From 4f5c603f415b8c623caa2539bd6bf5c1e7c49794 Mon Sep 17 00:00:00 2001 From: elhoim Date: Thu, 24 Sep 2026 11:23:02 +0000 Subject: [PATCH] Honour -o for backends returning dict results The dict branch of the single-output conversion called click.echo() without the output file, so the JSON went to stdout and the file given with --output/-o was never written, although the command exited 0. Pass the output file like all other result types do. Co-Authored-By: Claude Opus 5.5 (1M context) --- sigma/cli/convert.py | 2 +- tests/test_convert.py | 22 ++++++++++++++++++++++ 2 files changed, 23 insertions(+), 1 deletion(-) diff --git a/sigma/cli/convert.py b/sigma/cli/convert.py index 0e0172c..2333a44 100644 --- a/sigma/cli/convert.py +++ b/sigma/cli/convert.py @@ -582,7 +582,7 @@ def convert( output, ) elif isinstance(result, dict): - click.echo(bytes(json.dumps(result, indent=json_indent), encoding)) + click.echo(bytes(json.dumps(result, indent=json_indent), encoding), output) else: raise click.ClickException( f"Backend returned unexpected format {str(type(result))}" diff --git a/tests/test_convert.py b/tests/test_convert.py index a39794e..8123354 100644 --- a/tests/test_convert.py +++ b/tests/test_convert.py @@ -1,3 +1,5 @@ +import json + from click.testing import CliRunner import pytest from sigma.cli.convert import convert @@ -127,6 +129,26 @@ def test_convert_output_bytes(tmp_path): assert "ParentImage" in open(test_file, "r").read() +def test_convert_output_dict_to_file(tmp_path, monkeypatch): + """A backend returning a dict must honour --output/-o like all other result types.""" + monkeypatch.setattr( + sigma.backends.test.backend.TextQueryTestBackend, + "convert", + lambda self, rule_collection, output_format=None, correlation_method=None, callback=None: { + "queries": ["ParentImage"] + }, + ) + cli = CliRunner() + test_file = tmp_path / "test.json" + result = cli.invoke( + convert, + ["-t", "text_query_test", "-o", str(test_file), "tests/files/valid"], + ) + assert result.exit_code == 0 + assert "queries" not in result.stdout + assert json.loads(test_file.read_text()) == {"queries": ["ParentImage"]} + + def test_convert_unknown_backend(): cli = CliRunner() result = cli.invoke(