zjncs opened a new issue, #5613:
URL: https://github.com/apache/rocketmq-dashboard/issues/5613
## Description
`rmqctl/internal/catalog/generate/main.go` declares `var source []byte` at
line 302, but the single-file (`-input`) branch redeclares it with `:=` inside
the else block:
```go
var source []byte
var document catalogDocument
if inputDir != "" {
...
source = merged
...
} else {
source, err := os.ReadFile(inputPath) // := shadows the outer `source`
...
}
...
digest := sha256.Sum256(source) // outer source is nil in -input
mode
...
sdk, err := renderSDKContract(source) // nil again
```
So in `-input` mode the outer `source` stays nil and both consumers get the
zero value.
## Impact
Any run of `cataloggen -input ... -sdk ...` (both documented, tested flag
modes) bakes two lies into the generated artifacts:
- `Digest:
"e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855"` — **sha256
of the empty string, constant regardless of input**. The digest is a published
contract (explain metadata; catalog tests assert its shape).
- The SDK contract JSON file becomes literally `null\n`, silently destroying
the generated tools document.
- The Markdown output carries the same wrong SHA-256 line.
Live repro on master: `go run ./generate -input in.yaml -output
catalog_gen.go -sdk sdk.json` produced the empty-string digest while `sha256sum
in.yaml` differed, and `sdk.json` contained `null`.
The existing `main_test.go` exercises `-input` but never checks the digest
or passes `-sdk`, which is why this survived.
## Expected behavior
Assign to the outer variable so the digest and SDK rendering consume the
input actually read.
## Environment
- branch: master (0228dad5)
- file: `rmqctl/internal/catalog/generate/main.go` (~302-345)
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]