Skip to content

Refuse a leading U+FFFE in BOM-less UTF-16 - #351

Merged
Joncallim merged 1 commit into
masterfrom
review6-fffe-write
Oct 4, 2026
Merged

Joncallim merged 1 commit into
masterfrom
review6-fffe-write

Conversation

@Joncallim

Copy link
Copy Markdown
Owner

Summary

P3 from review pass 6 (found by encoding fuzz: 14 of 4,000 cases, all this shape). FileStore.encodedData refused a leading U+FEFF written without a BOM (it would be eaten as one on reopen) but not its mirror: a leading U+FFFE in BOM-less UTF-16 LE/BE is the byte pair FE FF / FF FE, i.e. the other byte order's BOM, which the reader rejects as a BOM/encoding mismatch. The save succeeded and the file then could not be reopened. The write is now refused (so the user is told, and nothing is written) unless a BOM is written; with a BOM it round-trips. encodedData moved to FileStore+EncodedData.swift (file-length limit; no behaviour change besides the new refusal).

Tests

BOM-less LE/BE refuse and write nothing; with an explicit BOM the text round-trips; fails on master; FileCore and Workspace suites pass.

🤖 Generated with Claude Code

🤖 Generated with Claude Code

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@Joncallim
Joncallim merged commit 80d3d07 into master Oct 4, 2026
3 checks passed
@Joncallim
Joncallim deleted the review6-fffe-write branch October 4, 2026 06:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant