Skip to content

Award expressions silently ignore extra operands #1341

Description

@gemshrine

Bug

The award calculator silently ignores extra operands for fixed-arity expressions. For example, plus, times, comparisons, and if read only their first two or three operands; they reject too few operands in some cases but never reject too many.

Steps to reproduce

  1. Build a bill from an award rule containing a fixed-arity expression with an extra operand, for example:

    (award (give (plus 1 2 100) "calculation"))
    
  2. Inspect the resulting bill.

Actual result

The bill is calculated as 3; the extra 100 is silently discarded. The same pattern applies to other fixed-arity expressions such as (times 2 3 100) and (if true 1 0 100).

Expected result

A malformed fixed-arity expression should fail with an arity error, rather than silently producing an amount based on only part of the written rule. This is especially important for award rules, where a typo can change the points paid without making the rule appear broken.

Evidence

lib/fbe/award.rb, Fbe::Award::BTerm#calc, indexes fixed-arity operands directly (for example to_val(@operands[0], bill) + to_val(@operands[1], bill)) and does not validate their total count. The if branch checks only @operands.size < 3, so operands after the third are also ignored. The query parser accepts the additional operands, and the custom award calculator handles these expressions itself.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions