Skip to content

t-7 FUZZ-040: shell-quote graph recovery commands - #713

Merged
randlee merged 105 commits into
integrate/phase-tfrom
fix/t-7-fuzz-040-recovery-quoting
Oct 8, 2026
Merged

randlee merged 105 commits into
integrate/phase-tfrom
fix/t-7-fuzz-040-recovery-quoting

Conversation

@randlee

@randlee randlee commented Oct 7, 2026

Copy link
Copy Markdown
Owner

Fixes comp-t-7.15 (f8fde08 -> 1f37cde). Rebased by the stack writer onto the linear phase-t top. At the top: clippy -D warnings clean, cargo fmt clean, codespell clean, workspace tests 1062 passed, 0 failed.

🤖 Generated with Claude Code

randlee added 30 commits October 7, 2026 06:49
randlee and others added 21 commits October 7, 2026 13:12
…accepts (FUZZ-013)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Re-ran the full four-worker campaign at the tested head d47d35e, whose
production trees are identical to 2e8f60b. Seeds were 7023 and a fresh
48611 (3508 cases, 3261 passed). This covers the six previously
unfuzzed commits c77838a, ba13841, cfef41c, 036ecda, d2dd10b and
2e8f60b.

- qa1-f1: new report 20261007-2 (JSON, four panels, HTML). It records
  the tested head and a rev-parse of each production tree.
- f3: itemises the nine run-1 R5 mismatches and all 52 run-2
  mismatches, each with a finding id. FUZZ-024 and FUZZ-031 are ruled
  intentional, citing the exact ADR-0021/ADR-0023 text.
- f5: adds a dedicated concurrent render --append family to the
  differential envelope. All 20 trials pass with no torn, lost or
  duplicate lines.
- f6: next_owner for FUZZ-012..020 is now the owning crate and file.
- f7: html-validate 11.16.2 and xmllint results are recorded in the
  report.

FUZZ-012..020 still reproduce. New confirmed bugs FUZZ-038..043 are
listed for filing and were not promoted.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@randlee
randlee added this pull request to stack #625 October 7, 2026 21:25
@randlee

randlee commented Oct 7, 2026

Copy link
Copy Markdown
Owner Author

QA fix verification: comp-t-7.15-qa (FUZZ-040) at 1f37cde

Verdict: FAIL. 1 carried finding still open.

Finding Disposition
fuzz-040 open (partial fix)

Fixed: the original repro. Ids are single-quoted, so $(id) and ; no longer execute; an embedded ' is handled; normal ids stay valid shell (now quoted, so not byte-identical to before; expectations were updated).

Still wrong:

  • Control characters go in $'...' using str::escape_default, which emits \u{7}. Bash does not parse that: printf '%s' $'a\u{7}b' prints the literal a\u{7}b, so the pasted argument is not the real id (reproduced by quality-mgr and the coordinator).
  • Bidi override/isolate characters (U+202E, U+2066, ...) are category Cf, not Cc, so char::is_control is false and they reach the terminal raw. The finding says they must be escaped (read from the code; no bidi input was run).
  • The regression test only unit-tests shell_quote on two strings. It never drives missing_edge_commands or the CLI text path with a hostile id, and has no bidi case.

Round 2 poured as comp-t-7.fuzz-040-r2-fix / -sanity / -qa.

Disclosures: CI not checked (rate-limit rule). Verified by the fuzz coordinator with no real bd. The finding is developer-filed, so the verifier was hand-locked to the bead deliverables (fix-round-scope cannot read it, known tool gap). The test was not run against the baseline (it calls shell_quote, which does not exist there).

…ph test

FUZZ-040 (1f37cde) shell-quotes every bd dep add recovery argument; the
real-bd graph test still expected the unquoted form and failed in CI.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@randlee
randlee removed this pull request from stack #625 October 8, 2026 00:45
@randlee
randlee changed the base branch from fix/t-7-fuzz-043-json-depth to integrate/phase-t October 8, 2026 00:49
@randlee
randlee added this pull request to stack #739 October 8, 2026 01:15
@randlee
randlee merged commit 19e4cb0 into integrate/phase-t Oct 8, 2026
21 checks passed
@randlee
randlee deleted the fix/t-7-fuzz-040-recovery-quoting branch October 8, 2026 01:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant