{"record":{"id":"5bcfb667ccbff5ac","repo":"ruvnet/ruflo","slug":"invalid-container-name-containername","errorCode":null,"errorMessage":"Invalid container name: ${containerName}","messagePattern":"Invalid container name: (.+?)","errorType":"validation","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"v3/@claude-flow/cli/src/commands/ruvector/import.ts","lineNumber":362,"sourceCode":"      output.writeln();\n\n      // Write to temp file for execution\n      const tempFile = path.join(process.cwd(), '.ruvector-import-temp.sql');\n      try {\n        fs.writeFileSync(tempFile, fullSQL);\n\n        output.printInfo('Executing import...');\n        output.writeln();\n        output.writeln(output.dim('Command:'));\n        output.writeln(output.dim(`  docker exec -i ${containerName} psql -U claude -d claude_flow < ${tempFile}`));\n        output.writeln();\n\n        // Execute via child_process (CRIT-02: use execFileSync to prevent command injection)\n        const { execFileSync } = await import('child_process');\n\n        // Validate containerName: alphanumeric, hyphens, underscores, dots only\n        if (!/^[a-zA-Z0-9][a-zA-Z0-9_.-]*$/.test(containerName)) {\n          throw new Error(`Invalid container name: ${containerName}`);\n        }\n\n        try {\n          const sqlContent = fs.readFileSync(tempFile, 'utf-8');\n          const result = execFileSync('docker', [\n            'exec', '-i', containerName,\n            'psql', '-U', 'claude', '-d', 'claude_flow',\n          ], {\n            encoding: 'utf-8',\n            timeout: 60000,\n            input: sqlContent,\n          });\n\n          if (verbose) {\n            output.writeln(output.dim(result));\n          }\n\n          output.printSuccess('Import completed successfully!');","sourceCodeStart":344,"sourceCodeEnd":380,"githubUrl":"https://github.com/ruvnet/ruflo/blob/fa13ee4ad60ac2090b1480656eb233521790d640/v3/@claude-flow/cli/src/commands/ruvector/import.ts#L344-L380","documentation":"Before execFileSync('docker', ['exec', '-i', <name>, 'psql', ...]) runs the SQL import, the ruvector import command validates the container name against ^[a-zA-Z0-9][a-zA-Z0-9_.-]*$ (CRIT-02 command-injection hardening). Slashes, colons, spaces, or a leading non-alphanumeric are rejected.","triggerScenarios":"Passing an image reference like postgres:16 instead of a running container name, a registry path registry.io/app/db (slashes), or a name beginning with . or -.","commonSituations":"Confusing container name with image name; copy-pasting compose service definitions that use colons; assuming Docker's relaxed naming rules match the CLI's stricter subset.","solutions":["List actual containers: docker ps --format '{{.Names}}' and pass one of those names","Restrict to alphanumerics, underscore, dot, dash, starting with an alphanumeric character","If the container is unnamed, restart it with --name claude-flow-pg and use that"],"exampleFix":"# before\nruflo ruvector import --container postgres:16 ...\n\n# after\ndocker ps --format '{{.Names}}'   # pick e.g. claude-flow-pg\nruflo ruvector import --container claude-flow-pg ...","handlingStrategy":"validation","validationCode":"const CONTAINER_RE = /^[a-zA-Z0-9][a-zA-Z0-9_.-]*$/;\nif (!CONTAINER_RE.test(containerName)) {\n  throw new Error(`'${containerName}' is not a container name — run: docker ps --format '{{.Names}}'`);\n}\nawait runImport(containerName);","typeGuard":"function isValidContainerName(v: unknown): v is string {\n  return typeof v === 'string' && /^[a-zA-Z0-9][a-zA-Z0-9_.-]*$/.test(v);\n}","tryCatchPattern":null,"preventionTips":["Always source container names from docker ps output, never from image tags","Name your containers explicitly (--name) at startup so the value is known-good","Remember the regex rejects leading dots/dashes and any colon or slash"],"tags":["cli","docker","container-name","command-injection","validation"],"backgroundTag":"invalid-container-name","analyzedSha":"fa13ee4ad60ac2090b1480656eb233521790d640","analyzedAt":"2026-08-18T21:34:22.708Z","contentChangedAt":"2026-08-18T21:34:22.708Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}