Repository navigation
Commit 62b6da4
authored
fix: complete security, concurrency, architecture, and test hardening (rebased on flux) (#309)
* fix(security,concurrency,arch): complete the hardening pass
Security:
- validatePathAllowed now fails closed without a ToolContext; tests attach a
permissive test context.
- Delete the dead, bypassable BoundaryChecker (no production callers).
- Wrap MCP/remote tool output as untrusted external content.
- Bound HTTP clients in stt/media; safewrite uses crypto/rand + O_EXCL;
hooks URL validation now actually rejects loopback; plugin index reads are
capped.
Concurrency:
- jobs: snapshot cancel status under lock; guard nil Done.
- git context, spec tools, watcher: bounded exec timeouts.
- planning prompt: context-aware prompt + ctx timeout.
- watcher: bounded fireChange workers.
- filewatcher/cron: idempotent Stop (no double-close panic).
- event bus RunWaterfall: snapshot handlers under lock.
- AutoCommit errors logged; AssertWritable returns an error; SessionPreparations
load/wait honor a context.
Architecture:
- Move IsSensitivePath/ResolvePath into internal/pathsafe; drop config->tool.
- Consolidate byte-unsafe truncate copies onto textutil (rune-safe).
- Delete dead types.ChatClient and the dead markdown_renderer.
* test(ci): de-flake tests, raise spec coverage, and tighten gates
- Fix a real bug in spec extractDescription: the requirement body excludes
the header, so descriptions were always empty and every ADDED/MODIFIED
requirement failed SHALL/MUST validation.
- Add spec tests (parse/validate/apply/DAG/config) lifting coverage from
2.4% to 24.3%, plus a fuzz target and benchmarks.
- Make ContextDecay clock injectable; rewrite the timing-flaky decay tests
deterministically.
- Un-skip TestParallelExecution, TestIntegration_FullSessionFlow, and the two
config-apply tests; remove the blanket CI -skip.
- Golden test restores rootCmd globals; add make update-golden.
- Add testutil.Eventually/Never.
- CI: per-package coverage floors, FuzzParseDeltaSpec target, version fixture
aligned to 0.0.1.
* style: format with the CI-pinned gofumpt/goimports
* fix(spec): don't panic on invalid UTF-8 in requirement names
applyRename built a regexp with regexp.MustCompile from an unescaped
requirement name; a name containing invalid UTF-8 (or a bad pattern) panicked
the whole process. Use regexp.Compile and fall back to leaving the content
unchanged, and ReplaceAllLiteralString so $$ in the new name is not treated as
a group reference. Found by the new FuzzParseDeltaSpec target.1 parent 49baee5 commit 62b6da4
68 files changed
Lines changed: 1014 additions & 3217 deletions
File tree
- .github/workflows
- cmd
- internal
- config
- engine
- ctxmgr
- errs
- git
- io
- planning
- feature/eval
- hooks
- jobs
- multiagent
- parallel
- pathsafe
- permissions
- plugin
- safewrite
- session
- spec
- stt
- testutil
- textutil
- tool
- types
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
135 | 135 | | |
136 | 136 | | |
137 | 137 | | |
138 | | - | |
| 138 | + | |
139 | 139 | | |
140 | 140 | | |
141 | 141 | | |
| |||
159 | 159 | | |
160 | 160 | | |
161 | 161 | | |
162 | | - | |
| 162 | + | |
163 | 163 | | |
164 | 164 | | |
165 | 165 | | |
| |||
249 | 249 | | |
250 | 250 | | |
251 | 251 | | |
252 | | - | |
| 252 | + | |
253 | 253 | | |
254 | 254 | | |
255 | 255 | | |
| |||
261 | 261 | | |
262 | 262 | | |
263 | 263 | | |
| 264 | + | |
| 265 | + | |
| 266 | + | |
| 267 | + | |
| 268 | + | |
| 269 | + | |
| 270 | + | |
| 271 | + | |
| 272 | + | |
| 273 | + | |
| 274 | + | |
| 275 | + | |
| 276 | + | |
| 277 | + | |
| 278 | + | |
| 279 | + | |
| 280 | + | |
264 | 281 | | |
265 | 282 | | |
266 | 283 | | |
| |||
540 | 557 | | |
541 | 558 | | |
542 | 559 | | |
| 560 | + | |
543 | 561 | | |
544 | 562 | | |
545 | 563 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
100 | 100 | | |
101 | 101 | | |
102 | 102 | | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
103 | 106 | | |
104 | 107 | | |
105 | 108 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
225 | 225 | | |
226 | 226 | | |
227 | 227 | | |
228 | | - | |
229 | | - | |
230 | 228 | | |
231 | 229 | | |
232 | 230 | | |
| |||
254 | 252 | | |
255 | 253 | | |
256 | 254 | | |
257 | | - | |
258 | | - | |
259 | 255 | | |
260 | 256 | | |
261 | 257 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
12 | 12 | | |
13 | 13 | | |
14 | 14 | | |
15 | | - | |
| 15 | + | |
16 | 16 | | |
17 | 17 | | |
18 | 18 | | |
| |||
25 | 25 | | |
26 | 26 | | |
27 | 27 | | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
28 | 35 | | |
29 | 36 | | |
30 | 37 | | |
| |||
0 commit comments