Skip to content

Feat/aui.boot fix hashing#709

Merged
Alex2772 merged 10 commits intodevelopfrom
feat/aui.boot-fix-hashing
Apr 9, 2026
Merged

Feat/aui.boot fix hashing#709
Alex2772 merged 10 commits intodevelopfrom
feat/aui.boot-fix-hashing

Conversation

@Alex2772
Copy link
Copy Markdown
Collaborator

@Alex2772 Alex2772 commented Mar 5, 2026

Closes #708

@gemini-code-assist
Copy link
Copy Markdown

Summary of Changes

Hello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request refactors the handling of build specifiers within the aui.boot.cmake module to improve robustness and address potential issues related to path lengths and build consistency. It introduces a dedicated hash for build specifiers used in directory paths and adds a validation mechanism to ensure that imported modules match their expected build configurations. Additionally, a helpful solution for cache cleaning has been added to an existing error message.

Highlights

  • Refactored Build Specifier Hashing: The BUILD_SPECIFIER variable is now hashed into BUILD_SPECIFIER_HASH and used for path generation, addressing potential path length issues on Windows and improving consistency in build directories.
  • Introduced Build Specifier Validation: A new EXPECTED_BUILD_SPECIFIER argument and a validation check were added to the auib_import function to ensure consistency between expected and actual build configurations during module import.
  • Enhanced Error Message: The error message for non-portable precompiled packages now includes 'Clean CMake cache (build directory)' as a primary solution, providing clearer guidance to users.

🧠 New Feature in Public Preview: You can now enable Memory to help Gemini Code Assist learn from your team's feedback. This makes future code reviews more consistent and personalized to your project's style. Click here to enable Memory in your admin console.

Changelog
  • aui.boot.cmake
    • Updated the error message for non-portable precompiled packages to include 'Clean CMake cache' as a solution.
    • Added EXPECTED_BUILD_SPECIFIER as a recognized argument for the auib_import function.
    • Modified the build specifier logic to use BUILD_SPECIFIER_HASH for generating installation and binary directory paths.
    • Implemented a mechanism to write the original BUILD_SPECIFIER to a file within the installation prefix.
    • Introduced a fatal error check to validate the BUILD_SPECIFIER against an EXPECTED_BUILD_SPECIFIER during import.
    • Ensured that the EXPECTED_BUILD_SPECIFIER is passed along when forwarding import arguments.
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for Github and other Google products, sign up here.

You can also get AI-powered code generation, chat, as well as code reviews directly in the IDE at no cost with the Gemini Code Assist IDE Extension.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution.

Copy link
Copy Markdown

@gemini-code-assist gemini-code-assist bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request refactors the build specifier hashing logic in aui.boot.cmake, separating the build specifier string from its hash to improve clarity and robustness of the dependency management script. However, it introduces a potential CMake code injection vulnerability in aui.boot.cmake. The EXPECTED_BUILD_SPECIFIER argument is appended to a global property without proper escaping of double quotes, which could allow an attacker to inject arbitrary CMake code into the generated aui-config.cmake file, leading to arbitrary code execution. A fix is suggested to escape the double quotes. Additionally, a suggestion has been made to improve an error message for better user-friendliness.

@Alex2772 Alex2772 merged commit e2ebbab into develop Apr 9, 2026
106 of 107 checks passed
@Alex2772 Alex2772 deleted the feat/aui.boot-fix-hashing branch April 9, 2026 10:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant