Affected: scripts/bash/common.sh:606, confirmed present at tag v0.11.9
(fetched from raw.githubusercontent.com/github/spec-kit/v0.11.9/scripts/bash/common.sh).
The wrap strategy substitutes the core content into the layer at each {CORE_TEMPLATE}
placeholder:
case "$layer_content" in
*'{CORE_TEMPLATE}'*) ;;
*) echo "Error: wrap strategy missing {CORE_TEMPLATE} placeholder" >&2; return 1 ;;
esac
while [[ "$layer_content" == *'{CORE_TEMPLATE}'* ]]; do
local before="${layer_content%%\{CORE_TEMPLATE\}*}"
local after="${layer_content#*\{CORE_TEMPLATE\}}"
layer_content="${before}${content}${after}"
done
The loop condition re-tests the string it just substituted into. If $content itself
contains the literal {CORE_TEMPLATE}, every iteration reintroduces the placeholder, the
condition never goes false, and layer_content grows by ${#content} each pass — an
unbounded loop that ends in memory exhaustion rather than an error message.
The guard above it does not cover this: it rejects a layer that is missing the
placeholder, and says nothing about the content being substituted in.
Suggested fix — scan left to right and never re-scan what was already substituted, which
also preserves the multi-placeholder behaviour the loop exists for:
out=""; rest="$layer_content"
while [[ "$rest" == *'{CORE_TEMPLATE}'* ]]; do
out="${out}${rest%%\{CORE_TEMPLATE\}*}${content}"
rest="${rest#*\{CORE_TEMPLATE\}}"
done
layer_content="${out}${rest}"
Reachability / why we are reporting rather than patching. Found while adopting a
Spec Kit-based plugin in a downstream repo. It is not reachable through that plugin: it
ships nothing that declares {CORE_TEMPLATE}, so $content never carries the placeholder
on that path (grep -rl CORE_TEMPLATE over the plugin returns nothing). It is reachable for
any consumer that authors a wrap template layer whose core content includes the literal
token — which is a normal thing to do by accident when a template documents its own
placeholder syntax.
Affected:
scripts/bash/common.sh:606, confirmed present at tagv0.11.9(fetched from
raw.githubusercontent.com/github/spec-kit/v0.11.9/scripts/bash/common.sh).The
wrapstrategy substitutes the core content into the layer at each{CORE_TEMPLATE}placeholder:
The loop condition re-tests the string it just substituted into. If
$contentitselfcontains the literal
{CORE_TEMPLATE}, every iteration reintroduces the placeholder, thecondition never goes false, and
layer_contentgrows by${#content}each pass — anunbounded loop that ends in memory exhaustion rather than an error message.
The guard above it does not cover this: it rejects a layer that is missing the
placeholder, and says nothing about the content being substituted in.
Suggested fix — scan left to right and never re-scan what was already substituted, which
also preserves the multi-placeholder behaviour the loop exists for:
Reachability / why we are reporting rather than patching. Found while adopting a
Spec Kit-based plugin in a downstream repo. It is not reachable through that plugin: it
ships nothing that declares
{CORE_TEMPLATE}, so$contentnever carries the placeholderon that path (
grep -rl CORE_TEMPLATEover the plugin returns nothing). It is reachable forany consumer that authors a
wraptemplate layer whose core content includes the literaltoken — which is a normal thing to do by accident when a template documents its own
placeholder syntax.