Repository navigation
Conversation
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds validation of the CloudFormation Metadata Context attribute (
Metadata.com.aws.cloudformation.Context) on the template and on each resource, as three rules evaluated identically by every engine selector.Three new rules.
I4010reports a template or architecture-relevant resource that has no Context block.W4011reports a Context block that has nowhyand no low-confidence trust declaration (trust.conf: low).W4012reports a Context block that does not match the Metadata Context schema. All three areBestPracticerules registered withCfnLintorigin inrules/src/registry.rs: cfn-lint 1.57.2 reserves these numbers for the same checks (ContextMissing.py,ContextMissingWhy.py,ContextSchemaViolation.py).One shared check. The check is a post-engine pass in
validation-engine/src/context_check.rs, invoked fromengine.rsafter rule evaluation, sorego,cel, andcompositeproduce the same findings by construction. A resource with a usableTypemust carry its own block unless its type is one of the subordinate types that attach to another resource (AWS::IAM::Policy,AWS::Lambda::Permission,AWS::Logs::LogGroup,AWS::Logs::LogStream,AWS::S3::BucketPolicy,AWS::SNS::TopicPolicy,AWS::SQS::QueuePolicy), a::MODULE, orAWS::CDK::Metadata; CDK framework helper resources (log-retention and custom-resource provider handlers) are skipped by logical ID. A block carried by an exempt resource is still validated byW4011andW4012. The template-level block is required once two or more resources lack their own. Missing resources are reported as oneI4010finding anchored at the first missing resource, listing every missing resource asLogicalId (Type)and attaching the rest asrelated_resourceswith their own spans; schema violations produce oneW4012finding per violated field, located at that field. The checks run on every template, including CDK-synthesized ones; the CDK gate still drops only its existing template-authoring rules (I1022,W3010).Published schema, embedded.
data-source/handwritten/metadata_context_schema.jsonis the Metadata Context schema v1 from the CloudFormation template reference, copied verbatim and embedded throughdata-source/build.rsasMETADATA_CONTEXT_SCHEMA. A unit test fails if a future revision of the schema introduces a keyword the validator does not interpret.Snapshots exclude the three rules.
I4010fires on nearly every corpus template, so persisting it would rewrite every snapshot entry.resources::exclude_snapshot_rulesremovesI4010,W4011, andW4012from the persisted report and from the snapshot harness's in-process report, after the rego/cel/composite parity comparison, which still covers them. All 718 pre-existing snapshot entries are byte-identical tomain; the only additions are the six new fixtures. The rules' behavior is pinned by those fixtures and thecontext_metadataintegration test instead.Related issue
None.
Validation
cargo fmt --all -- --checkandcargo clippy --locked --all-targets --workspace -- -D warnings: clean.cargo test -p cloudformation-validate-validation-engine: 259 pass, including 16context_checkunit tests and the CDK-gate test.cargo test -p cfn-validate --test context_metadata: 6 pass (YAML and JSON fixtures through all three selectors).cargo test -p cfn-validate --test snapshot_tests: 15 pass.cargo test -p resources --lib: 9 pass.cargo test -p cloudformation-validate-rules: 79 pass (rule count 311).cargo test -p cloudformation-validate-template-model: 813 pass.cargo test -p cloudformation-validate-data-source: 74 pass.cargo run --release -p resources --example generate_validation_reportsover the full corpus (724 templates) verifiesrego == cel == compositebefore the exclusion is applied, so the Context rules are included in the comparison.cfn-validate --engine rego|cel|compositeon each new fixture gives identical rule ID, severity, location, and message.--include-experimental --include-checks I): identical firing and location on every new fixture, and across the whole corpus forW4011andW4012(zero extra, zero missing). ForI4010the only differences are 32 templates where the existing transform-error gate suppresses everything exceptE0001, andbad/I4010_cdk_synthesized_missing_context.json, where cfn-lint skips CDK templates by design and this engine reports.Validation behavior changes
Expected behavior comes from the Metadata Context attribute documentation and its published schema:
TemplateContextadmitsarch,must,ref,owner;ResourceContextadmitswhy,must,mutable,mutability,trust,deps, withwhydefined as the rationale andtrust.confrecording confidence in it; both reject additional properties.Accepted:
good/metadata_context_complete.yamlcarries conforming blocks on the template and every resource and produces no Context finding.Rejected:
bad/I4010_context_missing.yamlandbad/I4010_context_missing.json(template and resource blocks absent; subordinate types not listed),bad/I4010_cdk_synthesized_missing_context.json(synthesized template; theAWS::CDK::Metadatarecord is not listed),bad/W4011_context_missing_why.yaml(conf: lowexcuses the omission,mediumandhighdo not, a subordinate type that supplies a block is held to it),bad/W4012_context_schema_violation.yaml(wrong field types, unrecognized enum values, missing requiredtrust.srcandref[].at, fields at the wrong level, undefined fields, a block that is not a mapping; one finding per violation).Checklist
selectors agree.
By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license.