INNER CODE UNIT · Python
_lock_string
IvanMurzak/Unity-MCP · .github/scripts/chain_feed.py:728
def _lock_string(where, value):
if not isinstance(value, str):
raise _lock_field_refusal(where, value, "a string")
if _CONTROL_CHARS_RE.search(value):
raise _lock_field_refusal(where, value, "free of control characters (CR, LF, NUL, ...)")
return value
def validate_lock(lock):
"""Refuse (exit 2) any lock whose scalars are not exactly the shape `lock.py` writes.
Runs in `build_context` straight after the JSON parse, BEFORE the lock hash, the node's sha,
the recipes or any writer reads a value — so a value that would change a shell command, a
git argv, a feed path, `$GITHUB_ENV` or `$GITHUB_OUTPUT` never reaches one:
* `nodes` keys — the node ids this file knows (`RECIPES`, which `recipes-check` pins to the
manifest); `follows` names one of them too;
* `sha` — exactly 40 lowercase hex (never an option-shaped `--upload-pack=...` git argv);