Skip to content

t-7 FUZZ-038: no panic on non-UTF-8 request paths - #711

Merged
randlee merged 1 commit into
integrate/phase-tfrom
fix/t-7-fuzz-038-non-utf8-path-panic
Oct 8, 2026
Merged

randlee merged 1 commit into
integrate/phase-tfrom
fix/t-7-fuzz-038-non-utf8-path-panic

Conversation

@randlee

@randlee randlee commented Oct 7, 2026

Copy link
Copy Markdown
Owner

Fixes comp-t-7.13 (bf2987d -> 12f047e). Rebased by the stack writer onto the linear phase-t top. At the top: clippy -D warnings clean, cargo fmt clean, codespell clean, workspace tests 1062 passed, 0 failed.

🤖 Generated with Claude Code

@randlee
randlee added this pull request to stack #625 October 7, 2026 21:25
@randlee

randlee commented Oct 7, 2026

Copy link
Copy Markdown
Owner Author

QA fix verification: comp-t-7.13-qa (fuzz-038) at 12f047e

Verdict: PASS. 1 carried finding verified fixed.

Finding Disposition
fuzz-038 fixed

Verified by the filing reviewer (sc-adversarial-fuzz-coordinator) at the pinned commit, locked to this finding: the original reproducer now behaves per the oracle and the regression test is un-ignored and passes. Local fmt, clippy and test run on the worktree: clean, all passing.

Disclosures: CI was not checked (rate-limit rule). Verification ran against a fake-bd runner, not a real bd. The dev-sanity check passed at this head before QA.

Verifier notes: all six request-path subcommands (render, validate, preview-pour, pour, preview-attach, attach) now exit 3 with BEADS_REQUEST_READ_FAILED in human and JSON mode on a non-UTF-8 request path (one-line to_string_lossy change); the test builds the path from raw bytes, asserts the typed code and fails on HEAD~1 with exit 101 at error_json.rs:25. UTF-8 byte-identity was by inspection, not a byte diff against the baseline binary. Latent, not reachable from the CLI and not a finding of this round: error_json.rs line 29 (OutputPathInvalid) still serializes a raw PathBuf in json!, which would panic for a non-UTF-8 path built by a library caller; to_string_lossy there would harden it. The finding was hand-locked to the bead deliverables (fix-round-scope cannot read developer-filed findings, known tool gap).

@randlee
randlee removed this pull request from stack #625 October 8, 2026 00:45
Base automatically changed from fix/t-7-fuzz-042-missing-output-dir to integrate/phase-t October 8, 2026 01:10
@randlee
randlee merged commit 7403758 into integrate/phase-t Oct 8, 2026
21 checks passed
@randlee
randlee deleted the fix/t-7-fuzz-038-non-utf8-path-panic branch October 8, 2026 01:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant