fix: --glob panics on a pattern gobwas/glob rejects - #1145
Merged
Conversation
Previously patterns were validated with doublestar but compiled with gobwas/glob during matching, causing different validation rules. Now patterns are compiled once in NewGlob, catching invalid patterns early.
tmeijn
pushed a commit
to tmeijn/dotfiles
that referenced
this pull request
Aug 21, 2026
This MR contains the following updates: | Package | Update | Change | |---|---|---| | [errata-ai/vale](https://github.com/errata-ai/vale) | minor | `v3.17.1` → `v3.18.0` | MR created with the help of [el-capitano/tools/renovate-bot](https://gitlab.com/el-capitano/tools/renovate-bot). **Proposed changes to behavior should be submitted there as MRs.** --- ### Release Notes <details> <summary>errata-ai/vale (errata-ai/vale)</summary> ### [`v3.18.0`](https://github.com/vale-cli/vale/releases/tag/v3.18.0) [Compare Source](vale-cli/vale@v3.17.1...v3.18.0) v3.18.0 is the largest expansion of Vale's format support since v3.0.0. [MDX](https://docs.vale.sh/formats/mdx) is now parsed natively — `mdx2vast` is no longer required. This release also adds support for four new markup formats: [Typst](https://docs.vale.sh/formats/typst) (through the new [`typst2vast`](https://github.com/jdkato/typst2vast) program), [Quarto](https://docs.vale.sh/formats/quarto), [MyST](https://docs.vale.sh/formats/myst), and [QDoc](https://docs.vale.sh/formats/qdoc). R Markdown now works out of the box, and comment extraction now covers Lua, PHP, Haskell, R, Perl, and SCSS. Beyond formats, there's a new `meta` [scope](https://docs.vale.sh/topics/scopes) for a document's machine-readable content, a `--plain-progress` flag, and per-package logging for `vale sync` in CI — plus a long list of fixes that make alert positions and scoping more accurate across every format. > ✨ Sponsor Spotlight > > Special thanks to [Promptless](https://vale.sh/sponsors/promptless) — Vale's newest sponsor and the latest to receive a [Spotlight page](https://vale.sh/sponsors/promptless). Promptless suggests doc updates when your product changes; you review, edit, and ship. #### Changelog - [`6c382ec`](vale-cli/vale@6c382ecd) fix: stop element-scoped rules from matching sentence fragments ([#​1150](vale-cli/vale#1150)) - [`9b9594d`](vale-cli/vale@9b9594d0) fix: don't treat a word before a code span as inline markup ([#​1147](vale-cli/vale#1147)) - [`2b159ab`](vale-cli/vale@2b159ab6) fix: stop corrupting suggestions containing 'PIPE' - [`390dda6`](vale-cli/vale@390dda6e) fix: compile glob patterns once at construction ([#​1145](vale-cli/vale#1145)) - [`fcf0740`](vale-cli/vale@fcf07409) fix(ls-metrics): prevent panic on empty directory ([#​1144](vale-cli/vale#1144)) - [`dd09d42`](vale-cli/vale@dd09d428) fix(core): resolve Lang and Transform in section order, not map order ([#​1143](vale-cli/vale#1143)) - [`85ee608`](vale-cli/vale@85ee6088) fix(dita): report dita's own error output instead of just the exit status ([#​1141](vale-cli/vale#1141)) - [`fd8c2e0`](vale-cli/vale@fd8c2e02) refactor: satisfy revive's empty-block - [`2f65b83`](vale-cli/vale@2f65b836) fix: close display math on any line ending with `$$` ([#​1148](vale-cli/vale#1148)) - [`e587329`](vale-cli/vale@e5873290) fix(lint): treat an HTML comment as a text boundary outside inline elements ([#​1140](vale-cli/vale#1140)) - [`4691bd3`](vale-cli/vale@4691bd36) docs: add new spotlight - [`37cb109`](vale-cli/vale@37cb109b) feat: add `--plain-progress` - [`12fbbd7`](vale-cli/vale@12fbbd7f) feat: log each package when sync isn't writing to a terminal - [`9a1a16c`](vale-cli/vale@9a1a16c3) fix: mark a QDoc image that has no alt text, and publish inline ones - [`c154ac2`](vale-cli/vale@c154ac2a) Keep the extracted text one line per source line ([#​1135](vale-cli/vale#1135)) - [`8fe9804`](vale-cli/vale@8fe98044) refactor: CLI clean up and subcommand help - [`ae6d749`](vale-cli/vale@ae6d7496) feat: add `vale test` - [`e5a0286`](vale-cli/vale@e5a0286a) fix: read a shebang as a POSIX path - [`eec2f59`](vale-cli/vale@eec2f59a) fix: read a .qdocinc as the include it is, and keep meta out of prose - [`7618d04`](vale-cli/vale@7618d044) fix: only hand the Docutils source to a Python interpreter - [`b596b0d`](vale-cli/vale@b596b0dc) fix: stop a string run's helper processes the way a file run does - [`f3f3402`](vale-cli/vale@f3f34021) fix: keep `vale off` working when QDoc prose is escaped - [`54efd3b`](vale-cli/vale@54efd3bb) fix: escape QDoc markup - [`5666297`](vale-cli/vale@5666297b) fix: treat a snippet marker inside a QDoc comment as markup - [`c2d1a55`](vale-cli/vale@c2d1a559) feat: add a meta scope for a document's machine-readable content - [`33e4012`](vale-cli/vale@33e40124) fix: close QDoc's code blocks on the right command, and scope its divs - [`5ae4867`](vale-cli/vale@5ae48670) fix: read only `/*!` as QDoc, and cover commands - [`e60b5bc`](vale-cli/vale@e60b5bc3) fix: keep a rule's level in the section that set it - [`c1e2fa0`](vale-cli/vale@c1e2fa01) fix: honor IgnoredScopes when a markup format is mapped onto source - [`85c1343`](vale-cli/vale@85c13436) fix: place a match inside a block that inline markup rewrote - [`b47ccb0`](vale-cli/vale@b47ccb06) fix: don't mask an autolink's URL twice - [`65f5687`](vale-cli/vale@65f5687f) fix: skip `$…$` inline math - [`b3bade4`](vale-cli/vale@b3bade4b) fix: lint a tight list item's own text as its own block - [`4a6b7cf`](vale-cli/vale@4a6b7cfd) Don't lint a shebang as a comment ([#​1134](vale-cli/vale#1134)) - [`77179c0`](vale-cli/vale@77179c0a) fix: report spans against the file's actual bytes - [`7f429e3`](vale-cli/vale@7f429e31) test: pin issue 1007's frontmatter and blockquote scenarios - [`b049e35`](vale-cli/vale@b049e35f) feat: support the .scss extension - [`b678b8d`](vale-cli/vale@b678b8d9) test: add QML case - [`e82432d`](vale-cli/vale@e82432d7) feat: extract Lua, PHP, Haskell, R, and Perl comments with tree-sitter - [`0e2f8bf`](vale-cli/vale@0e2f8bf3) eat: support QML sources via qml = qdoc - [`cc710aa`](vale-cli/vale@cc710aa2) fix: treat only block comments as QDoc documentation - [`bd1f33a`](vale-cli/vale@bd1f33a6) ci: install typst2vast, drop mdx2vast - [`9708be6`](vale-cli/vale@9708be61) feat: support Typst - [`15115bf`](vale-cli/vale@15115bfb) fix: place a rewritten block by its longest word, not its last - [`5c91639`](vale-cli/vale@5c916393) fix: skip a repeated match's prior occurrences by count, not by masking - [`db8c83c`](vale-cli/vale@db8c83cf) feat: support QDoc - [`fca7b79`](vale-cli/vale@fca7b79b) feat: support Quarto - [`286fc59`](vale-cli/vale@286fc59a) feat: parse MDX natively, dropping mdx2vast - [`fedaf20`](vale-cli/vale@fedaf204) feat: support MyST - [`eec788d`](vale-cli/vale@eec788d8) fix: read the character actually beside a match for inline code - [`590278e`](vale-cli/vale@590278e5) feat: lint R Markdown out of the box - [`4d8e228`](vale-cli/vale@4d8e2289) fix: strip tab indentation from block comments ([#​1131](vale-cli/vale#1131)) - [`02fb654`](vale-cli/vale@02fb6547) fix: switch on what every term of a chained scope needs - [`f011cb0`](vale-cli/vale@f011cb02) fix: keep 'scope: paragraph' out of headings, tables, lists, and blockquotes </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever MR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this MR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this MR, check this box --- This MR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yODguMCIsInVwZGF0ZWRJblZlciI6IjQzLjI4OC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJSZW5vdmF0ZSBCb3QiLCJhdXRvbWF0aW9uOmJvdC1hdXRob3JlZCIsImRlcGVuZGVuY3ktdHlwZTo6bWlub3IiXX0=-->
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What's broken
--globpanics on a pattern thatdoublestaraccepts andgobwas/globdoes not.The panic happens inside a goroutine partway through the walk, so it aborts the run with a stack trace rather than reporting a bad flag value.
After:
Same exit code, no stack trace.
Cause
NewGlobandMatchuse two different glob engines. Validation happens inNewGlobviadoublestar.PathMatch, but the actual matching inMatchcompiles the pattern withglob.MustCompile. The two grammars disagree on character ranges, so a pattern can pass construction and then panic on first use.MustCompilewas also being called once per candidate file, sinceMatchcompiled on every call.The fix
Compile in
NewGlobwithglob.Compileand store the result on the struct. An invalid pattern is now an error at construction, where the caller can report it, andMatchuses the already-compiled matcher.**patterns keep going throughdoublestar, which is what handled them before. Those leavecompilednil, andMatchbranches on that rather than re-testing the pattern string.Behaviour on valid patterns is unchanged. Same tree, before and after binaries, identical output for
*.md,**/*.md,!*.md,{*.md,*.txt},docs/**and*.Verification
TestInvalidGlobininternal/glob/glob_test.gocovers[a-]and[a-b-c], the range family where the two engines diverge.A
glob-invalidcase intestdata/e2e/config-flags.yaml, next to the existingglob-negated-dircase, pins the CLI behaviour end to end. Its golden was filled with the repo's owngo test ./internal/e2e -update, not by hand.Reverting
glob.gowhile keeping both fails them, and nothing else:go test ./internal/glob/... ./internal/e2e/...is green with the fix.golangci-lint run ./internal/glob/...reports 0 issues andgofmt -lis clean.Disclosure: written with AI assistance (Claude Code). I built both binaries from this tree, reproduced the panic and the fixed output with the commands above, checked the six real-world patterns for parity, and ran the revert check myself.