Relationships
⊘ blocks #2792#2680 gatorwalk-factory: check that CEL product references name declared products
Opened by skunk-ape · 9/29/2026· Shipped 10/1/2026
Follow-up from swamp-club #2663 (review finding on eject). The lifecycle schema syntax-checks CEL in work.bindings and cel gates, but nothing checks that a fixed product reference in CEL names a product the document declares: artifacts.x, artifacts["x"], evidence.x, validations.artifacts.x and validations["evidence"]["x"]. A typo, or a rename that eject could not follow, only shows up when a work item evaluates the expression (a binding that resolves to null fails dispatch; a cel gate never passes).
Proposal: when a lifecycle or plugin is checked, walk each CEL expression's AST (as eject's rewriteCel already does) and report every fixed reference to an undeclared artifact or evidence as an error with its path. Plugin contract inputs count as declared. Dynamic lookups (artifacts[k]) stay unchecked. This relies on the CEL vocabulary names being reserved (added in #2663), so artifacts/evidence/validations always mean the context's maps.
Out of scope: checking payload field paths (artifacts.x.payload.field) against payload schemas.
Shipped
Click a lifecycle step above to view its details.