
horaceewang-TT wants to merge 1 commit into
Universal-Commerce-Protocol:mainfrom
horaceewang-TT:fix/validate-capability-versions

Conversation

@horaceewang-TT

Copy link
Copy Markdown

Description

Fix capability version validation to prevent malformed or impossible date strings from bypassing requires compatibility checks.

Validate capability versions during parsing.
Reject invalid actual versions before lexicographical comparison.
Validate Gregorian calendar dates, including month lengths and leap years.
Add regression tests for malformed versions, invalid dates, and leap-year boundaries.

Category (Required)

Please select one or more categories that apply to this change.

  • Core Protocol: Changes to the base communication layer, global context, or breaking refactors. (Requires Technical Council approval)
  • Governance/Contributing: Updates to GOVERNANCE.md, CONTRIBUTING.md, or CODEOWNERS. (Requires Governance Council approval)
  • Capability: New schemas (Discovery, Cart, etc.) or extensions. (Requires Maintainer approval)
  • Documentation: Updates to README, or documentations regarding schema or capabilities. (Requires Maintainer approval)
  • Infrastructure: CI/CD, Linters, or build scripts. (Requires DevOps Maintainer approval)
  • Maintenance: Version bumps, lockfile updates, or minor bug fixes. (Requires DevOps Maintainer approval)
  • SDK: Language-specific SDK updates and releases. (Requires DevOps Maintainer approval)
  • Samples / Conformance: Maintaining samples and the conformance suite. (Requires Maintainer approval)
  • UCP Schema: Changes to the ucp-schema tool (resolver, linter, validator). (Requires Maintainer approval)
  • Community Health (.github): Updates to templates, workflows, or org-level configs. (Requires DevOps Maintainer approval)

Related Issues

Checklist

  • I have followed the Contributing Guide (including Conventional Commits title requirements and ! for breaking changes).
  • I have updated the documentation (if applicable).
  • My changes pass all local linting and formatting checks.
  • I have added tests that prove my fix is effective or that my feature works.
  • New and existing unit tests pass locally with my changes.
  • (For Core/Capability) I have included/updated the relevant JSON schemas.
  • I have regenerated Python Pydantic models by running generate_models.sh under python_sdk.

Screenshots / Logs (if applicable)

$ cargo test --all-targets
test result: ok. 154 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out
test result: ok. 78 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out
test result: ok. 15 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out
test result: ok. 68 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out

Unit tests covering this fix:

  1. types::tests::is_valid_version_format

    • valid versions: 2026-01-23, 2025-12-31
    • invalid formats: 2026-1-23, not-a-date, 20260123, empty string
    • invalid calendar dates: 2026-13-32, 2026-00-15, 2026-06-00, 9999-99-99
    • invalid month/day combinations: 2026-02-29, 2026-02-31, 2026-04-31
    • leap-year handling: accepts 2024-02-29, accepts 2000-02-29, rejects 1900-02-29
  2. types::tests::version_constraint_satisfied_by

    • rejects versions below min
    • accepts min boundary inclusively
    • accepts versions within range
    • accepts max boundary inclusively
    • rejects versions above max
    • rejects invalid actual versions: not-a-date, 2026-02-31
  3. compose::tests::parse_capabilities_rejects_invalid_version

    • rejects a capability entry whose version is not-a-date
    • returns ComposeError::InvalidCapability

@damaz91 damaz91 added status:needs-triage Signal that the PR is ready for human triage status:under-review and removed status:needs-triage Signal that the PR is ready for human triage labels Aug 13, 2026
@damaz91 damaz91 added status:stale-review Applied if a PR is waiting on a reviewer for too long and removed status:under-review labels Sep 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

status:stale-review Applied if a PR is waiting on a reviewer for too long

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants